Ohio · House Bill 96 · ORC 9.64

Ohio law now requires a cybersecurity program.

House Bill 96 wrote that requirement into ORC 9.64 for every political subdivision in the state. Both compliance dates have passed. If your subdivision has nothing adopted yet you are in very ordinary company, and the fix is smaller than the silence around it suggests: the work that satisfies the statute is the ordinary care your servers, directory, backups, storage and network need anyway. I do that work every month and produce the written record that it kept happening.

The short version

What the statute actually asks of you.

Five things, and none of them requires buying a product. This is my reading as the person who would build it, and your solicitor owns the legal reading.

Counties and cities
January 1, 2026

Passed. That date is now well over six months behind us.

Everyone else
July 1, 2026

Passed. Townships, villages, and school districts were the second wave.

Adopt

A written program, adopted by vote

Your legislative authority adopts a program safeguarding the availability, confidentiality and integrity of the subdivision's data and IT. The vote is theirs. The document is what I write.

Consistent with

Recognized practice, which the statute names

It points at the NIST Cybersecurity Framework and the CIS Controls. CIS Implementation Group 1 is scoped for small staffs with nobody dedicated to security, and it is a short list of ordinary infrastructure work done carefully.

Suggested

Six components, prefaced "may include"

The six elements everyone quotes are introduced with "may include, but are not limited to". I read that as suggestive, not mandatory. I build against all six anyway, because they describe the work regardless.

Nobody named

No designated officer is required

Every duty sits with the legislative authority as a body. Naming an accountable person is good framework practice and a sensible thing to do. It is not something the statute makes you do, whatever anyone selling you a title says.

Report

Two clocks, both from discovery

An incident is reported to the Ohio Department of Public Safety within seven days and to the Auditor of State within thirty. Both run from when you discover it, not from when you resolve it, which is the most commonly misread part of the section.

Shielded

These records are not public records

Program documents and incident reports are exempt under 9.64(E), and records naming your cybersecurity vendors are security records under 9.64(F). Publishing your own program would be a mistake, which is why mine is not on this website either.

Enforcement is an audit finding, not a fine

The section carries no direct penalty. What it carries is the Auditor of State, and a finding against a subdivision with nothing adopted is a public, political problem that outlasts the budget year it was written in. That is the real pressure, and it is also why paper alone does not settle the matter: what gets examined a year later is whether anything has been happening since the vote.

What the retainer covers

The program is the paperwork. This is the work.

Read 9.64(C) closely and it describes ordinary infrastructure maintenance written in framework vocabulary. Security is part of it and it is not the whole of it. The same nine jobs run for a township as for a machine shop, and the program document is what they produce.

Backups

Verified, and restored for real

Jobs checked and actual restores performed on a schedule. This is the single control that decides how a ransomware week ends.

Directory

Domain and core services

Active Directory, Group Policy, DNS and DHCP reviewed for clean replication and stale accounts. The layer that makes Monday morning logins work.

Storage

Shares and capacity

Minutes, resolutions, permits and personnel files live in shared drives. Capacity tracked before it runs out, permissions reviewed so a departed clerk is not still holding the keys.

Access

Accounts and who still has one

Named accounts reviewed for people who have left, shared logins, and administrative rights nobody remembers granting.

Perimeter

Firewall and remote access

Rules, port forwards and VPN access read line by line. Stale rules flagged, risky exposure closed, every change written down.

Patching

Servers and hypervisors

Updated in scheduled windows outside office hours, with a rollback position staged before anything is touched.

Monitoring

Uptime and disk health

Capacity, uptime and drive health reviewed monthly, so a weakening disk gets replaced on a purchase order instead of on an emergency.

Security

Intrusion and filtering review

Intrusion detection reviewed, DNS-level malware filtering kept current, and a plain summary of what actually reached your network.

Reporting

The monthly written report

What was verified, patched, found, and what needs a decision. Filed month after month it becomes the evidence an Auditor of State examination asks for.

How the two line up

The program elements are the same work, in the auditor's vocabulary.

The statutory element is on the left. The concrete recurring work is on the right. Nothing in the right column exists because of the statute; it is what careful infrastructure care looks like anywhere.

What the section says
What I build and run
9.64(C), opening sentence

Consistent with generally accepted best practices

The program must answer to recognized practice, and the statute names NIST CSF and the CIS Controls.

Written against the framework the auditor reads

Your program document is drafted against the CIS Controls implementation group meant for small entities, cross-referenced to the NIST functions. That vocabulary is the one the state points at, so the document answers the question before it is asked.

9.64(C)(1) and (2)

Critical functions, risks, and breach impacts

Name what matters, name the risks against it, and say what a failure would actually cost.

The written baseline

Onboarding produces a document mapping the environment host by host, stating the risks in language a trustee can read aloud, and saying what losing each piece would mean for the office. A real sample baseline is here (PDF).

9.64(C)(3)

Mechanisms to detect threats and events

Specify how potential threats and cybersecurity events get noticed at all.

Deterministic monitoring, read by a person

Uptime, disk health, and security monitoring on standard tooling, tuned against what actually reaches your network, and reviewed on a schedule by a human being. Alerting is deterministic by design. Nothing probabilistic sits in the detection path.

9.64(C)(4)

Communication channels, analysis, containment

Specify the procedures for opening communications, analyzing an incident, and containing it.

Procedures you hold, with the clocks in them

I write the containment and communication procedures and the runbook, with the seven-day and thirty-day notification steps already sitting in the sequence with the offices named. The documents live with you and name your own people.

9.64(C)(5)

Repair, and security afterward

Establish how impacted infrastructure gets repaired and how security is maintained once the incident is over.

Backups restored for real, on a schedule

A backup nobody has restored from is an assumption. Restores get performed and verified as routine work, and the result is written down each time, which is what puts evidence behind a recovery plan.

9.64(C)(6)

Training for every employee

Requirements scaled to each employee's duties, in frequency, duration, and detail.

Free, and it was never in my fee

The statute says so itself. Your program document points at the state training and the Ohio Persistent Cyber Initiative, and the box is checked at zero cost. Details in the next section, because this one deserves its own space.

The program, in operation

Adopted is a single day. Operating is every month.

An adopted-then-ignored program is the kind an Auditor of State finding catches, because the finding turns on whether anything is actually happening.

The monthly health report

Every month closes with a written record of what was verified, patched, found, and recommended. Twelve of those in a row are standing evidence that the program your board adopted has been running ever since. A consultant who hands over a binder and leaves has nothing to put in that folder. A real sample report is here (PDF).

Before you spend anything

The training requirement is already paid for.

Division (C)(6) requires training for all employees, scaled to their duties, and then answers the question of where it comes from. The statute says annual training provided by the state, and training provided for local governments by the Ohio Persistent Cyber Initiative of the Ohio Cyber Range Institute, satisfy the requirement.

So do not buy a training subscription for this. Your program document points at whichever programme applies and records who completed it, and that box is ticked at no cost. Training was never part of my fee either, so telling you this costs me nothing and saves you a recurring bill.

Where the lines are

The parts that stay yours, on purpose.

Some of what the section asks for is not mine to do. Saying so plainly is part of doing the rest honestly.

Adoption is an act of your legislative authority.

The statute says the legislative authority shall adopt the program. I write it and I operate it. The vote belongs to your commissioners, council, trustees, or board, and I do not take that step for you or pretend it is a formality.

The two notifications are legally the subdivision's.

The seven-day report to the Department of Public Safety and the thirty-day report to the Auditor of State are duties the statute places on your legislative authority. What I can do is pre-wire both clocks into your written procedures, with the offices, the timing, and the sequence settled while everyone is calm, so nobody is improvising the deadline math during an incident.

I do not give legal advice or certify compliance.

I am an infrastructure engineer. I build and run the technical program the section describes and produce the evidence that it is running. Whether that satisfies ORC 9.64 for your subdivision is a determination for your counsel and your legislative authority, and this page is not it.

This is program work and preparation, on a schedule.

Everything described here is built, documented, and operated on planned cadence. There is no emergency line on this site and no response clock attached to anything on this page, which is deliberate and stated in the contract as plainly as it is here.

No promise about outcomes, ever.

Nobody can promise a subdivision will not be breached, and anyone who does is selling something. What this work does is cut down the surface you present and hold an intruder in place if one gets in. It also makes a tested restore the realistic answer to a ransom demand.

Where to start

Find out where you actually stand.

Every engagement opens the same way, with a written baseline of what you actually have.

The baseline answers three questions in writing: what the statute asks of your subdivision, what you have in place today, and what is missing, item by item, with what each one takes to close. It carries a flat fee. Go ahead within 90 days and that fee comes straight off your first invoice. If you do not, the document is still yours, which is why it carries a price at all.

From there it is the ordinary work, every month, on a schedule, with a written report your board and your auditor can read. Retainers are published by environment size, with no hourly rate anywhere. The full pricing is on the main page.

I am selling the running of it. A binder handed over at the door is the thing auditors are learning to look past. What holds up is a program somebody operates every month and evidences in writing, which is why this is monthly work. The program document and any remediation are quoted flat, in writing, before anything starts.

Start with a written note

Reading this from outside Ohio?

You are in the right place. Ohio is just the state I have worked through in the most detail. Ohio put a statute behind an obligation that public entities everywhere already carry, which made it worth a page of its own. The underlying work does not change at the state line, and neither does who I serve, in or out of government.

The general government page covers the same program work written against NIST CSF and the CIS Controls instead of one state's code, which is the vocabulary nearly every jurisdiction's requirements point at in the end.