Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity Policy topic
No spam. Unsubscribe anytime.
Council adopts cybersecurity policy with emergency clause; law director says ransomware payments must be approved at public meeting
Summary
Greenville City Council adopted a cybersecurity policy, including an emergency clause, to meet state audit requirements and to require council approval before any ransomware payment; the policy also clarifies certain cyber incident records may not qualify as public records under Ohio law.
Get email alerts on the Cybersecurity Policy topic
No spam. Unsubscribe anytime.
Greenville City Council adopted a resolution that establishes a cybersecurity policy for the city and invoked an emergency clause so the policy takes effect immediately. The resolution explicitly cites Ohio Revised Code requirements (ORC section 9.64) and was read and adopted on the same evening after the council voted to suspend the rules.
Law Director Reaman told council that the draft included two additions requested by the state auditors: a provision that any ransomware payment made on behalf of the city may occur only after a vote of council at a public meeting, and a clarification that some records related to cyber threats and ransomware may not be public records under the ORC. Council members moved to suspend the rules for expedited consideration and then adopted the resolution by roll-call vote.
The resolution aims to strengthen protection of public data and to align city practice with state auditor guidance; council did not discuss implementation details such as assignment of responsible departments or reporting timelines during the meeting.

