
You purchased cyber insurance. Your business experiences a cyberattack. You file a claim.
Sounds straightforward—but there's an important part of the equation that business owners can easily overlook: the cybersecurity practices your company represented when applying for coverage.
Cyber insurance isn't a substitute for cybersecurity. Insurers increasingly want to understand how businesses protect their systems, employees, customers, and data before determining coverage terms.
For small businesses, this creates an important question:
Are the cybersecurity protections described on your insurance application actually being used throughout your organization?
Here are seven areas worth reviewing.
A password alone may no longer provide adequate protection for important business accounts.
Multi-factor authentication (MFA) adds another verification step when someone logs in. Businesses should consider where MFA is implemented, particularly for email, remote access, cloud applications, financial systems, and administrative accounts.
If your cyber application states that MFA is in place, make sure you understand exactly where and how it's being used.
Your employees can be one of your greatest cybersecurity defenses—or an unintended entry point for an attacker.
Phishing emails, fraudulent payment requests, malicious links, and increasingly convincing impersonation attempts can target employees directly.
Regular training can help employees recognize suspicious activity and know how to report it.
What would happen if ransomware suddenly made your company's files inaccessible?
Businesses should maintain reliable backups of critical information and periodically verify that those backups can actually be restored.
Simply assuming your cloud provider "has everything backed up" may not be an adequate recovery strategy.
Outdated software can leave known vulnerabilities available for criminals to exploit.
Businesses should have a process for keeping operating systems, applications, security tools, and devices updated.
This is particularly important for businesses that rely on multiple computers, remote employees, or specialized software.
Not every employee needs access to every system.
Limiting access based on an employee's responsibilities can reduce the amount of information potentially exposed if an account is compromised.
Businesses should also promptly remove access when employees leave the company or change roles.
Cybercrime isn't always about hackers breaking into a network.
Sometimes, criminals simply convince someone to send them money.
A fraudulent email appearing to come from an executive, vendor, or customer could request updated banking information or an urgent wire transfer.
Consider requiring secondary verification—such as a phone call to a previously verified number—before changing payment instructions or completing unusual transactions.
If your business discovered a cyberattack at 9:00 tomorrow morning, would everyone know what to do?
An incident response plan should identify who employees contact, how systems may be isolated, which technology professionals should be involved, and when your insurance carrier or Risk Advisor should be notified.
The middle of a cyber incident is not the ideal time to create the plan.
The goal isn't simply to satisfy an insurance application.
Strong cybersecurity practices can help prevent losses, reduce the severity of an incident, and make your organization more resilient.
That's what proactive risk mitigation is all about.
Your technology, employees, vendors, and operations can change throughout the year. Your cyber risk assessment should evolve with them.
If your business has added employees, adopted new software, expanded remote access, started using AI tools, or changed how you collect customer information, your cyber exposure may look very different today.
Contact one of the Risk Advisors at Fortis Risk Group for a policy and risk review. We'll help you evaluate your current cyber insurance strategy, identify potential coverage concerns, and make sure the protection you've purchased aligns with the risks your business actually faces.
