Missouri § 375.1407 - Cybersecurity event investigation, procedures.

Full text of Missouri Revised Statutes of Missouri § 375.1407 — Cybersecurity event investigation, procedures., with citation guidance and answers to common questions.

§ 375.1407. Cybersecurity event investigation, procedures.

1.  If the licensee learns that a cybersecurity event has or may have occurred, the licensee, or an outside vendor or service provider designated to act on behalf of the licensee, shall conduct a prompt investigation.

2.  During the investigation, the licensee, or an outside vendor or service provider designated to act on behalf of the licensee, shall, at a minimum, determine as much of the following information as practicable:

(1)  Determine whether a cybersecurity event has occurred;

(2)  Assess the nature and scope of the cybersecurity event;

(3)  Identify any nonpublic information that may have been involved in the cybersecurity event; and

(4)  Perform or oversee reasonable measures to restore the security of the information systems compromised in the cybersecurity event in order to prevent further unauthorized acquisition, release, or use of nonpublic information in the licensee's possession, custody, or control.

3.  If the licensee learns that a cybersecurity event has or may have occurred in a system maintained by a third-party service provider, the licensee shall complete the steps listed in subsection 2 of this section or confirm and document that the third-party service provider has completed those steps.

4.  The licensee shall maintain records concerning all cybersecurity events for a period of at least three years from the date of the cybersecurity event and shall produce those records upon demand of the director.

­­--------

(L. 2025 H.B. 974, et al.)

Effective 1-01-26; see § 375.1427

---- end of effective  01 Jan 2026 ----

use this link to bookmark section  375.1407

Source: official Missouri text · Last verified 2026-08-27

Frequently Asked Questions About Missouri § 375.1407

What does Revised Statutes of Missouri § 375.1407 cover?

Section 375.1407 ("Cybersecurity event investigation, procedures.") is part of the Revised Statutes of Missouri, the codified statutory law of Missouri. It sets out the legal rule or procedure described in the text above. Statutes are amended regularly, so always verify against the official source.

How do I cite Missouri § 375.1407?

A common citation format is "Revised Statutes of Missouri § 375.1407" (Missouri). Legal writing may require the code abbreviation, section number, and year or edition. Match the style required by your court, professor, or publisher.

Is this the official text of Missouri law?

No. This page is for research and education and may not include the most recent amendments. For official current law, check the Missouri official source linked on this page or consult a licensed Missouri attorney.

How does Missouri § 375.1407 apply to my situation?

Statutes are interpreted in context, and application depends on your specific facts. Only a licensed attorney in Missouri can advise on how this section applies to you. Contact your state or local bar association for a referral.

Sources & Verification

Not legal advice. Verify against the official source and consult a licensed attorney in Missouri.