Ohio Revised Code Section 9.64 requires a school district as a political subdivision to adopt a cybersecurity program that safeguards its data, information technology, and information technology resources. The Auditor of the State has set a deadline of July 1, 2026 for political subdivisions to implement a compliant cybersecurity program. See Bulletin 2025-007, p. 2 (Aug. 27, 2025). If your district has not yet adopted a cybersecurity program and policy, here are four things you need to know in anticipation of the July 1st deadline.
(1) The Cybersecurity Program Should Address Your School District’s Unique Needs
R.C. 9.64 is meant to help mitigate the risks of a “cybersecurity incident,” as defined in R.C. 9.64(A)(1). While R.C. 9.64 offers some guidance as to the minimum requirements of a compliant cybersecurity program, districts retain discretion to implement a program that fits their unique needs – there is no one-size-fits-all template or program that will be effective for every district.
Nevertheless, a compliant cybersecurity program must be consistent with generally accepted best practices for cybersecurity, such as the National Institute of Standards and Technology Cybersecurity Framework, or the Center for Internet Security Controls. A district’s cybersecurity program may also identify potential cybersecurity risks and impacts of a cybersecurity breach, specify mechanisms to detect potential threats, create procedures to contain cybersecurity incidents, or establish cybersecurity training requirements for all district employees. See R.C. 9.64(C)(1)-(6).
A district has flexibility to work with a third-party vendor to adopt a cybersecurity program, or develop a cybersecurity program in-house. Either way, your district should adopt a program that is tailored to its unique needs and educational environment.
(2) Your School District Should Not Publicly Select Its Specific Cybersecurity Program
Although districts must adopt a cybersecurity policy, it does not follow that your district should publicly adopt and disclose the specific cybersecurity program of its choosing. Instead, a district can adopt a generalized cybersecurity policy that may be viewed as a “statement of intent” to comply with R.C. 9.64’s requirements, and keep the particulars of the program confidential. Indeed, guidance from CyberOhio confirms that it is best practice not to include specific program information in a public resolution that could give cyber attackers information that may help them target your cybersecurity systems.
Moreover, R.C. 9.64(E) makes clear that “any records, documents, or reports related to the cybersecurity program and framework” concerning R.C. 9.64(C), and the reports of a cybersecurity or ransomware incident under R.C. 9.64(D), are not public records under R.C. 149.43. And any record identifying cybersecurity-related software, hardware, goods, and services that a school district is or may use (including vendor name, product name, project name, or project description) is deemed a “security record” under R.C. 149.433, and therefore exempt from public disclosure.
In light of the risks posed by disclosing details of a district’s cybersecurity program, a district should keep the specifics of its cybersecurity program confidential. In addition, districts should consult with legal counsel prior to responding to any public records requests concerning its cybersecurity program or program vendors.
(3) A Board of Education Must Approve Any Payment Towards a Ransomware Demand
R.C. 9.64(A)(3) defines “ransomware incident,” as a malicious cybersecurity incident where a person or entity gains unauthorized access to data, and demands a ransom to prevent publication of or restore access to the stolen data. If a district is faced with a ransomware incident and corresponding demand, the district cannot comply unless the school district board of education formally approves the ransomware payment or compliance with the demand. R.C. 9.64(B). The board of education must pass a resolution that specifically states why the payment or compliance with the ransom demand is in the best interest of the district. Id.
(4) The Board of Education Must Timely Report a Cybersecurity or Ransomware Incident to Federal and State Authorities
In the event of a cybersecurity or ransomware incident, a school district board of education has mandatory reporting obligations under R.C. 9.64(D). A board of education must timely notify, as soon as possible, both (1) the Executive Director of the Division of Homeland Security within the Department of Public Safety, no later than 7 days after discovery of the incident, and (2) the Auditor of the State, no later than 30 days after discovery of the incident.
The Auditor of the State is expected to begin testing compliance in 26FY Local Government Audits, which may include school districts’ compliance with R.C. 9.64. With the upcoming July 1st deadline, districts who have not yet implemented a tailored cybersecurity program should do so as soon as practicable.
Weston Hurd’s Education Law team is available to help guide your district on compliance with R.C. 9.64. If you have any questions, please contact Rebecca Singer-Milller, or any of the attorneys in our Education Law Group.


