Why government entities are a distinct risk category
The FBI's Internet Crime Complaint Center (IC3) has consistently identified government as a top-tier target for ransomware operators. Federal, state, and local government entities collectively account for a significant share of annual ransomware incidents, and the characteristics that make government attractive to attackers — public sector data, critical service dependencies, political pressure, and complex vendor ecosystems — also make government a distinct actuarial risk for insurers.
State and local government presents specific risk factors that cyber underwriters price separately from commercial enterprises:
- Service continuity pressure. Ransomware operators know that government agencies face immediate political accountability for service disruption. Benefits agencies that cannot process claims, DMV offices that cannot issue licenses, and emergency services that cannot dispatch all face direct constituent impact within hours. That pressure shortens the decision cycle on ransom payment.
- Legacy system exposure. Many state agencies run core functions on systems built decades ago, with limited patching cadence, minimal network segmentation, and integrations that were never designed with modern threat models. Legacy environments are disproportionately represented in ransomware incidents.
- Vendor and third-party access. State agencies routinely grant system access to software vendors, managed service providers, and consultants under long-standing agreements that predate current access management requirements. Lateral movement through third-party access is a documented attack path in documented state-sector incidents.
These characteristics are visible to insurers through underwriting questionnaires, loss history, and industry data. State and local government is not pooled with commercial enterprise. Underwriters apply government-specific models, and state CISOs who treat government insurance procurement as equivalent to commercial IT insurance are likely to misread the requirements.
The evolution of the underwriting questionnaire
Cyber insurance questionnaires have moved through three functional generations in the past decade.
First generation (approximately 2015–2019): Attestation-based. Questions were binary: "Do you have a security policy? Do you require MFA for remote access? Do you have an incident response plan?" Answers were self-reported without documentation requirements. Underwriters priced primarily on revenue, sector, and self-reported control posture.
Second generation (approximately 2020–2022): Coverage-based. Binary questions gave way to coverage percentages and population specifics. "What percentage of email accounts have MFA enforced?" "What percentage of endpoints have endpoint detection and response deployed?" "What percentage of privileged accounts are enrolled in privileged access management?" These questions required an answer that went beyond attestation — it required the agency to know its own coverage, which many did not.
The shift was driven by large claims. Ransomware incidents that resulted in multi-million-dollar recoveries — many of them in the government sector — revealed that yes/no attestations did not predict actual control effectiveness. An agency that attested to MFA but had only enrolled 40 percent of its accounts behaved very differently in a breach than one with full enrollment. Insurers repriced to reflect what the data showed.
Third generation (2023–present): Evidence-based. Current questionnaires from major government-sector cyber insurers include documentation requirements alongside attestations and coverage questions. IR plan submissions, tabletop exercise records, system architecture summaries, vendor access logs, and backup testing records are requested before binding. Some programs require a third-party validation of control posture for coverage above stated thresholds.
State CISOs should request a copy of their current insurer's questionnaire early — ideally 90 to 120 days before renewal — to understand which generation it represents and what documentation it will require.
What current questionnaires actually assess
The specific items that recur across government-sector cyber underwriting questionnaires include the following. Each item is followed by what an adequate response requires — not just the control itself, but the documentation that supports it.
Multi-factor authentication (MFA) Questions have moved from "do you require MFA?" to "what percentage of accounts enforce MFA for remote access?" and "what percentage of privileged and administrative accounts enforce MFA?" Adequate documentation is an identity management system report showing enrollment counts by account type, confirming that exceptions are approved and time-limited, and identifying the mechanism (token, authenticator app, hardware key) used for privileged accounts.
An agency that has deployed MFA broadly but cannot produce a coverage report is in a materially weaker position at renewal than the control posture alone would suggest. Insurers interpret the absence of a coverage report as a monitoring gap, which is itself a risk indicator.
Endpoint detection and response (EDR) Insurers ask for EDR coverage as a percentage of total managed endpoints, and increasingly ask separately about server coverage vs. workstation coverage and about operating system version distribution. Adequate documentation includes an asset inventory confirming total managed endpoint count, an EDR console report confirming enrolled endpoint count, and a process for onboarding new devices.
Privileged access management (PAM) Questions ask whether privileged credentials are vaulted, whether session recording is enabled for administrative sessions, and whether just-in-time access is implemented. Documentation requirements are a PAM platform report confirming vault enrollment by credential type, session recording coverage, and any exceptions with documented justification.
Network segmentation Questions ask whether critical systems are logically segmented from user endpoints, whether OT/ICS environments are isolated (where applicable), and whether east-west traffic is monitored. Documentation requires a network architecture summary confirming segmentation, VLAN structure, and access control lists governing cross-segment traffic.
Immutable or offline backups Questions have become specific: "Are backups stored in a location that is not accessible from the primary network?" "What is the tested recovery time for critical systems?" "When was the last backup restoration test performed?" Adequate documentation is a backup system report confirming offline or immutable storage status, a restoration test record with date and recovery time achieved, and a recovery time objective documented in the DR plan.
Email security controls Questions specifically ask whether DMARC is configured for all email domains, whether DKIM and SPF are implemented, and whether anti-phishing simulation training has been completed. Documentation includes DMARC configuration confirmation (enforcement-level, not monitor-only), and training completion records by completion date and percentage.
Incident response preparedness Current questionnaires ask for the date of the last tabletop exercise, whether external responders were included, and the scenarios tested. An IR plan document alone is not sufficient; insurers want evidence of practiced response. Documentation is a tabletop exercise record with date, scenario scope, participants, and findings.
Vendor and third-party access Questions ask whether a vendor access registry exists, whether privileged vendor access is time-limited, and whether vendors are required to meet security standards as a contract condition. Documentation is a vendor access inventory confirming current active vendor sessions and their access scope.
The documentation gap
The most common renewal friction for state agencies is not a missing security control — it is a missing record. Many state agencies have deployed MFA but cannot produce a report showing what percentage of accounts are enrolled. They have an IR plan but cannot provide a tabletop exercise record with a date in the past 12 months. They have EDR deployed but lack an authoritative count of total managed endpoints to calculate coverage percentage.
The documentation gap has two practical consequences at renewal. First, it forces the agency to collect the evidence under deadline pressure, which increases the risk of submitting inaccurate information. An accurate questionnaire requires the same evidence as a complete renewal packet; collecting it 10 days before renewal produces both a stressful process and a higher risk of errors.
Second, the inability to answer coverage questions — even when controls exist — signals a monitoring gap to underwriters. An agency that cannot answer "what percentage of endpoints have EDR deployed?" is communicating that it does not continuously measure its own security posture. Continuous measurement is itself a control, and its absence is a risk indicator independent of the underlying tools deployed.
Using the questionnaire as a security program driver
The practical value of the underwriting questionnaire is that it is more operationally specific than most state agency self-assessments. State security self-assessments tend to be policy-level documents: "we have an MFA policy, we have an EDR deployment plan." The questionnaire demands the operational evidence behind those policies.
For state CISOs building or improving security measurement programs, the questionnaire is a useful template. Working backwards from the questionnaire creates a prioritized list of measurements:
- MFA coverage by account type → requires identity management reporting
- EDR coverage percentage → requires authoritative asset inventory
- Privileged access under PAM → requires credential vault reporting
- Backup restoration test records → requires documented DR testing cadence
- Tabletop exercise date and scope → requires IR program formalization
- Vendor access registry → requires access management for external parties
Each measurement that the questionnaire requires is a measurement that would independently improve security visibility. Agencies that build their measurement program to answer the questionnaire will, as a side effect, build a more governed and measurable security posture.
A preparation timeline
For state CISOs managing annual renewal, the following sequence distributes the work appropriately rather than concentrating it at deadline.
90–120 days before renewal:
- Obtain a copy of the current underwriting questionnaire from the broker
- Compare questionnaire line items against the previous year's responses
- Identify items where the control has changed (upgraded, expanded, or reduced)
- Identify items where the documentation format has changed
60–90 days before renewal:
- Collect documentation for each questionnaire item from the relevant system owners (identity management, endpoint management, networking, backup, IR)
- Identify gaps where documentation cannot be produced
- For gaps, determine whether a documentation deficit or a control deficit exists
30–60 days before renewal:
- Assemble the completed questionnaire with supporting documentation
- Conduct an internal review with the CISO and CIO to verify accuracy
- Submit to the broker with sufficient lead time for underwriting review
At renewal:
- Confirm coverage terms, exclusions, and sub-limits
- Note any changes from prior year terms that reflect control improvements or deterioration
- Document renewal terms and questionnaire responses for use in next year's 120-day preparation
Coverage terms state CISOs should understand
Cyber insurance policies for government entities include terms and exclusions that are specific to the sector. State CISOs should understand the following before renewal, rather than discovering them at claim time.
State-sponsored actor exclusions. Some policies include exclusions for "acts of war" or events attributed to nation-state actors. Following the NotPetya attribution controversy, insurers developed more explicit language around state-sponsored cyber incidents. Government entities, which are disproportionately targeted by sophisticated state-affiliated actors, should ask their brokers to explain exactly what state-sponsorship attribution means in their policy's exclusion language and what evidence would trigger the exclusion.
Business interruption coverage for government services. Commercial business interruption coverage is typically calculated against revenue loss. Government entities do not have revenue in the same sense. Policy language should explicitly address the scope of business interruption coverage for government — specifically, whether it covers costs incurred to maintain services by alternative means during a system outage, including manual processing, contractor augmentation, or alternate-site operations.
Ransomware response and payment provisions. Policies vary on whether ransom payment is covered, under what conditions, and whether prior insurer approval is required. State CISOs should understand this provision before an incident, not during one. The operational reality is that ransom payment decisions are time-sensitive; a policy that requires prior approval needs a process for obtaining that approval at 2 a.m. on a Saturday.
Sub-limits for critical systems. Some policies apply sublimits to specific system categories, infrastructure types, or incident types. A sub-limit for critical infrastructure incidents in a state that runs water utility systems or power grid monitoring would significantly reduce effective coverage in the incidents most likely to draw public attention.
Spartan X's approach to state security assessment
Spartan X's security advisory work for state government clients integrates operational measurement with compliance and governance requirements. The pattern evident in state security engagements — controls deployed but not measured, tooling installed but not inventoried, coverage gaps that are invisible until a questionnaire or incident reveals them — is exactly the problem that security program documentation addresses. Understanding what you have, where it applies, and how to demonstrate it is the foundation of both a defensible insurance posture and an effective security program.
Sources and further reading
- FBI Internet Crime Complaint Center (IC3) Annual Report, 2023: ic3.gov
- National Association of Insurance Commissioners (NAIC), Cyber Insurance Working Group reports: naic.org
- CISA, "Cyber Insurance and Your Organization": cisa.gov
- CISA, "Understanding and Mitigating Russian State-Sponsored Cyber Threats to US Critical Infrastructure" (AA22-011A): cisa.gov
- CISA, Known Exploited Vulnerabilities Catalog: cisa.gov



