Key Deadlines
- Counties & Cities: Jan 1, 2026
- Townships & Schools: Jul 1, 2026
- Compliance Required Now
What the Law Really Says
Ohio Revised Code §9.64 requires political subdivisions to adopt a cybersecurity program aligned to recognized frameworks such as NIST CSF or CIS Controls. The program must address identification, protection, detection, response, recovery, staff training, incident reporting, and ransomware governance.
How Professionals Actually Read It
Compliance is not achieved by adopting a template. Auditors, insurers, and legal counsel evaluate whether controls are actually implemented, maintained, and exercised.
Key Takeaway
A binder that references controls you don't actually run is not compliance.
It is a finding waiting to be written and a liability waiting to be argued.
Inside a Real Incident Response Policy
- Roles & Severity — Incident ownership and classification.
- Response Lifecycle — Preparation through recovery.
- Communications & Evidence — Preserve communications and evidence.
- Statutory Reporting — Meet all state reporting requirements.
- Ransomware Governance — Board approval processes.
- Board Documentation — Resolutions, forms, workflows, and contacts.
Build It In-House or Bring Help?
Free state resources are valuable, but they are not a complete cybersecurity program. Organizations must still tailor, adopt, implement, and maintain the program.
The Dollars and Cents
The cost of a ransomware event, investigation, recovery effort, legal review, and operational downtime often exceeds the investment required to establish a compliant program.
Start Now, Get Compliant, Build As You Go
Begin with governance, multifactor authentication, backups, incident response planning, and staff training. Then mature the program over time.