Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cyber Insurance topic

No spam. Unsubscribe anytime.

Legislative committee hears that cyber insurance is available but costly and administratively demanding for Oregon schools and special districts

2732754 · March 21, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The Joint Legislative Committee on Information Management and Technology on March 30 heard that cyber insurance is more available than it was in 2023, but higher costs and stringent underwriting requirements mean many small special districts and school districts remain underinsured and struggle to meet coverage prerequisites.

The Joint Legislative Committee on Information Management and Technology on March 30 heard that cyber insurance is more available than it was in 2023, but higher costs and stringent underwriting requirements mean many small special districts and school districts remain underinsured and struggle to meet coverage prerequisites.

Frank Stratton, executive director of the Special Districts Association of Oregon, told the committee that most special districts buy basic coverage through the Special Districts Insurance Services (SDIS) trust but that limits are low: “$50,000 first party and a hundred thousand dollars third party,” he said, adding that roughly 95% of members take that minimal option because they cannot meet underwriting benchmarks or prefer the low-cost pooled option. Stratton said larger entities sometimes purchase excess coverage in the private market.

Why it matters: Local governments and schools hold sensitive personal data and provide essential services. Witnesses said better cyber hygiene reduces both risk and insurance costs, and that a centralized effort to assess and assist local entities could be more effective than simply researching market availability.

Speakers from school and local-government insurance pools described recent market and underwriting changes. Stratton explained that SDIS offers higher tiers (for example, $250,000 first-party and $500,000 third-party limits) only to members that implement controls such as multifactor authentication (MFA) for email and critical services, restricted administrative rights, daily backups, endpoint detection and a written incident-response plan. He warned that SDIS’s self-insured pool has a $2,000,000 aggregate annual cap on payouts.

Greg Harden, cybersecurity specialist and system architect for City County Insurance Services (CIS), said CIS saw 18 cyber claims in the last two-year cycle and that many members still carry minimum coverage. Harden described common claim types as funds-transfer fraud, business-email compromise and, less frequently for CIS in that period, ransomware. He said CIS is reinstating MFA as a requirement for higher-tier coverage and is simplifying tier structure while raising some minimum limits to encourage stronger protections.

For schools, the PACE (Property and Casualty Coverage for Education) trust buys a group policy from a carrier (named in testimony as AIG). According to testimony from Stratton, PACE provides $1,000,000 per member with a stated $500,000 combined limit for all members (as described to the committee); PACE also maintains a member deductible and a larger self-insured aggregate cap. PACE has progressively added underwriting requirements over successive years — rotating passwords, restricted privileges, daily backups, annual staff training, external vulnerability scans and scheduled backup recovery testing — and reported that approximately 265 of about 300 members have met current requirements.

Stratton and Harden described notable claims that illustrate third-party and vendor risks: a payroll and HR vendor breach affecting many school districts produced large notification and monitoring costs (Stratton estimated about $1 million that PACE would pay initially and then seek reimbursement from the vendor), and a separate, widely publicized vendor used by many districts (referred to as ProSchools) suffered a nationwide attack affecting student records.

Representatives from the Department of Administrative Services Risk Management Division (Shelly Hoffman, risk program manager, and Bonnie Robbins, risk consulting unit manager) summarized the state’s experience and insurer expectations. Bonnie Robbins said insurers have returned to the market since 2023 but now routinely require vulnerability scans, MFA, restricted administrative accounts, off-site backups and other controls; underwriters are limiting single-carrier capacity to roughly $5 million and often place sublimits or coinsurance on ransomware.

Robbins said state agencies typically pay first-party breach costs at the agency level (call centers, notifications, credit monitoring, recovery work); the division purchases a commercial cyber policy only for the Oregon Lottery, which in the most recent renewal obtained a layered (“tower”) $20 million program across multiple carriers and reduced its self-insured retention after improving cyber hygiene.

Discussion and recommendations: Presenters urged the committee to focus Center of Excellence resources on practical assessments and direct technical assistance (helping entities complete required controls and creating a statewide inventory of needs), rather than on a basic market availability study. Stratton, who also serves on the Oregon Cybersecurity Advisory Council, said the center could help evaluate vendor security practices and prioritize funding or grants to raise baseline protections.

Ending: Committee staff said they will collect and circulate more detailed claims data, vendor incident information and written testimony submitted after the hearing. No formal action or vote occurred during the informational session; the committee then opened a public hearing on House Bill 3228.