Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Euclid council adopts disaster recovery and cybersecurity incident response plan; city has no cyber insurance
Summary
Council adopted a disaster recovery and cybersecurity incident response plan required by recent Ohio law and was told the city does not carry cyber insurance; if ransomware payments were needed, payments would come from the general fund.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Euclid City Council on Nov. 17 adopted a disaster recovery plan and a cybersecurity incident response synopsis required under a recent change in Ohio law (Ohio Revised Code 9.64). The measure (Resolution 116-25) passed by roll call.
Administration said the version attached to the resolution is a synopsis of a larger document that lays out steps the city would take in the event of a cybersecurity incident. Under the law cited by administration, any ransom payment would require legislative approval before the city could make such a payment.
"It is a synopsis of a much larger document that lays out the steps that would be taken by the administration in the event there was a cybersecurity event," the administration representative said.
Councilwoman Hanum asked whether ransomware would be covered by insurance or require a separate fund; administration responded that the city does not have cyber insurance and would have to use the general fund to cover payments.
A resident later asked whether the city would explore cyber insurance; administration said premiums have historically made coverage cost-prohibitive at renewal and the city evaluates insurance annually.
The resolution passed on a roll-call vote. There were no specific funding actions to purchase insurance at the meeting; council directed no additional immediate fiscal action beyond adoption of the plan.
