Ohio Statutes
§ 3965.03 — Investigation of events
Ohio § 3965.03
This text of Ohio § 3965.03 (Investigation of events) is published on Counsel Stack Legal Research, covering Ohio primary law. Counsel Stack provides free access to over 12 million legal documents including statutes, case law, regulations, and constitutions.
Bluebook
Ohio Rev. Code Ann. § 3965.03 (2026).
Text
(A)If a licensee learns that a cybersecurity event has or may have occurred, the licensee or an outside vendor or service provider designated to act on behalf of the licensee shall conduct a prompt investigation.
(B)During the investigation, the licensee or an outside vendor or service provider designated to act on behalf of the licensee shall, at a minimum, do as much of the following as possible:
(1)Determine whether a cybersecurity event has occurred;
(2)Assess the nature and scope of the cybersecurity event;
(3)Identify any nonpublic information that may have been involved in the cybersecurity event;
(4)Perform or oversee reasonable measures to restore the security of the information systems compromised in the cybersecurity event in order to prevent further unauthorized acqu
Free access — add to your briefcase to read the full text and ask questions with AI
Legislative History
Effective: March 20, 2019 | Latest Legislation: Senate Bill 273 - 132nd General Assembly
Nearby Sections
11
§ 3965.01
Definitions§ 3965.02
Information security program§ 3965.03
Investigation of events§ 3965.04
Notification to superintendent§ 3965.05
Powers of superintendent§ 3965.06
Confidentiality§ 3965.07
Exemptions§ 3965.08
Affirmative defense§ 3965.09
Applicability and scope of chapter§ 3965.10
Adoption of rules§ 3965.11
AdministrationCite This Page — Counsel Stack
Bluebook (online)
Ohio § 3965.03, Counsel Stack Legal Research, https://law.counselstack.com/statute/oh/3965.03.