Don’t do SECURITY. Do business SECURELY.

Ohio cybersecurity safe harbour law takes effect

Ohio now gives organisations with a recognised cybersecurity framework an affirmative defence against data breach tort claims.

Ohio’s Data Protection Act (SB 220) comes into force today, the first US state law giving a legal “safe harbour” to organisations with a recognised cybersecurity programme.

Key points

  • Organisations that maintain a written cybersecurity programme reasonably conforming to an industry framework gain an affirmative defence to breach-related tort claims.
  • Recognised frameworks include ISO/IEC 27001, NIST CSF, NIST SP 800-171, CIS Controls and PCI DSS.
  • The programme must be scaled to the organisation’s size, activities and data sensitivity.
  • Compliance is voluntary.

The law shows how frameworks such as ISO/IEC 27001 can reduce legal exposure. UK organisations serving Ohio customers can benefit from certification, and other states are expected to follow.

Source: Ohio Revised Code Chapter 1354 (Ohio Laws)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights