In plain English
Ohio law expects political subdivisions to maintain a cybersecurity program that fits their operations and to report certain cyber incidents to the state within required timeframes. This page gives leaders a simple planning overview. Always confirm specific requirements with your attorney and official state guidance.
Who this usually covers
Cities, villages, counties, townships, school districts, public libraries, park districts, public authorities, and similar local public organizations—plus the people accountable for technology, finance, and operations.
What your program should cover
- Important services and systems (finance, utilities, schools, public safety touchpoints, public portals)
- Core safeguards such as access control, training, and practical monitoring
- How your organization will respond to a cybersecurity incident
- How essential services will be restored, including recovery and backups
- Key vendors and shared services that support your operations
- Ongoing review so the program stays current as your organization changes
Planning for ransom decisions
Ohio guidance strongly favors a no-ransom approach. If payment is ever considered, local legislative authority typically needs a formal public-interest decision path. Establishing that policy in advance gives leaders a clearer process to follow if a serious incident occurs.
When a reportable cyber incident occurs
Ohio Cyber Integration Center (OCIC)
- Timing theme: within about 7 days of discovery
- Where to start: cyber.ohio.gov / OCIC resources
- Commonly published contacts: 614-387-1089 · OCIC@dps.ohio.gov
Ohio Auditor of State
- Timing theme: within about 30 days
- Commonly published contact: Cyber@ohioauditor.gov
- Use the Auditor’s published reporting process
Planning note: The two reporting paths generally serve different purposes, so organizations should be prepared for both. See the incident readiness guide.
Security records and public records
Materials about cybersecurity programs and incidents are often treated as protected security records. Clear internal rules can help your organization manage what is retained, who has access, and when legal counsel should be involved.
How FalconForgeAI helps you
FalconForgeAI helps Ohio public organizations organize ORC § 9.64 readiness information and turn it into clear, usable material for leadership.
- Organize your evidence — Policies, inventories, training, vendor files, incident plans, and insurance answers.
- See what is already in place — Understand the evidence you already have and where additional follow-up would be useful.
- Set practical priorities — Turn review findings into a manageable list of next steps for the right owners.
- Prepare for incident reporting — Organize roles, contact trees, and both state reporting paths in advance.
- Leadership-ready summaries — Give administrators and governing bodies clear, carefully worded information they can review and discuss.
FalconForgeAI helps organize evidence, readiness information, and leadership summaries. Final decisions, official filings, compliance determinations, and legal advice remain with your organization and qualified advisors.