New Jersey has more than 560 municipalities, and most of them are townships and boroughs run by a clerk, an administrator and a governing body that meets twice a month. Very few have an IT department. Since January 1, 2023, most of them have had something else in common: their cyber insurance runs through the New Jersey Cyber Risk Management Fund, better known as the Cyber JIF, and that fund publishes a list of security controls it expects its members to meet. This post explains what the Cyber JIF is, who it covers, what it asks for, and how a town with no technical staff gets through it. Every program fact below comes from the fund's own website and public documents as read on September 16, 2026.
The Municipal Excess Liability Joint Insurance Fund, the MEL, is the shared insurance structure behind most of New Jersey's local government coverage. Faced with a hard commercial cyber insurance market and shrinking options for local governments, the MEL launched the Cyber JIF on January 1, 2023, modeled on its Environmental Risk Management Fund. It operates under N.J.S.A. 40A:10-36 and N.J.A.C. 11:15-2, the same statute and regulations that govern the other joint insurance funds.
The members of the Cyber JIF are not towns directly. Its members are the 19 affiliated local JIFs, from the Atlantic County JIF to the Suburban Municipal JIF, and each of those holds a commissioner seat on the Cyber JIF board. Look at the board list and you see who really runs it: the administrator of East Windsor chairs it, the township manager of Pequannock is secretary, and the rest are administrators, managers, a mayor, a fire chief and an authority director from towns like Red Bank, Lodi, Ventnor City, Bergenfield and Stafford. If your municipality, utilities authority, fire district or housing authority belongs to one of those 19 funds, the Cyber JIF is your cyber carrier.
The fund's 2026 Plan of Risk Management sets out the structure. The Cyber JIF retains the first $200,000 of each cyber claim, less the member's deductible. Above that, it buys excess insurance from AXA XL and Cowbell. It does not buy reinsurance. The limits each member carries are written into that member's policy and are deliberately not published, for security reasons. Claims go to a contracted claims administrator, and the fund runs a 24/7 Data Breach Hotline at 1-855-566-4724 for immediate triage. The fund is explicit that calling the hotline does not satisfy the notice requirements of the policy, which is a detail worth writing into your incident response plan now rather than discovering during an incident.
Coverage comes with a program. The fund's Documents page lays it out in four steps, with the working documents on a members-only secure page that your JIF has to approve you for.
The public controls infographic groups the framework into ten areas. None of them is exotic. All of them assume somebody is there to run them.
Two of those controls have a member benefit attached. Through its contracted risk control vendor, the Cyber JIF provides members with cyber awareness education and phishing simulation, and an external vulnerability assessment with a prioritized list of findings. The fund put both services out to bid again in 2026 (notices 26-01 and 26-02 on its Governance page), so the vendor name may change, but the benefit is part of membership. A township should be using both, and a provider who proposes to sell you the same thing again is not reading the program.
A county has an IT director. A borough of 6,000 people has a part-time contractor who also does the school. The framework is the same list for both. That is not a flaw in the framework, which is a reasonable modern baseline, but it does mean the smaller the entity, the bigger the gap between what the checklist asks and who is available to do it. The pattern we see is the same in almost every town: multi-factor authentication half rolled out, backups that have never been test-restored, an antivirus that lapsed at the last renewal, no written incident response plan, and one person who knows where everything is. Then the certification checklist arrives and the clerk is asked to sign it.
The work is not complicated, but it is work, and it has to be documented. The sequence we run for a municipality:
Written this way, the administrator signs the certification from a folder rather than from a feeling, the governing body has an answer when a resident asks whether the town is protected, and an OPRA request for the security documentation can be answered without exposing the technical detail, because it was written to be separable from the start.
If you are a clerk, administrator or manager in a Cyber JIF member entity, start with three questions. Do we have the current framework and certification checklist from our JIF? Do we have a written incident response plan with the hotline and the notice path in it? Can we show a tested restore of our backups from the last ninety days? If any answer is no, that is the gap to close first. Cloud Guardian's Cyber JIF readiness service takes an entity from wherever it stands to a certification it can sign, and our local government page lists the 19 affiliated JIFs with a page for each. Our office is in North Brunswick, Middlesex County, and we respond to public solicitations.
Sources: cyberjif.org home, About, Documents, Resources and Governance pages; the Cyber JIF 2023 Controls Infographic; the 2026 Plan of Risk Management (Resolution 20-26). All read September 16, 2026. Coverage terms, limits and deductibles are set by the fund and each member's policy, not by Cloud Guardian.
Get a free assessment and see how this applies to your business.
Hi. Ask us anything about your IT, pricing, or an issue you are having right now. We reply fast during business hours.
Pick where you want the reply. Your message comes with you, nothing is retyped.