Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Political Subdivisions topic

No spam. Unsubscribe anytime.

Senate committee hears sponsor testimony on bill requiring local governments to adopt cybersecurity plans, restricts ransom payments

3717469 · June 3, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Sponsor testimony on Senate Bill 203 asked the committee to require Ohio political subdivisions to adopt cybersecurity programs, set incident‑reporting deadlines, and bar ransom payments without a formal legislative vote; an amendment protecting procurement records from public disclosure at the request of the auditor was adopted.

Senator Schaeffer urged the Ohio Senate Financial Institutions, Insurance and Technology Committee to approve Senate Bill 203, which would require county, township, municipal and other political subdivisions to adopt a formal cybersecurity program and limit local officials’ ability to pay ransomware demands without a formal vote of their legislative body.

The bill’s sponsor said the measure was developed with State Auditor Keith Faber and is intended to “prevent and mitigate cybersecurity incidents and protect taxpayer dollars by giving local political subdivisions the tools that they need to properly address these situations.” The sponsor cited last July’s ransomware attack on the city of Columbus and a phishing theft in the Granville Recreation District as examples of the potential cost to taxpayers and operations.

The bill would require political subdivisions to notify the Division of Homeland Security and the Department of Public Safety no later than seven days after discovering a cybersecurity incident, and to notify the Auditor of State no later than 30 days after discovery. Senator Schaeffer also described an amendment requested by Auditor Faber that would make records identifying cybersecurity‑related software, hardware, goods and services used or under consideration for procurement exempt from disclosure under the Ohio Public Records Law to reduce the chance that attackers could target jurisdictions by inspecting procurement records.

Committee members asked how expensive compliance would be for smaller local governments and whether the state maintains an approved‑vendor list for cybersecurity products. Senator Schaeffer replied that the bill’s primary requirement is adoption of a written policy and that he would “get back” to the committee about whether the Division of Homeland Security maintains a list of approved vendors.

The committee debated no final policy beyond adopting the auditor’s exemption amendment. The amendment (No. 0592) was offered, explained by the sponsor and accepted by voice/roll without objection; the amended bill concluded its first hearing.

Why it matters: Sponsor testimony framed the measure as a response to recent ransomware and phishing incidents that disrupted services and generated multimillion‑dollar recovery costs. The Auditor’s office asked for the procurement‑records exemption to prevent potential attackers from using public records requests to map local jurisdictions’ defenses.

The committee took no final substantive action other than adoption of the auditor‑requested exemption amendment; no vote on the bill itself was recorded at the hearing.