Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

House bill would codify governor—s cybersecurity roles, create statewide response and municipal support

House Technology Innovation Committee · October 21, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Sponsors of House Bill 475 told the Technology Innovation Committee the bill would codify the governor—s 2022 executive order, make the state cybersecurity strategic advisor position permanent, require annual assessments of municipal cyber readiness, and authorize contracting with certified Ohio cybersecurity firms to assist local governments; the

Representatives Mohammed and White presented sponsor testimony on House Bill 475 on Oct. 14, saying the bill would codify the governor's 2022 executive order and create a permanent, statewide framework to assess municipal cybersecurity and respond to incidents.

Representative Mohammed told the Technology Innovation Committee that the legislation would ensure municipalities have access to training, reliable communications and consistent state support when cyber incidents occur. He said the bill would permit the state to contract with certified private cybersecurity firms, allowing even small communities to obtain technical assistance and enabling reinvestment into Ohio firms.

“We are creating state‑wide standards and guidance,” Representative White said, adding the bill aims to ‘‘level the playing field’’ so communities with limited IT resources can receive assessments and responses comparable to larger cities. Sponsors cited examples of past municipal cyberattacks that disrupted local operations and imposed recovery costs on jurisdictions, naming Cleveland, Columbus, Huber Heights and Washington Courthouse as past incidents.

Members asked practical questions about the operational design of the proposed help line and response times. Sponsors described a provision requiring a response within 48 hours and said they intend the help line to be a dedicated, hardwired connection to a live cybersecurity expert rather than a typical customer‑service queue. They also said the agency contracting with private firms will require technical qualifications and certifications for vendor firms.

Representative Mohammed confirmed the bill largely codifies the governor's executive order but includes additions such as a permanent statutory advisor position to replace the temporary appointment created by the order, and provisions to appoint qualified Ohio‑based firms for assessments and incident responses. The committee did not take a vote during the first hearing; sponsors said they will continue refining operational details such as criteria for emergency escalation and the dedicated line design.