Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Municipal Cybersecurity topic
No spam. Unsubscribe anytime.
Auditor and stakeholders urge statewide cybersecurity programs, limited ban on ransom payments in Senate hearing
Summary
Alexis Davis, deputy director of policy and legislative affairs for Auditor of State Keith Faber, told the Senate Financial Institutions, Insurance, and Technology Committee that amended Senate Bill 203 would require local governments to adopt cybersecurity programs, report incidents, and generally bar paying ransomware demands unless a legislative authority adopts a public resolution.
Get email alerts on the Municipal Cybersecurity topic
No spam. Unsubscribe anytime.
Hallie Beggeman, testifying for Ohio Jewish communities, urged lawmakers to treat cybersecurity training and workforce development as part of economic competitiveness and said the state should "showcase" international partnerships and invest modestly in training to attract firms.
Alexis Davis, deputy director of policy and legislative affairs for Auditor of State Keith Faber, told the Senate Financial Institutions, Insurance, and Technology Committee that amended Senate Bill 203 has three principal elements: a general prohibition on political subdivisions paying or complying with ransomware demands with a narrow exception; a requirement that political subdivisions adopt cybersecurity programs appropriate to their needs; and mandatory incident reporting to state agencies.
Davis described the compromise on ransom payments: the bill "bans political subdivisions from paying or otherwise complying with a ransomware demand," but allows a local legislative authority to approve payment if it "adopts a resolution explaining why payment or compliance is in the public interest." The purpose, she said, is to allow a rare, transparent local decision while discouraging routine payments.
The bill requires each political subdivision to adopt a cybersecurity program that may include identifying critical functions and risks, specifying detection and response procedures, establishing repair and maintenance procedures, and setting employee training requirements. Annual state training or courses provided by the Ohio Persistent Cyber Initiative Program would satisfy the training requirement, Davis said.
Reporting timelines in the draft require political subdivisions to notify the Ohio Department of Public Safety within seven days of discovering an incident and to notify the Auditor of State within 30 days. Davis said the differing windows are tied to each agency’s role: DPS provides immediate incident assistance; the Auditor needs incident information for audits and financial oversight.
Davis said the bill also exempts documents related to cybersecurity programs, incident reports to DPS and AOS, and procurement records for cybersecurity goods and services from public-records law to reduce security risk from disclosure.
Committee members raised operational questions. Senator Mora asked how a local legislative body could convene quickly enough to approve a ransom payment under a short deadline; Davis and others acknowledged practical challenges and said jurisdictions and future drafts might address thresholds or emergency procedures. Senator Manning asked why the bill did not follow Florida and North Carolina and impose an absolute ban; Davis said an outright ban was considered but stakeholders raised concerns that led to the current compromise allowing a public resolution for payment in specific circumstances.
The committee took testimony and did not vote on the bill during the session.
