Updated October 2026. Originally published January 30, 2025.
Every Ohio business, whatever its size or industry, now runs on IT systems, and the attacks against those systems are landing closer to home. In May 2025, Dayton-area Kettering Health was hit by the Interlock ransomware group, forcing a system-wide outage across its 14 medical centers and more than 120 outpatient facilities (Paubox). Strong cybersecurity is what keeps Ohio businesses competitive, compliant and open for business.
Why cybersecurity matters for Ohio businesses
High-profile incidents show what’s at stake when systems go down:
Ransomware can stop operations for weeks. At Kettering Health, attackers were inside the network for 41 days, from April 9 to May 20, 2025, before deploying ransomware, and the breach ultimately affected nearly 1.7 million people (Paubox). The health system canceled elective procedures, diverted ambulances until May 28, and wasn’t fully operational until June 10 (Schubert Jonckheer & Kolbe).
Even global brands go dark. In July 2020, WastedLocker ransomware took down Garmin’s website, apps, customer support and call centers (BleepingComputer).
Outages don’t have to be attacks to hurt. AT&T’s February 22, 2024 nationwide wireless outage was caused by a single misconfigured network change; the FCC found it blocked more than 92 million calls, including over 25,000 calls to 911 (Android Authority; Fierce Network).
The numbers behind those headlines keep climbing. IBM’s 2026 research puts the average U.S. data breach at $11.5 million (Baker Donelson), and Verizon counted 7,152 confirmed breaches at small and mid-sized businesses in its 2026 report (Verizon DBIR).
Every business needs to understand its own dependence on IT. If your operations rely on staying connected around the clock, you need a plan to keep running, or recover quickly, when a breach or outage hits.
Ohio’s legal incentive to act
Ohio offers something most states don’t: a legal reward for doing security well. Under the Ohio Data Protection Act (R.C. 1354), a business that creates, maintains and follows a written cybersecurity program reasonably conforming to a recognized framework, such as the NIST Cybersecurity Framework, can use it as an affirmative defense against tort claims after a data breach (Ohio Revised Code § 1354.02; Dinsmore). A written, followed plan is both good security and good legal protection.
A strategic approach to cybersecurity
Starfish Computer recommends four building blocks:
Risk assessment and strategy. Identify which parts of your business depend most on IT and which are most vulnerable. Unpatched software is now the most common way in, at 31% of breaches (Verizon), so start with what’s exposed to the internet.
Right-sized protection. Tailor security to the business, whether that’s protecting a small email-only operation or a full 24/7 environment.
Written plans and policies. Make sure your team knows exactly what to do in a crisis, including how to work remotely and connect securely. Use multifactor authentication on every remote connection; CISA recommends phishing-resistant MFA such as passkeys and security keys where possible (CISA).
Proactive monitoring and testing. Like a medical check-up, regular stress tests confirm that networks, backups and defenses work before an attacker tests them for you. Kettering’s 41-day dwell time shows why continuous monitoring matters.
Protect your Ohio business
If your business is ready to strengthen its cybersecurity, Starfish Computer can help. Our team focuses on proactive strategies that stay ahead of evolving threats, with protection tailored to your operations. Contact us for a consultation and take the first step toward a written, defensible cybersecurity program.
Protect your business: start with an assessment
The question isn’t whether your business will face a cyber threat, but whether you’ll be ready when it does. Since 1994, Starfish Computer Corporation has helped businesses across Northeast Ohio:
Assess current security posture and risk
Plan a cybersecurity roadmap aligned to NIST CSF 2.0
Implement the right tools and processes for your size and budget
Train your team on today’s threats, including AI-driven scams
Support and improve your security over time
Call (440) 808-0468 or visit starfishcomputer.com to schedule a security assessment.
About the author
R.J. Arhar is President of Starfish Computer Corporation. He has more than 35 years of experience in IT, served as a consultant to the National Institutes of Health, led IT operations for an international security company with more than 8,000 users, and is the author of Attack or Defend – When is Enough Cybersecurity Enough?
This post provides general cybersecurity guidance. Requirements vary by industry and business. Statistics are current as of October 2026; consult Starfish Computer Corporation for a plan tailored to your risk profile.
Sources
Paubox, “Kettering Health ransomware hit 1.7M, confirmed year after Interlock breach”
BleepingComputer, “Garmin outage caused by confirmed WastedLocker ransomware attack”
Fierce Network, “FCC says this is what caused AT&T’s big outage in February”
Android Authority, “AT&T’s February outage blocked over 25,000 calls to 911”
Baker Donelson, “Ten Takeaways from IBM’s 2026 Cost of a Data Breach Report”
Verizon, 2026 Data Breach Investigations Report, Executive Summary
Dinsmore, “Ohio Enacts First of its Kind Data Protection Act”

