Cyber Risk Management for Joint Insurance Funds & Risk Pools

Proven in New Jersey. Ready for your state. Xcitium powers the cyber risk management program protecting 600+ public entities today, now available to Joint Insurance Funds and Government Risk Pools nationwide.

Shadow AI Governance
Why Self-Reported Checklists Were Never Enough

Checklists slowed cyber losses for risk pools but never showed a member's true cyber posture.

Early Losses

Cyber coverage payouts for breaches quickly exceeded the funds collected from members as premium

Pooled Risk

Insurance providers organized as JIFs and GRPs to pool member premiums to amortize the rising cost of cyber breaches with a bigger premium pool.

Checklist Gap

Prerequisite checklists relied on members grading their own posture, leaving real exposure unverified.

Verified Posture

Independent assessment replaces self-reported forms with documented evidence of each member's true readiness.

Already Protecting New Jersey's Public Entities

New Jersey's Cyber JIF, formed by 19 JIFs in 2023, trusts Xcitium across 600+ members.

Forward Approach

New Jersey's JIFs chose independent posture verification over trusting member-completed checklist forms.

Competitive Selection

Xcitium won the first competitive bid issued to deliver risk management services across the entire fund.

Fund-Wide

One consistent program applied across all 600+ member entities, regardless of size or IT resources.

Renewal-Ready

Documented controls built to support underwriting and reinsurer conversations at every renewal cycle.

Proven Economics

Verification services cost funds far less than paying out rising breach claims and ransom demands.

Nationwide Ready

The exact same proven New Jersey program, now available to JIFs and GRPs across all US states.

What Every Member Entity Gets

The core risk management services protecting New Jersey's public entities today, delivered consistently across every member regardless of size, budget, or in-house IT resources.

SAFE Program

Security Awareness for Everyone turns staff into a first line of defense, combining awareness education with realistic phishing simulations that build readiness.

Vulnerability Scan

External scanning continuously identifies exposed, exploitable weaknesses across every member network, surfacing real risk before attackers find and use it first.

Fund Reporting

Risk managers and administrators get one consolidated view of cyber posture across every member entity, replacing siloed per-entity reports with fund-wide clarity.

Expanded Protection

Beyond the core Cyber JIF program, individual JIFs have added these optional services to strengthen their overall risk management. Available to any fund that wants them.

Gap Assessment

Every member entity is benchmarked against recognized security frameworks, identifying and closing posture gaps well ahead of renewal and underwriting conversations.

Penetration Testing

Simulated real-world attacks test member defenses end to end, exposing how an attacker could chain small weaknesses into a breach before a real one does.

Why Funds Choose Xcitium

Built around how public entity risk pools operate, not adapted from a generic enterprise security program.

Public Built

Programs built around the budget realities of municipalities, school boards, and agencies.

Underwriting Support

Underwriters and reinsurers receive documented evidence of fund-wide risk controls, not self-reported claims.

Proven Model

The same program running in production today as the risk control backbone of New Jersey's public entity risk pool.

Outcomes That Matter to the Fund

What fund administrators and member risk managers can expect once the program is in place.

Outcome Impact for the Fund and Its Members
Fewer Claims Reduce the frequency and severity of ransomware and phishing-driven losses across the pool.
Stronger Renewal Position Give underwriters and reinsurers documented evidence of active, fund-wide risk controls.
Consistent Member Compliance Apply the same cyber hygiene standard across every member, regardless of size.
Simplified Fund Oversight Give administrators one consolidated view instead of chasing member-by-member reporting.
Lower Total Cost of Risk Verified prevention costs the fund less than rising breach of payouts and ransom demands.
How It Works
Fund adoption

A JIF or GRP formally adopts the program as part of its member risk control services.

Member onboarding

Every member entity is enrolled with baseline awareness training and vulnerability scanning.

Continuous protection

Ongoing containment, training, and vulnerability management run quietly in the background.

Verified reporting

Documented, fund-wide results replace self-reported checklists for underwriting review.

Renewal support

Administrators receive documentation to support underwriting and renewal conversations.

See the Program Built for Your Fund

Talk to our team about bringing verified cyber risk management to your fund.

By submitting this form, you agree to our Privacy Policy and Terms of Service. Your information will be used to provide you with relevant product information and demo

Thanks for getting in touch. Someone from our team will reach out to you soon.
New Jersey Proved It. Your State Is Next.

Your fund is only as strong as its weakest member. Xcitium replaces guesswork with verified posture, holding every member entity to the same standard, and we'll show you how the New Jersey model adapts to your state.

  • Proven across 19 JIFs and 600+ member entities since 2023
  • Independent verification, not self-reported forms
  • Guidance on adapting the New Jersey model to your state
Frequently Asked Questions
A JIF or GRP is a risk-pooling structure where public entities, such as municipalities, school boards, and utility authorities, jointly self-insure and share risk management resources, including protection against cyber threats they may not be able to secure or afford individually.
Checklists rely on members self-reporting their own posture. This program uses independent assessment to verify actual posture, giving funds real evidence rather than assumptions. New Jersey's funds adopted this approach because verification proved more economical than rising breach and ransom payouts.
No. This is a risk management program, not an insurance policy. It works alongside your fund's existing coverage by strengthening member posture and supporting stronger underwriting outcomes.
No. The program was first proven inside New Jersey's Cyber JIF, formed by 19 JIFs in 2023, and the underlying platform is available to Joint Insurance Funds, municipal risk pools, and self-insurance trusts in any state.
Once a fund adopts the program, member entities are enrolled with baseline Xcitium Risk Management services. Most ongoing protection runs in the background with minimal day-to-day effort from member IT staff.
Documented, fund-wide risk controls give underwriters and reinsurers concrete evidence of active risk management, which can support more favorable renewal terms and conversations.
Yes. Brokers, risk pool administrators, and individual member entities are all welcome to reach out to start the conversation.

By clicking “Accept All" button, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. Cookie Disclosure

Manage Consent Preferences

When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.

These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.
These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.
These cookies enable the website to provide enhanced functionality and personalisation. They may be set by us or by third party providers whose services we have added to our pages. If you do not allow these cookies then some or all of these services may not function properly.
These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.