Ohio Law Incentivizes Businesses for Implementing Cybersecurity Programs

Ohio Law Incentivizes Businesses for Implementing Cybersecurity Programs

Ohio organizations that reasonably conform to established cybersecurity programs may be incentivized.

Ohio Gov. John Kasich has signed Senate Bill 220, also known as the Ohio Data Protection Act, making it the first law in the national which incentivizes businesses to implement certain cybersecurity controls by providing them with an affirmative defense.

Under the Act, eligible organizations may rely on their conformance to certain cybersecurity frameworks as an affirmative defense against tort claims in data breach litigation, according to Columbus Business First. The act is intended to provide organizations with a legal incentive to implement written cybersecurity programs.

In order to qualify, Ohio organizations much implement a written cybersecurity program designed to protect the security and confidentiality of personal information, protect against anticipated threats or hazards to the security and integrity of personal information and protect against unauthorized access to and acquisition of personal information that is likely to result in a material risk of identity theft or fraud.

Additionally, the organization must "reasonably conform" to one of the following cybersecurity frameworks:

  • National Institute of Standards and Technology's (NIST) Cybersecurity Framework
  • NIST special publication 800-171, or 800-53 and 800-53a
  • Federal Risk and Authorization Management Program's Security Assessment Framework
  • Center for Internet Security's Critical Security Controls for Effective Cyber Defense
  • International Organization for Standardization (ISO)/International Electrotechnical Commission’s (IEC) 27000 Family – Information Security Management Systems Standards.

About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

  • A Look at AI

    Large language models (LLMs) have taken the world by storm. Within months of OpenAI launching its AI chatbot, ChatGPT, it amassed more than 100 million users, making it the fastest-growing consumer application in history. Read Now

  • First, Do No Harm: Responsibly Applying Artificial Intelligence

    It was 2022 when early LLMs (Large Language Models) brought the term “AI” into mainstream public consciousness and since then, we’ve seen security corporations and integrators attempt to develop their solutions and sales pitches around the biggest tech boom of the 21st century. However, not all “artificial intelligence” is equally suitable for security applications, and it’s essential for end users to remain vigilant in understanding how their solutions are utilizing AI. Read Now

  • Improve Incident Response With Intelligent Cloud Video Surveillance

    Video surveillance is a vital part of business security, helping institutions protect against everyday threats for increased employee, customer, and student safety. However, many outdated surveillance solutions lack the ability to offer immediate insights into critical incidents. This slows down investigations and limits how effectively teams can respond to situations, creating greater risks for the organization. Read Now

  • Security Today Announces 2025 CyberSecured Award Winners

    Security Today is pleased to announce the 2025 CyberSecured Awards winners. Sixteen companies are being recognized this year for their network products and other cybersecurity initiatives that secure our world today. Read Now

  • Empowering and Securing a Mobile Workforce

    What happens when technology lets you work anywhere – but exposes you to security threats everywhere? This is the reality of modern work. No longer tethered to desks, work happens everywhere – in the office, from home, on the road, and in countless locations in between. Read Now

New Products

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction.

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities