Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Ohio Senate committee advances bill requiring local governments to adopt cybersecurity plans, limits ransom payments

3717468 · May 27, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

A Senate committee amended and advanced legislation that would require counties, townships, municipalities, school districts and other political subdivisions to adopt cybersecurity programs and set rules for ransom-payment decisions, and added a records exemption for procurement information.

The Senate Financial Institutions, Insurance and Technology Committee on May 27 advanced Senate Bill 203, a measure that would require Ohio political subdivisions — counties, townships, cities, villages, school districts, conservancy and park districts — to adopt a cybersecurity program and restrict when a local government may pay a criminal ransom demand.

Sen. Schafer, the bill sponsor, told the committee the bill "requires all political subdivisions in Ohio ... to adopt a cybersecurity program" and prohibits a political subdivision from paying a ransom unless the governing legislative body takes a formal vote to do so.

The proposal also would require political subdivisions to notify the Department of Public Safety’s Division of Homeland Security of a cybersecurity incident no later than seven days after discovery and to notify the auditor of state’s office no later than 30 days after an incident. Schafer said the bill includes an amendment requested by Auditor Keith Faber that would exempt from public-records disclosure any record identifying cybersecurity-related software, hardware, goods or services being used or considered for procurement by a political subdivision so that potential attackers cannot access that information.

Schafer cited the July ransomware attack on the city of Columbus as an example of the stakes involved. "While the city of Columbus did not pay the ransom, it did cost the city taxpayers over $7,000,000 in recovery costs," he said, and later itemized $2,400,000 for systems remediation and cyber threat monitoring, $1,640,000 for identity-protection services, $1,950,000 for legal counsel and $1,300,000 for long-term monitoring and litigation-related legal costs. He also described a 2023 phishing loss in his district, saying the Granville Recreation District lost $713,000 when a fraudulent account intercepted a funds transfer.

Committee members asked whether the state or the Department of Public Safety maintains a list of approved cybersecurity vendors for state agencies; Schafer said he would follow up and provide the information to the committee. Members also asked about cost impacts for smaller local governments. Schafer said the bill’s primary requirement is that political subdivisions “have a policy,” and that the bill is meant to encourage planning and mitigation rather than mandating a specific expensive technology investment.

The committee adopted an amendment (0592) described by Schafer as the auditor’s requested clarification on records exemptions, and the amended bill completed its first committee hearing.

Appointments and other committee business preceding the hearing included unanimous committee votes to forward two governor’s appointments to the committee on Rules and Reference and unanimous approval of several amendments to other bills on the agenda; those items were procedural and separate from the SB 203 discussion.

What happens next: The committee has advanced the amended bill through its first hearing and incorporated the auditor’s records-exemption amendment. The transcript does not show a final committee vote to report the bill to the full Senate; the bill was taken up for a first hearing and amended. Further committee action, votes or floor consideration were not recorded in this transcript.