Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Council briefed on proposed state cybersecurity mandate that would require incident reporting and plans
Summary
City staff summarized proposed Auditor of State legislation to require municipal cybersecurity programs aligned with NIST/ODAS, mandatory staff training and seven‑day incident reporting; legal counsel said compliance would create liability protections but also add costs.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Riverside City Manager Josh briefed council on proposed cybersecurity legislation moving through the Ohio Legislature that would require local governments to adopt cybersecurity programs, conduct ongoing training and report incidents to state agencies.
The staff presentation described three elements of the proposal: (1) adopt a cybersecurity program aligned with recognized standards such as the National Institute of Standards and Technology (NIST) Cybersecurity Framework or Ohio Department of Administrative Services guidance; (2) implement incident-response procedures and annual staff training; and (3) report cyber incidents or ransomware attacks to the Auditor of State and the Department of Public Safety within seven days.
"A cyber security incident ... that is disruptive of service and is an unauthorized access" was the working definition presented by staff. The presentation distinguished general cyber incidents from ransomware incidents, which staff described as unauthorized access followed by a demand for payment.
Staff said the proposed law would also create limited exemptions to the Public Records Act for documents related to cybersecurity implementation plans and incident reports to avoid publishing material that could help attackers. Jim, a staff legal advisor, told council the exemption mirrors existing public-safety carve-outs and would protect sensitive system details from public disclosure.
"By the state using its expertise ... it provides a safe haven for liability," Jim said, describing a legal benefit when municipalities follow state-mandated best practices.
Council discussed operational implications. Staff warned the mandate would impose costs — new hardware, software, monitoring and ongoing staff time — and that the legislation currently does not include dedicated funding. Manager Josh said staff will raise the funding concern during the Ohio Municipal League (OML) Legislative Day and seek state support to implement any mandate.
Staff noted some local cybersecurity practices are already in place, including subscription training tools that deliver simulated phishing emails and short trainings for employees who click decoys. The manager said the statewide policy would codify practices many peer cities already perform and would shift consistency and technical guidance to state agencies with existing cybersecurity expertise.
Staff will continue monitoring the legislation and will inform council of developments; the manager said he plans to discuss the issue with state legislators at the upcoming OML event.

