

HOT TOPICS
THEY'RE HACKING WHAT NOW?
Cyber risk is moving beyond the computer screen. Here's what I'm watching.
By Kaci Garner, President | Outlaw Insurance Group
I went down a cyber rabbit hole recently, and some of what I found surprised me. Cyberattacks are constantly in the news right now, and it would be pretty easy to assume most of it has nothing to do with your business. But when you start looking at what's actually being targeted, that assumption gets a little uncomfortable.
We're talking telecommunications networks, critical infrastructure, operational technology, and equipment that controls real-world systems. There are verified concerns involving compromised telecom networks, vulnerable infrastructure, and foreign-linked telecommunications equipment. The line between a "cyber" problem and an actual operational problem is getting really blurry.
And that got my attention.
YOUR BIGGEST CYBER RISK MAY NOT BE A LAPTOP.
Think about how much technology is involved in running a business now. Your fleet may have GPS and telematics. Crews and field teams use apps. Accounting lives online. Contracts, payments, project information, and sensitive data move electronically. Equipment is increasingly connected. And companies working in telecommunications and infrastructure may be working directly on the systems the rest of us depend on.
The more connected our businesses become, the more ways there are for a cyber event to affect the actual operation. A cyberattack doesn't necessarily have to steal your data to hurt your business. Losing access to the systems you depend on can be enough.
THE COST ISN'T ALWAYS WHAT YOU THINK.
Ransomware gets a lot of attention, and for good reason. But the ransom itself isn't necessarily the whole loss.
Think about what happens if your team suddenly can't access email, accounting systems, project files, dispatch, estimating software, cloud platforms, or other systems your business depends on every day. Now add multiple locations, hundreds of employees, a large fleet, connected equipment, subcontractors, vendors, and millions of dollars moving through the operation.
And getting systems back online may only be the beginning. If protected information was accessed, there may be legal and regulatory notification requirements depending on the circumstances. Then potentially comes forensic investigation, attorneys, notification expenses, credit monitoring, data restoration, business interruption, and figuring out exactly what was compromised.
A breach can get expensive without a hacker ever stealing $1 from your bank account.
NOW THROW AI INTO IT.
This may be the part I'm most interested in watching.
AI can do some incredible things for businesses. It can also change what a convincing attack looks like. Emails can sound right. Information can be gathered and used faster. Voices and video can be manipulated. Some of the red flags we've spent years teaching people to look for may become harder to recognize.
And insurance is having to evolve right alongside the technology.
We're beginning to see the insurance industry address AI through policy language, exclusions, limitations, and new coverage approaches. That doesn't mean "AI isn't covered," and it doesn't mean every AI-related event is a cyber claim. It means how the loss happened and what the policy actually says are becoming increasingly important questions.
That's the part I think businesses should be paying attention to now, while this landscape is still developing.
SO, WHAT DO YOU DO WITH ALL OF THIS?
Start with the basics. Use multifactor authentication. Back up critical systems. Control administrative access. Have a separate verification process for banking changes and significant payments. And make sure your people know what to do and who to call if something happens.
Then look at the insurance side. And I don't just mean asking, "Do we have cyber?"
How would a ransomware event affect your operation? What happens if your systems are down for three days? What if protected information is compromised and people have to be notified? What response resources come with the policy? Where could crime coverage come into the conversation? And as AI changes the way some of these losses happen, is the policy language changing too?
Those answers are going to look different for a contractor with 20 employees than they do for a national infrastructure company with employees all over the country, or even the world. That's the point.
Cyber insurance should make sense for the business that's actually buying it.
I don't know exactly what this landscape will look like five years from now. None of us do. But I'm paying attention to where it's going, what carriers are doing, and what it could mean for the businesses we work with.
If this made you think, "I probably need to look at this," talk to an insurance agent you trust.
And if you don't have one, give us a call. We'd love to nerd out with you.
LET'S TALK →
Built with grit. Backed by purpose.