Key Takeaways

  • Cyber insurance remains essential for public entities as ransomware, AI-enabled attacks, and data breaches continue to evolve.
  • Lower cyber insurance premiums may give municipalities an opportunity to reevaluate coverage limits.
  • Stronger underwriting requirements can help improve cybersecurity controls and reduce risk.
  • Third-party vendor exposure should be reviewed as part of a comprehensive cyber risk management strategy.

Managing Rising Cybersecurity Threats for Public Entities and Municipalities

For local government organizations and cities of all sizes, cybersecurity is a core operational, financial, and governance concern that extends beyond IT and influences everything from budgeting decisions to purchasing strategies. While cyber insurance market conditions have improved significantly in recent years, municipal leaders are still navigating an increasingly complex landscape shaped by evolving threats and technologies like AI as well as stricter underwriting expectations.

Public entities and municipalities are no longer asking whether they need cyber insurance. Now, they need to know whether they have enough of it, whether their controls meet expectations, and how to better protect themselves from existing and new risks.

Why Cities and Government Agencies Need a Stronger Cyber Insurance Strategy

Cyber insurance helps public entities offset the financial impact of ransomware, data breaches, business interruption, forensic investigations, legal expenses, and recovery efforts.

Cybercriminals target public entities because local governments often maintain extensive personal, financial, and operational data. From ransomware attacks that shut down city services to data breaches that expose citizen information, the consequences of a cyber incident can be severe and long-lasting.

Adding another layer of complexity is the rapid advancement of artificial intelligence. AI creates opportunities for governments to improve efficiency and citizen services, but it’s also empowering cyber threats with new tools that automate response efforts and identify vulnerabilities faster than ever before.

AI-powered cyber risks can include:

  • Sophisticated phishing emails that can be created in seconds.
  • Social engineering campaigns that are more convincing.
  • Deepfake technology that can imitate voices and video communications with surprising accuracy.

For municipal leaders, the risks are becoming more sophisticated and harder to detect. Outsourcing risk management processes can help streamline operations for public entities, but it’s still crucial to understand the threat environment and take proactive steps to reduce risk.

Lower Premiums Create an Opportunity to Reevaluate Limits

The insurance market may be softening, but city leaders shouldn’t mistake favorable pricing for reduced exposure.

After years of significant rate increases driven by ransomware attacks and claim volatility, competition among insurers has increased and declining premiums have created a valuable opportunity for public entities to revisit their insurance programs.

Historically, many public entities purchased cyber limits based largely on budget constraints. When premiums increased dramatically several years ago, some organizations reduced limits or accepted higher retentions to control costs. Today, those same entities may find they can secure higher coverage limits at a more manageable price point.

This presents an important strategic question: If your organization can purchase additional protection for a relatively modest increase in premium, should you?

For many public entities and municipalities, the answer may be yes.

How to Evaluate Cyber Insurance Limits

Municipal leaders should evaluate their cyber insurance limits against today’s threat environment rather than relying on historical purchasing patterns.

The right limit should reflect current exposures, operational dependencies, populations served, technology infrastructure, and third-party relationships. In some cases, a significant cyber incident can create millions of dollars in expenses before normal operations are fully recovered.

Recovery costs often include:

  • Forensic investigations
  • Legal expenses
  • Regulatory notifications
  • Credit monitoring
  • Public relations support
  • Business interruption losses
  • Data restoration
  • Ongoing remediation efforts

Of course, budget considerations will always matter, and public dollars must be managed responsibly. However, if budget flexibility exists, increasing cybersecurity while rates remain favorable deserves serious consideration.

Tighter Underwriting Drives Better Cybersecurity

Cyber insurers have become much more disciplined in evaluating risks. The underwriting process forces organizations to examine potential weaknesses, document controls, and establish more formal cybersecurity governance structures.

Several years ago, cyber coverage could often be obtained with minimal scrutiny. Today, insurers routinely assess a municipality’s cybersecurity controls before offering terms.

Common areas of review now include:

  • Multi-factor authentication
  • Endpoint detection
  • Employee training programs
  • Backup procedures
  • Incident response plans
  • Network monitoring capabilities

While some organizations initially viewed these requirements as burdensome, the results have been largely positive.

Stronger underwriting standards have helped many public entities improve their cybersecurity posture. To qualify for favorable pricing and coverage terms, public entities have been encouraged to implement best practices that also reduce their overall likelihood of experiencing a loss.

Don’t Overlook Vendor Cyber Risk

While underwriting improvements have strengthened internal cybersecurity controls, there is one area that deserves continued attention: third-party vendor risk.

Public entities rely on a growing network of:

  • External technology providers
  • Software vendors
  • Managed service providers
  • Payment processors
  • Cloud-hosting companies
  • Other partners that support critical operations

These relationships create efficiencies, but they also expand cyber exposure. A municipality may have strong internal controls and well-trained staff yet still experience significant disruption if a key vendor suffers a cybersecurity incident.

Recent high-profile supply chain attacks have demonstrated how vulnerabilities at a single service provider can impact hundreds or even thousands of organizations simultaneously. For city governments and organizations, a vendor breach can interrupt citizen services, compromise sensitive information, delay communications, and create significant recovery costs.

Leaders should know which vendors have access to sensitive data, how those vendors protect their information, and what requirements exist regarding cybersecurity. Assessments, questionnaires, incident reporting, and insurance verification should all be part of a comprehensive risk management strategy for public entities.

Cyber insurance policies should also be reviewed carefully to ensure that vendor-related incidents are appropriately contemplated within coverage provisions—this also provides an opportunity to determine if your contractors are insured.

Final Thoughts

While favorable premiums may create opportunities to reassess coverage, evolving threats, AI-enabled attacks, and third-party vendor exposure mean public entities and municipalities need to treat cyber insurance as part of a broader risk strategy—not a standalone purchase.

Keep these steps in mind as you plan for next year and beyond:

  • Use lower premiums as an opportunity to evaluate cyber insurance limits and financial protection.
  • Continue strengthening cybersecurity controls to meet underwriting expectations and reduce risk.
  • Review third-party vendor relationships, contracts, and insurance requirements for potential exposures.
  • Treat cyber insurance as one component of a comprehensive public entity risk management strategy.

As an extension of your staff, our team at Charlesworth Consulting can support your risk management strategy so you can focus on what matters most: your people. Reach out today to learn more about our solutions.