HB 96 / Budget Bill (2025-26)
ORC § 9.64 requires every Ohio school district (and other political subdivisions) to adopt a cybersecurity program that safeguards data, IT systems, and IT resources. The program must be consistent with generally accepted best practices — the statute names NIST or CIS. Four operative duties: (1) legislative-authority-adopted cybersecurity program in place by July 1, 2026; (2) ransomware payments prohibited unless the legislative authority formally approves via resolution or ordinance (§ 9.64(B)); (3) cybersecurity incidents reported to the executive director of the Ohio Division of Homeland Security within 7 days of discovery, and to the Auditor of State within 30 days (§ 9.64(D)); (4) cybersecurity training required for all employees, with frequency and detail scaled to each employee's duties (§ 9.64(C)(6)). Auditor of State begins compliance checks July 1, 2026.