Skip to main content
  • Claims Center
  • Contact Us
  • Español
  • Brokers
  • Agents
Hiscox Insurance
Menu Toggle
  • Home
  • Small Business Insurance Toggle Menu Toggle Menu
    Protect your business, plan for the unexpected, and help your business grow.
    • Top Coverages

      • General Liability Insurance

        The basic protection for claims against your business.

      • Errors and Omissions

        Protection against claims of negligence

      • Professional Liability

        Protection for specific risks in your field.

      • Business Owner's Policy

        General Liability plus coverage for property.

      • Cyber Security Insurance

        Protection from cyber-related security risks.

      • Workers Compensation

        Protection from work-related illness or injury.

      • Short-Term Liability Insurance

        Purchase coverage for a specific period of time.

      • Medical Malpractice

        Protection for claims against your medical practice.

      • More Coverages

        Umbrella, Auto, Directors and Officers, and more

    • Top Industries

      • Architects & Engineering
      • Beauty
      • Contractors
      • Consulting/Freelancing
      • IT/Technology
      • Landscapers
      • Marketing
      • View All Industries
    • Coverage In 49 States

      • View All States

    Small Business Insurance Main Page

  • Why Hiscox Toggle Menu Toggle Menu
    With a single focus on Small Business Insurance, we provide fast, customized coverage just for you.
      • About Us
      • Customer Stories
      • Ratings & Reviews
      • Our Brand
      • Newsroom

    About Hiscox Main Page

  • Resources Toggle Menu Toggle Menu
    Insights and information to empower you and your business.
    • Blog
      • Start Your Business
      • Grow Your Business
      • Protect Your Business
      • Celebrate Courage
    • Podcast
      • Side Hustle to Small Business
    • Tips and Tools
      • Business Insurance 101
      • Research & Insights
      • Partner Services
      • Insurance Glossary
      • Profit Calculator
      • Business Templates

    Resources Main Page

  • Policy Management Toggle Menu Toggle Menu
    We make it easy for policy-holders to make changes, access documents, and report claims.
    • Manage Your Policy Online

      • Hiscox Policy Management

        • Change Business Address
        • Get an ACORD Certificate
        • Get a Certificate of Insurance
        • Issue an ACORD for an Additional Insured
        • Request Policy Documents
        • And more

    • Claims

      • Claims Center
      • Report a Claim
      • Claims FAQs
      • Claims Customer Reviews
      • Cyber Vendor Services
      • Refer a friend

    Policy Management Main Page

  • Claims Center
  • Contact Us
  • Español
  • Brokers
  • Agents
  • About
  • Get a Quote Get a Quote
  • About
  • Get a Quote Get a Quote
  • Blog Home
    Start Your Business
    Grow Your Business
    Protect Your Business
    Celebrate Courage
    Small Business Insights
    Sign up to get the latest small business news delivered right to your inbox.
    Protect Your Business
    padlock on red and black background depciting cyber security

    A cyber security expert answers your ransomware questions

    Cyber

     | 

    Industry Spotlight

    By:
    Karen Doyle

    Share Image

    Embed Image

    Copy

    Share Article:

    Most businesses rely on their computers to communicate with customers and vendors, track their performance and generally get their work done. So, the thought of not being able to access your data is nerve-wracking. If a hacker got into your system and held your data hostage, would you know what to do?

    We sat down with Christopher Hojnowski, Vice President and Product Head, Technology and Cyber for Hiscox USA to talk about how to protect your business from ransomware attacks. 

    What is ransomware?

    “Ransomware is when a threat actor gains access to your computer system and basically steals your data,” said Hojnowski. “Then they either encrypt your data so you can’t get to it – only they can – or they threaten to delete it or release it. They’ll do any of the many things that would interrupt your business or harm your reputation with clients or vendors.”

    How do these threat actors get into a computer system?

    “There are several different ways that someone could gain access to your system,” Hojnowski said. The most tried and true way is by phishing – when they send an email saying they are someone they’re not. The email includes a link or an attachment. If you click the link or open the attachment, it loads malware on your system which lets the hacker get in there and do their thing.
     
    “They may also gain access because you give them credentials – again, because they said they are someone they’re not – or access to some information they shouldn’t have. 

    “Another easy way they can get in is through open ports in your system. Using remote desktop protocol or RDP, a hacker gains access to your system through an open port on the internet. Then they tunnel through the system to get the information they need. They can scan several companies’ systems and see if there are any remote desktop or legacy operating systems running. Once they find one, in they go.”

    Related: What’s your cyber security IQ?

    What kinds of systems are most vulnerable?

    “I mentioned legacy operating systems before, and this can be a critical vulnerability,” said Hojnowski. “Older operating systems that are no longer being patched, such as Microsoft Internet Explorer, are an issue. Now that Microsoft has changed over to Microsoft Edge, there may be a vulnerability that everyone on the internet knows about, but it will never be patched because it’s a legacy system that’s no longer supported. Now expand that to every piece of software you could be using that runs on that legacy system that will never be patched.

    “You can also run a scan for critical vulnerabilities. There’s a database of critical vulnerabilities that is put out every year so that companies can address them. But that same information is valuable to hackers because it tells them which of their tools they can use to exploit them. Once they do that, they’re in your system.”

    Related: The top 5 cyber risks for businesses

    How can small business owners protect themselves?

    “Just as there are many ways your system can be compromised, there are many ways to protect yourself,” Hojnowski said. “To protect against phishing email, never, ever click on a link in an email, even if it looks legitimate. It used to be easy to identify a phishing email – there would be grammar or spelling errors, or it would be so generic as to be obviously fake. But now hackers are using ChatGPT and other artificial intelligence tools to write their phishing emails, so it’s a lot harder to pick them out. So don’t click links unless you’re 100% certain of who it came from and where it will take you. 

    “Another important step to take is to run every patch as soon as it comes out. Once a patch comes out, it’s common knowledge that there is a vulnerability, so someone will try to exploit that. Suppose someone gets into your system and encrypts all your data. You think, ‘Oh, well, it’s fine because I have my data backed up on site or I have physical backups.’ But what you don’t know is when the actual attack occurred. Sometimes a threat actor will get into a system and just sit dormant for three or four months to see how the system operates. By then, they’re fully ingrained in the system. Then they decide to flip a switch, encrypt the data and demand a ransom. But you have no idea how long they’ve been in there or how much data they’ve had access to. 

    “I saw a situation recently where there was a known vulnerability, and a patch was released. This company didn’t run the patch right away – they waited a few months. Once they ran it, they found that someone had been sitting in their system all that time, encrypting backups and things like that. So they thought everything was backed up, but their backups were also encrypted and all their data was gone. 

    “Finally, and maybe most importantly, get cyber security insurance. Besides covering the costs that may be associated with a ransomware demand, cyber security insurance can provide breach prevention training, access to professional incident response services, coverage for defense costs, and more.“

    If you get a ransomware demand, should you pay it?

    “If you get a ransomware demand, you want to immediately reach out to your cyber insurance carrier,” said Hojnowski. They have experts who can go in and determine what went wrong, where the breach is, how to fix it, and what data was exposed. They can determine whether a ransom should be paid or not, but even more importantly, they can help get your business back up and running.”

    Computers are an essential part of your business, but keeping your data safe requires vigilance. Take the first step by getting a quote for cyber security insurance. It’s fast and easy, and your business could be covered today.


    Bettering Your Business

    Protect the business you’ve worked so hard to build. Get a fast, free quote and your business could be covered today.

    Get a Quote
    Get a Quote
    Subscribe to our newsletter

    Subscribe to the Hiscox Entrepreneurial Digest on LinkedIn

    Entrepreneurial Digest Graphic and Hiscox Logo
    QR Code Linking to https://www.linkedin.com/newsletters/hiscox-entrepreneurial-digest-7138188446967160832

    Get valuable business resources, timely tips and inspiring success stories in your LinkedIn feed every month.

    Subscribe
    Subscribe

    Related Articles

    6 Min Read
    Man sitting on couch wearing tan sweater with his arm in a red sling.

    What to do when a customer gets injured at your business

    Management

     | 

    Insurance 101

    Learn the steps to take when a customer gets injured at your business and how general liability insurance can protect you from potential claims and lawsuits. 

    Get the details

    5 Min Read
    Businesswoman standing to the right side, arms crossed. On the left black background with FACTS and myths running through

    5 Common misconceptions about General Liability insurance debunked

    General Liability

     | 

    Insurance 101

    Don't let these common misconceptions about general liability insurance hold you back. Get the facts and debunk the myths with this informative guide.

    Just the facts

    6 Min Read
    cookie in business owners hand as it crumbles in two pieces in front of light blue background

    Crumbling under bad press? Lessons from the Girl Scouts on handling tough headlines

    Management

     | 

    Entrepreneur

    Discover how the Girl Scouts are addressing health concerns about their cookies and what small business owners can learn from their approach to negative media.

    Spin the narrative


    We’re here to help.
    We provide tailored insurance for the specific risks you face, so you can take the right risks to grow your business.
    Get a Quote
    Get a Quote

    Footer menu 1

    • What We Cover
      • Business Insurance
      • General Liability Insurance
      • Professional Liability Insurance
      • Errors and Omissions
      • Cyber Security Insurance
      • Workers Compensation
      • Other Coverage
    • Who We Cover
      • Small Business Owners
      • LLC
      • Sole Proprietors
      • Entrepreneurs
      • Side Hustle
      • Contractors
      • Home Businesses
    • For Our Customers
      • Refer a Friend Program
      • Claims Center
    • For Business Owners
      • Save with our Partners
      • Blog
    • About Hiscox
      • About Us
      • Careers
      • Contact Us
      • Hiscox Corporate
      • Investors
      • Foundation
      • Newsroom
      • Diversity, Equity and Inclusion
      • Affiliate Partner Program

    Footer menu 2

    • Accessibility
    • Site Map
    • Privacy Policy
    • Terms of Use
    • Legal Notices
    • Español

    Your privacy choices Privacy opt-out icon

    Feefo Reviews: Hiscox rated 4.7/5 with 1,312 reviews between January 1, 2024 - January 1, 2025

    © 2025 Hiscox Inc. All rights reserved. Underwritten by Hiscox Insurance Company Inc., 30 N. LaSalle St., Suite 1760, Chicago, IL 60602. As of December 31, 2024, HICI had admitted assets of $1,985,481,103 and policyholders surplus of $558,441,204. Total liabilities were $1,427,039,899 (inclusive of $846,124,559 of loss reserves) and paid-up capital stock was $4,242,000.

    icon-facebook
    icon-youtube
    icon-twitter
    icon-linkedin