Ohio 2025-2026 Regular Session

Ohio Senate Bill SB203

Caption

Require political subdivisions to adopt a cybersecurity program

Impact

If enacted, SB203 will have significant implications for state and local laws concerning data management and cybersecurity practices. Political subdivisions will be required to establish and implement a cybersecurity program that follows established best practices. The bill details procedures for managing cybersecurity incidents, including the necessity of legislative approvals before responding to ransomware demands. The shift towards proactive cybersecurity measures is intended to ensure better protection of public data and enhance operational resilience against potential attacks.

Summary

Senate Bill 203, introduced by Senator Schaffer, aims to mandate that political subdivisions in Ohio adopt a comprehensive cybersecurity program. The bill addresses the growing concerns over cybersecurity threats, including ransomware incidents, and establishes requirements for how local governments should respond to such incidents. The bill defines a 'cybersecurity incident' broadly, encompassing various forms of data breaches and disruptions, and sets out clear guidelines for political subdivisions regarding the handling and reporting of these incidents.

Sentiment

The general sentiment towards SB203 appears to lean positively, as many stakeholders recognize the necessity of empowering local governments to better protect their information technology systems. Advocates argue that such measures are essential in today’s digital age where cybersecurity threats are increasingly prevalent. However, there may also be some dissent regarding the adequacy of resources and support for political subdivisions to effectively implement these requirements, especially in smaller jurisdictions that may lack the necessary infrastructure.

Contention

One notable point of contention surrounding the bill includes the potential financial and administrative burden on smaller political subdivisions, which may struggle to meet the requirements set forth. Critics may argue that while the intention of the bill is commendable, the actual implementation could divert critical resources away from other essential services. Additionally, the stipulation that no ransom payments can be made without legislative approval could create delays in response time during a cybersecurity crisis, presenting a possible challenge for local governments in effectively managing incidents.

Companion Bills

No companion bills found.

Similar Bills

CA SB265

Cybersecurity preparedness: critical infrastructure sectors.

IA HSB15

A bill for an act creating a cybersecurity unit within the office of the chief information officer.

CA SB892

Cybersecurity preparedness: food and agriculture sector and water and wastewater systems sector.

CA AB1242

Information security.

CA AB276

Local educational agencies: charter schools.

IA HF698

A bill for an act establishing the cybersecurity simulation training center at the Iowa state university of science and technology, and including contingent effective date provisions.(Formerly HF 139, HSB 14.)

CA AB405

Public postsecondary education: community college districts: baccalaureate degree cybersecurity pilot program.

CA AB569

California State University: Cybersecurity Regional Alliances and Multistakeholder Partnerships Pilot Program.