Ohio Auditor Keith Faber spends a lot of time on the road. As the state’s chief compliance officer, he makes regular appearances across 88 counties, and at least two each week include cybersecurity presentations.
In fact, Faber discussed his work recently with Government Technology while literally on the road to Lima, Ohio, which is located north of Dayton. Faber easily quotes cyber-related financial losses — millions of dollars in some cases — affecting both businesses and local government, and he is eager to put a stop to them. And he now has a new means of doing it.
Last year, Ohio lawmakers gave Faber a way to press his message. House Bill 96 created Revised Code 9.64, which took effect last September, and it requires counties, cities and townships to adopt cybersecurity programs to protect data and IT systems. Counties and cities had until Jan. 1, 2026, while other covered entities had until July 1 to comply. The bill also requires cybersecurity training to be in place.
This was the first year that local governments were required to report their own cyber and ransomware incidents to Ohio Homeland Security within seven days of discovery, as well as to the Auditor of State within 30 days. The law also made it illegal for a local government to pay a ransom unless its legislative body formally approved the payment, explaining why making it is in the public’s best interest.
“Success is relative,” Faber said. “The fact of the matter is we have to be correct 100 percent of the time. Scammers and hackers only need to be right once, and, unfortunately, we’ve had roughly $15 million worth of losses across Ohio recently. That’s the government, and then consumers are hit with even more.”
Faber said Ohio isn’t alone in this, and that cybersecurity incidents there haven’t always been disclosed, making the total losses difficult to quantify.
“What we did was identify that we had an ongoing problem — that some communities weren’t reporting, or certainly weren’t reporting promptly,” he said. “We got the Legislature to do two things: one, to require everybody to take fraud training, and two, our organization has the force of law to audit and actually try and stop these vendor redirects and payroll redirects [from governments], and for the most part, it’s helped dramatically.”
Faber is referring in part to business email compromise, in which criminals impersonate vendors or payees to redirect payments. One somewhat recent example of this was in 2024, when Arlington, Mass., lost $446,000 after scammers persuaded the city to switch a vendor from check payments to electronic funds transfer.
Faber said one safeguard now in place is to require any request to change a payee, bank account or other payment information to be verified in person. He said entities that have adopted that practice have prevented losses, while those that haven’t continue to have problems.
“Is it onerous? Yes, but we know in many cases taking that extra step can stop huge losses,” he said.
More broadly, the law requires covered entities to submit cybersecurity programming to the auditor’s office and to expect an audit of those plans. Covered entities include cities, counties, school districts, villages, townships and other local government bodies.
“I have 800 employees in 11 offices,” Faber said. “I do something on cyber fraud at least a couple of times a week, ranging from your local chamber of commerce to school business officials and everything in between.”
Earlier this year, interim state CISO Matt Hemker also shared some of the ways the state was supporting local cybersecurity and HB 96 implementation. By February, CyberOhio had held seven webinars and presented at conferences, events and other meetings, reaching at least 6,000 people. Local resources also include the Ohio Persistent Cyber Improvement program and the Ready-Made Security Program through the Ohio Cyber Reserve.
Hemker also said the Ohio Persistent Cyber Improvement Program provides local governments with tiered cybersecurity awareness and training. By February, more than 21,000 local government employees had participated or were participating in the program, representing jurisdictions with more than 7 million Ohio residents.
Beyond planning and training, Faber said local governments need to test whether their cybersecurity preparations will work. He said he advised one county that wasn’t testing data recovery that a $3,500 testing fee was a hedge against hundreds of thousands of dollars in potential losses. He also stressed that entities must act quickly upon discovering a cyber intrusion, saying a college recently recovered a large sum when they brought in federal help.
“Is it going to be perfect? No, but it’s a process. We’re better than we were before the law passed,” Faber said. “We’re going to continue to encourage and train and support people to get 100 percent compliance. We’re moving in the right direction.”
