Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

North Bend council reviews cybersecurity policy draft and SWCA recommendations; aims to finalize by July

Village of North Bend Council · May 18, 2026
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Council heard a detailed finance-committee briefing on an updated cybersecurity-policy draft and a Southwest Ohio Computer Association review recommending adoption of a NIST framework, inventorying assets, patch management, multifactor authentication where available, and vendor breach-notification clauses; council debated cost and complexity for measures such as centralized logging and monthly restoration testing and targeted a July finalization date.

Council member Dave presented an updated draft cybersecurity policy and an SWCA (Southwest Ohio Computer Association) review, and led council members through a list of recommendations.

Key recommendations the village discussed included adopting a recognized framework (SWCA suggested NIST), maintaining an inventory of hardware and software assets, strengthening patch management and password practices, implementing multifactor authentication where available, and including vendor breach-notification clauses (72-hour notification) in contracts. Dave cautioned that North Bend’s IT environment is simple and recommended selective adoption of controls that match village needs and resources; he recommended against adopting centralized logging, routine monthly restoration testing requiring separate hardware, and several separate advanced email-authentication systems because of cost and operational complexity.

Council discussed statutory responsibilities: Ohio requires local jurisdictions to notify the state in the event of a serious breach; council asked staff to confirm the village’s insurance coverage and contractual exposure for primary versus secondary breaches. Dave said the policy team aims to finalize the cybersecurity policy by July and requested an editable Word version of the draft for additional edits.

Why it matters: even in a small municipal IT environment, reasonable cybersecurity controls (patching, inventorying, multifactor authentication, vendor breach clauses) reduce the risk of data loss and operational disruption. The council weighed protection benefits against cost and operational burden.

Next steps: staff will incorporate selected recommendations, confirm insurance and vendor-contract coverage for breach events, and return a finalized draft to council for approval by July.