Before an incident happens

Incident readiness — plain language

Know your clocks, your contacts, and your proof. FalconForgeAI helps Ohio public organizations prepare before a crisis.

In plain English

Watching news about breaches is not a plan. Public organizations need known reporting clocks, trusted official sources, and proof that their own basics (access, backups, vendors, roles) would hold up.

~7 daysOCIC notification theme after discovery
~30 daysAuditor of State notification theme
SeparateDo not assume one filing covers every duty
PreparePractice before you need the phone tree

Prepare these tracks now

TrackWhat to prepare
State (ORC § 9.64)Who declares an incident, who calls OCIC, who files with the Auditor, and how you document it
Federal prep (CIRCIA themes)Know this may be an extra track later—do not treat state filing as automatic federal coverage
Program evidenceAdopted program, training, backups, vendor files—ready for leadership and audit conversations
Insurance & vendorsNotice requirements and contacts in contracts

Trusted places to look

cyber.ohio.gov

State cyber resources and OCIC pathways.

Open site →

Self-check questions

  • Do we know who is on-call if systems fail on a weekend?
  • Is multi-factor authentication on email and remote access?
  • Have we tested restoring a critical system from backup?
  • Do we have our top vendors listed with contacts and security documents?
  • Could we notify OCIC and the Auditor without scrambling for forms?

How FalconForgeAI helps you

We turn “we should be ready” into a concrete readiness package for Ohio public organizations.

  • Incident role map — Who decides, who calls, who documents, who speaks publicly.
  • Dual-track checklist — State clocks prepared as separate paths.
  • Evidence review — Backups, access, vendors, and program documents in one view.
  • Tabletop support — Practice the first hours/days before a real event.
  • Leadership brief — What is ready, what is not, and what to fund next.

We help you see and organize the story. Your leaders still decide. We do not file state or federal reports, certify compliance, or give legal advice.