Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Local Government topic

No spam. Unsubscribe anytime.

Committee hears HB 283 requiring local governments to adopt cybersecurity programs and reporting rules

5553367 · June 3, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The House Technology and Innovation Committee on Oct. 11 held the first hearing for House Bill 283, a measure that would require Ohio political subdivisions to adopt cybersecurity programs, complete specified training and notify state authorities after an incident.

The House Technology and Innovation Committee on Oct. 11 held the first hearing for House Bill 283, a measure that would require Ohio political subdivisions to adopt cybersecurity programs, complete specified training and notify state authorities after an incident.

The bill’s sponsors, Representative Adam Matthews and Representative Brett Matthews, told the committee the measure was drafted with input from the auditor’s office and aims to ensure local governments “have the resources in place to adequately respond and protect our taxpayer resources.” Representative Adam Matthews said, “Political subdivisions in Ohio have recently been subject to increasing rates of cyber security incidents, including numerous incidents of spear spear phishing attacks that have cost taxpayers hundreds of thousands of dollars in damage, losses, and improper payments.”

HB 283 would require each political subdivision’s legislative authority to adopt a cybersecurity program that conforms to generally accepted best practices and may include elements such as identifying critical functions and cybersecurity risks, specifying mechanisms to detect potential risks, establishing procedures to repair infrastructure after an incident, and requiring cybersecurity training for all employees. Representative Brett Matthews told the committee the bill “requires political subdivisions following each cybersecurity incident to notify the executive director of the division of homeland security within the department of public safety within 7 calendar days of discovering the incident and the auditor's state within 30 days of discovering the incident.”

The bill also prohibits political subdivisions from complying with ransom demands for ransomware incidents unless the legislative authority approves the payment in an open resolution or ordinance and “explicitly state[s] the reason that the ransom payment is in the best interest of the political subdivision and its taxpayers,” language the sponsors said is intended to bolster transparency.

Committee members questioned scope and implementation. Representative Ty Matthews asked who establishes the list of “generally accepted practices” and whether local governments that use private vendors would be required to defer to a state list; sponsors responded that the bill allows private vendors to be used so long as their programs substantively comply with the bill’s requirements and that the auditor’s office would coordinate standards. Representative McLean asked whether the bill’s definition of “cybersecurity” expands existing code; sponsors said the definition appears to be new to this bill and that they would confirm and follow up.

Members raised resource concerns for smaller jurisdictions. Representative Mohammed asked whether HB 283 provides additional staff, funding or training for subdivisions with limited capacity. The sponsors noted that the bill recognizes state-provided annual cybersecurity training and training offered by the Ohio Persistent Cyber Initiative of the Ohio Cyber Range Institute as satisfying the training requirement, but acknowledged the bill does not currently appropriate dedicated funds or a specific outreach campaign. Representative Brett Matthews and others recommended outreach through county and municipal associations, the auditor’s office and existing state channels to increase awareness of available resources.

Several members asked about institutions not covered by the bill. Representative Hall noted a recent cyber attack on Kettering Health Hospital and asked whether hospitals were covered; sponsors replied the bill applies to political subdivisions and could be amended later if the committee chose to expand scope.

The committee also heard an extended technical briefing from Thomas McClellan, director of government affairs for Palo Alto Networks, who described trends in ransomware, industrial control system (ICS) attacks and supply-chain vulnerabilities and offered recommendations for state-level responses. McClellan said the speed and sophistication of attacks have increased, noting that data exfiltration that once took days can now take hours. He described ransomware as a business and gave the following characterization of recent incident economics: “The initial request average of what we're seeing, about 3.8, about 3,800,000.0 in USD,” and added that negotiated payments are often lower.

McClellan recommended several collective approaches state legislatures can adopt or support: incident-response retainers so local governments can quickly scale external help after an attack; attack-surface management to inventory and monitor public-facing assets; and joint security operations centers to centralize detection and response for multiple local entities. He also discussed the software bill of materials (SBOM) concept to track components in software and limit the reach of supply-chain compromises such as the SolarWinds incident. He warned that some adversary activity (he referenced a campaign named Veil Typhoon) is targeting critical infrastructure and said states should plan for both known and unknown vulnerabilities.

On workforce and tools, McClellan said automation and AI are essential to scale defenses given shortages of trained personnel. He urged legislators to ask state IT leaders for mean time to detect and mean time to respond metrics and to explore collective, platform-based investments that can lower per-jurisdiction costs.

No formal vote was taken on HB 283 during the hearing. The committee approved the minutes from its May 27 meeting without objection. Sponsors asked for favorable consideration and indicated they expect further testimony and drafting changes in the coming days.

The committee adjourned after the presentations; members and staff signaled plans to continue discussions on HB 283, training availability, and potential technical amendments.