Oregon binds a private-sector manufacturer of an Internet-connected consumer device to a market-entry security duty at ORS 646A.813 (2019 c.193, House Bill 2395-A), which requires a manufacturer that sells or offers to sell a connected device, a physical object connected directly or indirectly to the Internet and used primarily for personal, family or household purposes, in the state to equip it with reasonable security features: a unique preprogrammed authentication credential or a requirement that the user set new credentials before first use, or compliance with an applicable federal security requirement.
The section reaches only the manufacturer of the physical device itself, expressly disclaiming any duty over software, firmware or peripheral devices that another manufacturer makes and a consumer later adds, so it does not by itself reach a developer who ships only an app or other software with no connected device of its own, and it exempts a device already regulated under Health Insurance Portability and Accountability Act (HIPAA) or under the Food and Drug Administration's medical-device rules.
A violation is declared an unlawful trade practice under ORS 646.607, enforceable by the Attorney General or a district attorney by injunction under ORS 646.632 and by a civil penalty of up to $25,000 per willful violation under ORS 646.642(3); Oregon's general private right of action for unlawful trade practices, ORS 646.638, reaches only a practice declared unlawful under the separate ORS 646.608, so the connected-device duty carries no private remedy of its own.
Separately, the Oregon Consumer Information Protection Act's safeguards provision, ORS 646A.622 (originally 2007 c.759, most recently amended 2019 c.180), requires a covered entity, a person who owns, licenses, maintains, stores, manages, collects, processes, acquires or otherwise possesses an Oregon consumer's personal information in the course of business, vocation, occupation or volunteer activity, including a public body, and a vendor that holds that information on a covered entity's behalf, to develop, implement and maintain reasonable administrative, technical and physical safeguards; a covered entity or vendor complies either by already being regulated under Gramm-Leach-Bliley Act Title V, HIPAA and HITECH, or another law providing greater protection, or by running an information security program with the administrative, technical and physical elements the statute lists, and a small business may scale its program to its own size and the sensitivity of the information it holds.
The Director of the Department of Consumer and Business Services enforces the safeguards duty by investigation, subpoena and a cease-and-desist or consumer-compensation order, with a civil penalty of up to $1,000 per violation capped at $500,000 for any one occurrence; the sections name no private right of action of their own.
No Oregon statute requiring a private business to report an exploited vulnerability or a security incident to an authority, a CSIRT or users is described here; none was located in the sources checked.
No state-specific sector cyber-resilience regime, a financial-services or insurance information-security regulation binding a class of regulated entity, is described here either; Oregon's insurance trade-practices chapter, ORS 746, returned no match for an information-security or cybersecurity program duty on a compliant and two browser-rendered reads, but the rest of Oregon's insurance and financial-services statutes were not read, so their silence or content on the point is not established here.
Oregon's breach-of-security notice duty, ORS 646A.604, is part of the same Oregon Consumer Information Protection Act as the safeguards provision above but is already this jurisdiction's privacy row and is not repeated here.