cybersecurity-training

Gallia County Cybersecurity and AI Awareness Training

Gallia County Cybersecurity and AI Awareness Training

Required Annual Training. All Employees, Officials, Contractors, and Vendors.

Why this matters: Ohio law (HB 96 / ORC § 9.64) requires the county to train its people, and state auditors check it. More to the point: one clicked link can take down payroll, 911, or the courts. You are the control that stops it. This takes about 5 minutes. Read it, then submit your name at the bottom.

Part 1: Everyday Security

  • Passphrases (we’re moving off passwords): Use 15 or more characters. A few unrelated words are ideal, for example “Purple7-Anchor-Kettle” (don’t use that one). Make the switch when next prompted. Never reuse it, never share it, and remember that IT will never ask for it.
  • MFA / 2FA is required: Turn it on everywhere it’s offered.
  • Email: County Microsoft 365 only. Hover over links before clicking, and be suspicious of urgency (“wire this today,” “send gift cards now”). Don’t open unexpected attachments, even from people you know.
  • Verify money and credential requests out of band: For any request to move money, change payment details, or hand over a password, confirm it by calling a number you already have, never one from the message.
  • Save work in approved places only: County network drives or OneDrive (Office 365). Not Dropbox, personal Google Drive, iCloud, or a personal USB without IT approval. Never forward county email to a personal account.
  • Lock your screen (Windows + L) whenever you step away, and report a lost or stolen device the same day.
  • County “GC” Wi-Fi is for county business only, with no personal streaming or downloads. On a personal phone, use the Outlook app with your county account (not the built-in mail app), and you must have 2FA on that device.
  • Working remotely? Cisco AnyConnect VPN is required for all remote access; it is our FIPS 140-3 validated connection. Connect it before using any Wi-Fi you don’t control.
  • New app or cloud service? Get IT Director approval before using it for county work. The default answer isn’t “no,” it’s “let’s check it first.”

Remember: County email, files, and AI prompts are public records under Ohio law, and IT may monitor any use of county technology. If you wouldn’t want it released, don’t type it.

Part 2: Using AI Safely

The county wants you to use AI. It is an assistant, never an authority, and a human is always responsible for the result.

  • Approved tool: Microsoft 365 Copilot Chat. Sign in with your county account and look for the green shield. Personal ChatGPT, Claude, Gemini, or Meta AI accounts are not approved, and paying for one doesn’t make it approved.
  • Never paste sensitive data into any AI tool: SSNs and PII, HR or personnel records, law-enforcement/CJIS data, medical information, JFS client data, legal-privileged material, bank or payment data, passwords, Federal Tax Information, or anything Confidential. Rule of thumb: if you wouldn’t post it on the county website, don’t paste it.
  • AI never decides: It can’t be the basis for hiring, firing, discipline, benefits or permit eligibility, law-enforcement calls, or legal conclusions. “The AI said so” is never an answer.
  • You own the output: AI invents facts, fakes citations, and gets math wrong while sounding sure of itself. Check every fact, figure, date, and citation before it leaves your desk.
  • Watch for AI-powered scams: Phishing is polished now, and voices can be cloned. Verify anything involving money or credentials by calling a number you already have.
  • Not on the approved list? Ask IT first. Don’t install AI software or browser extensions on county devices.

Part 3: Report It Fast

A breach caught in 10 minutes is an inconvenience; the same breach caught in 10 days is a countywide event. Ohio law requires reporting within 7 days (state cyber center) and 30 days (Auditor), and that clock includes AI incidents.

CRITICAL: CALL THE IT DIRECTOR NOWROUTINE: IT HELPDESK, NORMAL HOURS
Ransomware, locked files, or a ransom demandPhishing email you received but didn’t click
You clicked a phishing link or entered credentialsSuspicious call where you gave nothing away
You gave a password or code to a caller or websiteSecurity software blocked something
A payment or wire went out on a fake emailForgot passphrase (routine reset)
Your account is sending email you didn’t sendComputer slow, printer issues, email not syncing
County device lost or stolenNeed software installed
Confidential data leaked, or entered into any AI toolHelp with MFA or AnyConnect VPN setup
Suspected deepfake, voice clone, or AI impersonationQuestions about a policy or tool

When in doubt, call. Over-reporting beats under-reporting; nobody here has been disciplined for reporting a false alarm. And self-reporting is protected: if you clicked it, pasted it, or sent it, say so right away. Concealing a mistake is treated far more seriously than making one.

Critical: call the IT Director immediately. After hours, contact backup IT, then the Commissioners. Routine: IT Helpdesk or a support ticket.

IT Director: Tracy Atkins  •  tatkins@galliacountyoh.gov  •  (740) 446-4612 x1358


Acknowledge This Training

By submitting your name below, you acknowledge that you have read and understand this training and agree to the statements that follow.

  • You have received, read, and understand this training, and agree to follow the county Cybersecurity Policy Framework and Artificial Intelligence Use Policy.
  • You will protect your passphrase, use MFA/2FA, and never share your credentials, including 2FA on any personal device you use for county email.
  • You will store county data only in approved locations and use only county-approved AI tools, keeping prohibited data out of them.
  • You will verify AI output before relying on it, and understand AI may not be the sole basis for any decision affecting a citizen’s rights, benefits, employment, or legal standing.
  • You understand county email, files, and AI prompts are public records and that you have no expectation of privacy in your use of county technology.
  • You will report security incidents immediately, and understand prompt self-reporting of your own mistake is protected.
  • You understand violations may result in discipline under Personnel Policy Manual Chapter 8, up to termination, and criminal prosecution where applicable.
Name