New Ohio Law Mandates Cybersecurity Standards for Local Governments
Ohio’s newly enacted House Bill 96 requires local
governments to establish a formal cybersecurity program. These programs must
follow recognized best practices, such as the NIST Cybersecurity Framework
(CSF) or CIS standards. They must include risk assessment, threat detection,
incident response procedures, employee training, and plans to repair and
maintain security infrastructure. Although the bill no longer includes funding
provisions, state-supported resources like the Ohio Cyber Integration Center (OCIC),
the Ohio Persistent Cyber Initiative (O-PCI), and the Ohio Cyber Reserves are
available to assist with compliance. The law also mandates annual training,
restricts ransomware payments without formal approval, and requires incident
reporting to state officials within set timeframes.
Read more about this legislation and the new requirement at Cleveland.com.