Delaware's product-security and baseline-security posture rests on one enacted state statute standing outside a comprehensive regime: Del. Code Ann. tit. 6, section 12B-100, part of the Computer Security Breaches chapter and added by 81 Del. Laws, c. 129, section 1 (approved August 17, 2017, effective April 14, 2018, 240 days after enactment), which requires any person who conducts business in Delaware and owns, licenses, or maintains personal information to implement and maintain reasonable procedures and practices to prevent the unauthorized acquisition, use, modification, disclosure, or destruction of that personal information collected or maintained in the regular course of business.
The chapter's own definition of 'person' at section 12B-101(6) reaches a government or governmental subdivision as well as a private actor, so the duty binds both. No enacted Delaware statute sets security requirements a connected device or software product must meet before or after it reaches the market, and no such bill was located pending before the General Assembly, so this is a researched absence rather than a gap in coverage.
Delaware has no general private-sector duty to report an exploited vulnerability or a security incident, as distinct from a personal-data breach, to a state authority.
The one sector-specific cyber-resilience regime located, the Delaware Insurance Data Security Act, Del. Code Ann. tit. 18, ch. 86 (82 Del. Laws, c. 176, section 1), requires an insurer domiciled in Delaware or a producer whose home state is Delaware, a 'licensee,' to maintain an information security program, adopt a written incident response plan, investigate a cybersecurity event, notify the Insurance Commissioner within 3 business days of determining one occurred, notify affected consumers within 60 days, and certify compliance to the Commissioner annually by February 15.
Because its bound party, an insurance licensee, is a role the LexLint activity vocabulary cannot yet express, it is deferred rather than flagged on a guess (#6740), and no instrument for it is filed here.
Section 12B-104 gives the Attorney General, through the Director of Consumer Protection of the Department of Justice under Title 29, Chapter 25, authority to bring an action in law or equity to address a violation of the chapter and to recover direct economic damages, or both; the chapter's own text neither grants nor expressly disclaims a private right of action for a violation of section 12B-100, and no published enforcement record specific to the safeguards duty, as against the chapter's breach-notice half, was located.
Delaware's breach-notification duty, Del. Code Ann. tit. 6, sections 12B-101 to 12B-104, the other half of the same chapter, is already this jurisdiction's privacy row rather than repeated here; it requires notice to an affected Delaware resident without unreasonable delay and no later than 60 days after determination of a breach, and notice to the Attorney General where more than 500 residents are affected.
The Delaware Personal Data Privacy Act's own security-of-processing duty, Del. Code Ann. tit. 6, section 12D-106(a)(3), requiring a controller to establish, implement, and maintain reasonable administrative, technical, and physical data security practices, is that comprehensive regime's own security clause and stays with this jurisdiction's privacy row rather than being split out here, the same rule the corpus applies to General Data Protection Regulation (GDPR) Article 32.
Delaware's computer crime statute, Del. Code tit. 11, sections 932, 939, 941, is an offense committed against a system by an intruder and belongs to this jurisdiction's scraping row rather than this one; a computer-misuse offense alone is not a security-topic presence.