Resources
Free reference material for Ohio township and village officials. Everything here links to its primary source, and nothing asks for your email address. Facts checked against the sources on July 22, 2026.
ORC §9.64: where things stand
Ohio’s local-government cybersecurity law (ORC §9.64, enacted through House Bill 96) took effect September 30, 2025. The adoption deadlines have now passed: January 1, 2026 for counties and cities, July 1, 2026 for townships, villages, and all other political subdivisions.
If your subdivision hasn’t adopted a cybersecurity program yet, the useful response is to adopt one now, not to wait for the next audit cycle — the Auditor of State has said compliance procedures will be incorporated into the Ohio Compliance Supplement, which is what auditors test against.
What the law requires (AOS Bulletin 2025-007): your legislative authority must adopt a cybersecurity program that safeguards the subdivision’s data and IT resources — availability, confidentiality, integrity — consistent with generally accepted best practices (NIST and CIS are the examples AOS names). The program should be tailored to your entity’s size and needs; a township program doesn’t need to look like a county’s.
Self-assessment checklist
The program elements below are from Bulletin 2025-007. This is a plain checklist, not a score — it exists so you can see where you stand.
- Our legislative authority has formally adopted a cybersecurity program (resolution on record)
- We’ve identified our critical functions and cybersecurity risks
- We’ve identified what a breach would actually impact
- The program specifies how we detect potential threats and incidents
- We have procedures for incident communication, analysis, and containment
- We have procedures for repairing affected infrastructure and keeping it secure after an incident
- Every employee has cybersecurity training matched to their duties (annual O-PCI completion satisfies this — see below)
- The people who’d handle an incident know the reporting clocks: 7 days to OCIC, 30 days to the Auditor of State
- Our trustees know a ransom cannot be paid without a formal public vote (resolution or ordinance stating why payment is in the subdivision’s best interest)
If you have an incident right now
Two notifications are required by law after discovering a cybersecurity or ransomware incident:
- Within 7 days: Ohio Homeland Security’s Ohio Cyber Integration Center — OCIC@dps.ohio.gov or 614-387-1089.
- Within 30 days: the Ohio Auditor of State — Cyber@ohioauditor.gov, or the form on the AOS cybersecurity page.
Also worth knowing in the moment:
- If you carry cyber insurance, call your insurer’s incident response line early — that’s what it’s for.
- A ransom demand cannot be paid or complied with unless your legislative authority formally approves it in a public resolution or ordinance.
- Your incident reports and cybersecurity program records are not public records (ORC §9.64) — reporting an incident does not mean publishing it.
Free training that satisfies the law
The state’s O-PCI program (Ohio Persistent Cyber Improvement, run by the Ohio Cyber Range Institute) is free for local governments, role-based (executive / IT / general staff), and — per Bulletin 2025-007 — annual O-PCI training satisfies the §9.64 training requirement. Register at ohiocyberrangeinstitute.org/opci.
There is no reason for a township to pay for compliance training.
Grants: check unspent awards first
Before chasing new money, check whether your subdivision already has a cybersecurity or technology grant award with an unspent balance — that’s often the faster win. Federal SLCGP funding has declined and the most recent CyberOhio round has closed, so prior awards matter more than new applications right now.
Award recipient lists are public record, and subdivisions can generally spend their own awards on outside vendors and services. Current program status and resources: CyberOhio grants & resources.
Primary sources
Everything above, in the original:
- ORC §9.64 — Political subdivision cybersecurity (statute text)
- AOS Bulletin 2025-007 — Adoption of Cybersecurity Program (Aug 27, 2025)
- AOS Cybersecurity page (incident form, additional guidance)
- Ohio Cyber Integration Center (7-day incident reporting)
- O-PCI — Ohio Persistent Cyber Improvement (free training)
- CyberOhio grants & resources