Walk down the main streets of Winnetka, Wilmette, Glencoe, or Highland Park and you'll pass dozens of the businesses that make the North Shore what it is: boutique retailers, dental and medical practices, law and financial advisory firms, salons, restaurants, contractors. Different industries, same shared exposure — every one of them runs on computers, point-of-sale systems, email, and client data. That shared exposure is exactly why cybercriminals have shifted their attention downmarket.

The Numbers Business Owners Rarely See Coming

Recent industry data paints a clear picture: 43% of all cyberattacks now target small businesses — not the Fortune 500 headlines you're used to reading about. Only around 17% of U.S. small businesses carry cyber insurance, despite being frequent targets. Average cyber claims for small businesses have ranged from roughly $79,000 to well over $200,000, depending on business size and the type of incident — enough to seriously strain, or sink, a small operation with no coverage in place. The most common attack vectors aren't exotic. Phishing emails, compromised passwords, and ransomware account for the overwhelming majority of incidents — meaning most attacks start with something as simple as a staff member clicking the wrong link.

What Cyber Insurance Actually Covers

A commercial cyber liability policy typically helps with: Breach notification costs — legally required notices to affected clients/patients Data recovery and forensics — figuring out what happened and fixing it Business interruption — covering lost income while systems are down Ransomware response — negotiation and, in some policies, extortion payments Legal and liability costs — if a client or patient sues over exposed data Standard general liability and property policies usually don't cover these costs — cyber incidents typically require a dedicated policy or endorsement.

It Pairs With Good Habits, Not Instead Of Them

Insurers increasingly ask about basic safeguards before writing a policy — and for good reason, since they lower both your risk and your premium: Multi-factor authentication on email and financial accounts Regular, tested data backups (a 3-2-1 backup approach is a simple standard) Basic staff training on phishing recognition None of this needs to be complicated or expensive to start. It just needs to start.

The Real Risk Isn't "If" — It's "Are You Covered When It Happens"

Most small business owners assume they're too small to be a target. The data says the opposite: smaller businesses are targeted precisely because they tend to have weaker defenses. The good news is that closing this gap doesn't require an enterprise-level overhaul — just an honest look at what you're currently carrying, and what a policy would cost to fill the gap. Not sure what your current policy actually covers? [Contact North Shore Insurance Associates] for a business insurance review — we'll walk through your exposure in plain English. This article is educational and general in nature. Cyber insurance availability, terms, and pricing vary significantly by carrier, industry, and business size — speak with a licensed agent for guidance specific to your business.

Frequently Asked Questions

Do small businesses really get targeted by cyberattacks? Yes — recent industry data shows roughly 43% of all cyberattacks now target small businesses, not just large corporations. What does cyber insurance typically cover? A standard cyber liability policy typically covers breach notification costs, data recovery, business interruption, ransomware response, and related legal/liability costs. Does general liability insurance cover a data breach? Usually not. Standard general liability and property policies typically exclude cyber incidents, which is why a dedicated cyber policy or endorsement is generally needed.