Cybersecurity compliance for local government

A cybersecurity program your board can adopt — and your auditor will accept.

SecuredRoots walks townships, villages, cities, and counties from first risk assessment to a board-adopted, audit-ready cybersecurity program. No IT department required.

Built on NIST CSF and CIS Controls — the frameworks state law points to.

RESOLUTION NO. 2026-14

A Resolution Adopting a Cybersecurity Program

WHEREAS, state law requires each political subdivision to adopt a cybersecurity program appropriate to its size and operations; and

WHEREAS, a risk assessment has been completed and policies, training, and an incident response plan have been established;

NOW, THEREFORE, be it resolved that the Board hereby adopts the attached Cybersecurity Program, effective immediately.

Chair
Fiscal Officer
ADOPTED
BUILT ONNIST CSF & CIS Controls — the frameworks state laws point to
STATE MANDATESCyber program laws are spreading — and deadlines are passing
AUDITSFindings for missing programs are public record
INSURANCECarriers now ask for documented programs at renewal
Why now

Deadlines pass. The obligation doesn't.

State after state now requires local governments to adopt a cybersecurity program — and it's an ongoing obligation, not a one-time filing. Without one, three things are already in motion:

Audit exposure

Findings are public record

State auditors now check for an adopted cybersecurity program during regular audit cycles. A missing program can be cited as noncompliance — in a document anyone can read.

Insurance pressure

Renewals ask hard questions

Cyber-insurance carriers increasingly require a documented program, training records, and an incident response plan before they'll quote — or renew.

Real risk

Small governments are targets

Limited budgets, aging systems, and public payment workflows make local governments a favorite target for ransomware and payment fraud.

How it works

From "where do we even start?" to adopted — in four steps.

Every step is written in plain language for trustees, council members, and fiscal officers. No security background needed.

STEP 1

Assess

A guided questionnaire inventories your systems and identifies risks — mapped automatically to NIST CSF or CIS Controls, your choice.

STEP 2

Generate

SecuredRoots drafts your cybersecurity policies and incident response plan, tailored to your answers and sized for your community.

STEP 3

Adopt

Get a complete board packet — resolution, program summary, and talking points — ready for the vote and the minutes.

STEP 4

Maintain

Annual training tracking, evidence collection, and incident reporting clocks keep you compliant year after year — not just adoption day.

What's included

Everything the law expects. Nothing you don't need.

Six modules, one workspace, built for the smallest government offices on earth.

Risk assessment wizard

Plain-language questions build your asset inventory and risk register — no consultant required to get started.

Policy & plan generator

Cybersecurity policy, acceptable use, and incident response plans drafted from your assessment, editable in your own words.

Board adoption packet

A ready-to-vote resolution and summary your board can adopt at the next meeting — and your clerk can drop straight into the minutes.

Incident reporting clocks

If something happens, guided reporting starts the state and auditor notification timers so a bad day doesn't become a violation.

Training tracker

Assign annual cybersecurity awareness training and keep completion records auditors actually ask for.

Evidence vault

Every policy, vote, training record, and review in one place — so audit prep is an export, not a scramble.

Works in any state

A universal core, with your state's rules on top.

SecuredRoots is built on the national frameworks every state law points to. State packs layer on local reporting rules, deadlines, and required approvals.

● LIVE

Ohio

ORC § 9.64 requirements: 7-day and 30-day incident notices, ransomware payment resolutions, auditor-ready documentation.

COMING

Indiana

Local government cyber incident reporting requirements, mapped into the same workspace.

COMING

Kentucky

State reporting rules and personal information breach notification duties for public agencies.

COMING

Your state

No pack yet? The NIST/CIS core works everywhere today — and we build packs where our members are.

Pricing

Priced for public budgets.

Simple annual or monthly plans a fiscal officer can approve without a special meeting.

Township & Village

For the smallest subdivisions — trustees, clerk, fiscal officer.

$99/month

  • All six modules
  • One subdivision workspace
  • Board adoption packet
  • Email support from real humans
Start free assessment

Partner

For MSPs and consultants serving multiple local governments.

Let's talk

  • Multi-client dashboard
  • White-label options
  • Volume pricing
  • Partner onboarding & training
Book a partner call
Questions

Asked at every board meeting.

Our deadline already passed. Is it too late?

No — and waiting makes it worse. The requirement is ongoing, so a subdivision without a program is simply out of compliance until it adopts one. Most communities can go from first assessment to a board-adopted program within a few weeks.

We don't have an IT person. Can we really do this?

Yes. SecuredRoots was designed for offices where "IT" is whoever set up the printer. The questions are in plain language, the policies are drafted for you, and nothing assumes technical staff.

NIST or CIS — which framework should we choose?

Either satisfies the law. Most small subdivisions choose CIS Controls because the guidance is more concrete for small organizations. The assessment recommends one based on your answers, and you can switch later without starting over.

What happens if we have a cyber incident?

You'll follow your incident response plan, and SecuredRoots' guided reporting keeps you on the clock for the notifications your state requires — including what must go to the state and your auditor, and when.

Is this a one-time thing?

Adoption is the milestone; maintenance is the requirement. Annual training, periodic review, and evidence of both are what auditors look for in the years after adoption — that's the part SecuredRoots quietly handles in the background.

Who is SecuredRoots?

A cybersecurity company focused entirely on governance for local government — grassroots government is literally in the name. We do one thing: get subdivisions to an adopted, audit-ready program and keep them there.

Find out where your subdivision stands.

The free readiness check takes about ten minutes and shows exactly what you have, what's missing, and what to bring to your next board meeting.

Start the free readiness check