1. Written program
Not a forgotten PDF. A program your organization has formally adopted and can still find.
For Ohio local leaders
A short guide for public leaders who need to understand Ohio’s cybersecurity program expectations—and how FalconForgeAI helps you get ready for review.
HB96 is the policy conversation many Ohio leaders use when they say “cyber is no longer optional.” The day-to-day rules public organizations work with are largely under ORC § 9.64: have a real cybersecurity program, keep it current, and know how to report incidents on time.
Administrators, fiscal officers, IT and security staff, board and council members, school and library leaders, park districts, public authorities, and anyone who has to answer: “Are we prepared?”
Not a forgotten PDF. A program your organization has formally adopted and can still find.
It matches how you actually run finance, utilities, schools, public safety, or public services.
Who gets called, who decides, and who talks to the state if systems go down.
Staff who handle email, payments, and records get practical cyber awareness—not a one-time checkbox.
You know which companies run critical systems and what proof they provide.
Backups and restore plans are tested, not just “configured somewhere.”
| Who | Typical timing theme | Why it matters |
|---|---|---|
| Ohio Cyber Integration Center (OCIC) | About 7 days after discovery | State cyber notification path |
| Ohio Auditor of State | About 30 days after discovery | Separate reporting path—do not assume one filing covers both |
| Your insurer / key vendors | Per contract | Late notice can create extra problems |
Details: Incident readiness guide and ORC § 9.64 summary.
We help local leaders turn “we think we’re okay” into a clear, reviewable picture.
We help you see and organize the story. Your leaders still decide. We do not file OCIC or Auditor reports, certify compliance, or give legal advice.
If your program lives in email threads and shared drives, we can help you make it clear enough for leadership review.