What Colorado small businesses get wrong about cyber liability
In June, the National Association of Insurance Commissioners disclosed that an unauthorized party had exploited a previously unknown vulnerability in Oracle PeopleSoft to access part of its environment. NAIC contained the intrusion, brought in outside cybersecurity experts, and coordinated its response with the FBI. A group later claimed to have taken a significant volume of data, although NAIC disputes the scope of that claim.

The point is not to criticize NAIC. It is to recognize what the incident says about cyber risk today. If an organization with real resources and a direct role in insurance regulation can be affected by a flaw nobody knew existed, a twelve-person accounting firm or a regional contractor cannot reasonably assume it is too small to face a serious cyber event. The FBI's 2025 Internet Crime Report puts a number on the scale: more than one million complaints and losses approaching $21 billion for the year, both records.
The market is easing on price
Marsh's Global Insurance Market Index shows cyber rates fell again in the fourth quarter of 2025, continuing several consecutive quarters of declines, and Aon's latest cyber risk report describes the market as buyer-friendly overall. Businesses with reasonable controls in place can often find broader coverage and better pricing than they could a few years ago.
What has changed is not price so much as proof. A carrier will now ask whether multifactor authentication is enforced on business email, remote access, cloud applications and administrative accounts, not just generally. Basic antivirus software often no longer satisfies underwriters who want endpoint detection tools capable of spotting and isolating suspicious activity. Backups must be tested occasionally, not merely scheduled. Underwriters may also ask about employee training, wire transfer procedures and a written information security policy.
That wire transfer question is not boilerplate. We recently had an employee at one of our insured businesses process a coworker's direct deposit change after an email that appeared to come from that coworker, requesting new bank details. Nobody caught it until the real employee asked, a month later, why their paycheck had not arrived. By then the money was gone, sent to an account outside the business’ control. A single unverified email cost that business tens of thousands of dollars, exactly the kind of loss a wire transfer verification procedure is built to prevent.
The businesses that struggle most are rarely the ones with no security at all. More often, they have several of the right pieces in place but cannot show exactly how those protections are configured. That kind of gap rarely comes from negligence. It comes from an owner who was never asked the right question in a way they recognized. Proof now matters almost as much as practice.
Colorado adds a reason to have this conversation before an incident, not after. Under state law, a business that becomes aware that a breach may have occurred must conduct a prompt, good-faith investigation. If the investigation confirms a qualifying breach, the business must notify affected Colorado residents no later than 30 days after that determination. Notice to the Colorado Attorney General is also required if 500 or more residents are affected, on the same timeline. The law allows limited delay for legitimate law enforcement needs or to determine the scope of a breach but carves out no exception for small businesses. Thirty days disappear quickly once a company is coordinating forensic investigation, legal review and consumer notices at the same time.
Why a cyber policy is crucial
A cyber policy also does more than reimburse a loss after the fact. It can provide access to breach counsel, forensic investigators and notification services during the response itself, when a business often needs expertise more than money. Asking whether a business has cyber insurance is the wrong question. The better one is whether the policy matches the business's real exposure.
None of this requires an enterprise-level security budget. It requires having the insurance and security conversation before a renewal deadline forces it. Most owners are surprised by how much of what underwriters ask for they already have, once someone walks through the terminology in plain language. The gap is usually smaller than owners fear, but it must be identified and documented before an application is submitted, not discovered during underwriting or questioned after a loss.
© Entire contents copyright 2026 by InsuranceNewsNet.com Inc. All rights reserved. No part of this article may be reprinted without the expressed written consent from InsuranceNewsNet.com.
Rob Whittet is an agency partner at The Brokerage Insurance Group in Centennial, Colo. Contact him at [email protected].


How advisors can prepare clients for an uncertain retirement landscape
Cigna reports more AI, more health customers and more profit in strong Q2
Advisor News
- Embracing a family-centric approach to financial planning
- Family communication: Financial planning’s growing blind spot
- Americans aren’t turning retirement plans into action, LIMRA finds
- Ashley Hinson ‘death tax’ story collides with truth
- How advisors can prepare clients for an uncertain retirement landscape
More Advisor NewsAnnuity News
- Cayman Islands premier to meet with U.S. reinsurance regulators
- Investigation finds deceptive sales, churning of annuities targeting postal workers
- Corebridge annuity sales slip ahead of Equitable marriage
- California teachers settle class-action lawsuit over in-plan annuity fees
- Jackson Financial CEO caps 40-year career with blockbuster Q2
More Annuity NewsHealth/Employee Benefits News
- Data on Managed Care Detailed by Researchers at Harvard Medical School (Geographic Access to Retinal Care in the United States): Managed Care
- New Hampshire fines Anthem and Matthew Thornton Health Plan
- $20M in long-term care money for WA immigrants to cover fewer than 200 people
- Arkansas Healthcare Providers Alarmed by Potential End of State's Medicaid Expansion
- Arizona, others sue feds over rule experts say cuts health care costs
More Health/Employee Benefits NewsLife Insurance News
- LIMRA: Individual life sales continue growth trend in Q2, led by whole life and VUL
- New York Life Awards 20 Golden Futures Scholarships, Expanding Student Support Through Financial Education and Career Development
- Built to Last: Winston-Salem—a quiet industrial powerhouse
- The silver economy ushers in a new era of life insurance growth
- Family communication: Financial planning’s growing blind spot
More Life Insurance News