Ask a business owner what happens if they get hacked, and the most common answer is some version of the same thing: we would call our IT person. It is a reasonable instinct. It is also how a lot of businesses discover, in the worst week of their year, that fixing the computers was the smallest part of the problem.
October is Cybersecurity Awareness Month, which makes it a good time to separate two things that get confused constantly: keeping attackers out, and dealing with everything that happens after they get in.
What Your IT Person Does Well
A good IT provider is essential. They manage your network, patch your systems, set up backups, configure firewalls and email filtering, enforce multi-factor authentication, and restore systems when something breaks. When an incident occurs, they can help identify what happened and get you running again.
That is prevention and technical recovery, and it matters enormously. But a cyber incident is not only a technical event. It is also a legal event, a regulatory event, a financial event, and often a liability event. Those parts are outside what most IT providers do, and in several cases outside what they are legally able to do.
What Happens After a Breach That IT Cannot Handle
Forensic investigation
Determining exactly what was accessed, when, and how requires specialized forensic work. It matters because your legal obligations depend on the answer. Many insurers and attorneys also prefer the forensic firm be engaged through counsel so that its findings are protected by privilege, which your regular IT provider generally cannot offer.
Legal and notification obligations
Every state has a data breach notification law, and the requirements differ in what triggers notification, who must be told, and how quickly. Some situations require notifying a state attorney general or other regulators. Getting this wrong creates penalties and liability of its own. This work belongs with a breach coach or privacy attorney, not an IT technician.
Ransomware response
If systems are encrypted and a ransom is demanded, decisions about negotiation, payment, and sanctions compliance carry legal consequences. Specialized negotiators and counsel handle these situations, and making them up as you go is a significant risk.
The money
Here is the part that ends the “we will just call IT” conversation. According to IBM’s 2026 Cost of a Data Breach Report, the global average cost of a data breach reached a record $4.99 million, and the average for U.S. organizations was $11.5 million. Those averages skew toward larger organizations, but the cost categories apply to everyone: investigation, legal counsel, notification, credit monitoring for affected individuals, lost revenue during downtime, and claims from customers or partners. Your IT provider can rebuild your server. They cannot pay for any of that.
Lost income
While systems are down, revenue stops and payroll continues. Standard business interruption coverage generally requires physical damage, which a cyberattack usually does not cause.
Third-party claims
If client data is exposed, the people affected can bring claims against your business. So can partners whose systems were compromised through yours.
What Cyber Insurance Actually Adds
A well-structured cyber liability policy fills the gaps your IT provider cannot. Depending on the policy, that can include:
- Access to a breach response team, often through a hotline, with forensic investigators, privacy attorneys, and notification vendors already lined up.
- Coverage for response costs, including investigation, legal fees, notification, and credit monitoring.
- Business interruption for income lost while systems are down from a cyber event.
- Cyber extortion and ransomware response.
- Funds transfer fraud and social engineering coverage, which is frequently sublimited and worth reviewing closely.
- Liability coverage for claims and certain regulatory proceedings arising from a breach.
The response team is often the most valuable part. The first hours after an incident shape how much it ultimately costs, and having specialists on call rather than searching for them under pressure makes a real difference.
Your IT Provider and Your Insurer Should Work Together
None of this diminishes your IT provider. The strongest position is a business where IT handles prevention and recovery, and the cyber policy handles everything else. Cyber underwriters will also ask about the controls your IT provider manages, such as multi-factor authentication, backups, and endpoint protection, and those controls affect both your eligibility and your premium.
A few questions worth asking your IT provider this month:
- Is multi-factor authentication enabled on email, remote access, and administrative accounts?
- Are backups kept separate from the network, and when were they last tested?
- What is the plan if we are hit with ransomware tomorrow, and who do we call first?
- Does that plan include notifying our cyber insurer before engaging outside vendors?
That last question matters. Many cyber policies require you to use the insurer’s approved vendors or obtain consent before incurring response costs, so calling your insurer early protects your coverage.
Build a Real Cyber Plan with Inszone
Your IT person keeps the lights on. A cyber policy keeps the business standing after the lights go out. An Inszone commercial agent can review your exposure, explain what a cyber policy would and would not cover for your operation, and help you put the response plan in place before you need it. Contact Inszone Insurance to start the conversation.
Frequently Asked Questions
If I have a managed IT provider, do I still need cyber insurance?
Yes. A managed provider handles technical prevention and recovery. Cyber insurance covers the legal, notification, financial, and liability consequences that follow a breach, which IT providers do not cover.
Does my general liability policy cover a data breach?
Generally no. Most general liability policies exclude electronic data and the disclosure of confidential information. Cyber exposure requires a dedicated policy.
Who should I call first after a cyber incident?
If you have a cyber policy, contact your insurer or its breach hotline promptly. Many policies require notice and the use of approved vendors, and early notice protects your coverage.
Are small businesses really targets?
Yes. Attackers frequently target smaller organizations precisely because they tend to have fewer security resources, and the response costs that follow a breach can be severe relative to a small business’s revenue.