Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Ohio Senate committee advances bill requiring local governments to adopt cybersecurity programs, restricts ransom payments

3717460 · May 6, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Senator Greg Schafer told the Senate Financial Institutions, Insurance and Technology Committee that Senate Bill 203 would require every political subdivision in Ohio to adopt a cybersecurity program and would bar payment of ransom demands unless the local legislative body votes to approve it.

Senator Greg Schafer told the Senate Financial Institutions, Insurance and Technology Committee that Senate Bill 203 would require every political subdivision in Ohio — counties, townships, cities, villages, school districts, conservancy districts and park districts — to adopt a cybersecurity program and to limit when a subdivision may pay a ransom demand.

The bill would require political subdivisions to notify the Division of Homeland Security within the Ohio Department of Public Safety of a cybersecurity incident no later than seven days after discovery and to notify the auditor of state’s office no later than 30 days after an incident, Schafer said. The bill also prohibits a political subdivision from paying a ransom unless the governing legislative body has conducted a formal vote to do so.

“The overall goal of this legislation is to prevent and mitigate cybersecurity incidents and protect taxpayer dollars by giving local political subdivisions the tools that they need to properly address these situations,” Schafer said.

Schafer cited recent incidents to illustrate potential costs to local governments: the July ransomware attack against the city of Columbus, which he said cost taxpayers more than $7,000,000 in recovery costs, and a 2023 phishing fraud against the Granville Recreation District that resulted in a $713,000 loss. Schafer provided a breakdown of the Columbus recovery costs: $2,400,000 for systems remediation and cyber-threat monitoring, $1,640,000 for Experian identity-theft protection, $1,950,000 for legal counsel related to incident response, and $1,300,000 for long-term threat monitoring and litigation-related counsel.

Schafer said the bill includes an amendment requested by State Auditor Keith Faber that would exempt from public-records disclosure any record that identifies cybersecurity-related software, hardware, goods or services under consideration or in use by a political subdivision; the change is intended to keep procurement details from potential bad actors.

During questioning, Senator Craig asked whether the Division of Homeland Security maintains an approved-vendor list for cybersecurity products for state agencies; Schafer said he would follow up and provide that information to the committee. Several members also asked whether the bill would impose substantial new costs on smaller political subdivisions; Schafer responded that the bill primarily requires a policy to be in place and that the policy requirement should not be a large expense, while noting that preparedness can reduce the much larger costs of incident response.

The committee adopted amendment 0592 — described in the hearing as clarifying the public-records exemption — without objection and concluded the first hearing on the amended bill.

Next steps: the committee concluded the first hearing on the amended Senate Bill 203; no formal vote on final passage was taken during this meeting.