Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity Policy topic
No spam. Unsubscribe anytime.
Council adopts state-directed cybersecurity policy, including 'no ransom' statement
Summary
Mount Orab adopted Ordinance 1347 as an emergency measure to meet an Ohio requirement to adopt a cybersecurity program and appoint an IT director; the ordinance publicly declares the village will not pay ransom payments and requires annual review of security practices.
Get email alerts on the Cybersecurity Policy topic
No spam. Unsubscribe anytime.
The council adopted Ordinance 1347, an emergency ordinance adopting a cybersecurity program and policy pursuant to a revised Ohio Revised Code Section 9.64. Solicitor Chris Moore explained the state asked local legislative authorities to adopt a generalized cybersecurity statement and to name an internal IT director who will work with municipal IT support. The policy contains a provision publicly declaring participating municipalities will not pay ransomware demands: "It does state that... all the municipalities to adopt this in Ohio are publicly declaring we will not pay ransom," Moore said.
Moore said the policy is a basic administrative framework that requires an annual review to ensure controls and procedures are in place. Because the state set a deadline, council declared the ordinance an emergency and approved it by roll call at the meeting.
What happens next: The council will appoint or designate an internal IT director to oversee implementation of the policy and schedule the annual review required by the ordinance; the emergency adoption ensures compliance with the state timeline.

