Bloomington School District 87 in Illinois has released its cybersecurity incident insurance renewal details, and the cost has increased from $6,661 in 2021 to $22,229 this year.

See also: Dutch cybersecurity agency warns of lingering Log4j risks
This dramatic 334% increase in insurance premiums is attributed to the sudden increase in the number of threats, their severity, and the potential for costly consequences.
“In light of the events that negatively impacted the Cybersecurity Insurance market, SSCIP was initially unable to find the required coverage for the group,” the note.
SSCIP group that allows school districts to come together to negotiate better insurance rates and lower management fees.
The most significant problem driving this sudden increase in costs is ransomware and the disruption that encryption attacks and data theft can cause to compromised school networks, employees, and students.
Ransomware actors target smaller school districts because they are rarely well protected from attacks and usually cannot afford to employ a specialized IT and security team.
See also: RRD: Confirms data theft from Conti ransomware attack
However, as schools usually have active insurance policies, they are attractive targets for malicious users hoping for a quick payout from insurance companies.

Emsisoft has published a report to summarize ransomware against the US public sector, counting 77 governments, 1,043 schools, and 1,203 healthcare victims.
As the District 87 memo stated, the insurance company also asked the district to fully implement multi-factor authentication protection on all of its accounts, as part of cybersecurity.
The school estimates that they can complete this change by March 30, 2022. However, until this happens, the coverage limits will remain reduced, well below the amount they have agreed to.
This reflects the importance that insurers and security experts place on using MFA to protect network connections.
See also: CISA: Hackers bypassed MFA to compromise cloud service accounts!
Ransomware carriers typically deploy their encryption tools using compromised user credentials to access target systems, so having MFA is often enough to stop an attack before it even starts.
Also, backup service connections should be protected using MFA so that ransomware operators cannot access and delete backups. Having reliable backups significantly weakens a ransomware gang’s bargaining position and speeds up data recovery.
