Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Waseca County approves supplemental cybersecurity insurance after learning lessons from other counties’ incidents
Summary
After hearing lessons from recent ransomware incidents and that existing coverage caps were insufficient, the board approved supplemental cyber insurance (materials showed limits up to $3 million) and endorsed technical steps such as immutable backups and multifactor authentication; the premium in meeting materials was read as about $12,403.30.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
WASECA, Minn. — The Waseca County Board of Commissioners approved a supplemental cybersecurity insurance package and discussed technical changes to reduce ransomware risk after staff reviewed recent county incidents elsewhere.
County IT and administration described a neighboring county’s ransomware incident that exposed gaps in insurance and incident response; staff said the county purchased an immutable backup appliance and is working toward required security measures. The board heard that the county’s primary insurer (MCIT) caps some coverages and that supplemental coverage would broaden liability limits (materials referenced an aggregate up to $3,000,000).
A county presenter outlined common attack methods (dictionary and credential attacks) and emphasized multifactor authentication and immutable backups as key mitigations. "Buying the supplemental insurance... the cost of lost wages recovery, physical, mental well-being of our community, IT team... outweighs the premium cost tenfold," the presenter said.
At the meeting the premium in the materials was read aloud as approximately $12,403.30 (several speakers described it as "about $12,000 and some change" during discussion). The board moved and approved the supplemental policy and discussed options to increase certain sublimits (for a modest additional premium).
What happens next: County IT will complete required pre-insurance security steps, finalize the supplemental policy and continue to implement MFA, immutable backups and other recommendations. Staff said they will report back on compliance with insurer stipulations before the policy takes effect.

