To enact section 9.64 of the Revised Code to require political subdivisions to adopt a cybersecurity program.
HB283 would require Ohio political subdivisions—such as counties, townships, municipal corporations, and other local governmental bodies—to adopt a formal cybersecurity program. The program must protect data, information technology, and IT resources and be aligned with generally accepted cybersecurity best practices, including frameworks such as the National Institute of Standards and Technology (NIST) Cybersecurity Framework and Center for Internet Security guidance. The bill also outlines core elements the program may include, such as identifying critical functions and risks, detecting threats, establishing incident response procedures, repairing affected infrastructure, and providing employee cybersecurity training.
The bill further restricts local governments from paying ransomware demands unless the political subdivision’s legislative authority approves the payment by resolution or ordinance and explains why the payment is in the subdivision’s best interest. It also requires local governments to notify the Ohio Department of Public Safety’s homeland security division within seven days of discovering a cybersecurity or ransomware incident, and to notify the Auditor of State within thirty days. In addition, the bill makes records related to the cybersecurity program and incident reports exempt from public records disclosure, and treats records identifying cybersecurity-related software, hardware, goods, and services as security records.
HB283 would add a new section to the Revised Code imposing statewide cybersecurity planning, incident reporting, and ransomware-payment approval requirements on political subdivisions. It would create new compliance duties for local governments, establish mandatory reporting to state officials after cybersecurity incidents, and expand confidentiality protections for cybersecurity-related records and procurement information. The bill would affect local government operations, public records law, and the handling of cybersecurity procurement and incident response.
Because the bill was only introduced and has no recorded committee votes or transcripts, there is no documented legislative debate or vote-based sentiment in the available materials. Based on the text alone, the measure appears framed as a cybersecurity and local-government resilience bill, with an emphasis on best practices, training, and incident reporting rather than punishment or broad regulatory expansion.
The main potential points of contention are the mandatory nature of the cybersecurity program, the limits on paying ransomware demands, and the reporting obligations imposed on local governments. Local officials may view the bill as adding administrative and compliance burdens, especially for smaller political subdivisions with limited IT resources. On the other hand, supporters would likely emphasize the need for stronger defenses, standardized training, and state visibility into cyber incidents. The public-records exemptions and security-record designation could also draw scrutiny from transparency advocates concerned about reduced public access.