Key Takeaways
- Ohio House Bill 96, signed by Governor Mike DeWine on June 30, mandates that all political subdivisions adopt a cybersecurity program aligned with recognized best practices.
- Villages and townships must comply by July 1, while counties and cities have until January 1 of the following year.
- Fairport Harbor Village Council has approved a cybersecurity policy that incorporates the NIST Cybersecurity Framework and the CIS Controls.
- The village’s IT vendor, CMH Solutions, will lead implementation, documentation, and an annual review to maintain state‑required alignment.
- The policy expressly prohibits ransomware payments unless the Village Council takes formal legislative action approving the payment as being in the village’s best interest.
- Cybersecurity incidents must be reported to the Ohio Cyber Integration Center within seven days and to the Ohio Auditor’s Office within thirty days of discovery.
- Records pertaining to the cybersecurity program, incident reports, and purchases of security hardware/software are to be kept confidential.
- The initiative aims to strengthen Fairport Harbor’s resilience against cyber threats while ensuring transparency and accountability to state oversight bodies.
Overview of Ohio House Bill 96 and Statewide Cybersecurity Mandate
Ohio House Bill 96, enacted in the summer of 2024, represents a statewide effort to elevate the cybersecurity posture of all local government entities. The legislation was signed by Governor Mike DeWine on June 30 and became effective three months later, on September 30. Its core provision requires every political subdivision—including villages, townships, cities, and counties—to “adopt a cybersecurity program consistent with best practices to protect data, information technology and information technology resources.” By setting a uniform baseline, the bill seeks to mitigate the growing risk of cyberattacks that could disrupt essential services, compromise resident data, and incur significant financial losses. The law also tasks the Ohio Department of Public Safety’s Ohio Cyber Integration Center with providing guidance and overseeing compliance reporting.
Implementation Timeline for Different Types of Political Subdivisions
Recognizing the varied capacities of local governments, HB 96 establishes staggered deadlines for compliance. Villages and townships, which often have smaller IT staffs and budgets, must adopt and implement their cybersecurity programs by July 1 of the year following the bill’s effective date. Counties and cities, typically possessing more robust administrative structures, are granted a longer window, with a compliance deadline of January 1 in the subsequent calendar year. This tiered approach allows smaller jurisdictions like Fairport Harbor Village to focus on immediate action while giving larger entities time to scale their programs appropriately. The law also encourages ongoing annual reviews to ensure that cybersecurity measures remain current with evolving threats and technological advancements.
Fairport Harbor Village Council’s Adoption of Cybersecurity Policy
In response to the mandate, the Fairport Harbor Village Council convened a special session and unanimously approved a resolution to adopt a formal cybersecurity policy. The resolution explicitly states that the program will be implemented in accordance with generally accepted cybersecurity best practices, referencing both federal and industry‑recognized standards. By codifying the policy through council action, the village ensures that the initiative carries the weight of local law, facilitating enforcement, budget allocation, and accountability. The approval also signals to residents and stakeholders that the village is taking proactive steps to safeguard its digital infrastructure and the personal information it handles.
Alignment with National Cybersecurity Frameworks and Standards
The village’s cybersecurity program is anchored to two widely respected frameworks: the National Institute of Standards and Technology (NIST) Cybersecurity Framework and the Center for Internet Security (CIS) Controls. The NIST framework offers a flexible, risk‑based approach organized around five core functions—Identify, Protect, Detect, Respond, and Recover—allowing Fairport Harbor to tailor its defenses to its specific assets and threat landscape. Complementarily, the CIS Controls provide a prioritized set of actionable safeguards, such as inventory management, secure configuration, and continuous vulnerability assessment, that address the most common attack vectors. By aligning with these standards, the village not only satisfies the state’s legal requirement but also positions itself to qualify for potential grant opportunities and to benchmark its performance against peers.
Role of CMH Solutions in Program Implementation and Oversight
Fairport Harbor has contracted CMH Solutions, its established IT vendor, to spearhead the operational aspects of the cybersecurity program. CMH Solutions will coordinate directly with the mayor and the village administrator to oversee the deployment of security technologies, develop detailed documentation of policies and procedures, and conduct an annual review to verify continued alignment with both state mandates and evolving best practices. This partnership leverages the vendor’s technical expertise while maintaining village leadership’s strategic oversight. The arrangement also includes provisions for staff training, incident response drills, and periodic penetration testing, ensuring that the program remains dynamic rather than a static checklist.
Provisions on Ransomware Payments and Council Approval Process
A critical component of the village’s policy addresses the increasingly prevalent threat of ransomware. The resolution explicitly prohibits any ransomware payment or other compliance with ransom demands unless the Village Council formally approves the transaction through legislative action. Such approval must be accompanied by a clear justification explaining why the payment is deemed to be in the best interest of Fairport Harbor, taking into account factors such as the potential impact on public safety, the availability of decryption alternatives, and the likelihood of data recovery. This requirement introduces a layer of democratic oversight, discouraging impulsive decisions that could inadvertently fund criminal enterprises while ensuring that, in extraordinary circumstances, the council can deliberate and document its rationale.
Reporting Requirements to State Agencies and Timelines
Transparency and timely communication with state authorities are mandated by HB 96, and Fairport Harbor’s policy reflects these obligations. Upon discovery of a cybersecurity incident, the village must report the event to the Ohio Department of Public Safety’s Ohio Cyber Integration Center within seven days. This rapid notification enables the state to offer immediate assistance, coordinate regional response efforts, and gather threat intelligence that can benefit other jurisdictions. Additionally, a more detailed incident report must be submitted to the Ohio Auditor’s Office within thirty days of discovery, providing a comprehensive account of the breach, mitigation steps taken, and any lessons learned. These reporting timelines are designed to balance the need for swift action with the necessity of thorough documentation.
Confidentiality and Record‑Keeping Obligations
To protect sensitive information and maintain the integrity of ongoing investigations, the village’s policy stipulates that records related to the cybersecurity program, incident reports, and the acquisition of cybersecurity software and hardware must be kept confidential. This confidentiality extends to both internal village documents and any materials shared with third‑party vendors or state agencies, except where disclosure is required by law or necessary for coordinated response efforts. Safeguarding these records helps prevent adversaries from gleaning insights into the village’s defenses and ensures that personal data of residents remains protected in accordance with applicable privacy statutes.
Anticipated Benefits and Challenges for Fairport Harbor
Implementing a structured cybersecurity program offers Fairport Harbor several tangible benefits. Enhanced detection and response capabilities can reduce the likelihood of prolonged service disruptions, thereby preserving public trust and maintaining the continuity of essential services such as water utilities, emergency communications, and public records access. The policy’s emphasis on regular training and awareness campaigns also empowers village staff to recognize phishing attempts and other social engineering tactics, thereby reducing human‑error‑related vulnerabilities. However, the initiative also presents challenges, including the need to allocate limited financial resources toward security tools and expert consultations, the ongoing effort to stay abreast of rapidly evolving threats, and the potential complexity of integrating new technologies with legacy systems. Successful navigation of these hurdles will depend on sustained commitment from village leadership, effective collaboration with CMH Solutions, and active participation from all municipal employees.
Broader Implications for Ohio Local Governments and Future Steps
Fairport Harbor’s proactive adoption of a compliant cybersecurity program serves as a model for other small municipalities across Ohio that face similar resource constraints. By demonstrating how a village can leverage state mandates, align with national frameworks, and partner with a competent IT vendor, the resolution provides a replicable pathway for achieving cyber resilience. Looking ahead, the village plans to participate in regional information‑sharing forums hosted by the Ohio Cyber Integration Center, conduct annual tabletop exercises with neighboring jurisdictions, and explore grant opportunities administered by the Ohio Department of Administrative Services to further bolster its defenses. As cyber threats continue to grow in sophistication, Fairport Harbor’s commitment to continuous improvement will be essential in safeguarding both its digital assets and the well‑being of its residents.

