Insurance For Texans Blog

All the Insurance Topics a Texan Could Want

  • There are no suggestions because the search field is empty.

Why Cyber Coverage Is More Important Than Ever

Posted by Ron Wadley on Oct 8, 2026, 8:00:01 AM
Ron Wadley

 

Key Takeaways

Are small businesses really targets for cyber attacks?
Yes. Small and midsize businesses are often attractive targets because hackers know they may have fewer security resources than larger companies.

Can multi-factor authentication stop every cyber attack?
No. MFA adds an important layer of protection, but phishing attacks can still trick employees into approving access or entering credentials on fake login pages.

What happens if a hacker gets into a business email account?
They may read emails, impersonate employees, send fraudulent messages, access customer information, or use the account to launch additional attacks.

For more information on this topic, see our FAQ section at the bottom of the page.

 

Last Wednesday was just like any other Wednesday. I grabbed my coffee and sat down to work on the list of things that sat there waiting for me. When the first message came in asking if I had sent an email requesting a signature, I was confused. When the second and third ones came in moments later, my heart fell to the floor.

I frantically started evaluating the email that was forwarded to me. I first looked at the sender to see if our name and likeness was just being spoofed. It was not. I then shifted to the DMARC data to see how they violated our security protocols. Everything was just as it should be. That is when the heart palpitating panic set in. This was no longer a spoof, this was potentially a full blow breach.

Click To Get Texas Cyber Insurance

My next step in this process was to reach out to one of our trusted partners who helps with email deliverability. Scott is a wealth of information on all things email and I knew that he could help me decipher if my worst thoughts were true. As quickly as he confirmed that our email server had been breached in some way he told me to have everyone cycle their passwords. Then he helped me to contact a cyber expert so that we could determine what happened, how much the outside party snooped around, and what our next steps needed to be in light of this information.

Misperceptions Of Cyber Hacks Today

Most small to medium business owners don't consider themselves vulnerable to a cyber breach. They have three key thoughts that keep them from preparing for and having a plan.

  1. They believe that hackers are really only interested in bigger companies than their own.
  2. They believe their people would never do something wrong or dumb.
  3. They think they have foolproof systems in place.

If I am being honest, I had some feelings for both numbers two and three. And let me tell you that was a fatal flaw last week.

The reason these misperceptions exist is because a lot of them were true a few years ago. The hacker type was looking for large companies where they could make quite a bit of money at one time. But they have realized over the years that smaller companies don't have systems that are as robust as the larger companies, which make them easier to compromise. If they do enough volume, they eventually create some nice wealth. And the AI tools available today make it easier to do those things in volume to create more income.

Why Your Cyber Security Systems And Policies Are Likely Outdated

Many small to medium business owners have close relationships with all of their people. We spend a lot of time together working on projects and initiatives to push our businesses forward. As a result, there is misplaced trust in the ability to not get caught by something that comes via email. Let's cycle back to last Wednesday and look at how this trust was appropriate, but totally breached because of reality.

Our agency is at the time of the year where contracts are being renewed. It is common for us to get requests for electronic signatures that include the need for us to supply data to our insurance company partners. We received an email from one of our partners that had a request for signature included in it. It looked exactly like a DocuSign email that needed to be completed. Our team member clicked that link in good faith to clear the task the needed completion so that we could continue with helping people. That link took him to a screen that required him to "log in" using his email service provider authentication. Again, it all looked very legit and official. But what happened next became our nightmare.

That authentication page allowed a nefarious hacker to gain authentication into our email server. It felt innocuous in the moment as it was an email directly from our partner that was requesting a signature. Once the authentication was complete, it served a "timed out" page since they had gained what they wanted. The "suspicious login attempt" was not escalated because the MFA had been cleared. And then the hacker sat and did nothing with the access for two weeks.

The average employee doesn't think twice about what I just described until they get to the "timed out" page. Completing signatures and authenticating a login happens to many white collar workers every day. The key here was that the link wasn't actually expected. It randomly appeared at an opportune time. If you think your staff is not susceptible to what I just described, you are either willfully naive or wrong. Either option can cost you your business.

why cyber coverage is more important than ever

Steps To Obtain Cyber Protection From Email Hacks

In the end, our hacker poked his head up two weeks later. He decided to look at a couple of emails and then send approximately 100 emails before we noticed what was happening. Our entire team cycled our passwords to revoke any sort of MFA credentials that were hanging out there and the crisis was stopped. Fortunately for us, this was a solo breach and we were able to prove that no sensitive data was compromised. But there was some reputational damage done to us.

The easiest way to avoid this for your business is to follow some simple steps for you and your employees.

  1. Never click a link unless you have confirmed that it is appropriate with the sender.
  2. Use a real email system rather than a personal Gmail, Hotmail, Etc to give you auditable data and additional security protections.
  3. Require multi-factor authentication on all business accounts. Using Passkeys is even better.
  4. Require the rotation of passwords periodically to shake out any hackers that are sitting inside your system waiting to act.
  5. Monitor your system alerts to look for anomalies in logins and authentications.

These five steps can help prevent a lot of pain and heartache. We had a customer file a cyber claim this week who was caught by a similar problem to ours. They are in the medical field and the audit showed that HIPAA data was compromised. Fortunately, there was coverage available to them through their policy. This is reminder that this is a real threat all the time.

Get Real Cyber Coverage

The bottom line is that all businesses are target for hackers these days. If you deal in any amount of customer data, you are at risk. If you are processing electronic payments, you have some risk. Running a business without cyber liability coverage is a fool's errand. The good news is that it is easy to protect your business and future with cyber liability insurance. The agents at Insurance For Texans are here to help you understand your risk and find ways to protect against it.

Many of the cyber insurance carriers will help you with training to avoid pitfalls while also being at the ready to help you clean up a problem when it does occur. Artificial Intelligence is pretty amazing, but the bad guys also have access to it. You need to protect yourself now, more than ever.

Click the button below to get your cyber analysis and game plan to protect your business the right way.

Click To Get Texas Cyber Insurance

Frequently Asked Questions

What does cyber liability insurance typically cover?

Coverage varies by policy, but cyber insurance may help pay for forensic investigations, data recovery, customer notifications, legal expenses, regulatory issues, business interruption, and certain cyber-related liability claims.

Does general liability insurance cover a cyber breach?

Usually not. General liability policies are primarily designed for bodily injury and property damage claims. Businesses typically need separate cyber liability coverage for many data breach and cyber attack exposures.

Do I still need cyber insurance if I have strong cybersecurity systems?

Yes. Security tools can reduce your chances of a breach, but they cannot eliminate the risk. Employees can make mistakes, vendors can be compromised, and attackers continually change their methods. Cyber insurance provides another layer of financial protection when prevention fails.

Topics: cyber insurance

Ron Wadley
About the Author

Ron Wadley

Ron is the principal agent at Insurance For Texans and has more than 20 years in the insurance business. This experience allows him to find creative solutions to your insurance problems. "Uncle Ron" started Insurance For Texans, an independent insurance agency located in Dallas-Fort Worth, in 2017 after seeing a need to provide many different kinds of solutions to the everyday problems that folks have. After having an agency that could only offer a single solution for insurance for a few years, he came to the conclusion that it was time to make a change for the betterment of all Texans. And Insurance For Texans was born out of a vision to put the customer first ahead of a big insurance company.