Cybersecurity governance for local government

A cybersecurity program your board can adopt — and your auditor can verify.

SecuredRoots walks townships, villages, cities, and counties from their first risk assessment to a board-adopted, audit-ready cybersecurity program.

Built on NIST CSF and CIS Controls.

RESOLUTION NO. 2026-14

A Resolution Adopting a Cybersecurity Program

WHEREAS, applicable law requires the political subdivision to adopt a cybersecurity program appropriate to its size and operations; and

WHEREAS, a risk assessment has been completed and policies, training, and an incident response plan have been established;

NOW, THEREFORE, the Board adopts the attached Cybersecurity Program, effective immediately.

Chair
Fiscal Officer
ADOPTED
BUILT ONNIST CSF & CIS Controls
STATE PACKSLocal requirements, applied cleanly
AUDITSEvidence organized before it is requested
CONTINUITYA living program, not a one-time binder
Why now

Deadlines pass. The obligation doesn't.

Cybersecurity governance is an ongoing responsibility. Without a documented, adopted program, three pressures keep building.

Audit exposure

Findings are public record

Auditors can ask for an adopted program and the evidence that it is maintained.

Insurance pressure

Renewals ask hard questions

Carriers increasingly expect documented controls, training, and response plans.

Operational risk

Small governments are targets

Public payment workflows, limited staff, and aging systems create real exposure.

How it works

From “where do we even start?” to adopted — in four steps.

Every step is written for public officials. No security background is assumed.

STEP 1

Assess

A guided questionnaire inventories your current safeguards and maps the answers to NIST CSF or CIS Controls.

STEP 2

Generate

Create cybersecurity policies and an incident response plan tailored to your answers and community.

STEP 3

Adopt

Prepare a board packet with the resolution, program summary, and talking points ready for a public meeting.

STEP 4

Maintain

Track training, evidence, reviews, and incident deadlines so the program stays current after adoption.

What's included

Everything your program needs. Nothing it doesn't.

Six focused modules in one workspace built for local government.

Risk assessment wizard

Plain-language questions build your risk picture and prioritized action plan.

Policy & plan generator

Draft editable cybersecurity policies and response plans from assessment results.

Board adoption packet

Prepare a ready-to-vote resolution and summary for the meeting and minutes.

Incident reporting clocks

Start the notification timelines required by the active state pack.

Training tracker

Maintain annual awareness training records in one auditable place.

Evidence vault

Keep policies, votes, training records, and reviews organized for the next audit.

Built to travel

A universal core, with your state's rules on top.

National frameworks form the core. State packs add the reporting rules, deadlines, and approvals that apply to each organization.

● LIVE

Ohio

Incident notices, adoption requirements, and auditor-ready documentation.

COMING

Indiana

State requirements layered into the same national-framework workspace.

COMING

Kentucky

State requirements layered into the same national-framework workspace.

COMING

Your state

State requirements layered into the same national-framework workspace.

Pricing

Priced for public budgets.

Simple plans with no implementation project required.

Township & Village

For the smallest subdivisions — trustees, clerks, and fiscal officers.

View plan/month

Annual billing available /year

  • All six governance modules
  • One subdivision workspace
  • Board adoption packet
  • Email product support
Start free readiness check

Partner

For organizations coordinating governance across multiple local governments.

Custom

  • Multi-organization workspace
  • Portfolio-level reporting
  • Volume pricing
  • Guided onboarding
Contact us
Questions

Asked at every board meeting.

Our deadline already passed. Is it too late?

No. The obligation continues, so the best next step is to document your current state and begin adoption.

We don't have a dedicated security person. Can we do this?

Yes. The questions and guidance are in plain language, and the workflow is designed for small public offices.

NIST or CIS — which framework should we choose?

Both are supported. The readiness check helps indicate which starting point better fits your organization.

Is this a one-time project?

No. Adoption is a milestone; evidence, training, review, and incident readiness keep the program current.

Free readiness check

Find out where your subdivision stands.

Answer six plain-language questions and leave with a prioritized summary.

Start the free readiness check