Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cyber Security topic
No spam. Unsubscribe anytime.
Moreland Hills council adopts cyber security policy under new state rules
Summary
Moreland Hills council voted unanimously June 10 to adopt a village cyber security policy required by Ohio House Bill 96, adding employee training, incident reporting timelines and a council approval requirement for any ransomware payment.
Get email alerts on the Cyber Security topic
No spam. Unsubscribe anytime.
Moreland Hills on June 10 adopted Ordinance 2026-27, approving a village cyber security policy intended to meet requirements set out by Ohio House Bill 96 and the Ohio Revised Code.
The ordinance requires the village to develop a cybersecurity program consistent with industry best practices (such as NIST or CIS controls), to include training for all employees and procedures for reporting cybersecurity and ransomware incidents. The policy specifies that the village must report incidents to the Department of Homeland Security within seven days of discovery and to the auditor of state within 30 days. It also requires that any ransomware payment be approved by council prior to payment.
Mrs. Irish Glass introduced the item and moved that council consider the ordinance; the council suspended the rules and passed the measure by roll-call vote. The law director noted portions of the policy are confidential and recommended an executive session for discussion of nonpublic details.
The policy follows the village’s audit and insurance review cycle: Finance Director Mr. Shaw told the council earlier in the meeting that the village’s cyber insurance policy expires June 17 and staff has sought renewal quotes. Mr. Shaw estimated annual cyber insurance costs at about $5,000 to $6,000.
Council members said they expect follow-up implementation steps, including employee training and notification procedures required under state law. No additional funding for the program was specified at the meeting.
The ordinance was adopted; council members voted in favor by roll call. Next steps include implementation of the policy and staff reporting back to council on training and any confidential incident response protocols.

