Indiana Municipalities and the Push for Vulnerability Reporting: What Cities Need to Know

Vulnerability Reporting – G6IT

Key Takeaways

  • Short timeline: Indiana law requires counties, municipalities, townships and other government subdivisions to report cybersecurity incidents to the Indiana Office of Technology no later than two business days after discovery. This includes exploited software vulnerabilities.
  • Legal enforcement: Senate Enrolled Act 472 raises the bar further because Indiana municipalities must adopt formal technology and cybersecurity policies by the end of 2027 and then submit them to the state on a recurring schedule.
  • Anticipating need: Vulnerability reporting is the legal floor, not the goal, so additional planning is required beyond compliance. Cities that pair on-time reporting with proactive vulnerability management close security gaps before attackers find them.

If you lead a city, town or county in Indiana, the state has made one thing clear: Cybersecurity is no longer optional. A series of attacks on local entities, including a ransomware incident at the Kokomo Public Library, pushed lawmakers to enact requirements for vulnerability reporting to all entities (Diaz, 2021). 

The result is a layered set of policy requirements that every municipality must understand, and the right IT partner for government agencies can make compliance easier than going it alone.

The stakes are real: Sophos found that 34 percent of state and local government organizations were hit by ransomware in 2024. For a city, what can that look like? Some examples include: 

  • Utility billing going offline
  • Police records locking up 
  • Public trust eroding

Getting vulnerability reporting right, and getting ahead of it, is now part of administering a responsible local government entity. Please note that we offer general guidance on new reporting requirements, not legal advice.

What Is Vulnerability Reporting and What Does Indiana Require?

Sharing an event with other municipalities involves gathering information that affects cybersecurity risks and sending it to a central hub. Vulnerability reporting in Indiana means notifying the Indiana Office of Technology (IOT) and the Indiana Information Sharing and Analysis Center (IN-ISAC) when a cybersecurity incident occurs, including the exploitation of known or unknown software vulnerabilities. 

Governmental subdivisions must report incidents without unreasonable delay and no later than two business days after discovery, using the state’s online incident reporting form (Shackle, 2025). Timely receipt of sensitive information at the IOT protects others in the state government ecosystem.

This requirement comes from a previous law that established statewide cyber incident reporting for public entities (Diaz, 2021). The state’s IN-ISAC guidance describes the window as 48 hours from discovery (IN-ISAC, 2026). Each governmental organization must also designate a primary point of contact who is authorized to report incidents and receive threat information from the state. 

As Indiana’s then-chief information security officer explained when the law passed, statewide reporting warns other local entities about active threats and gives lawmakers real data for future policy (Diaz, 2021).

Which Indiana Government Offices Have to Report Cybersecurity Incidents?

Large cities are not the only ones affected by these new policies: All government entities must report a cybersecurity incident within the specified timeframe in order to maintain compliance. According to guidelines by IN-ISAC, the following types of government organizations must report incidents to IOT within the required window:

  • Counties, municipalities and townships
  • School corporations and library districts
  • Local housing authorities and fire protection districts
  • Public transportation corporations and local building authorities
  • Local hospital authorities or corporations and local airport authorities
  • Special service districts, special taxing districts and other separate local governmental entities that can sue and be sued

If your organization is a unit of Indiana local government that can be named in a legal suit, you must assume the law applies to you. Size does not exempt anyone, nor is a lack of technology usage policy a reasonable defense. 

In our experience, smaller towns and districts are often the least prepared to detect an incident, which makes the two-business-day clock especially unforgiving when struggling with a security attack.

What Counts as a Reportable Security Incident?

Indiana defines a cybersecurity incident broadly: a malicious or suspicious occurrence that jeopardizes, or may potentially jeopardize, the confidentiality, integrity or availability of an information system, threatens public health and safety or violates security policies (IN-ISAC, 2026). A reportable security incident takes many forms, so the state specifically lists these attack types as reportable:

  • Ransomware: Malicious software that blocks access to systems until payment is made
  • Business email incident: Any email compromise such as when an attacker sends a phishing attack or a bogus attachment
  • Vulnerability exploitation: Attackers leveraging flaws in operating systems, software or applications to gain unauthorized access
  • Zero-day exploitation: Attacks on vulnerabilities unknown to the software vendor and not yet patched
  • Distributed denial of service: Flooding a network with traffic to paralyze it
  • Website defacement: Unauthorized changes to a government website’s appearance

Notice that two of the six categories are about vulnerabilities being exploited. That is the heart of the state’s reporting purpose: Indiana wants visibility into which weaknesses attackers are actually using against a local government so it can warn everyone else before more damage is incurred.

What Is Required By SEA 472 in 2026 and 2027?

Reporting after an incident was only step one. In 2025, Governor Mike Braun signed Senate Enrolled (SEA) Act 472, which requires public entities to adopt formal policies and prove ongoing compliance. The table below summarizes the key obligations and deadlines for Indiana municipalities in 2026 and 2027:

RequirementWho It Applies ToDeadline
Report cybersecurity incidents to IOTPolitical subdivisions and state educational institutionsNo later than two business days after discovery
Provide primary reporter contact info to IOTPolitical subdivisions and state educational institutionsBy September 1, 2026, following an incident
Adopt a technology resource use policy and a cybersecurity policyPublic entities (political subdivisions, state agencies, school corporations, state educational institutions)No later than December 31, 2027
Submit cybersecurity policy to IOTPublic entitiesDecember 31 of each odd-numbered year beginning in 2027
Train employees on both policiesAll public entitiesMandatory ongoing program
Vulnerability Reporting Table Mobile  G6 IT

Most public entities will write their own policies based on guidelines from IOT, while school corporations must adopt uniform policies developed at the state level (Shackle, 2025). A public entity may use a third party to assess its cybersecurity policy but must share the assessment results with IOT (Shackle, 2025). 

December 2027 sounds distant, but policy development, governance, risk and compliance management and employee training programs take real time to build. Cities that start in 2026 will not be scrambling in 2027.

How Can Cities Plan for Vulnerability Reporting?

The best way to handle mandatory incident reporting is to prevent reportable incidents as much as possible. That means moving from reactive compliance to proactive cybersecurity management. We’ve seen municipal clients make the biggest gains with four moves:

  1. Continuous vulnerability management services scan your systems for known flaws and prioritize fixes. The federal agency CISA offers no-cost vulnerability scanning for state and local governments, and it reports that enrolled organizations typically reduce risk and exposure by 40 percent within the first 12 months (CISA, n.d.).
  2. Test your defenses like an adversary would. Periodic penetration testing goes beyond scanning to show how an attacker could actually chain weaknesses together inside your environment.
  3. Establish a baseline through a risk assessment and continue to check it. A formal cybersecurity audit documents where you stand today, which doubles as the foundation for the cybersecurity policy SEA 472 requires.
  4. Security awareness training addresses the business email compromise scenarios on the state’s reportable list, and a practiced incident response plan with tabletop exercises means your team can detect, contain and report within the appropriate timeframe without panic.

Around-the-clock monitoring matters, too. An incident discovered Friday evening still starts the reporting clock, and a managed SOC watching your environment 24/7 is often the difference between discovering an intrusion in hours versus weeks.

Vulnerability Reporting for Indiana Municipalities

Indiana has decided that local government cybersecurity is a statewide concern, and the requirements now run in both directions: Report incidents within two business days and prove you have policies, training and controls in place by the end of 2027. Cities that treat these requirements as a catalyst will become genuinely harder to attack.

G6 IT supports government agencies across the Midwest with managed IT services, security monitoring and compliance expertise built on years of work with federal and defense-grade environments. If you want a clear picture of where your municipality stands, book a meeting with our team. No jargon, no pressure, just a straight assessment.

References

Cybersecurity and Infrastructure Security Agency. (n.d.). Cyber hygiene services. https://www.cisa.gov/cyber-hygiene-services

Diaz, K. (2021, July 21). Indiana law changes the rules for cyber incident reporting. Government Technology. https://www.govtech.com/security/indiana-law-changes-the-rules-for-cyber-incident-reporting

Indiana Information Sharing and Analysis Center. (2026). Cyber incident reporting law. Indiana Cybersecurity Hub. https://www.in.gov/cybersecurity/in-isac/cyber-incident-reporting-law/

Shackle, D. T. (2025, June 24). Indiana’s new cybersecurity requirements effective July 1, 2025. Frost Brown Todd. https://frostbrowntodd.com/indianas-new-cybersecurity-requirements-effective-july-1-2025/

Sophos. (2024, August 14). The state of ransomware in state and local government 2024. https://www.sophos.com/en-us/blog/the-state-of-ransomware-in-state-and-local-government-2024

IN THIS POST
    ABOUT THE AUTHOR
    Blake King
    Blake King

    Blake King, co-founder and CEO of G6 Communications, launched the veteran-owned managed IT and cybersecurity firm in 2007 after serving as a tactical network engineer in the United States Marine Corps, where he was a non-commissioned officer honor graduate and received the Navy and Marine Corps Commendation Medal. He and his team have almost two decades of experience designing, building and securing enterprise-level IT environments for diverse organizations, from DoD and DOE agencies to small and mid-sized businesses. He now leads G6’s strategic advisory practice, helping business owners align technology decisions with operational goals and compliance. Connect with Blake on LinkedIn

    Share This