Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Ross County prepares cybersecurity policy to meet House Bill 96 deadline

Ross County Commission ยท December 2, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

County officials discussed a draft cybersecurity policy to comply with House Bill 96, with a framework due next week and county-level compliance expected by Jan. 1 for counties and cities; the plan will require incident reporting and varying tiers of controls.

Andy, a county official, told commissioners the county is preparing a draft cybersecurity policy to comply with House Bill 96 and expected to circulate a review copy 'next week.' He said counties and cities must have policies in place by Jan. 1, while townships and villages have later deadlines.

The discussion outlined three tiers of compliance in House Bill 96 โ€” a 'basic hygiene' level, a more aggressive operational level and a nation-state level โ€” and noted the county will not be required to implement nation-state controls. Unidentified Speaker 6, speaking on IT operations, said the bill will bring employee training and tabletop exercises into scope and that incident reporting requirements will route certain incidents to the secretary of state and other agencies.

Speakers flagged practical implementation issues: multiple elected offices and autonomous departments may submit separate plans tailored to their risks, and the county will likely produce a unified framework for the departments managed by county IT. Unidentified Speaker 6 said the county is planning security exercises, a call/notification tree and recovery planning so outages can be measured in hours and days rather than weeks.

The immediate next step is distribution of a draft policy for review next week; commissioners were told they will receive a more presentable document outlining standards and recommended implementation tasks. The meeting record shows officials intend to follow national guidance (NIST/CISA) while allowing department-specific risk assessments.