Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Talawanda City hears cybersecurity briefing; Ohio law will require formal cyber program by July 2026

5781058 · September 13, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Mark Hopkins, chief technology officer of the Southwest Ohio Computer Association, told the Talawanda City School District board on Sept. 11 that the district must treat cyber security as an ongoing program and meet new Ohio reporting and program requirements under House Bill 96 and Senate Bill 29.

Mark Hopkins, chief technology officer of the Southwest Ohio Computer Association, told the Talawanda City School District board on Sept. 11 that the district must treat cyber security as an ongoing program rather than a one-time project and meet new state reporting and program requirements.

Hopkins, addressing the board and district staff, said Ohio House Bill 96 requires school districts to adopt a formal cyber security framework by July 1, 2026, and triggers new incident-notification deadlines: the Ohio Cyber Incident Center must be notified within seven days of a qualifying event and the state auditor within 30 days. Hopkins also described Senate Bill 29’s data-privacy provisions that expand district obligations when third-party vendors have access to student records.

"We have to accept that we're never going to be there and we're never going to be done when talking about cyber security," Hopkins said, urging the board to plan for continuous improvement rather than a final endpoint.

Why it matters: Hopkins cited national breach data and sector trends to make the case that education remains a high-risk sector for attackers. He told the board that in the report he used, 86% of reported incidents in education led to confirmed breaches, a much higher rate than other sectors. He warned that student personally identifiable information (PII) has long-term value to threat actors because K–12 records can go undetected for years.

Hopkins outlined concrete compliance steps the district must take under HB 96 and related frameworks: update the district incident response plan; assess where data reside (on-premises, cloud, third-party systems); evaluate third-party contracts for required notification and data-protection language; publish district technology providers as required by SB 29; and select and adopt a recognized cyber-security framework before the July 2026 deadline. He also noted that HB 96 creates a new public-records exemption (citing Ohio Revised Code 149.433) for security records and incident details.

District staff presented related policy changes as a first reading. Dr. Bailey said the policy revisions in the board packet largely reflect the 2025 biannual budget bill (House Bill 96) and that the district uses NEOLA policy services for legal updates. "The majority of the revisions that are in the policy are a reflection of the 2025 budget bill," Bailey said during the meeting.

Hopkins stressed the human factor in most successful attacks and recommended role-specific employee training. "These two things have one thing in common and that they are attacking the weakest element in any cyber security platform. It's not the server... it's us, the human beings," he said.

No formal board action to adopt a framework or finalize policy occurred at the Sept. 11 meeting; Hopkins and staff said they will return with draft policy language and implementation steps for board consideration ahead of the July 2026 adoption deadline.

Documents and next steps: Hopkins and staff noted the district already has an incident response plan that needs revision and that NEOLA is preparing policy language aligned with HB 96. Board members asked staff to circulate drafts to the public and return with a recommended framework and timeline.

The presentation and the policy first reading together framed compliance tasks the district must complete to meet state reporting and governance obligations without establishing a final board policy on Sept. 11.