The New Jersey Cyber JIF sets the cyber controls that member municipalities, authorities and public entities have to meet and attest to. Most of those controls were written for an organization with an IT department. Most members do not have one. Cloud Guardian reads the framework, maps it to what you actually run, closes the gaps, and hands you the evidence, so the attestation is a formality rather than a fire drill.
A borough with a part-time IT contractor gets the same list as a county. The controls are reasonable; the assumption that someone is there to run them is not.
It comes around every year whether the work is done or not, and it is usually the clerk or the administrator who has to sign it.
Where you stand against the controls is part of how the fund sets what it carries for you. Guessing is expensive in both directions.
A firewall invoice is not a control. The fund wants the control operating and documented, and a box on a shelf does neither.
The Cyber JIF publishes its control list and updates it. The current version on cyberjif.org is the one we work from, line by line. The controls fall into families any public entity will recognize, and every one of them is something we already run for managed clients or can stand up quickly.
MFA on email, remote access and every administrative account, with the accounts that should not exist any more actually gone.
Managed protection on every workstation and server that can see it, isolate it and tell someone, not an antivirus that expired two renewals ago.
Copies an attacker cannot encrypt or delete, with restores performed on a schedule and the results written down.
SPF, DKIM and DMARC enforced on the entity's domain, filtering in front of the mailbox, and impersonation of the mayor or the CFO caught before it lands.
Operating systems and applications kept current on a documented cadence, and the machine under the clerk's desk that cannot be patched replaced or fenced off.
Staff trained on a schedule with phishing simulation, and completion records the fund can be shown.
A named person responsible, written policy, and an incident response plan that has been walked through at least once before anyone needs it.
Who can reach your systems from outside, what they can reach, and whether the software vendor holding your records meets the same bar you do.
The Cyber JIF's own controls document is the authority, and it changes. We check the published version at the start of every engagement rather than working from a copy, and we map each control on it to what is in place, what is missing and what the evidence will be. See the program's governance and controls material at cyberjif.org.
The controls exist because municipalities are the softest large targets in the state: public records, payroll, tax collection and utility billing, run by small staffs on aging equipment. Meeting the list is how you stop being that.
Cloud Guardian takes an entity from wherever it stands to an attestation it can sign with confidence, and keeps it there year to year.
Every control on the current list checked against what is actually in place, with the gaps ranked by risk.
The gaps closed in priority order: MFA rolled out, backups fixed, endpoints protected, systems patched or retired.
A document behind every line of the attestation: screenshots, reports, policies and records, organized the way the fund asks.
Awareness training delivered on a schedule, tested with simulated phishing, with completion records kept.
A written plan with names and phone numbers in it, walked through with your people before it is ever needed.
Before each attestation, the list is checked again against the current published version and the evidence refreshed.
Every engagement is quoted to the entity: its size, its systems and how many controls need work. Onsite across New Jersey. Need something else? Tell us.
For an entity that needs to know exactly where it stands before the attestation comes around.
The gaps closed and the evidence assembled, so the next attestation is signed from a folder rather than a guess.
The controls run day to day by us, so the entity stays where the attestation says it is all year.
A staged path from where the entity stands today to evidence in hand, with the order of work agreed before anything starts.
Which JIF you belong to, when the attestation is due, what you know is missing and what you are not sure about.
We work from the controls document as published at that moment, never from a copy.
Every control checked against what is actually running, and the gaps ranked by what would hurt most.
Highest risk first. Each fix gets an owner, a date and a piece of evidence when it is done.
One folder, one document per control, organized the way the fund asks for it.
The attestation is signed from the folder. Next year starts with a re-check, not from zero.
The Cyber JIF's own member form lists these joint insurance funds. If your municipality, authority, housing authority, utility or first-responder organization belongs to one of them, the Cyber JIF program is the one your cyber coverage runs through.
Not on the list, or not sure which fund you belong to? Ask your risk manager or fund administrator, or ask us and we will find out with you.
Cloud Guardian is based in North Brunswick and works onsite across Middlesex, Somerset, Mercer, Monmouth, Union and the surrounding counties. We know the framework, we know what a three-person borough office actually runs, and we know the distance between the two.
Tell us which JIF you belong to and when the attestation is due. We come back with where you stand and what it takes to be ready, in writing.
Request a Readiness ReviewA joint insurance fund that provides cyber coverage to New Jersey local public entities through the affiliated municipal, county and specialty JIFs. It publishes the cyber controls that member entities are expected to meet and attest to, and it keeps that list current. The official list and program details are at cyberjif.org.
No. The fund does both. What we do is prepare you: map every control to what you actually run, close the gaps, and produce the evidence that sits behind each line of the attestation. You sign it knowing it is true and provable.
No. Readiness work is scoped on its own. Many entities have an existing IT contractor, and we work alongside them. If you would rather one provider run the controls day to day, that is available too, and it is priced for public budgets.
Yes, and it is the most common starting point. We treat a deficiency as a scoped project with a date on it: what the control requires, what is in place, what is missing, who owns the fix and what the evidence will be. Then we close it and document it.
It depends on how many controls are already operating and how large the environment is. A small borough or authority with a modern email platform and decent backups is usually weeks. An entity with legacy servers, no endpoint protection and no training program is a longer project, and we tell you the order of work up front so the highest-risk gaps close first.
Every engagement is quoted to the entity: its size, its systems and how many controls need work. Tell us what you have and we come back with a number in writing. Nothing is billed that you have not already seen.
Tell us which JIF you belong to and what you have. We reply in writing with where you stand against the current controls and what it takes to close the gaps.
Hi. Ask us anything about your IT, pricing, or an issue you are having right now. We reply fast during business hours.
Pick where you want the reply. Your message comes with you, nothing is retyped.