Skip to main content
  • Claims Center
  • Contact Us
  • Español
  • Brokers
  • Agents
Hiscox Insurance
Menu Toggle
  • Home
  • Small Business Insurance Toggle Menu Toggle Menu
    Protect your business, plan for the unexpected, and help your business grow.
    • Top Coverages

      • General Liability Insurance

        The basic protection for claims against your business.

      • Errors and Omissions

        Protection against claims of negligence

      • Professional Liability

        Protection for specific risks in your field.

      • Business Owner's Policy

        General Liability plus coverage for property.

      • Cyber Security Insurance

        Protection from cyber-related security risks.

      • Workers Compensation

        Protection from work-related illness or injury.

      • Short-Term Liability Insurance

        Purchase coverage for a specific period of time.

      • Medical Malpractice

        Protection for claims against your medical practice.

      • More Coverages

        Umbrella, Auto, Directors and Officers, and more

    • Top Industries

      • Architects & Engineering
      • Beauty
      • Contractors
      • Consulting/Freelancing
      • IT/Technology
      • Landscapers
      • Marketing
      • View All Industries
    • Coverage In 49 States

      • View All States

    Small Business Insurance Main Page

  • Why Hiscox Toggle Menu Toggle Menu
    With a single focus on Small Business Insurance, we provide fast, customized coverage just for you.
      • About Us
      • Customer Stories
      • Ratings & Reviews
      • Our Brand
      • Newsroom

    About Hiscox Main Page

  • Resources Toggle Menu Toggle Menu
    Insights and information to empower you and your business.
    • Blog
      • Start Your Business
      • Grow Your Business
      • Protect Your Business
      • Celebrate Courage
    • Podcast
      • Side Hustle to Small Business
    • Tips and Tools
      • Business Insurance 101
      • Research & Insights
      • Partner Services
      • Insurance Glossary
      • Profit Calculator
      • Business Templates

    Resources Main Page

  • Policy Management Toggle Menu Toggle Menu
    We make it easy for policy-holders to make changes, access documents, and report claims.
    • Manage Your Policy Online

      • Hiscox Policy Management

        • Change Business Address
        • Get an ACORD Certificate
        • Get a Certificate of Insurance
        • Issue an ACORD for an Additional Insured
        • Request Policy Documents
        • And more

    • Claims

      • Claims Center
      • Report a Claim
      • Claims FAQs
      • Claims Customer Reviews
      • Cyber Vendor Services
      • Refer a friend

    Policy Management Main Page

  • Claims Center
  • Contact Us
  • Español
  • Brokers
  • Agents
  • About
  • Get a Quote Get a Quote
  • About
  • Get a Quote Get a Quote
  • Blog Home
    Start Your Business
    Grow Your Business
    Protect Your Business
    Celebrate Courage
    Small Business Insights
    Sign up to get the latest small business news delivered right to your inbox.
    Protect Your Business
    December 2, 2024
    Business owner's hand holding mobile device displaying 'prevent' on screen for guide to preventing cyber attack

    Part 1: How to prevent a cyber attack

    Deep Dive Topics

     | 

    Cyber

    By:
    Karen Doyle

    Share Image

    Embed Image

    Copy

    Share Article:
    In this Article:
    • Preventing a cyber attack
    • Passwords and multi-factor authentication
    • Software updates and data back ups
    • Securing networks and devices
    • Cyber training and education
    • Also in this series

    Cyber crime is big business. According to the FBI’s Internet Crime Report 2023, the FBI received complaints of cyber crimes in 2023 that totaled $12.5 billion, and the agency estimates it receives complaints in only about 20% of cases. This includes crimes committed against individuals, as well as businesses of all sizes. Everyone should be concerned about cyber security, and small businesses are certainly not immune.

    Since the big data breaches are the ones that make the news, small businesses may feel that the cyber criminals only have big companies in their sights, perhaps looking for the biggest possible payday. But the fact is that small businesses are vulnerable too and may be even easier targets than the big firms, simply because they may have fewer safeguards in place.

    If you own a small business, here are three steps you can take to limit the impact of the increasing risk of cyber attacks and protect your businesses. You need to prevent an attack from happening in the first place, detect an intrusion quickly if one does occur, and mitigate the damage to your business and your reputation.


    Preventing a cyber attack

    The best-case scenario, of course, is to prevent a cyber attack from ever taking place. This can be challenging, since hackers always seem to be one step ahead. But there are steps you can take to minimize the likelihood that you will be the victim of a cyber attack.

    Here are 10 best practices to help your small business keep data safe.

    Back to top

    1. Use strong passwords

    Everyone knows you shouldn’t use ‘password’ or ‘123456’ for your password, but a lot of people still use the same password for multiple accounts. If you do this, a hacker who gets access to one of your accounts can easily access them all.

    🛡️ Pro tip: Password managers can generate a random password when you first set up an account on a new site. It will be stored in the password manager so you don’t have to remember it, and it will be much harder to crack because it won’t be your dog’s name or your anniversary. PC Mag lists five favorites.  

    2. Change your passwords frequently

    If a password of yours is compromised you may not realize it right away, and once you do it may be too late. So get in front of it by changing your passwords every 90 days.

    🛡️ Pro tip: There’s a reason why many sites won’t let you use a password you’ve used in the past – the object of the game is to avoid having a detectable pattern.

    3. Use multi-factor authentication

    It’s annoying to have to enter a six-digit code every time you want to access a frequently used account, but it’s even more annoying to have your data compromised by a hacker. Multi-factor authentication requires you to enter a password and then verify your identity by entering a code you receive on a different device. Use multi-factor authentication (MFA) wherever possible.

    🛡️ Pro tip: If you want to add multi-factor authentication to an existing account, check the security settings on the account, and look for ‘multi-factor authentication’ or ‘two-factor authentication.’ The Cybersecurity and Infrastructure Security Agency (CISA) has more information on multifactor authentication.  

    Back to top

    4. Keep your software up to date

    One of the most common ways a hacker can get entry into your system is through a vulnerability in your software. Once software providers learn of these vulnerabilities, they write code to repair, or ‘patch,’ them. But that doesn’t help you unless you install the patch, which is typically done via an upgrade. So whenever a program or operating system asks you if you want to update, the answer is ‘yes,’ and the sooner the better.

    🛡️ Pro tip: Running patch management software on a regular basis will help ensure you don’t miss any updates. If you use an IT consultant to help with your system, they should be able to manage this for you. 

    5. Back up your data regularly

    Having up-to-date data backed up to a secure location will help you get back to business if your data is held for ransom or destroyed. Back up your data regularly – a daily automatic backup is best – to the cloud or to an external device that is stored away from your physical office space.

    🛡️ Pro tip: For most businesses, backing up data to the cloud is going to be the easiest solution. There are a lot of options, so look for the one that best fits the size of your business and the configuration of your system, as well as your budget. Read about PC Mag’s best picks for cloud backup for business.  

    Back to top

    6. Make sure your Wi-Fi network is secure

    Make sure your Wi-Fi network is encrypted with WPA2 (Wi-Fi Protected Access 2) or WPA3 and that your password is secure. WPA3 is more secure than WPA2 so if your network supports WPA3, use it.

    🛡️ Pro tip: If you haven’t updated your router in a few years, it may still be using WPA2. Updating it to one that uses WPA3 is a good idea. Learn more about WPA3 and how to set it up from PC Mag.  

    7. Control physical access to devices

    Only authorized staff should have access to your company’s devices, and only to the ones they need.

    🛡️ Pro tip: If you have employees using their own devices (known as BYOD or bring your own device), make sure you have a written acceptable use policy that includes documentation of required security measures and how you address data protection and privacy concerns. Have a policy for removing company data from any employee-owned device in the event an employee leaves the business.

    Back to top

    8. Educate yourself and your employees

    Learn how to recognize a phishing email or smishing (text) message, and how to recognize and report a suspected cyber incident.

    🛡️ Pro tip: Conduct phishing simulations by sending emails to your employees that look legitimate and ask the recipient to click a link or download a file. If you notice any clicks on this link, it will alert you that more training is needed.

    9. Have a security plan in place and keep it updated

    Develop a written plan for what to do in the event of a cyber attack, including whom to contact and what to do immediately. Revisit the plan at least yearly to be sure it’s current.

    🛡️ Pro tip: A written plan that everyone has access to, with roles and responsibilities identified, will make your response to a cyber incident much more efficient. The Federal Communication Commission (FCC) has a great tool for creating a security response plan for your business, and CISA offers some helpful tips too.  

    10. Monitor your system

    Keep an eye out for unusual activity, using an intrusion detection system or security information and detection management system. These systems will monitor your network and detect any unusual activity.

    🛡️ Pro tip: Intrusion detection systems can range in price from free to tens of thousands of dollars, but even the pricier ones are cheaper than a cyber attack. If you don’t have an IT person on staff, you may need to hire someone to set up your IDS, but once set up it will monitor your system continuously.

    Back to top

    💡✍ This sounds like a lot, but it’s worthwhile, as it protects what could be your company’s most valuable asset: your data. Prevention is critical, but unfortunately it’s not completely foolproof. To learn what to do if you are attacked, read Part 2: Detect an Attack Early.

    📢 Also in this series:

    • Small Business Guide to Cyber Security Part 2: Detect an Attack Early
    • Small Business Guide to Cyber Security Part 3: Mitigate the Damage of an Attack

    Back to top


    Bettering Your Business

    Protect the business you’ve worked so hard to build. Get a fast, free quote and your business could be covered today.

    Get a Quote
    Get a Quote
    Subscribe to our newsletter

    Subscribe to the Hiscox Entrepreneurial Digest on LinkedIn

    Entrepreneurial Digest Graphic and Hiscox Logo
    QR Code Linking to https://www.linkedin.com/newsletters/hiscox-entrepreneurial-digest-7138188446967160832

    Get valuable business resources, timely tips and inspiring success stories in your LinkedIn feed every month.

    Subscribe
    Subscribe

    Related Articles

    6 Min Read
    Man sitting on couch wearing tan sweater with his arm in a red sling.

    What to do when a customer gets injured at your business

    Management

     | 

    Insurance 101

    Learn the steps to take when a customer gets injured at your business and how general liability insurance can protect you from potential claims and lawsuits. 

    Get the details

    5 Min Read
    Businesswoman standing to the right side, arms crossed. On the left black background with FACTS and myths running through

    5 Common misconceptions about General Liability insurance debunked

    General Liability

     | 

    Insurance 101

    Don't let these common misconceptions about general liability insurance hold you back. Get the facts and debunk the myths with this informative guide.

    Just the facts

    6 Min Read
    cookie in business owners hand as it crumbles in two pieces in front of light blue background

    Crumbling under bad press? Lessons from the Girl Scouts on handling tough headlines

    Management

     | 

    Entrepreneur

    Discover how the Girl Scouts are addressing health concerns about their cookies and what small business owners can learn from their approach to negative media.

    Spin the narrative


    We’re here to help.
    We provide tailored insurance for the specific risks you face, so you can take the right risks to grow your business.
    Get a Quote
    Get a Quote

    Footer menu 1

    • What We Cover
      • Business Insurance
      • General Liability Insurance
      • Professional Liability Insurance
      • Errors and Omissions
      • Cyber Security Insurance
      • Workers Compensation
      • Other Coverage
    • Who We Cover
      • Small Business Owners
      • LLC
      • Sole Proprietors
      • Entrepreneurs
      • Side Hustle
      • Contractors
      • Home Businesses
    • For Our Customers
      • Refer a Friend Program
      • Claims Center
    • For Business Owners
      • Save with our Partners
      • Blog
    • About Hiscox
      • About Us
      • Careers
      • Contact Us
      • Hiscox Corporate
      • Investors
      • Foundation
      • Newsroom
      • Diversity, Equity and Inclusion
      • Affiliate Partner Program

    Footer menu 2

    • Accessibility
    • Site Map
    • Privacy Policy
    • Terms of Use
    • Legal Notices
    • Español

    Your privacy choices Privacy opt-out icon

    Feefo Reviews: Hiscox rated 4.7/5 with 1,312 reviews between January 1, 2024 - January 1, 2025

    © 2025 Hiscox Inc. All rights reserved. Underwritten by Hiscox Insurance Company Inc., 30 N. LaSalle St., Suite 1760, Chicago, IL 60602. As of December 31, 2024, HICI had admitted assets of $1,985,481,103 and policyholders surplus of $558,441,204. Total liabilities were $1,427,039,899 (inclusive of $846,124,559 of loss reserves) and paid-up capital stock was $4,242,000.

    icon-facebook
    icon-youtube
    icon-twitter
    icon-linkedin