06/02/2026
Audits are happening right now, and most Ohio local governments still don't realize what's on the line.
Since January 1, 2026, the Auditor of State has been checking every political subdivision in Ohio for compliance with ORC 9.64, the cybersecurity mandate that quietly entered law through House Bill 96 of the 136th General Assembly.
If you serve on a township board, city council, school board, or county commission, your subdivision is now required to have:
β A formal, adopted cybersecurity program
β Six specific program elements covering risk, detection, response, recovery, and training
β A documented process to notify Ohio Homeland Security within 7 days of an incident
β A documented process to notify the Auditor of State within 30 days
The piece that catches most boards off guard? You cannot pay a ransom. Not without your legislative authority passing a formal resolution stating why payment is in your best interest. No exceptions.
If you don't have a compliant program when the auditor reviews your subdivision, expect an item of noncompliance on your next audit.
The good news is that compliance is achievable with a clear roadmap. We've built a policy template aligned to NIST CSF and CIS Controls that any Ohio political subdivision can adopt by resolution, along with a one page summary to share with your board.
If you want a copy, send me a message.