ݮƵ

Skip to main content
ݮƵ
ݮƵ
Industries
Resources
About Us

How to Fortify Your Business’s Defenses Against Cyberthreats

Laptop with cybersecurity screen

July 9, 2026

Contributors: Thomson Reuters

Cyber risks are a major threattobusinesses today.Anewsurveyfrominsurance provider QBEfoundthat two-thirds of U.S. businesseshadexperienceda cyberattack in the past 12 months. The findingshighlightthe importance ofimplementing strong internal controlsthatspecificallytargetthisrisk.Here’sa closer look at the survey’s findings and practical ways toidentifyyour vulnerabilities and strengthen your cybersecurity practices.

Recent trends

QBEsurveyed 400U.S.businesses with100to 2,000 employeesbetween March 31, 2026, and April 17, 2026.The online survey revealed the followingfindings about reported cybersecurityeventsin the past year:

  • 58%were caused by or related to a supplier,
  • 58%led to a loss of revenue,and
  • 25%resulted in a business interruption for more than one business day.

Many respondents expressed concern about future threats, and 75% plan toincrease their cybersecurity budget in the coming year.“This research underscores the importance of stronger defenses as companies navigate an evolving risk environment that includes emerging technologies,” concludedIan Walsh, VicePresidentand U.S. Product Leader at QBE North America.

Identifyingcyberrisks

No business is immunetocyberthreats. But some are more vulnerable than others.The first step in protectingat-riskassets istoinventorythem.Manybusinessespossesssensitivecustomer or employee datathat hackersmight want to steal, including:

  • Personally identifiable information,such asphone numbers, physical and emailaddressesand Social Security numbers,
  • Protected health information, and
  • Payment card data.

Businessesare requiredtohave effectivecontrolsover this data tocomply withtheir obligations under federal and state laws and industry standards.

Hackers may also try to accessyournetwork to steal intellectual property, such as customer lists, proprietary software, formulas, strategic businessplansand financial data. These intangible assets may be sold or used by competitors to gain market share.

Strengthening controls

Onceyou’veidentifiedthe assets that are vulnerable to cyberattacks, you need totake practical steps to makeyourdata more secure.Cybersecurity is part of your business’s overall internal environment.Consider these best practices:

Vet yourpartners.Cyberattacksare often perpetrated througha business’ssuppliers andvendors.That’sbecause attackers look for the easiest point of entry — whetherthat’sa small provider withlimitedresources or a widely used platform that gives them access to many businesses at once.

When you rely on outside vendors,you’retrustingthem with parts of your business.Before you start working with abusiness partner, ask simple questions: How do they protect your data?What happens ifthey’rebreached?Whowill be able toaccess your information? Reputable vendors should be comfortableproviding answers.Alsocheck for basic safeguards,includingwritten security policies or independent audits.

Limityour business partners’ access todata toonly the information they truly need.Alsoreview yourexisting suppliers andvendorsperiodically, becausea trusted partner today can become a risk if their practices change.

Limitemployeeaccess.Your employees should have access only to the systems and data they need to do their jobs.Limiting access reduces the risk of sensitive information being exposed, either accidentally or through a cyberattack.

Evaluate which devices need internet access and take steps to secure remote connections,such asrequiring strong passwords or multi-factor authentication. Educate employees about cybersecurity risks and install encryption on devices that access company data.You should alsoreview access rights periodically and promptly remove access when employees leave the organization.

Keepsoftwareup-to-date.Protecting againstcyberthreats is an ongoing challenge, not a one-time event.Establish a documented process to ensure software updates and patches are applied consistently andpromptlyacross your organization.Why?Patches and updatesoften revealvulnerabilities, and hackerscan exploitthese gaps before you have timeto install the fix.

Cover your assets.Another popular security measure is cyber insurance.Professional and general business liability insurance policies typicallydon’tcover losses arising from a cybersecurity incident.Cyber insurance can cover a variety of risks, depending on the scope of the policy. It typically protects against liability or losses that come from unauthorized access to yourbusiness’s electronic data and software.

Instead ofpurchasinga standalone cyberinsurancepolicy, you might be able to add a cyber-liability endorsement to your errors and omissions policy. Not surprisingly, the coverageunderanendorsementisn’tas extensive as the coverage in a standalone policy.

Seek outside help.Cybersecurity is an important task that few organizations can handle exclusively in-house. Consider seeking outside resources to reinforce your current information technology (IT) policies and procedures. For example,you coulduseexternalcomputer securityprovidersto evaluate vulnerabilities inyournetwork and testyourITstaff’sperformance.

However, cyber risks are more than an IT concern. Weaknesses in cybersecurity can lead to lost revenue, businessdisruptionsand reputational damage. These risks should be managed just like other operational and financial risks — througha strong systemof internal controls.Gaps in access controls, vendoroversightor system updates can signal broader weaknesses in your control environment.

A financial statement audit can help you get a better handle onyour internal control system.From an auditor’s perspective, cybersecurity is part of the broader risk assessment process.Your auditor can help assess whether your cybersecurity controls areproperly designed, consistentlyappliedand regularly reviewed.

Be proactive, not reactive

Taking a more structured,controls-based approach to cybersecurity not only helps protect your data — it strengthens your overall business resilience.Contact your accountant to gain an independent perspective on your internal controls andidentifypotential gaps before they lead to costly disruptions.

©2026