Ohio political subdivisions

ORC § 9.64 — in plain language

A practical overview of Ohio cybersecurity program and incident reporting expectations—and how FalconForgeAI can help you organize the information leaders need.

In plain English

Ohio law expects political subdivisions to maintain a cybersecurity program that fits their operations and to report certain cyber incidents to the state within required timeframes. This page gives leaders a simple planning overview. Always confirm specific requirements with your attorney and official state guidance.

ProgramAdopt and maintain a real cybersecurity program
~7 daysOCIC reporting timeframe after discovery
~30 daysAuditor of State reporting timeframe
ProtectCybersecurity records receive special handling under the law

Who this usually covers

Cities, villages, counties, townships, school districts, public libraries, park districts, public authorities, and similar local public organizations—plus the people accountable for technology, finance, and operations.

What your program should cover

  • Important services and systems (finance, utilities, schools, public safety touchpoints, public portals)
  • Core safeguards such as access control, training, and practical monitoring
  • How your organization will respond to a cybersecurity incident
  • How essential services will be restored, including recovery and backups
  • Key vendors and shared services that support your operations
  • Ongoing review so the program stays current as your organization changes

Planning for ransom decisions

Ohio guidance strongly favors a no-ransom approach. If payment is ever considered, local legislative authority typically needs a formal public-interest decision path. Establishing that policy in advance gives leaders a clearer process to follow if a serious incident occurs.

When a reportable cyber incident occurs

Ohio Cyber Integration Center (OCIC)

  • Timing theme: within about 7 days of discovery
  • Where to start: cyber.ohio.gov / OCIC resources
  • Commonly published contacts: 614-387-1089 · OCIC@dps.ohio.gov

Ohio Auditor of State

  • Timing theme: within about 30 days
  • Commonly published contact: Cyber@ohioauditor.gov
  • Use the Auditor’s published reporting process

Planning note: The two reporting paths generally serve different purposes, so organizations should be prepared for both. See the incident readiness guide.

Security records and public records

Materials about cybersecurity programs and incidents are often treated as protected security records. Clear internal rules can help your organization manage what is retained, who has access, and when legal counsel should be involved.

How FalconForgeAI helps you

FalconForgeAI helps Ohio public organizations organize ORC § 9.64 readiness information and turn it into clear, usable material for leadership.

  • Organize your evidence — Policies, inventories, training, vendor files, incident plans, and insurance answers.
  • See what is already in place — Understand the evidence you already have and where additional follow-up would be useful.
  • Set practical priorities — Turn review findings into a manageable list of next steps for the right owners.
  • Prepare for incident reporting — Organize roles, contact trees, and both state reporting paths in advance.
  • Leadership-ready summaries — Give administrators and governing bodies clear, carefully worded information they can review and discuss.

FalconForgeAI helps organize evidence, readiness information, and leadership summaries. Final decisions, official filings, compliance determinations, and legal advice remain with your organization and qualified advisors.

Official sources