How To Reduce Cyber Risk: Best Practices for Small Businesses

Posted By: Christopher Moody II,
business liability insurance

A cyber incident can stop a company from billing customers, lock employees out of critical systems, expose sensitive information, or lead to fraudulent payments. When reviewing business liability insurance, small businesses should consider how they would prevent and respond to a cyber event. Insurance may help with certain covered financial consequences, but preventing an incident — or limiting its damage — is the best line of defense.

What Are the Best Ways To Reduce Cyber Risk?

Cybersecurity doesn’t require a small business to replicate a large corporation’s security program. Controls should reflect the company’s technology, data, staffing, vendors, and operational dependencies.

The consequences can be substantial for smaller organizations. Verizon’s 2026 Data Breach Investigations Report and Breach Impact Study found that, in the most severe 2.5% of small- and medium-sized business breach cases, financial losses exceeded 7% of the organization’s revenue. Verizon also found that exploitation of software vulnerabilities accounted for 31% of initial breach access, a 55% increase from the previous year.

Those findings reinforce the need for prevention to address both technology and day-to-day business practices. The National Institute of Standards and Technology, for one, developed its NIST Cybersecurity Framework 2.0 Small Business Quick-Start Guide for small and midsize organizations, including those with limited cybersecurity resources.

Rather than trying to protect everything equally, businesses should first identify the systems, information, vendors, and technology they depend on most. A billing platform, customer database, email system, or cloud-based application may each affect operations differently if it becomes unavailable or compromised. Knowing which assets are critical helps a business decide where stronger controls and recovery planning deserve priority.

Which Cybersecurity Controls Should Small Businesses Prioritize?

The right safeguards will vary by organization, but several basic practices can reduce common cyber exposures:

  • Use multifactor authentication. Require an additional form of authentication wherever practical, particularly for email, remote access, administrator accounts, financial systems, and applications containing sensitive information.
  • Keep systems and software current. Assign responsibility for security updates companywide rather than relying on individual employees to install them. Include operating systems, applications, browsers, network equipment, and other connected technology.
  • Limit access. Give employees access only to the systems and information they need for their jobs. Review permissions when roles change, and disable accounts promptly when someone leaves.
  • Train employees to recognize suspicious requests. Phishing can involve convincing requests to change banking information, open shared documents, reset credentials, or send confidential information. Employees should know how to verify unusual requests through a separate, trusted communication channel.
  • Review third-party access. Vendors, contractors, cloud applications, and outsourced service providers may connect to company systems or hold company data. Periodically review who has access, what they can reach, and whether that access is still necessary.

What If Defenses Fail?

Even strong safeguards can’t eliminate cyber risk. Businesses should decide how they will operate after an incident before they are forced to deal with one.

Go Beyond Backups

Maintaining copies of critical files and systems can help a company recover from ransomware, hardware failure, or data corruption. But simply having a backup isn’t the same as being able to recover. Businesses should protect recovery copies so that an attacker who compromises the primary network cannot automatically compromise the backups, and they should periodically test whether critical data can be restored.

Backups also solve only certain problems. They won’t reverse a fraudulent wire transfer, keep stolen data from being disclosed, or remove an attacker who still has valid credentials. Recovery planning should also address how the business will isolate affected systems, reset compromised credentials, contact financial institutions, bring in outside technical or legal support, communicate with employees and customers, and restore critical operations in priority order.

Develop Incident Response Plans

An incident response plan should identify who has the authority to make decisions and whom to contact. Depending on the business, that may include internal leadership, IT personnel, an outside technology provider, legal counsel, financial institutions, an insurance professional, and other specialists.

The plan should answer practical questions before an emergency occurs. 

  • Who can disconnect affected systems? 
  • Who can authorize outside forensic help? 
  • Who contacts the bank if funds are transferred fraudulently? 
  • Who determines whether customers or regulators must be notified? 
  • Who communicates with employees if the usual email is unavailable?

A plan sitting in a folder is less useful if no one knows how to execute it. Periodic exercises can expose missing contact information, unclear responsibilities, inaccessible backups, or decisions that haven’t been assigned to anyone.

Where Business Liability Insurance Fits Into Cyber Risk Management

Businesses shouldn’t assume a standard business liability insurance policy will respond to ransomware, data restoration, privacy notification expenses, cyberextortion, fraudulent transfers, or losses caused by a network shutdown. Whether a policy responds depends on its language, exclusions, endorsements, and the circumstances of the claim.

Cyber exposures may require separate attention when evaluating cyber liability insurance for small businesses. Depending on the policy, cyber insurance may address first-party expenses incurred by the insured business, third-party claims against it, or both. Coverage terms vary, so the discussion should focus on how the company operates rather than a generic list of cyber threats.

Useful questions include what data the company collects, how long it retains that information, which systems are necessary to generate revenue, whether employees can access systems remotely, and which vendors hold data or provide critical technology services. Businesses should also understand how the policy handles issues such as incident response, business interruption, social engineering, cyberextortion, and events involving third-party technology providers rather than assuming every cyber policy responds the same way.

Organizations that maintain substantial member or donor information face their own considerations. Our discussion of cyber liability for trade associations and nonprofits shows how data, financial transactions, and reliance on outside platforms can affect the insurance conversation.

Build Prevention Into Your Risk-Management Strategy

Cyber risk changes as a business changes. Adding a cloud platform, hiring remote employees, collecting a new type of customer information, switching payment systems, or giving a new vendor network access can create exposures that didn’t exist during the last security review.

For that reason, cybersecurity should be an ongoing effort. Business leaders should revisit access permissions, employee training, software updates, backups, vendor relationships, incident response procedures, and small-business insurance as operations evolve.

Ask yourself: If a critical system went offline tomorrow, if an employee’s email account were compromised, or if sensitive information were exposed, would the company know what to do next? Preventive controls can reduce the chance that the company ever has to answer that question under pressure. Insurance can then serve its proper role — helping manage certain covered financial consequences when prevention isn’t enough.

Contact Moody Insurance Worldwide to review your current insurance program and discuss how coverage fits with the steps your business is taking to manage cyber and operational risks.

About the Author

Christopher Moody is President of Moody Insurance Worldwide, a leading independent insurance agency located just outside Washington, D.C. He has been serving clients in the insurance industry for more than 30 years. Moody Insurance Worldwide offers a wide range of insurance options, serving clients in all 50 states and overseas. Moody specializes in tailoring insurance programs to fit the unique needs of our clients because when it comes to insurance, one size does not fit all.

About Moody Insurance Worldwide

We are a specialized, independent insurance agency that provides all types of business insurance. In addition to essential Property, Liability, and Benefits insurance, we have expertise in Professional Liability, Cyber Liability, Director & Officer Liability, and International insurance coverage.