
Florida security scanning laws require an MSP to examine both access and knowledge that the access or manner of use is unauthorized. The security-operations exception in § 815.06(7)(c) specifies authorized operations; being a security company is not a substitute for that condition.
Evidence before outreach · Part 8: Florida. Research date: October 6, 2026. Preliminary statutory analysis, not legal advice or clearance. Relevant decisions, other claims and application to actual methods remain unresolved.
- Florida security scanning laws include a broad access definition and an express knowledge element in § 815.06(2)(a).
- The security-operations exception concerns authorized operations, not every security-related business activity.
- The civil remedy in § 815.06(5) identifies an action against a person convicted under the section.
- SCOUTz prospect intelligence distinguishes indexed public evidence from authorized Microsoft 365 review.
- An objection changes the facts that the assessment team must evaluate.
Why does knowledge of the permission boundary matter?
A direct request to a public service and a request made after a clear objection can present different facts. Florida's knowledge language makes the record of permission, restrictions and communications particularly relevant.
Keep that record before a dispute occurs. A generic description such as read-only cannot establish what the team knew about the permission for a particular request.
What should MSPs review under Florida security scanning laws?
The official Florida Computer Crimes Act, consulted October 6, 2026, supplies the starting point. Section 815.03(1) defines access to include approaching, instructing, communicating with, storing data in, retrieving data from or otherwise using computer resources.
Section 815.06(2)(a) begins with willful, knowing conduct without authorization or exceeding authorization. Paragraph (a) addresses access with knowledge that it is unauthorized or that the manner of use exceeds authorization.
Do not quote the broad definition without the offense elements. Nor should an MSP assume those elements are irrelevant because the service was reachable from the internet.
| Provision | Statutory distinction | Practical question |
|---|---|---|
| § 815.03(1) | Broad access definition | Which resources did the request communicate with or use? |
| § 815.06(2)(a) | Unauthorized access and knowledge | What did the operator know about permission and limits? |
| § 815.06(2)(b) | Disruption or denial of transmission ability | Did the conduct interfere with an authorized user? |
| § 815.06(7)(c) | Authorized security operations | What specifically authorized the operation? |
| § 815.06(5)(a)–(b) | Conviction-linked civil remedy | Has the identified statutory predicate been met? |
The table organizes the statutory questions. It is not a rating of permitted collection methods.
What should the request and permission records show?
An existing third-party index can provide an observation without a new verification request to the indexed resource. Published DNS queries involve a different service interaction. Live web requests, port enumeration and testing create other facts.
For every collector, record the source, request destination and information sought. Separately retain the evidence supporting permitted use and any notice changing that understanding.
Relevant permission records include:
- The agreed scope, where an assessment was authorized.
- The organization and system to which the permission applies.
- The person granting authority and their role.
- Applicable restrictions or conditions identified by the review.
- An objection, withdrawal or instruction to stop.
- The action taken after that communication.
These are suggested controls for making the facts reproducible. This article does not decide whether a particular public service supplies implied authorization.
Insight: security work still has a permission boundary
Section 815.06(7)(c) excludes a person performing authorized security operations of a government or business. The word authorized matters. It is not an exception for any vendor that sells security services or describes its methods as beneficial.
Section 815.06(7)(a)–(b) also includes other circumstances, including lawful employment, but their application requires the actual role and conduct. Do not assume that the MSP's employment relationship with its own representatives authorizes work on a prospect's systems.
A security purpose explains why you acted. It does not, by itself, establish who permitted the act.
Treat an objection as a stop event
A clear objection is a reason to suspend disputed direct interactions and review the permission basis. Do not keep probing to prove that the observation was useful. That introduces additional facts after the team has received notice.
The stopping recommendation is an interim risk control, not a claim that every objection creates every element of a Florida offense. Counsel still needs to evaluate the nature of the requests and the relevant law.
Does Florida's specific civil remedy require conviction?
Section 815.06(5)(a)–(b) describes an owner or lessee's compensatory-damages action against a person convicted under the section, in addition to other available civil remedies. Paragraph (b) permits reasonable attorney fees to the prevailing party in that action.
That is not a freestanding statement that every suspicious request creates the particular statutory remedy. It also does not mean there is no civil exposure before conviction under any other law. Separate the identified provision from other claims requiring review.
Cross-jurisdiction access remains relevant
Section 815.06(8) addresses access caused between jurisdictions and deems personal access in both for actions under the section. Sending requests from another state does not remove the need to examine Florida connections.
Identify the request origin, service operator and relevant system locations where known. Do not substitute the prospect's office address for technical facts you have not established.
Where the described SCOUTz workflow fits
SCOUTz's free domain review uses public records and passive enumeration, according to the team. Indexed observations are publicly discoverable and are not verified by a request to the indexed resource. Preserve those limits in the report and email.
The deeper Microsoft 365 review follows prospect authorization and full sign-up through a permission-based connection. The team describes read-only assessment without content reads, exploit checks, brute-forcing or authentication testing.
Reports are diagnosis only, without threatened disclosure or built-in remediation upselling. Those facts help narrow the review but do not create a statewide exemption. Collection, protected access and commercial email still require separate analysis.
What remains unresolved
This installment reviews the indicated official statutory text. It does not complete a Florida case-law survey, an analysis of every civil claim, or a legal review of every SCOUTz collector.
Ask counsel to examine the knowledge element, public-service permissions, exceptions, any restrictions or objections and the actual request behavior. Review the report's factual claims separately from whether the collection was permitted.
FAQ
Does Florida define access only as logging in?
No. Section 815.03(1) includes communicating with and otherwise using computer resources.
Does Florida's access offense include a knowledge element?
Yes. Section 815.06(2)(a) addresses knowledge that access is unauthorized or the manner of use exceeds authorization.
Does being a security company establish the security exception?
No. Section 815.06(7)(c) specifies authorized security operations.
Does § 815.06(5) allow every prospect to sue over any scan?
The identified remedy is directed at a person convicted under the section. Other civil remedies require their own analysis.
What should an MSP do after an objection?
Suspend disputed direct activity and review the permission basis with the responsible owner. Do not continue testing to justify the original outreach.
Is this Florida clearance for SCOUTz?
No. It is preliminary statutory research, not a completed case-law or method-specific legal opinion.
One last thing
Permission records should include when the understanding changed. The team's response to a stop request can matter as much as the original reason for the assessment.
Use the methods guide to distinguish collection actions and the state index to identify pending work. The outreach guide covers the separate commercial message. SCOUTz's trust page describes its access boundary, not immunity. Compare this with Texas's effective-consent definition.
Is the federal research policy the same as Florida's exception?
No. 18 U.S.C. § 1030(a)(2)(C), (a)(5), (g) contains federal access, damage and conditional civil-remedy provisions. The DOJ Justice Manual § 9-48.000 B.3(8), C is guidance on charging good-faith research, not Florida's authorized-security exception and not immunity from either civil or state claims.
The federal text is the official 2024 edition, effective January 6, 2025. A current-2026 comparison remains pending.
Sources
Statutes: Florida's official pages identify the 2026 Statutes; §§ 815.03(1), 815.06(2)(a)–(b), (5), (7), (8) are linked near claims. Federal § 1030(a)(2)(C), (a)(5), (g) uses the dated official edition above.
Court decisions: none is asserted; knowledge, authorization and civil-remedy decisions remain pending.
Agency guidance: DOJ Justice Manual § 9-48.000 is charging policy, not statutory authorization.
Product sources: SCOUTz trust and the team's stated workflow. Sources consulted October 6, 2026; an exhaustive amendment comparison, other civil claims and collector-specific legal clearance remain incomplete.
