
You Got Hacked. You Got Sued. Utah Says You Might Walk Away. Here's How.
There's a law on the books in Utah that most business owners have never heard of. It could be the difference between surviving a data breach and losing everything.
Picture this.
It's a Tuesday morning in North Logan, Utah. Gus Torquemada walks into his glass-walled office above the production floor at Gravitron Dynamics, coffee in one hand, phone in the other. He stops cold. Every screen is flashing the same message: a ransomware demand, denominated in Bitcoin, with a 72-hour countdown timer ticking like a bomb.
Gus is the IT director at Gravitron, a 250-person amusement ride manufacturer that builds roller coasters and tower rides for parks across 30 countries. He's also the procurement manager, the unofficial facilities guy, and the only person in the building who truly understands how the network works. He built most of it himself.
In the span of minutes, the ransomware encrypted everything. The proprietary simulation engine that the engineering team uses to design rides carrying thousands of people daily. The procurement system tracking 17,000 unique parts. Customer records. Project files for eight active installations across three continents. The CFO couldn't run payroll. The CEO couldn't pull safety specifications. Three multimillion-dollar projects ground to a halt before anyone had finished their first cup of coffee.
Then it got worse.
Within a week, a customer whose personal information was exposed in the breach filed a lawsuit against Gravitron. The claim: the company failed to protect their data, and they wanted damages.
Gravitron's story isn't unusual. Utah logged 6,877 cyber-crime complaints in 2024, with businesses and residents losing $129.4 million to online fraud, according to the FBI's IC3 Annual Report. That's a new incident roughly every 76 minutes. Small and mid-size companies without dedicated security teams are hit hardest, often discovering a breach only after the damage is done.
Now here's where the story takes a turn that almost nobody sees coming. Gravitron had something most companies don't: a written cybersecurity program. Gus, for all his one-man-band chaos, had documented the whole thing. He'd trained the staff. He'd aligned it with a recognized security framework. And under Utah's Cybersecurity Affirmative Defense Act, that piece of paper became the single most valuable asset in the building, worth more than every roller coaster on the production floor combined.
What Is the Utah Cybersecurity Affirmative Defense Act?
Utah Code §78B-4-702, part of the Cybersecurity Affirmative Defense Act (originally HB 80), has been on the books since May 2021. Utah was the second state in the country to pass this kind of law, following Ohio's Data Protection Act in 2018. Since then, Connecticut, Iowa, Tennessee, Oklahoma, and Texas have followed suit. Almost nobody talks about it. That's a mistake.
The premise is simple: if your business has a written cybersecurity program that follows a recognized framework, and you were actually following it when a data breach happened, you can raise that as a legal defense in court.
The legal term is "affirmative defense." Don't let the jargon scare you. It doesn't make lawsuits disappear. It doesn't mean you can't be sued. What it means is that you can stand in front of a judge, point to your cybersecurity program, and say: "We did what responsible people do. We had a plan. We followed it. Here's the proof."
In a world where the average data breach costs small businesses over $3 million, that's not just legal protection. That's survival.
What Types of Data Breach Lawsuits Does This Law Defend Against?
When a breach hits, the lawsuits that follow almost always take one of three forms. Utah's cybersecurity safe harbor law gives you a defense against every one.
"Your security wasn't good enough." The most common claim. The company didn't put reasonable controls in place, and that failure opened the door for hackers. If you had a written cybersecurity program that met the law's requirements and you were following it? Defense.
"You botched the response." This one comes after the dust settles. The accusation is that you knew about the breach and handled it poorly. If your written program included incident response protocols and you actually followed them? Defense.
"You didn't warn the people whose data was stolen." Notification matters, legally and morally. If your cybersecurity program included notification procedures and you executed them within the required window? Defense.
At Gravitron, Gus had all three bases covered. His incident response playbook kicked in within the first hour. Affected customers were notified on schedule. The lawsuit didn't vanish overnight, but the affirmative defense held. The company lived to build another coaster.
What Qualifies as a Written Cybersecurity Program Under Utah Law?
Here's where most business owners check out. They hear "written cybersecurity program" and picture a 400-page binder that costs six figures to produce and requires a dedicated security team to maintain.
Forget all that.
Yes, it has to be written down. It can't live in somebody's head. It can't be "well, Gus knows what to do." Documentation is non-negotiable.
Yes, it needs administrative, technical, and physical safeguards. That sounds intimidating until you realize it means things like password policies (administrative), firewalls and encryption (technical), and locked server rooms (physical). Your company already does some of this. The law just wants you to write it down and follow a recognized cybersecurity framework.
The law names several approved frameworks. You only need to follow one:
NIST SP 800-171 or 800-53 are the federal government's playbooks for protecting sensitive information. Think of them as building codes for your digital infrastructure.
CIS Critical Security Controls is widely considered the most practical, approachable framework for small and mid-size businesses. If you're looking for a starting point, this is a strong one.
ISO/IEC 27001 is the international standard for information security management, more common in companies doing business overseas or in regulated industries.
HIPAA and HITECH apply if you touch health data. PCI DSS applies if you process credit cards. GLBA covers financial institutions.
Here's the part that matters most: the law explicitly says your program should be scaled to fit your business. Your size. Your complexity. The sensitivity of the data you hold. The resources you can realistically commit. A 40-person accounting firm in Murray is not held to the same standard as a defense contractor. The Utah Cybersecurity Affirmative Defense Act was built with businesses like yours in mind.
How Does the "Reasonably Complies" Standard Work?
Read the statute carefully and you'll notice something critical. It never says "perfectly complies." It says "reasonably complies." That word shows up throughout the text, and it's doing more heavy lifting than anything else in the entire law.
You don't need a flawless security program. Perfection isn't the standard. Evidence is. Did you write it down? Did you train your people? Did you test your defenses? Did you update the program when things changed? Did you make a genuine, documented effort to protect the information your customers trusted you with?
If the answer is yes, and you can prove it, you're in a strong position.
Industry estimates suggest that spending less than $10,000 on a third-party cybersecurity audit and a five-year plan can bring most small businesses into compliance. Compare that to the $3.3 million average cost of a data breach for companies with fewer than 500 employees, and the math speaks for itself.
A 30-person marketing agency and a 250-person ride manufacturer won't have identical programs. The law doesn't expect them to. It only asks whether each company did what was reasonable for its situation. The bar isn't perfection. The bar is: did you give a damn, and can you prove it?
What Can Disqualify You From the Affirmative Defense?
There's a catch. And it's a fair one.
If you had actual notice of a specific threat to your systems, sat on it, didn't act in a reasonable amount of time, and that exact threat caused the breach? The defense disappears. You can't know your front door is unlocked, shrug, go to bed, and then claim you took security seriously when someone walks in.
But here's the nuance that makes this law genuinely smart: a risk assessment that finds problems is not considered "actual notice" of a threat. The law explicitly protects you for doing audits, discovering gaps, and working to close them. If you hire a security firm to test your defenses and they find vulnerabilities (which they will, because that's the whole point), the act of looking for weaknesses doesn't trigger the exception.
Ignoring a known, specific threat for months? That triggers it.
The distinction is everything. This law wants you to look for problems. It only punishes you for finding them and walking away.
What Does the Utah Cybersecurity Affirmative Defense Act Mean for My Business?
This law has been sitting quietly on the books for nearly five years. Most Utah business owners have no idea it exists, which means they're leaving one of the most powerful legal protections available to them completely on the table.
Think about what happened at Gravitron. The ransomware was going to hit no matter what. No security program on earth stops every attack. But here's what the written cybersecurity program did stop: it stopped the lawsuit from becoming a death sentence. The breach cost Gravitron time, money, and more than a few sleepless nights. Without the affirmative defense, it could have cost them the entire company.
Now flip it around. What does a written cybersecurity program cost? A fraction of what you'd spend on a single lawsuit. A fraction of what you'd lose in a single week of downtime. A fraction of what it costs to tell your customers you lost their data and you weren't even trying to protect it.
Utah is telling business owners something extraordinary: do the work, and we'll help protect you when things go wrong. That's not a vague promise. It's a statute. It's on the books. And it's waiting for you to use it.
What Should You Do Right Now?
If you don't have a written cybersecurity program, get one. Not next quarter. Not after the next board meeting. Now.
If you have one but you're not sure it lines up with a recognized framework, get it reviewed. If it's been collecting dust in a drawer since 2022, crack it open and bring it current. The law gives you one year to conform to framework updates after they're published, so "we'll get to it eventually" has an expiration date.
Gus had his program documented before the ransomware hit the Drop Tower. That documentation didn't stop the attack. Nothing could have. But it stopped the lawsuit from destroying the company he'd spent a decade building alongside Eleanor, Scrouge, and the rest of the Gravitron team.
The best time to build your defense was May 2021, when this law took effect. The second best time is this week.
Summit Technology helps businesses in Salt Lake City and across Utah build and maintain cybersecurity programs that qualify for protection under the Utah Cybersecurity Affirmative Defense Act. If you're not sure where your company stands, let's talk.
Source: Utah Code §78B-4-701 through §78B-4-706, Cybersecurity Affirmative Defense Act, enacted May 5, 2021 (full text)
Frequently Asked Questions
What is the Utah Cybersecurity Affirmative Defense Act? The Utah Cybersecurity Affirmative Defense Act (Utah Code §78B-4-701 through §78B-4-706) is a state law enacted in May 2021 that provides businesses with a legal defense against data breach lawsuits. If a company maintains a written cybersecurity program that reasonably conforms to a recognized framework like NIST, CIS Controls, or ISO 27001, and was following that program at the time of a breach, the company can raise that as an affirmative defense in court.
Does the Utah cybersecurity safe harbor law apply to small businesses? Yes. The law explicitly states that a cybersecurity program should be scaled to the size and complexity of the business, the sensitivity of the data it holds, and the resources available to it. A 30-person company is not held to the same standard as a Fortune 500 corporation. The law was designed to protect businesses of all sizes, including small and mid-size companies in Utah.
What cybersecurity frameworks qualify under Utah's affirmative defense law? The law recognizes several frameworks including NIST SP 800-171, NIST SP 800-53, the CIS Critical Security Controls, ISO/IEC 27001, FedRAMP, HIPAA, HITECH, PCI DSS, and GLBA. A business only needs to reasonably conform to one recognized framework (or a combination) to qualify for the defense.
How much does it cost to create a qualifying cybersecurity program? For most small businesses, the cost of a third-party cybersecurity audit and a written cybersecurity plan is estimated at under $10,000. Compare that to the average data breach cost for companies with fewer than 500 employees, which exceeds $3 million, and the investment becomes one of the highest-return decisions a business owner can make.
Can I lose the affirmative defense even if I have a written cybersecurity program? Yes. If you had actual notice of a specific threat to your systems, failed to act in a reasonable time to fix it, and that specific threat caused the breach, the defense does not apply. However, the law explicitly states that a risk assessment identifying potential issues is not considered "actual notice" of a threat. The law protects businesses that proactively audit and improve their security.
Is Utah the only state with a cybersecurity safe harbor law? No. Ohio was the first state to pass cybersecurity safe harbor legislation in 2018. Utah followed in 2021, and since then Connecticut, Iowa, Tennessee, Oklahoma, and Texas have enacted similar laws. More than 15 additional states had cybersecurity safe harbor bills under consideration as of 2025, indicating a strong national trend toward rewarding businesses that invest in cybersecurity.