Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Warren County adopts cyber policy; IT staff warn breaches are likely and outline next steps
Summary
Commissioners adopted a countywide cybersecurity policy required by state changes and heard IT staff say breaches are probable; staff outlined a CIS‑based framework, incident reporting timelines, backup requests for the 2026 budget and planned briefings for commissioners in early 2026.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Warren County commissioners voted to adopt a countywide cybersecurity policy after staff explained the policy aligns with changes to the Ohio Revised Code and requires sub‑jurisdictions to maintain consistent cyber protections.
County staff said the policy implements a recognized control framework and sets incident reporting timelines. "All jurisdictions now are required to have a cybersecurity policy," a staff presenter said, noting the template and guidance were developed over recent months with input from county prosecutors and external templates provided by the County Commissioners Association of Ohio (CCAO).
During a follow‑up discussion IT staff told the commission the county must focus on core defensive practices and that, despite protections, a breach remains likely. An IT staff member told commissioners, "We're going to get a breach. It will happen." Staff said the new department will conduct a gap analysis against CIS controls, finalize an incident response plan, and produce a "Cyber 101" briefing for elected officials so commissioners better understand incident business impacts and insurance coverage limits.
Staff also said they have requested funding in the 2026 budget for immutable backups and other protective measures; they asked for a few months to align staffing and report back with detailed recommendations and Q1 briefings. Commissioners emphasized they want to see specific timelines and details about what insurance will and will not cover in cyber incidents.
The motion to adopt the cybersecurity policy was moved and approved by roll call; the auditor/prosecutor sign‑off was noted as completed in the meeting record. Staff said the policy must take effect by January 1 under the new ORC requirement and that further operational details will follow in the coming quarter.

