What Colorado Small Businesses Get Wrong About Cyber Liability
In June, the National Association of Insurance Commissioners disclosed that an unauthorized party had exploited a previously unknown vulnerability in Oracle PeopleSoft to access part of its environment. NAIC contained the intrusion, brought in outside cybersecurity experts, and coordinated its response with the FBI. A group later claimed to have taken a significant volume of data, although NAIC disputes the scope of that claim.
The point is not to criticize NAIC. It is to recognize what the incident says about cyber risk today. If an organization with real resources and a direct role in insurance regulation can be affected by a flaw nobody knew existed, a twelve-person accounting firm or a regional contractor cannot reasonably assume it is too small to face a serious cyber event. The FBI's 2025 Internet Crime Report puts a number on the scale: more than one million complaints and losses approaching $21 billion for the year, both records.
The market is easing on price
Marsh's Global Insurance Market Index shows cyber rates fell again in the fourth quarter of 2025, continuing several consecutive quarters of declines, and Aon's latest cyber risk report describes the market as buyer-friendly overall. Businesses with reasonable controls in place can often find broader coverage and better pricing than they could a few years ago.
What has changed is not price so much as proof. A carrier will now ask whether multifactor authentication is enforced on business email, remote access, cloud applications and administrative accounts, not just generally. Basic antivirus software often no longer satisfies underwriters who want endpoint detection tools capable of spotting and isolating suspicious activity. Backups must be tested occasionally, not merely scheduled. Underwriters may also ask about employee training, wire transfer procedures and a written information security policy.
That wire transfer question is not boilerplate. We recently had an employee at one of our insured businesses process a coworker's direct deposit change after an email that appeared to come from that coworker, requesting new bank details. Nobody caught it until the real employee asked, a month later, why their paycheck had not arrived. By then the money was gone, sent to an account outside the business’ control. A single unverified email cost that business tens of thousands of dollars, exactly the kind of loss a wire transfer verification procedure is built to prevent.
The businesses that struggle most are rarely the ones with no security at all. More often, they have several of the right pieces in place but cannot show exactly how those protections are configured. That kind of gap rarely comes from negligence. It comes from an owner who was never asked the right question in a way they recognized. Proof now matters almost as much as practice.
Colorado adds a reason to have this conversation before an incident, not after. Under state law, a business that becomes aware that a breach may have occurred must conduct a prompt, good-faith investigation. If the investigation confirms a qualifying breach, the business must notify affected Colorado residents no later than 30 days after that determination. Notice to the Colorado Attorney General is also required if 500 or more residents are affected, on the same timeline. The law allows limited delay for legitimate law enforcement needs or to determine the scope of a breach but carves out no exception for small businesses. Thirty days disappear quickly once a company is coordinating forensic investigation, legal review and consumer notices at the same time.
Why a cyber policy is crucial
A cyber policy also does more than reimburse a loss after the fact. It can provide access to breach counsel, forensic investigators and notification services during the response itself, when a business often needs expertise more than money. Asking whether a business has cyber insurance is the wrong question. The better one is whether the policy matches the business's real exposure.
None of this requires an enterprise-level security budget. It requires having the insurance and security conversation before a renewal deadline forces it. Most owners are surprised by how much of what underwriters ask for they already have, once someone walks through the terminology in plain language. The gap is usually smaller than owners fear, but it must be identified and documented before an application is submitted, not discovered during underwriting or questioned after a loss.
© Entire contents copyright 2026 by InsuranceNewsNet.com Inc. All rights reserved. No part of this article may be reprinted without the expressed written consent from InsuranceNewsNet.com.
The post What Colorado small businesses get wrong about cyber liability appeared first on Insurance News | InsuranceNewsNet.
Popular Products
-
Fireproof Document Bag with Zipper Cl...$60.87$31.78 -
Acrylic Desktop File Organizer with 5...$100.99$69.78 -
Child Safety Cabinet Locks - Set of 6$83.56$41.78 -
Travel Safe Lock Box with 4-Digit Cod...$146.99$78.78 -
Dual Laser Engraver$5,068.99$3034.78