Affirmative defense for a breach of system security.

Utah Code § 78B-4-702, under Part 78B-4-7: Cybersecurity Affirmative Defense Act.

Utah Code § 78B-4-702

78B-4-702. Affirmative defense for a breach of system security.

(1) A person that creates, maintains, and reasonably complies with a written cybersecurity program that meets the requirements of Subsection, and is in place at the time of a breach of system security of the person, has an affirmative defense to a claim that: (4) is brought under the laws of this state or in the courts of this state; and alleges that the person failed to implement reasonable information security controls that resulted in the breach of system security.

(2) A person has an affirmative defense to a claim that the person failed to appropriately respond to a breach of system security if: the person creates, maintains, and reasonably complies with a written cybersecurity program that meets the requirements of Subsectionand is in place at the time of the breach of system security; and (4) the written cybersecurity program had protocols at the time of the breach of system security for responding to a breach of system security that reasonably complied with the written cybersecurity program under Subsectionand the person followed the protocols. (2)(a)

(3) A person has an affirmative defense to a claim that the person failed to appropriately notify an individual whose personal information was compromised in a breach of system security if: the person creates, maintains, and reasonably complies with a written cybersecurity program that meets the requirements of Subsectionand is in place at the time of the breach of system security; and (4) the written cybersecurity program had protocols at the time of the breach of system security for notifying an individual about a breach of system security that reasonably complied with the requirements for a written cybersecurity program under Subsectionand the person followed the protocols. (3)(a)

(4) A written cybersecurity program described in Subsections,, andshall provide administrative, technical, and physical safeguards to protect personal information, including: (1) (2) (3) being designed to: protect the security, confidentiality, and integrity of personal information; protect against any anticipated threat or hazard to the security, confidentiality, or integrity of personal information; and protect against a breach of system security; reasonably conforming to a recognized cybersecurity framework as described in Subsection; and 78B-4-703(1) being of an appropriate scale and scope in light of the following factors: the size and complexity of the person; the nature and scope of the activities of the person; the sensitivity of the information to be protected; the cost and availability of tools to improve information security and reduce vulnerability; and the resources available to the person.

(5) Subject to Subsection, a person may not claim an affirmative defense under Subsection,, orif: (5)(b) (1) (2) (3) the person had actual notice of a threat or hazard to the security, confidentiality, or integrity of personal information; the person did not act in a reasonable amount of time to take known remedial efforts to protect the personal information against the threat or hazard; and the threat or hazard resulted in the breach of system security. A risk assessment to improve the security, confidentiality, or integrity of personal information is not an actual notice of a threat or hazard to the security, confidentiality, or integrity of personal information.