Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity Policy topic
No spam. Unsubscribe anytime.
Knox County adopts cybersecurity policy; officials cite vendor oversight, ransomware reporting and training needs
Summary
Kyle Webb presented a county cybersecurity policy aligned to state guidance (House Bill/ORC references); the board approved the policy after discussion about multifactor authentication for 911, vendor oversight, password management and new reporting requirements for ransomware incidents.
Get email alerts on the Cybersecurity Policy topic
No spam. Unsubscribe anytime.
Kyle Webb presented the county cybersecurity policy and a program of related practices to the Knox County Commissioners on Oct. 21, saying the plan follows the state’s guidance and national frameworks such as NIST and CIS.
He told the board that a recent 911 audit required changes to multifactor authentication at dispatch, and IT deployed authenticator keys for dispatch stations because staff cannot use phones at the consoles. Kyle said the county has completed a computer replacement cycle and is budgeting for 2026 replacements while splitting server duties (domain controllers separated from file servers) to reduce single points of failure.
Kyle described a candidate county password‑management solution that integrates with remote‑support tools and could be offered to staff; he noted exported password backups would be kept offline in a fireproof safe as a contingency. He said the IT team plans to absorb juvenile/probate court servers into the county stack to save roughly $15,000 and centralize support, and that integration work with vendors (for example, a jail commissary vendor replacing an existing supplier) requires careful coordination with the county jail management system.
On vendor oversight and supply‑chain risk, Kyle urged stronger recording and access controls when vendors remotely access county systems so the county can audit vendor activity. He also described increased state requirements about ransomware: if a public entity decides to pay a ransom it must be brought before the public and reported; additionally, counties must notify the Ohio Department of Public Safety within seven days and alert the auditor under the new rules.
Commissioners discussed concerns that public disclosure of ransom decisions could reveal payment willingness to attackers; Kyle responded that the rules aim to increase accountability and that sound preparation and recovery planning reduces the need to pay ransoms. He also noted that cybersecurity plans, risk assessments and incident documentation are explicitly exempted from public‑records disclosure under the state bill to avoid creating operational roadmaps for attackers.
After discussion about annual review and training cadence, the board moved to adopt the cybersecurity policy; the chair called for a voice vote and the policy was approved. Kyle said he would circulate incident‑response templates, risk assessments and training materials to partner jurisdictions and the county will schedule annual reviews as required by the policy.
No fines, penalties or ransom payments were reported during the meeting; the item concludes with the board-approved policy and direction to implement training and vendor oversight measures.

