Welcome back to Inside the Cyber Risk Playbook, a series where we speak with public entity risk pool leaders about how they're navigating rising cyber expectations, evolving insurance dynamics, and the practical realities of protecting their organizations.
This installment features Gavin Lobmeyer, Department Head of Risk Management for Laramie County, Wyoming. Gavin also serves on the Board of the Wyoming Association of Risk Management (WARM), giving him a unique perspective on cyber risk from both the public entity and risk pool viewpoints.
We sat down with Gavin to discuss why he believes cybersecurity isn't simply a technology challenge—it's a communication challenge. Our conversation explored the importance of translating technical risk into business decisions, measuring progress over perfection, and the critical role risk pools can play in helping members build cyber resilience.
For many risk pools, the challenge is no longer simply identifying cyber risk. The harder question is what happens next: how members understand the findings, who owns the next action, what evidence demonstrates improvement, and how the pool can show meaningful progress across a diverse membership.
Cyber Isn't Just a Technology Problem—It's a Translation Problem
Before joining Laramie County, Gavin spent several years working in enterprise cybersecurity, evaluating governance, compliance, and cyber risk across large organizations. While that technical experience proved invaluable, it also shaped how he approaches risk management today. Gavin often compares his role to that of a construction project manager.
"The project manager doesn't need to know how to pour concrete or wire the building. They need to understand enough to coordinate the experts, ask the right questions, and keep everyone moving toward the same objective."
For Gavin, risk management works much the same way.
Risk managers don't need to be the deepest technical experts in every discipline. Instead, they create value by bringing together IT, finance, legal, operations, executive leadership, and governing boards—helping each group understand risk through its own lens while ensuring everyone is working toward the same outcome. Throughout our conversation, Gavin returned to one idea repeatedly.
"It's not that the data isn't there. It's that the data isn't together."
Technical teams understand vulnerabilities. Finance understands budgets. Leadership focuses on organizational priorities. Operations understands service delivery. Individually, each perspective is valuable. Together, they create a more complete picture of risk.
Or, as Gavin likes to say:
"Every problem goes through the risk car wash."
That mindset has become increasingly important as cyber risk extends well beyond the IT department. Today's conversations involve governance, operations, finance, insurance, and public trust—and someone has to connect the dots.
For risk pool leaders, this challenge is multiplied across every member organization. Each entity has different resources, different priorities, and different levels of cyber maturity, yet many are wrestling with the same fundamental challenge: turning technical cyber information into practical business decisions.
Public Entities Need Progress, Not Perfection
As cyber threats continue to evolve, public entities face growing pressure to strengthen resilience while balancing limited staff, competing priorities, and increasing expectations from leadership and insurers.
Gavin is realistic about the constraints public entities face.
"Nobody has unlimited time, unlimited people, or unlimited budget. You have to focus on what moves the needle."
That's why he believes success isn't measured by implementing every possible security control. It's measured by understanding where risk exists, prioritizing the actions that matter most, and demonstrating meaningful progress over time.
As Gavin put it:
"You have to tell the story."
That story isn't built on technical metrics alone. It's about helping leadership, governing boards, insurers, and other stakeholders understand how cyber risk is changing, where investments are making a difference, and why those decisions matter.
One story Gavin shared perfectly illustrates that mindset.
He recalled sitting in a meeting where a small community was requesting funding to modernize the controls for its water system. At first glance, it seemed like a routine infrastructure discussion. But Gavin recognized something others hadn't yet articulated. Modernizing those controls wasn't simply about replacing aging infrastructure. It was also about reducing cyber risk. Water systems, power infrastructure, communications, and other critical services are increasingly connected, meaning a cyberattack on one system could have real-world operational consequences.
By helping connect those dots, the conversation shifted. It wasn't simply about funding equipment anymore. It was about protecting essential public services.
For risk pools, this is the heart of the issue. Cyber risk isn't abstract when it affects water systems, public safety, schools, courts, finance systems, emergency services, or other essential public services. The opportunity isn't to turn every member into a cybersecurity expert. It's to help members understand which risks matter most, what actions are realistic given their resources, and how to demonstrate meaningful progress over time.
The lesson extends well beyond one county. Across every risk pool, member organizations are making similar decisions every day—balancing operational realities, constrained resources, and evolving cyber threats. The challenge isn't unique. It's shared across the public sector.
Organizations don't need to solve every cyber challenge overnight. They need to make informed decisions, communicate progress, and continuously strengthen resilience over time.
Why Risk Pools Are Uniquely Positioned to Help
Serving on the WARM Board has reinforced something Gavin sees every day: no two members are starting from the same place. Some organizations have mature cybersecurity programs. Others have one person juggling IT, cybersecurity, and countless other responsibilities.
Yet despite those differences, many are asking the same questions:
- Where should we focus first?
- How do we explain cyber risk to leadership?
- How do we know whether we're making progress?
Helping members answer those questions consistently can have an impact far beyond any individual assessment or annual renewal.
For Gavin, one of the greatest opportunities for risk pools isn't simply providing cyber resources—it's helping members make sense of cyber risk. By meeting organizations where they are, helping them prioritize what matters most, and giving them a practical framework for continuous improvement, risk pools can strengthen resilience across their entire membership.
That's where risk pools create lasting value—not by expecting every member to become cybersecurity experts, but by helping them become better risk managers.
From Insight to Action
Gavin's perspective reinforces something we hear from risk pools across the country.
The challenges he described aren't unique to Laramie County. They're playing out across hundreds of member organizations every day. While every public entity has its own resources and priorities, many are asking the same fundamental questions: Where do we start? What should we focus on next? How do we demonstrate progress? For risk pools, that creates both a challenge and an opportunity.
The opportunity is to help members operationalize cyber risk management—not through one-time assessments or overwhelming amounts of data, but by giving them continuous visibility into their cyber exposure, helping them prioritize action, and enabling more informed conversations with leadership and governing boards.
That's where KYND helps.
KYND gives risk pools a consistent view across their membership, helps identify where attention is needed, and translates cyber findings into practical, member-friendly actions. For pools, that means stronger visibility, clearer conversations with members, and better evidence of progress for leadership, boards, brokers, and insurers.
Questions Every Risk Pool Should Be Asking
- Which members need the most support?
- Which cyber themes are emerging across our membership?
- Do our members know what action to take next?
- Can members demonstrate that key cyber controls are actually in place?
- What evidence can we share with our board, broker, or insurer to demonstrate progress?
Key Takeaways
Our conversation with Gavin reinforced several important lessons for public entities and risk pools alike:
- Cyber risk is fundamentally a business and governance challenge—not just an IT responsibility.
- The most effective risk managers connect people, information, and priorities, translating technical insights into better business decisions.
- Meaningful progress is more valuable than perfection. Organizations should focus on continuous improvement rather than trying to solve every challenge at once.
- Risk pools are uniquely positioned to help members operationalize cyber risk by providing visibility, guidance, and a framework for continuous improvement.
- Better visibility, stronger communication, and measurable progress create more resilient organizations over time.
As cyber expectations continue to rise, Gavin's perspective offers an important reminder: the challenges facing one public entity are rarely unique. Across every risk pool, members are navigating the same balancing act—translating technical risk into business decisions, prioritizing limited resources, and demonstrating progress over time.
For risk pools, the opportunity isn't simply to insure those organizations. It's to equip them with the visibility, guidance, and confidence they need to build stronger cyber resilience together.
