Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Insurance topic

No spam. Unsubscribe anytime.

Humboldt County raises cyber liability coverage to $1 million; staff highlight limits and ongoing IT work

5382511 · July 14, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The board approved increasing the county's cyber liability policy from $250,000 to $1,000,000 through the county insurance pool (ICAP). Staff and the county's IT adviser warned of coverage exclusions and emphasized continued investments in IT safeguards.

Humboldt County supervisors voted to increase the county’s cyber liability coverage from a $250,000 base policy to a $1,000,000 combined limit by adding a $750,000 excess layer offered through ICAP.

County staff explained the change during a detailed presentation on cyber coverage components and limitations. The policy structure retains an underlying $250,000 base policy with a $750,000 excess endorsement to produce a $1,000,000 total limit. Staff noted the policy covers third‑party exposures (for example, payment card data compromises) and first‑party costs such as breach response, incident response fees and cyber extortion payments. County staff also identified several important exclusions or limits: post‑breach remediation that requires purchasing new software or making substantive equipment upgrades may remain the county’s responsibility, and coverage does not automatically replace software or systems that are rendered unusable (commonly described in the policy language as "bricking").

Chris, who reviewed the renewal with staff last week, summarized the rationale in plain terms: "250,000 wasn't gonna get us much," he said. County staff and the board cited the recent hiring of a dedicated IT person as a complementary measure to reduce claim risk; staff said improved internal practices could help limit future surcharges or premium impacts.

Board members asked about programmatic steps the county could take to lower risk and whether ICAP would offer credits for improved security practices; staff said ICAP relies on renewal questionnaires and that IT improvements and claim avoidance are the primary mitigants.

The board approved the coverage increase by voice vote. Staff said no signatures are required to effect the change; the county insurance administrator will notify ICAP and provide departmental premium breakout information.

What changed and what it means - New combined limit: $1,000,000 (underlying $250,000 + $750,000 excess). - Third‑party exposures covered include multimedia security and privacy liability and payment card industry (PCI DSS) exposures tied to card acceptance. - First‑party coverage items include breach event costs, system failure coverage, cyber extortion and cybercrime; some sublimits apply (for example, cybercrime underlying $100,000 plus $150,000 excess to provide $250,000 for that sub‑coverage). - Exclusions/limits: post‑breach remediation costs and some replacement software/equipment costs are not fully covered; "bricking" remediation may require the county to rely on backups or maintenance agreements.

The board directed staff to notify ICAP and return departmental breakout cost information to the auditor’s office for billing and budgeting.