Compliance Coffee Talk covers a new topic each month – RSVP for the series.
June: “How do you manage cyber risk at small/mid-sized counties?”
Gavin Lobmeyer (Risk Manager, Laramie County, Wyoming) joined John for a fast 30 minutes on cyber risk for small and mid-sized public agencies. Gavin’s vantage point is unusual — he came into risk management from a cyber/IT background, and he’s running risk for the largest county in the least-populated state, which happens to host seven data centers and an NCAR supercomputer. The throughline: small agencies often get hit first because they’re the test bed for attacks that later scale up to bigger systems, but the path to a stronger program isn’t more headcount — it’s leaning on partnerships (broker, IT, state cyber teams, larger municipalities) and getting basic cyber hygiene right. Topics included Gavin’s broker creating a custom coverage tier in response to his program’s strength, his explanation that “security is a process, not a product,” and a sober heads-up that cyber reinsurance is on track to outpace the liability market in the next couple of years.
Watch the full replay, or keep scrolling for a summary of some of the key insights and practical tips from the session.
Meet the Expert
We’ll discuss:
We’ll start with a few insights Gavin gave John at PRIMA a few weeks ago – what’s unique about small/mid-sized counties, what it’s like coming into Risk from the world of IT, and where to get started when you’re playing catchup on cyber risk.
Then we’ll jump into questions and specific scenarios from attendees. If you’ve got questions or scenarios, you can always send them in ahead of time to john.rote@evidentid.com, or just ask live during the session.
Key Takeaways
Small and mid-sized agencies are the test bed, not the afterthought. Attackers use them to develop and refine exploits because they share software with larger agencies and run weaker defenses — successful techniques then scale up.
“Oftentimes [small and mid-sized agencies] are considered the test runs for most bad actors… most people do not have the resources, the team, the money to really have a robust cyber system or practice in place. Attackers know that.”
“Security is a process, not a product.” Stop waiting to feel ready. Baby steps, then more baby steps. Anyone selling completeness is selling fiction.
Use upcoming broker requirements to build the internal case for resources. Gavin secured a dedicated cybersecurity hire by surfacing that his cyber insurance would require one in the next renewal cycle. Look at what’s mandated next year, not just this one, and let that build your business case before it’s a fire drill.
“When you’re too small to do it yourself, you rely on your partners.” Brokers (free annual pen tests, audits), state/federal joint teams (Wyoming’s CARE team is a model worth asking your own state about), and larger municipalities are leverage you may already have access to and aren’t using.
Step-one cyber hygiene: clean up terminated-user access. Dormant accounts let attackers “live off the land” — they don’t need to create a new identity if they can squat on someone else’s. Costs nothing; most municipalities haven’t done it.
Step-two cyber hygiene: get visibility and policy around AI tool usage. The most dangerous risk is one you don’t know about. AI tools are proliferating department-by-department and most agencies can’t name what’s in use.
Reframe incident planning from “if/when” to “do we know or don’t we?” In cyber you may already be compromised and not know it. That changes what you prioritize — detection and hygiene over hypothetical playbooks.
“It’s not if or when. It’s you either know or you don’t know. And the most dangerous risk is something you don’t know about.”
Risk and IT share ownership of cyber, but the lanes are clear. IT drives where they have the expertise; risk owns awareness, facilitation, and connecting IT to external resources (brokers, state teams, federal grants). Schedule regular check-ins to keep things moving.
Cyber reinsurance is projected to outpace the liability market in the next couple of years. Plan accordingly when budgeting renewals and modeling future premium trajectories — this is not a stable line item.
Piggyback on larger entities’ SaaS contracts for better mid-vendor terms. With mega-vendors (Microsoft, etc.) you won’t move the terms — but you do inherit the protection of their in-house cyber teams.
The next big emerging contract question is where cyber liability sits when public-sector data lives on third-party SaaS servers we don’t control. Worth getting ahead of in your standard language now.
A certification like ISO/IEC 27001:2022 (ISMS internal auditor) gives you the language and foundation — useful for the bridge role between risk and IT, but it’s not a substitute for cyber expertise. Good candidate for whoever sits in the middle.
That’s all for now, but there’s a lot more in the recording.
Join us next month. As always, let us know if there are topics or questions you’d like to see covered in future sessions.