Cybersecurity insurance can be affordable


Key Takeaways

From Our Partners

This post is sponsored by our partners at CAI.

Rising threats, expensive coverage

Cybersecurity insurance has undergone many changes since its inception. As the threat landscape continues to evolve, so does cybersecurity insurance pricing. Policyholders experienced higher cyber insurance rates in 2022—according to CBIZ, an industry-leading financial and benefits insurance provider, some insurance customers with unique exposures or lacking loss control measures were hit with 50–100 percent rate increases. Along with these rate increases, many policyholders also experienced coverage restrictions—leading some to wonder if cybersecurity insurance is a viable option for local governments. However, with the average cost of a breach being $4.45 million and increasing, these organizations can find themselves in a precarious position. While premiums may seem like a cost they cannot afford, lacking insurance in the event of a breach leaves them with minimal to no protection.

Minimizing your cyber insurance premium

Cybersecurity insurance aids your organization in responding to and recovering from the financial repercussions of a cyberattack. It can help offset the costs of repairing systems, engaging experts, paying fines, recovering data, managing day-to-day disruptions and more. With rising threats and an increasingly complex threat landscape, the importance of this insurance has heightened.

Insurance costs have risen due to the severity of cyberattacks. While several factors impact your insurance premiums, organizations can take steps to minimize the impact of a breach. Your organization’s risk is measured by your cybersecurity maturity posture, which insurance companies assess through questionnaires. The higher the level of maturity, the lower the risk to the insurance company. Taking preemptive measures to strengthen your posture can make you a stronger candidate for insurance, lowering your cost while keeping you protected. Should a cyberattack occur, your higher maturity posture will make your organization more resilient and reduce the impact.

Many experts highlight preventative measures you can take to achieve this, though the tasks may seem overwhelming. The optimal way to determine your options for cyber insurance is to collaborate with your insurance broker as well as a trusted cybersecurity advisor. From there, you can contemplate different scenarios and understand your organization’s maturity.

Understanding your organization’s cybersecurity maturity

A cybersecurity maturity assessment will illustrate your organization’s current risk and exposure. This, followed by improvement recommendations, can help guide your organization to a better posture. At CAI, we employ the 6 functions from the National Institute of Standards and Technology (NIST) 2.0 when measuring cyber maturity:

  1. Identification— An organization’s ability to understand and recognize the cybersecurity risks to systems, assets, data, and capabilities
  2. Governance— Emphasizing that senior executives and the board of directors have the responsibility for managing cybersecurity risks as part of the organization's overall risk management strategy
  3. Protection— Developing and implementing the appropriate safeguards to ensure the delivery of services
  4. Detection— Identifying the occurrence of a cybersecurity threat
  5. Response— Developing and implementing the appropriate actions regarding a cybersecurity occurrence or threat
  6. Recover— Deploying the appropriate activities to maintain resilience and to restore capabilities that were impaired due to a cybersecurity event

We consider each factor independently and in relation to the other factors. The diagram below exemplifies a maturity assessment we would provide to a partner organization, scoring each element based on our criteria.


After your organization undergoes a maturity assessment, collaborate with a trusted cybersecurity partner to develop a plan for enhancing your overall cybersecurity maturity over time. This plan, known as a remediation roadmap, offers a pragmatic approach to addressing gaps and improving your cybersecurity maturity. It is a crucial element of reducing your risk and improving your opportunities for lower insurance premiums. CAI assesses your organization on 5 levels:

Level 1— The means to manage and organize processes are in development. Results are unpredictable and reactive. 
Level 2— Repeatable and consistent processes. Projects are planned, performed, measured, and controlled. 
Level 3— Further defined, repeatable processes are more proactive than reactive. Organization-wide standards provide guidance. 
Level 4— The ability to measure and control processes quantitatively. The organization is data-driven with performance improvement objectives. 
Level 5— Stable and flexible optimized processes. Focus on continuous improvement and designed to respond to opportunity and change. 
Our objective is to assist organizations in reaching a level 3 or better in all areas. The appropriate maturity level is based on the risks to the organization and the impact if breached or compromised.

With a stronger cybersecurity posture stemming from a maturity assessment, remediation roadmap, and best practice implementation, you will be better protected against cyber threats, and insurance companies will perceive you as lower risk. Your premiums will decrease, and you will feel more secure as an organization.

Get started with a maturity assessment

Selecting the appropriate broker and cybersecurity advisor will help you navigate this challenging path. With the right approach, you will experience the benefits of both a stronger cybersecurity posture and more affordable insurance rates. Additionally, you will be better equipped to cost-effectively protect your organization and minimize the impact if a breach occurs.

Working with our partners, we’ve developed a unique approach of tying common questions asked by insurance providers with the NIST framework and other standards. This knowledge helps organizations better understand which elements of their cybersecurity strategy they should prioritize optimizing. 

If you’re looking to lower your cyber insurance premiums and want the help of a trusted partner, contact us at CAI to discuss if this is a good option for your organization.

Post Sponsor


Stories from our partners

NACo partners with the private sector on solutions.

Together, we are highlighting innovative solutions for counties, as we work with our federal, state, local and private sector partners to build healthy, safe and vibrant communities.

View all stories


Investing Over $100 Billion in American Infrastructure

AT&T has invested over $140 billion in the past five years to enhance American connectivity, focusing on expanding its role as the nation's largest fiber internet provider and improving its reliable 5G network, which now serves nearly 290 million people.

Computer servers

Building Networks for the Next Century, Not the Last One

AT&T emphasizes its nearly 150-year history of innovation and connectivity as it transitions from traditional copper landlines to modern fiber and wireless technologies, highlighting the importance of adapting to current consumer demands and technological advancements.

Home construction

Travis County Develops 2,000 Units of Housing to Address Homelessness

This post is sponsored by our partners at Guidehouse. Through Guidehouse's comprehensive support, Travis County is on track to successfully create over 2,000 units of affordable, supportive housing by 2027.


Feeding kids during the summer requires county officials

The introduction of the Summer Electronic Benefit Transfer program marks a pivotal shift in addressing childhood hunger, especially during the summer when school meals are unavailable. This nationwide initiative, offering substantial grocery benefits, promises transformative support for over 29 million children, with a significant impact on communities facing systemic inequalities.


Why customer-centric strategy is vital for digital service adoption

The importance of a customer-centric strategy in digital service adoption for county governments is emphasized, highlighting the need for thoughtful design, clear communication, and multi-channel engagement to meet user expectations and improve customer experience.


Fighting opioid addiction – one life at a time

The opioid crisis, a major national issue, saw a 55% increase in drug overdose deaths from 2019 to 2022, with 75% involving opioids. Effective strategies to combat this include integrated care, policy enhancement, and technology, focusing on whole-person care and intervention opportunities to save lives.

Building facade

Planning for the post-American Rescue Plan Act future

Guidehouse outlines strategies for state and local governments to sustain programs after the end of American Rescue Plan Act (ARPA) State and Local Fiscal Recovery Funds (SLFRF) funding. It emphasizes the need for reassessing constituent needs, measuring program impact, and considering fiscal implications to ensure long-term viability and effective resource allocation for programs initially funded by SLFRF.

Group with hands in

How voluntary benefits can help improve your employee benefit package

Voluntary benefits, tailored to diverse employee needs and often at reduced costs, are proving essential in enhancing employer benefit packages, attracting, and retaining talent, and addressing specific wellbeing issues across different age and income groups.


A countywide opioid misuse prevention campaign is easier to implement than you think

The Deterra Household Mailing Campaign delivers educational tools and deactivation pouches directly to homes. To save lives by tackling the opioid crisis.

Fire danger sign

From prevention to resilience: Strategies in wildfire mitigation

Explore a multifaceted approach to wildfire mitigation with Tidal Basin. From creating defensible spaces to early detection systems, discover strategies fostering resilient communities, protecting lives & property. Urgent action is crucial amidst rising wildfire risks. Learn more at 

San Francisco smog

A breathing crisis: Rising concerns over U.S. air quality

Facing a stark rise in hazardous air quality, the U.S. grapples with the health implications of escalating pollutants. The alarming data from the American Lung Association urges a renewed focus on air quality management. Federal and local initiatives are in play, yet a unified approach is crucial to mitigate risks and safeguard public health. 


Cybersecurity insurance can be affordable

Cybersecurity insurance rates rose significantly in 2022, with some policyholders experiencing up to 100% rate increases due to the evolving threat landscape and their own cybersecurity measures. CAI emphasizes the importance of understanding and improving an organization's cybersecurity maturity using the NIST 2.0 framework, which can not only strengthen protection against cyber threats but also potentially lower insurance premiums.

Image of GettyImages-1402667894.jpg

Equitable climate resilience (ECR) for local governments: Using data to drive decision making

Discover vital strategies for embedding social equity in your climate resilience plans.

Related Resources


Building Resilience Against Climate Change — Insights from Tidal Basin

Carlos J. Castillo, President of Federal Services at Tidal Basin, emphasized the critical role of emergency management in local climate resilience at the 2024 NACo Legislative Conference and Annual Conference. Highlighting the necessity of integrating emergency management with innovative climate adaptation practices, his presentations provided a comprehensive approach for communities to tackle the immediate and long-term challenges posed by climate-related disasters.


Investing Over $100 Billion in American Infrastructure

AT&T has invested over $140 billion in the past five years to enhance American connectivity, focusing on expanding its role as the nation's largest fiber internet provider and improving its reliable 5G network, which now serves nearly 290 million people.

Computer servers

Building Networks for the Next Century, Not the Last One

AT&T emphasizes its nearly 150-year history of innovation and connectivity as it transitions from traditional copper landlines to modern fiber and wireless technologies, highlighting the importance of adapting to current consumer demands and technological advancements.