Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Trumbull County auditor seeks board authorization to craft cybersecurity program required by House Bill 96
Summary
Trumbull County Auditor Martha Young briefed commissioners on House Bill 96, which requires local political subdivisions to adopt cybersecurity programs by Jan. 1, 2026. The auditor asked the board to authorize county staff and the prosecutor's office to draft a compliance program for later adoption.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Trumbull County Auditor Martha Young and Chief Deputy/IT director Tim Hannaford briefed the Board of Commissioners about implementation of House Bill 96 and asked the commissioners to authorize the auditor's office and the prosecutor's office to draft a county cybersecurity program for formal board adoption.
Young said House Bill 96, effective Sept. 30, 2025, requires political subdivisions to adopt cybersecurity programs that include accepted best practices, employee training requirements, an incident response plan and reporting procedures for cyber incidents including ransomware. The auditor's office described training options and recommended partnering with the Ohio Cyber Range Institute for county-wide end-user training.
Hannaford said the major implementation elements include annual training for all employees, a documented cyber incident response plan, and a process to identify and remediate cyber risks. County officials also discussed reporting obligations: cyber incidents must be reported to the state, and ransomware payments are permitted only in limited circumstances where backups and other mitigation are unavailable.
Young asked the commissioners to place a resolution on the next agenda authorizing the auditor's office, in coordination with the prosecutor, to draft the county's cybersecurity program for subsequent formal approval by the board. Commissioners signaled support for moving forward and for returning a draft policy in time to meet the Jan. 1, 2026 implementation date.
Audit staff also noted that the cybersecurity program itself is not a public record under the statutory exemption described in guidance they distributed, and that details about controls would be withheld from public disclosure to prevent revealing defensive posture to potential attackers.

