This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| Ohio Cybersecurity and Privacy Protection (OC3) | |
|---|---|
| Agency name | Ohio Cybersecurity and Privacy Protection (OC3) |
| Jurisdiction | Ohio |
| Formed | 2019 |
| Headquarters | Columbus |
| Parent agency | Office of the Governor |
Ohio Cybersecurity and Privacy Protection (OC3) Ohio Cybersecurity and Privacy Protection (OC3) is a state-level cybersecurity and privacy office in Ohio created to coordinate cybersecurity strategy, incident response, and privacy policy for state agencies, critical infrastructure, and local partners. OC3 operates within the administrative context of the Office of the Governor and interacts with federal entities such as the Cybersecurity and Infrastructure Security Agency, the Federal Bureau of Investigation, and the United States Department of Homeland Security to align state practice with national standards.
OC3 functions as a centralized hub for digital risk reduction, incident coordination, and privacy guidance across Ohio state departments, municipal bodies like Cleveland, Cincinnati, and Columbus, as well as utilities and educational institutions such as Ohio State University and Case Western Reserve University. Its remit includes incident detection and response, policy development, threat intelligence sharing with organizations like Multi-State Information Sharing and Analysis Center (MS-ISAC), and outreach to the private sector including firms headquartered in Akron and Youngstown. OC3’s mission intersects with statutory actors such as the Ohio Attorney General and coordination with federal programs administered by National Institute of Standards and Technology and Department of Homeland Security components.
OC3 was established during the administration of Governor Mike DeWine in response to statewide incidents and evolving threat landscapes that affected entities including OhioHealth, FirstEnergy, and municipal bodies following ransomware campaigns that also targeted Baltimore and Atlanta. Legislative and executive actions paralleled initiatives in states like Texas and California, reflecting national trends after high-profile breaches involving Equifax, SolarWinds, and Colonial Pipeline. Foundational directives referenced standards promulgated by NIST Cybersecurity Framework adopters and federal advisories issued by CISA and the Federal Trade Commission.
OC3’s governance structure links the office to the Office of the Governor while coordinating with agency heads such as the Ohio Department of Public Safety director and the Ohio Department of Administrative Services chief. Executive leadership typically liaises with the Ohio General Assembly committees on technology and appropriations, and with appointed officials including the Ohio Attorney General and state chief information officer models similar to those in New York and Massachusetts. The office organizes operational units that mirror federal constructs found at the Department of Homeland Security and partner with law enforcement elements like the FBI’s Cyber Division and regional fusion centers.
OC3 runs programs for incident reporting, tabletop exercises, and cybersecurity training for personnel across institutions such as Cuyahoga Community College, University of Cincinnati, and Wright State University. Services include a 24/7 incident coordination center similar to MS-ISAC and threat intelligence sharing modeled after Infragard partnerships; outreach includes workshops with trade groups like the Ohio Chamber of Commerce and supply-chain resilience efforts akin to programs run by Department of Energy. OC3 supports grant administration for federal funding streams from Bureau of Justice Assistance and Economic Development Administration-linked cybersecurity grants, and assists compliance efforts tied to standards from NIST and privacy frameworks referenced by Federal Trade Commission guidance.
OC3 operates within the statutory and executive framework of Ohio Revised Code provisions and coordinates legal responses with the Ohio Attorney General and state prosecutors. Its activities are informed by state statutes on breach notification, consumer protection precedents involving Equifax litigation analogues, and federal statutes such as the HIPAA when interfacing with healthcare providers like The Cleveland Clinic. The office references model rules from entities such as National Association of Attorneys General and practices consistent with federal guidance from CISA and NIST but does not itself enact independent criminal enforcement beyond coordination with entities like the FBI and state law enforcement.
OC3 has launched statewide exercises and partnerships with academic research programs at Ohio State University and Case Western Reserve University, technology collaborations with corporations headquartered in Columbus and Cleveland, and public-private threat-sharing arrangements analogous to MS-ISAC and regional Information Sharing and Analysis Organizations. It has engaged in partnerships with federal counterparts including CISA and FBI, and collaborated on resilience initiatives paralleling efforts after incidents like the Colonial Pipeline disruption and the SolarWinds supply-chain compromise. OC3 has participated in interstate compacts and working groups with states such as Michigan and Pennsylvania and with national associations including the National Governors Association.
Critics have argued that OC3’s creation duplicated functions found in the Ohio Attorney General’s cyber unit and existing state IT structures like the Office of Information Technology and raised concerns mirrored in debates in California and New York over centralization versus decentralization of cyber authority. Privacy advocates referenced frameworks from Electronic Frontier Foundation-aligned critiques and civil liberties discussions similar to controversies around CALEA and surveillance programs, questioning oversight, transparency, and potential overlaps with law enforcement coordination exemplified in scrutiny of Fusion centers. Budgetary and efficacy debates have mirrored controversies in other jurisdictions following incidents involving Equifax and municipal ransomware events in Baltimore and Atlanta.
Category:Ohio state agencies