US States Turning To Insurance

Cyber-attacks on government agencies, like the recent event where hackers gained access to Iowa’s State public employee pension accounts, stealing hundreds of thousands of dollars, have become increasingly common.

In response, more US states are purchasing insurance plans specifically tailored to protect the State from potential cyber-attacks.

No Iowa agencies have cyber-attack insurance, but the topic has been discussed among State leaders. “It’s a huge discussion,” said Robert von Wolffradt, Iowa’s chief information officer. Earlier this month, hackers were able to gain access to more than 100 accounts in Iowa’s public employee pension system and steal hundreds of thousands of dollars, according to state officials.Officials do not believe the hackers gained direct access to the State system, but rather obtained identifying information, Social Security numbers and birth dates, for example, through other means and used that to access the system.

The event served as a reminder that government agencies in recent years have increasingly become the target of cyber-attacks.

In 2016, government tied finance as the most-targeted sector for cyber-attacks worldwide, according to an annual global threat intelligence report from Dimension Data, a South Africa-based information technology services company.
When hackers attack a financial institution, they are looking for money. When hackers attack a governmental agency, they are looking for sensitive, and thus valuable, information, experts said. “The biggest threat is the government is the one that has all our data,” said Doug Jacobson, an Iowa State University professor of computer and electrical engineering. “They’re the ones that have all our Social Security numbers, they have our addresses. They have everything about us. That’s the biggest thing (governments) have to try to protect.”Or, von Wolffradt said, hackers are simply “trying to subvert government and just make government look bad.”

In order to protect themselves from cyber-attacks, more states are purchasing cyber insurance.

More than a dozen states have cyber insurance policies, according to a report from the Pew Charitable Trusts “Stateline.”
Cyber insurance policies generally cover costs related to data theft or corruption, the unauthorised sharing of data, and legal costs, according to a report on cyber insurance policies from PNC Financial Services.

Such policies can be expensive. Montana has a $2 million policy that covers all agencies and the state’s public university system; Utah bought a policy in 2015 after a data breach on its health department servers, according to the Pew report.
“It’s expensive. It’s a big budget item for us. But it’s absolutely worth it,” Michael Hussey, Utah’s chief information officer, said in the Pew Report. “You’re seeing breaches now that cost companies and states millions and millions of dollars.”

Would a cyber insurance policy benefit Iowa’s State government agencies? That discussion is taking place, von Wolffradt said. He called it “a very complex issue” that is being considered by the state budget department. Iowa government is currently self-insured, von Wolffradt said. “I think the issue is, if you’re self-insured, how much does this (cyber insurance) cost and how much protection does it afford you and what do you use it for,” von Wolffradt said.

In addition to coming at a high price tag, cyber insurance policies typically require the customer, state government, in this case, have certain levels of protections already in place. “Insurance companies are smart. They’re not going to go into something blind. So they require the agencies to do certain things, have certain protections and certain reasonable responses in place,” von Wolffradt said. “And then that will change the rates that (agencies) are getting charged for insurance.”

Von Wolffradt said he has recommended the state budget department consider a cyber insurance policy.
“We’ve recommended looking at it because we think that as the industry grows, and it’s relatively new, as the insurance matures a little bit, there may be some opportunities there,” von Wolffradt said. Jacobson said Iowa state government has been proactive on cyber security for the past decade.

In December 2015, then-Gov. Terry Branstad issued an executive order for the creation of a state cyber security initiative. A state cyber security strategy was published in July of 2016; Jacobson said other states look to the Iowa plan as a model.
The state also in October opened its new cyber security operations center, which enables state security officials to monitor systems and respond to incidents almost immediately, according to state officials.

The chief information office said it responded to nearly 1,900 incidents in the state budget year that ended June 30. The most common incident is a malware attack that attempts to extract data, von Wolffradt said.

“Everybody’s trying to do the best they can,” Jacobson said. “It’s a rigged game. The attackers only have to be right once, and we have to be perfect. That’s not very fair. But that’s the game we’re being forced to play.”

WCFCourier

You Might Also Read:

More Sensitive US Voter Records Leaked:

Local Government Computer Systems Are Soft Targets:

Georgia - A State Of Cybersecurity:

 

 


 

 

 

« UK Drone ‘pilots’ Must Pass Safety Tests
Cybersecurity Firms Deploy AI Against Hackers »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Infosecurity Europe, 3-5 June 2025, ExCel London

Infosecurity Europe, 3-5 June 2025, ExCel London

This year, Infosecurity Europe marks 30 years of bringing the global cybersecurity community together to further our joint mission of Building a Safer Cyber World.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Zerto

Zerto

Zerto provides enterprise-class disaster recovery and business continuity software specifically for virtualized data centers and cloud environments.

Yubico

Yubico

Yubico sets new global standards for simple and secure access to computers, mobile devices, servers, and internet accounts.

AllClear ID

AllClear ID

AllClear ID provides products and services that help protect people and their personal information from threats related to identity theft.

Convercent

Convercent

We offer comprehensive and integrated compliance management, reporting, and analytics. A 360-degree view of compliance drives efficiency by aligning initiatives and data into a single dashboard.

BlackBerry Cybersecurity

BlackBerry Cybersecurity

Blackberry provides intelligent security software and services to enterprises and governments around the world.

Cycura

Cycura

Cycura provide advanced, customized, and confidential cyber security services, cyber investigation services, and digital forensic services to governments, companies, and organizations.

MOXFIVE

MOXFIVE

MOXFIVE is a specialized technical advisory firm founded to bring clarity to the complexity of cyber attacks.

Technisanct

Technisanct

Technisanct works with Governments, especially Law Enforcement and Defence agencies, helping them in monitoring threats, managing their data and resolving their forensic needs.

LogicBoost Labs

LogicBoost Labs

LogicBoost Labs has the expertise, experience, funding and connections to make your startup succeed. We are always interested in new ways to change the world for the better.

AVEVA

AVEVA

AVEVA has a long history in providing Supervisory Control and Data Acquisition software for meeting complex and evolving automation requirements.

Association for Uncrewed Vehicle Systems International (AUVSI)

Association for Uncrewed Vehicle Systems International (AUVSI)

AUVSI is the world's largest nonprofit organization dedicated to the advancement of uncrewed systems and robotics. Focus areas include cyber security for uncrewed systems and robotics.

Kaine Mathrick Tech (KMT)

Kaine Mathrick Tech (KMT)

KMT deliver comprehensive cyber-first outsourced technology support and solutions that scale with your business.

Sirar by STC

Sirar by STC

Sirar is an advanced technology and cybersecurity company established by STC, the MENA region’s ICT and digital services provider.

Staris

Staris

Human based defense is dead. Staris is reinventing application security for an increasingly AI driven world.

Locket Cybersecurity

Locket Cybersecurity

Locket’s certified students provide pro-bono security audits for small and medium-sized businesses in the Chicagoland area.

Cybermate

Cybermate

Cybermate is the first affordable, gamified ‘Psybersecurity’ awareness training platform that reduces behavioural risk and achieves compliance with Australian cybersecurity standards.