Financial Poise
Cybercrime

The Threat of Cybercrime for Small and Midsize Business

For the Threat of Cybercrime, Get a Cyber Liability Policy

Cybercrime is an umbrella term for any criminal activity using or targeting a computer. The threat of cybercrime can take many forms — from hijacking sensitive robotics to holding consumer data at ransom — and the impact on your operation (and reputation) can be crippling.

In 2021, I wrote that if cybercrime were a nation-state, it would be the world’s third-largest by GDP,  just after the US and China. In 2026, cybercrime is expected to cost the global economy over $20 trillion, basically equal to China’s GDP in the same year. That’s growth!

To better understand how big the threat of cybercrime is becoming and how fast it’s growing, consider these statistics:

Remote work looks like it’s here to stay, and this represents additional cybersecurity threats to small businesses with unsecured home wi-fi networks, phishing attacks targeting remote employees, data breaches due to personal device usage, weak password hygiene, lack of proper data encryption, and potential vulnerabilities when utilizing video conferencing software.

What Kinds of Cybercrime Exist?

You’ve probably heard of or seen obviously malicious emails asking for highly personal information, often targeting the elderly and vulnerable. You’ve probably also heard of identity theft and insurance fraud. However, cybercrime against small businesses can be much harder to detect and prevent.

Here are a few examples.

  • Phishing: Often in email form, recipients are sent a link or an attachment that can hack their computer and their data. Hackers will go so far as to use legitimate company logos or fake email addresses.
  • Fraud: Just as a hacker can access your personal account or credit card information and make charges on your behalf, a cybercriminal can do the same to your business, using either personal data or customer information.
  • DDoS Attack: This form of cybercrime bombards an online site with fake traffic to take down the network and gain access to valuable information.
  • Ransomware: A type of malware, ransomware encrypts data on a computer and demands ‘ransom’ in exchange for unlocking the device.
  • Cryptojacking: Hackers mine cryptocurrency using a company’s computing power. The company finds out when it gets an outsized surprise in its electric bill.

75% of all cyber-attacks start with an email and an employee clicking on something they shouldn’t.

You’re Never Too Small for the Threat of Cybercrime

While Fortune 500 companies have the resources to stay ahead of cybercrime, small to midsize businesses are often woefully behind in cybersecurity practices, making them easy targets for criminals.

Has your current insurance agent recommended cyber liability insurance? Shame on them if they haven’t. Did you respond, “We’re all good” or ”Our IT people have us covered”? While your IT team is probably great at what they do, their ability to protect you from cybercrime is still limited. As noted above, 75% of all cybercrimes start with an email and somebody clicking on something they shouldn’t.

Think you’re not a target? In the global cybercrime game, the scale of your business is less important than your data and how easy it is to get it. So, while you may feel off-the-radar given your size, if your data is critical to running your business, you’re a target.

For example, if your website claims your company is an industry leader to let everyone know you’re killing it, you’re inviting the hackers.  You’re letting them know you’ve got money for them to take.

Ransomware: The Proverbial Trojan Horse

Let’s talk about ransomware, still the most common threat of cybercrime. Consider this scenario:

Imagine someone in accounting gets an invoice from a customer with a complaint. The recipient clicks and opens the invoice. It’s not even your company’s invoice, so the person deletes it. No harm, no foul. All seems well.

However, the Trojan Horse is now within ‘the city walls.’ Just as the Greek warriors waited patiently, today’s hackers have similar patience. They wait and watch. They learn your backup systems and protocols and wait some more. Then the blue screen of death flashes across all your computers with the message, “Pay $X,XXX,XXX in the next 24 hours to get your data back, or the price will multiply and continue to do so every 24 hours.”

No problem. Your IT people go to the redundancy servers — but they’re infected. No need to panic. IT goes to the tapes. But the tapes are infected. The hacker has infected all backup repositories for the last three weeks!

Now, you face the dilemma: Pay the ransom to restore the lost data, or cease operations to recreate the data. The costs of either are often debilitating. In some cases, it’s enough to put the company out of business.

A current trend in cybercrime is RAAS — Ransomware As A Service. That’s right: The bad actor who infiltrates your system isn’t even the guy who’s going to take your money. He hands it off to the ‘professionals’ who pay him a commission. It’s a franchise business.

Cyber Liability Insurance: A Defense Better Than an NFL Team

Even the greatest NFL defensive lines of all time let some attackers get through. They can’t buy insurance to protect against those intruders, but you can. A cyber liability policy can cover:

  • Revenue lost due to a variety of reasons
  • Cost of an all-out data reconstruction effort
  • Bodily injury (think of robots being hacked)
  • Ransomware payoff
  • Fraudulently transferred funds
  • Regulatory fines and penalties

The good news is the more you’re doing upfront to protect your data and systems from the threat of cybercrime, the less you’ll have pay for this line of defense against the bad guys!


We think you’ll also like:

  1. Cybersecurity Best Practices: Guidelines for Breach Prevention and Response
  2. Critical Tactics for Safeguarding Your Ideas and Intellectual Property Rights
  3. Fraud Prevention for Suckers: Phishing Scams

[Editors’ Note: To learn more about this and related topics, you may want to attend the following on-demand webinars (which you can view at your leisure, and each includes a comprehensive customer PowerPoint about the topic):

  1. How to Build and Implement your Company’s Information Security Program
  2. Introduction to EU General Data Protection Regulation: Planning, Implementation, and Compliance
  3. Introduction to US Privacy and Data Security: Regulations and Requirements

This is an updated version of an article originally published on May 17, 2021.]

©2024. DailyDACTM, LLC d/b/a/ Financial PoiseTM. This article is subject to the disclaimers found here.

Share this page:

About Gary Kirshenbaum

Gary is a Vice President of Alera Group and the Director of Alera Global Trade Risk Management (AGT). Under his guidance, AGT provides companies with the ability to strategically manage commercial trade risk, both domestic and export, while mitigating the political risk of international business investments. Share this page:

Read Full Bio »