Skip to main content
An Ohio township finance officer at a desk comparing a cyber insurance renewal packet against a printed compliance checklist, a red pen the only color accent
Compliance / Risk

Cyber Insurance Requirements for Ohio Public Entities: What Underwriters Now Demand

The controls a carrier scores at renewal are the same controls ORC 9.64 and NIST CSF 2.0 describe. Here is the checklist, the mapping, and how to bring the evidence to the table.

By William Bradshaw | June 29, 2026 | 10 min read

For an Ohio township, fire or EMS district, or municipal office, the cyber insurance application is where the cybersecurity program meets the budget. A carrier does not ask whether you intend to be secure. It asks whether specific controls are in place today, prices the premium against the answers, and in a growing number of cases declines to cover the gaps. Renewal season for many public entities lands near the July 1 fiscal-year start, which makes late spring the window where this becomes a board-level conversation.

The encouraging part, if you serve Ohio public-sector clients, is that the underwriter's questionnaire and the ORC 9.64 program are asking for the same things. A political subdivision that has adopted a recognized framework and documented its controls has already produced most of the evidence an insurer wants. The work is not duplicate. It is the same control set, presented to two different audiences.

This article walks the controls underwriters now require, maps each one to ORC 9.64 and the NIST Cybersecurity Framework 2.0, and shows how to turn a network assessment and a vulnerability scan into the documentation a renewal requires. If you are already running an ORC 9.64 program, treat this as the insurance-facing view of work you have started; our guide on maintaining ORC 9.64 after July 1 is the companion piece.

Why the Requirements Tightened

Cyber insurance was, for years, an easy line item: a modest premium, a short application, and broad coverage. Ransomware ended that. A wave of claims that paid out ransom demands, recovery costs, and business-interruption losses pushed the market into a hard correction. Premiums rose sharply, coverage limits fell, and carriers replaced the short application with a detailed supplemental questionnaire that functions as a controls audit.

The market has since stabilized, but the questionnaire did not go back. Underwriters learned which controls actually reduce claims, and they now price against those controls and decline applicants who lack them. Multi-factor authentication is the clearest example: carriers found that accounts protected by MFA were dramatically less likely to lead to a paid ransomware claim, so MFA moved from a discount item to a condition of coverage.

Public entities feel this acutely. Townships and special districts run lean IT, often without a dedicated security function, yet they hold the same personally identifiable information, payment systems, and operational technology that make a target attractive. ORC 9.64 exists in part because the state recognized that exposure. The cyber insurance market reached the same conclusion from the claims side. The two pressures now point at the same control set.

The Underwriter Control Checklist

The supplemental questionnaire varies by carrier, but the core controls are consistent across the market. These are the questions that determine whether you are quoted, surcharged, or declined.

Multi-factor authentication (MFA)

Required on email, remote access (VPN and remote desktop), and privileged or administrator accounts. This is the single most common condition of coverage. Missing MFA on remote access is, for several carriers, grounds to deny a ransomware claim outright.

Endpoint detection and response (EDR)

A managed EDR or managed detection and response capability on servers and workstations, not just legacy antivirus. Underwriters distinguish between signature-based AV and behavior-based EDR, and the distinction affects the quote.

Tested, segmented backups

Backups that are offline or immutable, separated from the production network, and restored on a tested schedule. The question is not "do you back up?" but "have you proven you can restore?" An untested backup is treated as no backup.

A defined patch cadence and vulnerability management

A documented schedule for applying critical patches and a process for finding and closing vulnerabilities. Increasingly, underwriters ask for evidence of recent vulnerability scanning, not just a policy statement.

Email filtering and protection

Filtering for phishing, malicious attachments, and spoofed senders, since email remains the primary intrusion path. SPF, DKIM, and DMARC alignment is often part of the question.

A written, exercised incident-response plan

A documented plan that names roles, escalation paths, and the carrier's own breach hotline, and that has been walked through at least once. A plan that exists only as an intention does not satisfy the question. Our incident response plan guide for Ohio public entities covers what that plan must contain, including the statutory notification duties a generic template misses.

Recurring security-awareness training

Periodic training and phishing simulation for staff. Carriers view the workforce as the largest attack surface, so a recurring program (not a one-time orientation) is what the question is looking for.

How Each Control Maps to ORC 9.64 and NIST CSF 2.0

ORC 9.64 directs Ohio political subdivisions toward a recognized cybersecurity framework, and the NIST Cybersecurity Framework 2.0 is the common choice. Its six functions (Govern, Identify, Protect, Detect, Respond, Recover) line up with the underwriter checklist almost one to one. Build the program once and it answers both audiences.

Underwriter control NIST CSF 2.0 function ORC 9.64 program element
Multi-factor authentication Protect (identity and access) Access control safeguards
Endpoint detection and response Detect Continuous monitoring
Tested, segmented backups Recover Recovery and continuity planning
Patch cadence and vulnerability management Identify and Protect Risk assessment and remediation
Email filtering and protection Protect Data and communications safeguards
Written incident-response plan Respond Incident-response procedures
Security-awareness training Govern and Protect Workforce training and policy

The practical takeaway: there is no separate "insurance project." The ORC 9.64 program, built around NIST CSF 2.0, is the insurance project. Our compliance framework mapping guide walks the same control-to-framework translation in more detail, including how a single piece of evidence can satisfy several requirements at once.

Producing the Evidence Underwriters Ask For

The gap between a control that exists and a control you can prove is where renewals stall. Attesting on the questionnaire that you "patch regularly" is one thing; producing a dated scan report that shows the current state of every host is another. Two artifacts close most of that gap.

The first is a network assessment. Before you can attest to controls, you need an accurate inventory of what you are protecting: every server, workstation, network device, and the operating system and patch level of each. Many public entities discover during an assessment that the network holds more than the documentation reflects, an unmanaged switch here, an end-of-life server there. The assessment turns "we think we are covered" into a documented baseline.

The second is a recurring vulnerability scan. A scan enumerates the known weaknesses across the inventory, ranks them by severity, and gives you a remediation list. Run on a schedule, it produces exactly the patch-cadence and vulnerability-management evidence underwriters now request, with dates attached. The open-source netvuln-tool scanner performs this baseline at no license cost, and Bullium's managed collection portal keeps the resulting reports current and reviewable when you want the recurring cadence handled for you.

The same two artifacts serve the ORC 9.64 review and any compliance audit. Produce the assessment and the scan once, keep them current, and you have built a single evidence base that the insurer, the framework, and the auditor all draw from. That reuse is the efficiency a lean public-sector IT operation needs.

A Renewal-Prep Checklist (60 to 90 Days Out)

Starting early is what separates a clean renewal from a scramble. Begin two to three months ahead of the policy date so there is time to close a gap rather than attest to a control that is not yet live.

Days 1-30

Baseline and inventory

Run a network assessment and a vulnerability scan. Confirm MFA is enabled on email, remote access, and administrator accounts. Identify any end-of-life systems that will draw an underwriter question, and decide how you will answer for each.

Days 31-60

Close the gaps

Remediate the high-severity findings from the scan. Confirm EDR coverage on every endpoint. Test a backup restore and record the result. Walk through the incident-response plan with the people named in it. Each closed gap is a "yes" you can defend on the questionnaire.

Days 61-90

Assemble and submit

Complete the supplemental questionnaire with the evidence attached: the assessment, the latest scan and remediation record, the backup-test result, and the incident-response plan. Keep a copy of the submission so next year's renewal starts from documentation, not memory.

Frequently Asked Questions

Do cyber insurers require multi-factor authentication?

Yes. MFA on email, remote access, and privileged accounts is now a baseline condition on most applications. Many carriers decline coverage or apply a surcharge without it, and several treat missing MFA on remote access as grounds to deny a ransomware claim.

What controls do underwriters ask about in 2026?

Multi-factor authentication, endpoint detection and response, tested and segmented backups, a defined patch cadence, email filtering, a written and exercised incident-response plan, and recurring security-awareness training. Evidence of recent vulnerability scanning is increasingly part of the request.

How does ORC 9.64 relate to cyber insurance?

ORC 9.64 points Ohio political subdivisions toward a recognized framework, commonly NIST CSF. The controls that framework describes are the same controls underwriters score, so a subdivision running an ORC 9.64 program has already produced most of the insurance evidence.

Does a vulnerability scan help with renewal?

Yes. A recent scan and a remediation record demonstrate the patching and vulnerability-management controls underwriters ask about, and the report is reusable evidence across the renewal, an ORC 9.64 review, and a compliance audit.

When should we start preparing?

Begin 60 to 90 days before the renewal date. For many Ohio public entities that date falls near the July 1 fiscal-year start, so late spring is the planning window. Starting early leaves time to close a control gap before the questionnaire is due.

Walk Into Your Renewal With the Evidence in Hand

Bullium works with Ohio townships, fire districts, and public entities to baseline their environment, close the control gaps underwriters score, and assemble the evidence a renewal requires. We start with a network assessment and a vulnerability scan, then map the results to ORC 9.64 and your carrier's questionnaire. No commitment to engage further.