Skip to main content
Article Last Updated 04/16/2026

Article Reviewed by a licensed insurance professional: Sam Meenasian (CA dept of insurance license #0F75955).

Estimated reading time: 5 minutes

Remote and hybrid work can expand cyber risk if devices, networks, email systems, vendors, and user access are not properly secured. IBM’s Cost of a Data Breach Report 2025 puts the global average cost of a data breach at about $4.4 million. When personally identifiable information, or PII, is exposed, the financial impact can include forensic investigation, legal guidance, customer notification, business interruption, and reputational harm.

That does not mean remote work is inherently unsafe. It means employers need a practical cybersecurity program that covers governance, people, devices, access controls, vendors, incident response, and recovery. FTC guidance for small businesses follows that same structure, and it aligns well with how commercial insurance buyers should think about cyber risk.

Ongoing Communication and Education

Cybersecurity training should not be a once-a-year event. Employees should get regular refreshers, updates on new threats, and clear instructions on what to do if a device is lost, a suspicious email arrives, or a system behaves unexpectedly. Regular training matters even more when employees work from home, travel, or log in from client sites.

Your employee guidance should emphasize long, unique passwords or passphrases, no password sharing, immediate reporting of suspicious emails, careful treatment of attachments and links, and the use of approved password managers. Current NIST guidance no longer recommends arbitrary forced password changes or mandatory character-composition rules as the core standard. Length, uniqueness, and protection against compromised passwords matter more.

Your written remote-work policy should also cover approved file-sharing tools, rules for transmitting sensitive information, handling of payment-change requests, social engineering red flags, and how quickly suspicious activity must be reported. The goal is to make secure behavior operational, not theoretical.

Secure Devices and Remote Access

Whenever possible, use company-managed devices for work. If employees or vendors connect from personal devices, require those devices to meet your security standards before they access company systems. FTC guidance recommends current software, full-disk encryption for laptops and mobile devices, secure router settings, and home Wi-Fi protected by WPA2 or WPA3.

Public Wi-Fi deserves special caution. Employees should avoid it when possible, disable automatic connections, and use secure remote-access controls when they must connect outside the office. A VPN can help protect data in transit, but it should be part of a broader remote-access standard, not the only control.

Before any device connects to your network, verify that it meets your security requirements. That applies to employee-owned devices, contractor laptops, and vendor systems just as much as company-issued equipment.

Limit Access to What People Actually Need

Remote work does not change the need for least-privilege access. Employees, contractors, and vendors should only have access to the systems and data they need for their roles. Sensitive information should be segmented, access should be reviewed regularly, and vendor access should be limited both by scope and by time.

Use Multi-Factor Authentication and Strong Identity Controls

Multi-factor authentication should be required for employees, contractors, and others who access company systems. For higher-value or sensitive systems, present stronger methods such as authenticator apps, hardware tokens, or other phishing-resistant options as the preferred standard when practical. Password-only access is no longer enough for modern business risk.

Strengthen Email, Vendor, and Third-Party Controls

Many cyber incidents begin with email deception or third-party weakness. Businesses should implement email authentication using SPF, DKIM, and DMARC, and they should build security requirements into vendor agreements. Vendors that handle sensitive information or connect to company systems should be subject to access limits, encryption requirements, and periodic verification of compliance.

Prepare for a Breach Before One Happens

A strong cybersecurity program tells people what to do before an incident, not just how to prevent one. Every business should have a written incident response plan, disaster recovery plan, and business continuity plan. Regular backups and restore testing also matter, because recovery is part of cyber resilience, not an afterthought.

If a breach does happen, move quickly to secure systems, preserve evidence, involve legal and forensic support, and update compromised credentials. FTC guidance recommends bringing in the right people early, including IT, legal, operations, HR, communications, management, and outside specialists where needed, because reporting and notification duties can vary by the facts and applicable laws.

Make Sure Your Insurance Matches the Exposure

Even strong controls do not eliminate cyber risk. That is where insurance becomes part of the plan. A good cyber policy can include first-party protection for forensic services, legal counsel, customer notification, call center support, data restoration, business interruption, crisis management, cyber extortion, and certain fees, fines, or penalties, while third-party coverage can help with claims, settlements, lawsuits, and regulatory response.

It is also important to explain what many business owners miss. Most commercial property and general liability policies do not cover cyber risk, and cyber policies are highly customized. Buyers should review limits, retentions, vendor-related incidents, business interruption wording, ransomware-related provisions, and whether the carrier offers a breach hotline or a duty to defend. Coverage depends on the issued policy’s terms, conditions, exclusions, endorsements, and claim facts.

Work With a Cyber Insurance Specialist Who Understands Small Businesses

At USA Business Insurance, we help small and mid-sized businesses compare cyber liability options in plain language. We explain what cyber policies commonly cover, where gaps can exist, and how to line up protection with your operations, compliance needs, and budget.

If your company has remote or hybrid employees, stores employee or customer PII, relies on outside vendors, or depends on digital systems to stay open, now is a good time to review both your cybersecurity controls and your insurance program. The right question is not just “Do we have cyber insurance?” It is “What events are we actually exposed to, what would they cost us, and does our policy clearly address those costs?”

Learn more about Cyber Liability Insurance for Small Businesses. Coverage availability varies by state and underwriting, and coverage descriptions do not alter the terms of the issued policy.

Sam Meenasian

Sam Meenasian is the Operations Director of USA Business Insurance and an expert in commercial lines insurance products. With over 20 years of experience and knowledge in the commercial insurance industry, Meenasian contributes his level of expertise as a leader and an agent to educate and secure online business insurance for thousands of clients within the Insurance family. CA dept of insurance license #0F75955