That is one state. Multiply it across the country and you get a picture that should concern every executive, board member, and city administrator reading this: cybersecurity is no longer optional, and named accountability is the new standard.
The laws are specific. The deadlines are real. The audits are coming. The question is whether your organization is building toward compliance or waiting to get caught.
The Law Has Caught Up to the Threat
State and Federal Mandates
Ohio Revised Code Section 9.64, signed into law in 2025, requires every political subdivision in the state to establish and maintain a formal cybersecurity program. Counties and municipalities faced audit beginning January 1, 2026. All remaining subdivisions follow by July 1, 2026.
Requires a formal cybersecurity program for every political subdivision: townships, school districts, and special districts. Prohibits ransomware payments without a formal board motion. Removes cybersecurity plans from public records to reduce attacker intelligence. Mandates incident reporting to the Ohio Cyber Integration Center within 7 days of discovery.
AUDIT LIVE: JAN 1, 2026The Florida Cybersecurity Act sets mandatory standards for state agencies, aligned to NIST CSF. The Local Government Cybersecurity Act extends identical obligations to counties and municipalities. Chapter 60GG-2 defines exactly how public sector organizations must manage cybersecurity risk.
NIST CSF ALIGNEDFully effective since June 2023. Requires every non-bank financial institution to designate a Qualified Individual who oversees the information security program and reports to the board at least annually. Penalties reach $100,000 per violation and $43,000 per day for each consent violation. The breach notification requirement, enforceable since May 2024, now posts violations on a public FTC database.
PENALTY: $100K / VIOLATIONCovers banks, credit unions, insurance companies, and other NYDFS-regulated entities. Requires a formally designated CISO who reports to the board annually. The CEO and CISO must co-sign annual compliance certifications. The final compliance phase, including MFA requirements, took effect November 1, 2025. NYDFS has pursued multi-million-dollar enforcement actions when certifications proved inaccurate.
FINAL PHASE: NOV 1, 2025Why Named Accountability Is the Central Requirement
The CISO Mandate
Read through the laws above and you find a phrase in almost every one of them: a designated, named individual who owns cybersecurity. Not a committee. Not a shared responsibility. One person.
The FTC calls this person the Qualified Individual. The NYDFS calls it the CISO. Ohio ORC 9.64 requires that someone be accountable for the program's implementation and ongoing maintenance. The SEC's cybersecurity disclosure rules require public companies to describe their CISO's experience in annual filings.
Why does named accountability matter so much to regulators? Because organizations without it fail at the basics. Incident response plans do not get tested. Risk assessments do not get updated. Training lapses go unnoticed. When no one owns it, everyone assumes someone else does.
Source: IBM Cost of a Data Breach Report, 2025.
Who in your organization can answer these right now?
- What are your three highest-risk systems, and when were they last assessed?
- Do you have a tested incident response plan, and when was it last executed?
- Who gets notified first when a breach occurs, and what is the legal reporting window?
- Has your board reviewed your cybersecurity posture in the last 12 months?
- Are you currently compliant with the laws that apply to your organization?
If there is hesitation in any of those answers, you have a governance problem.
The Case for External Security Leadership
Why Most Mid-Market Organizations Cannot Go It Alone
Hiring a full-time CISO is expensive. Median CISO compensation in the U.S. runs $250,000 to $400,000 annually, with total packages at mature organizations exceeding $500,000. That is before benefits, recruiting fees, or the 6 to 12 months it takes to find and onboard someone qualified.
For mid-market organizations, the math rarely works. The legal obligation does not adjust for budget. Ohio does not waive ORC 9.64 because you are a small township. The FTC does not reduce penalties because you have a lean IT team. The NYDFS does not make exceptions for credit unions with fewer than 50 employees.
This is the gap a managed security services provider fills. The right MSSP delivers CISO-level expertise, operational security capabilities, and compliance program management at a fraction of the cost of building it internally. The FTC Safeguards Rule explicitly allows the Qualified Individual to be a service provider, not an employee. Ohio ORC 9.64 allows political subdivisions to use managed services to meet program requirements.
Ask hard questions before you sign anything
- Do their principals hold recognized credentials? CISSP, CISM, CISA, or equivalent certifications signal real expertise, not marketing copy.
- Can they document your compliance posture, not just monitor your network? Operational security and compliance management are different disciplines.
- Do they deliver in writing? Board-ready reporting, risk registers, incident response plans, and compliance attestations should be standard deliverables.
- Are they available when you need them, not only during business hours? Threats do not schedule themselves around 9-to-5 windows.
The Real Cost of Waiting
What Inaction Looks Like in Practice
Organizations that treat cybersecurity as a cost center invest reactively: after a breach, after an audit finding, after a fine. By then, the cost has multiplied.
Consider what a single ransomware incident costs a mid-market company: incident response fees, forensic investigation, legal counsel, regulatory notification costs, operational downtime, and reputational damage. IBM's 2025 data puts the average U.S. breach cost at $10.22 million. A proactive managed security program at the $12,500-per-month level costs less than $150,000 per year.
The compliance risk is separate from the operational risk. ORC 9.64 audits are conducted by the Ohio Auditor of State, and findings become part of the public record. NYDFS enforcement actions are published and covered widely. FTC breach reports are now publicly accessible in a federal database. The reputational exposure alone should move this conversation to the executive agenda.
Then there is the compounding factor. IBM's 2025 report found that shadow AI adds $670,000 to average breach costs. As your employees adopt AI tools, often without IT approval or governance, your attack surface grows in ways your existing controls were not designed to address. That is a new risk category that did not exist three years ago.
What Ready Actually Looks Like
A Practical Standard
Organizations that pass regulatory scrutiny and respond to incidents effectively share a few characteristics. They have a documented program aligned to a recognized framework. They have a named leader who owns the program and reports to the board. They test their controls regularly and update their risk assessment at least annually. They have a practiced incident response plan with defined notification workflows.
That is the standard, and it is what the laws already require. Getting there takes three things: the right expertise, the right tools, and the right governance structure. Most mid-market organizations get all three through the right MSSP without building any of it from scratch.
Aetos One delivers fractional CISO leadership, AI-enhanced security operations, and compliance automation to mid-market organizations. Our principals hold CISSP, CISM, CISA, CIPP, and JD credentials. We operate on documented frameworks aligned to NIST CSF 2.0, CIS, CMMC, HIPAA, FFIEC, NCUA, and GLBA. Every engagement produces board-ready reporting, a risk register, and a compliance posture your leadership team can stand behind.
If you operate in Ohio, the clock on ORC 9.64 compliance is already running. If you are in financial services, the NYDFS and FTC Safeguards Rule have been enforceable for years. If you are pursuing federal contracts, CMMC 2.0 requirements apply at the point of contract award, and new DoD solicitations are already naming the required level. The window for building a defensible program before your next award depends on it is narrowing.
Three Questions Worth Answering This Week
- Which cybersecurity laws apply to your organization, and who on your team can verify your current compliance status?
- Do you have a named individual who owns your cybersecurity program and reports to your board?
- What would a breach cost your organization today, and what would it cost to prevent it?
If you want to work through those questions with someone who does this full-time, reach out. We will give you a straight answer.
One Provider. Named Accountability at Every Level.
Mid-market organizations face the same board scrutiny as enterprises, with smaller teams and tighter budgets, and without the luxury of a full-time CISO. Aetos One was built for that reality. If your board is asking the right questions and not getting the right answers, we should talk.
Schedule a 30-minute conversation