CurrentTechnology

Cybercriminals Don’t Care How Small Your Business Is

8 Mins read

Many small business owners assume cyber insurance is only necessary if they suffer a major ransomware attack. But today’s biggest cyber threats often begin with something much more ordinary—a convincing email, a fake invoice, or a fraudulent request that appears to come from a trusted vendor. I talked with Anna Kagan, Vice President of Cyber at AmTrust Financial Services, about the evolving cyber risks facing small businesses, what cyber insurance really covers, and the steps every business should take before an incident occurs.

The situation is particularly concerning right now since fraud and phishing have overtaken ransomware as executives’ top cyber concern, according to the World Economic Forum’s 2026 Global Cybersecurity Outlook.

Cybersecurity Isn’t Just a Big-Business Problem

Rieva Lesonsky: Many small business owners assume they’re too small to be targeted by cybercriminals. Why is that one of the biggest misconceptions you encounter?

Anna Kagan: One of the most dangerous misconceptions I encounter is the belief that cyber risk is a problem reserved for large corporations.

In reality, cybercriminals don’t need [to attack] a billion-dollar company to make money. They need a business that handles payments, trusts vendors, manages customer information, or simply needs to keep its doors open.

What surprises many owners is that the question isn’t whether their business is important enough to attract attention. The question is whether they have something worth disrupting, stealing, or exploiting. Most businesses do.

I’ve found that the greatest risk often isn’t a lack of technology or resources. It’s a false sense of security. When business owners assume, “It won’t happen to us,” they’re less likely to prepare for when it does.

Cybersecurity isn’t a big-business issue anymore. It’s a business issue. And the organizations that fare best are often not the largest ones, but the ones that recognized their exposure before an incident forced them to.

Lesonsky: What types of cyber incidents are small businesses most likely to experience today, and how have those threats changed over the past few years?

Kagan: Small businesses today face a range of cyber threats, including ransomware, phishing, business email compromise, credential theft, and payment fraud.

What has changed is that attacks have become much more difficult to distinguish from normal business activity. A fraudulent invoice can look like every other invoice. A phishing email can appear to come from a trusted vendor, customer, or colleague.

Many of the costliest cyber incidents don’t begin with a sophisticated hack. They begin with an employee taking what appears to be a routine business action. That’s why cybersecurity today is as much about awareness, verification, and processes as it is about technology.

What Cyber Insurance Really Covers

Lesonsky: Many owners think cyber insurance only covers ransomware attacks. What does a typical cyber insurance policy actually cover?

Kagan: Many owners think cyber insurance only covers ransomware, but a comprehensive cyber policy addresses a much broader range of risks.

Depending on the policy, coverage may include ransomware and cyber extortion, business email compromise, funds transfer fraud, data breaches, privacy liability, regulatory investigations, business interruption, and the costs associated with restoring systems and data.

Many policies also provide access to specialized resources, such as forensic investigators, breach coaches, privacy attorneys, customer notification services, credit monitoring, and crisis communications support.

What surprises many business owners is that the cyber event itself is often only one part of the challenge. A strong cyber policy helps businesses navigate the financial, operational, legal, and reputational issues that can arise from a cyber incident.

A ransomware demand may make the headlines, but for many businesses, the real impact comes from the disruption, recovery efforts, and obligations that follow.

Why Business Email Compromise Is So Dangerous

Lesonsky: Business email compromise (BEC) and phishing attacks are becoming more common than ransomware. Why are these scams so successful, and what warning signs should business owners watch for?

Kagan: BEC and phishing attacks are so successful because they don’t look like attacks. They look like everyday business. A request from a vendor, a note from a customer, a message from an executive, or an invoice that appears completely legitimate.

The warning signs are often subtle: unexpected requests for wire transfers, changes to banking information, password reset requests, or any message that creates pressure to act immediately. Whenever money, credentials, or sensitive information is involved, it’s worth taking a moment to verify via a separate phone call or a trusted communication channel.

One of the biggest lessons for business owners is that cybercriminals are no longer just trying to break into systems. They’re trying to blend into normal business operations.

The most effective defense isn’t just better technology. It’s creating a culture where employees pause, verify, and question requests that don’t seem quite right. One phone call can prevent a six-figure mistake.

Lesonsky: If a small business falls victim to a phishing attack or business email compromise, what immediate steps should the owner take?

Kagan: If a business falls victim to a phishing attack or business email compromise, the first priority is speed. Secure affected accounts, change passwords, contact your IT provider or incident response team, and notify your bank immediately if money or banking information may be involved.

One mistake I see too often is waiting to see what happens. Cyber incidents rarely improve over time. The faster a business responds, the better its chances of limiting financial loss and operational disruption.

The most important thing to remember is this: don’t handle it alone. The first few hours after an incident can make all the difference.

Choosing the Right Cyber Policy

Lesonsky: What should small business owners look for when evaluating a cyber insurance policy? Are there key coverages they should make sure aren’t missing?

Kagan: One of the biggest mistakes I see is businesses shopping for cyber insurance based solely on price. A cyber policy isn’t a commodity. When something goes wrong, the differences between policies become very clear.

Business owners should look for coverage that addresses today’s most common threats, including ransomware, business email compromise, funds transfer fraud, business interruption, data breaches, and the costs of restoring operations afterward.

Just as importantly, they should understand which resources are included in the policy. Access to forensic investigators, privacy attorneys, breach response experts, and recovery support can be invaluable during a cyber event.

The best cyber policy isn’t necessarily the cheapest one. It’s the one that responds the way your business needs it to when the unexpected happens.

Lesonsky: Are there cybersecurity practices insurers now expect businesses to have in place before issuing coverage, such as multifactor authentication or employee training?

Kagan: Absolutely. Today, insurers increasingly expect businesses to have foundational controls in place such as multifactor authentication, employee cybersecurity training, secure backups, strong password management, and timely software updates.

What many business owners don’t realize is that these aren’t simply insurance requirements. They’re often the difference between a minor incident and a business-threatening event. We’ve seen situations where a company recovered quickly because it had secure backups, while another faced weeks of disruption because it didn’t.

The reality is that most cyber incidents don’t happen because criminals outsmarted cutting-edge security. They happen because a password was compromised, an employee trusted a convincing email, or critical data couldn’t be recovered.

The controls insurers care about are often the same controls that help keep a cyber incident from becoming a business crisis.

Lesonsky: How can business owners reduce both their cyber risk and, potentially, the cost of their cyber insurance?

Kagan: Business owners can reduce both cyber risk and, potentially, insurance costs by focusing on resilience, not just security. That means implementing foundational controls, such as multifactor authentication, employee training, secure backups, and software updates, while also having an incident response plan and business continuity strategy in place before they’re needed.

The reality is that cyber incidents aren’t just technology events. They’re business disruptions. The organizations that recover fastest are usually the ones that planned for the possibility of an attack long before it happened.

Cybersecurity isn’t measured by whether an incident occurs. It’s measured by how well your business can respond, recover, and continue operating when it does.

AI Is Changing the Threat Landscape

Lesonsky: Artificial intelligence is making scams more convincing. How is AI changing the cyber threat landscape for small businesses?

Kagan: Artificial intelligence is changing the game because it’s making cyber scams faster, cheaper, and far more convincing. What once took an attacker hours can now be done in minutes, whether that’s crafting a realistic phishing email, impersonating a vendor, or creating a message that sounds exactly like a trusted colleague.

The biggest challenge for small businesses is that many of the warning signs people relied on in the past are disappearing. The grammar is perfect. The message is personalized. The request looks legitimate.

The greatest risk isn’t that AI is creating new threats. It’s that it’s making existing threats harder to recognize. In a world where a fake message can look real, verification becomes just as important as prevention.

Lesonsky: Are there any real-world examples—without identifying the businesses—of a cyber incident involving a small business that illustrates why cyber insurance matters? What happened, and what did the business learn from the experience?

Kagan: One example involved a small business employee who received what appeared to be a routine email from a trusted vendor. The message looked legitimate, so the employee clicked a link and entered their credentials. Nothing seemed unusual until employees arrived at work days later and couldn’t access critical systems, customer records, accounting software, or business files.

Operations quickly ground to a halt. Customers experienced delays, revenue was impacted, and the company received a demand for cryptocurrency in exchange for restoring access to its systems and data.

What the business learned was that the attack itself was only the beginning. The real challenge was responding to everything that followed: restoring operations, determining what information had been accessed, maintaining customer trust, addressing potential legal and regulatory obligations, and keeping the business running during the disruption.

The experience reinforced several lessons: multifactor authentication matters, employee training matters, secure backups matter, and every business should have an incident response and business continuity plan before it’s needed. Most importantly, they learned that cyber incidents rarely stay confined to technology. They can quickly affect operations, revenue, customers, reputation, and growth.

What started as a single click became a company-wide challenge. That’s the reality of cyber risk today, and it’s why preparation is often the difference between a setback and a crisis.

In today’s threat landscape, cyber insurance isn’t simply about covering losses. It’s about ensuring a business has experienced professionals ready to respond when every minute counts and every decision matters.

Prepare Before an Attack Happens

Lesonsky: If you could give every small business owner just one piece of advice to better protect their business from cyber threats, what would it be?

Kagan: Prepare for a cyber incident before you experience one.

Most businesses have a plan for a fire, severe weather, or a supply chain disruption. Far fewer have a plan for losing access to customer records, payment systems, email, or critical business data.

Ask yourself: If your systems were unavailable tomorrow, how long could your business continue operating?

Could you access customer records? Process payments? Pay employees? Fulfill orders? Communicate with customers and vendors? Recover critical data? Meet contractual obligations?

The businesses that recover fastest aren’t always the ones that avoid cyber incidents. They’re the ones that prepare for them. Cybersecurity isn’t just about preventing attacks. It’s about ensuring your business can continue operating when the unexpected happens.

Rieva Lesonsky is the founder of Small Business Currents, a content company focusing on small businesses and entrepreneurship. You can find her on Twitter @Rieva, Bluesky @Rieva.bsky.social, and LinkedIn. Or email her at Rieva@SmallBusinessCurrents.com.

Photo courtesy Getty Images for Unsplash+

Related posts
CurrentMoney

Your Bank May Need You More Than You Think

3 Mins read
Are you frustrated by your bank? Many small business owners are. Ironically, many do business with the same bank as consumers and…
CurrentTechnology

9 Things AI Assistants Check Before They Recommend Your Business

5 Mins read
A customer sits in a parked car outside a flooded kitchen and types a question into ChatGPT: who should I hire to…
CurrentManage

The Outsourcing Mistake Owners Blame on the Model When the Handover Was the Problem

7 Mins read
A firm signs an offshore provider in January. Week two, somebody sends 40 returns because that was the capacity. The work comes…