Skip to main content

Three open doors most businesses don’t know they have

30 Sep 2026

Cybercriminals are using artificial intelligence to sharpen the same tricks they've always relied on, making fake payment requests more convincing and helping them move faster once they're inside. The claims that follow still start in familiar places: a changed invoice or a password that was easy to guess. And some claims involve no cybercriminal at all. Last year brought a notable rise in claims over the tracking tools on businesses' own websites.1

Most small and midsize businesses have already implemented the protection they need: 86.8% have multifactor authentication in place, the extra verification step after a password, and 88.4% keep backups of their data. However, only 51.1% require that extra step on all their key business accounts, and only 61.4% have tested a backup to confirm it restores.2

Those gaps are where losses happen. A control that covers most of a business leaves the rest standing open, and the openings cybercriminals use are ordinary ones. Ordinary is good news, because ordinary openings are the easiest to address. Three of those doors show up repeatedly in claims data.

An invoice that looked legitimate

The most common cyber loss for a business this size doesn’t involve breaking into anything. Someone simply gets into an email account and reads.

Business email compromise and funds transfer fraud together accounted for 58% of all cyber claims last year.3 More than half of the funds transfer cases, 52%, began in a compromised inbox.4 And 71% came down to social engineering, where a person is persuaded to move money on instructions that look legitimate, usually under time pressure.5

Coalition’s claims data describes one case in detail: A property management company received updated payment instructions inside a live email thread with a client. Four payments went out, totaling $539,000. The attacker had altered a single character in the client’s email address, and had been sitting inside the mailbox for two months, implementing inbox rules that redirected replies so nobody noticed the thread had a third participant.6

Fortunately, its cyber insurance went to work. By working with the company’s payment processor, the claims team recovered $290,000 of the stolen funds. The company met the first $25,000 itself, and its funds transfer fraud coverage paid the remaining $224,000.7 A $539,000 loss cost that business $25,000.

Closing the door: verify every change in payment details by phone, and never through contact information supplied in the email itself.

A password that’s easy to guess

An attacker holding a working password has no need for malware and sets off no alarms. From the inside, the login looks like an employee arriving at work. In CrowdStrike’s 2026 global threat data, 82% of detections involved no malware at all, because the intruders arrived through valid credentials and the same tools staff use every day.8

Passwords are guessed more often than business owners assume. Automated software tests thousands of combinations every second, and length is what defeats it. An eight-character password falls in seconds no matter how many symbols it holds, while a complex 16-character password would take billions of years.9

Passwords and identity verification are doors many businesses have already started closing. More than a third of small and midsize businesses, 35.7%, require that extra verification step on only some of their accounts.10 Unfortunately, an account left outside that requirement is the easiest for an attacker to find.

Closing the door: turn the extra verification step on everywhere it’s offered, starting with email and remote access. Then move passwords into a password manager, which makes a 16-character password cost nothing to remember.

A tracking code on your own website

The third door involves no cybercriminal at all.

Most business websites run tools the owner stopped considering after setup: an advertising pixel, an analytics script, a chat widget. Each one can collect information about the people who visit. When the site’s privacy policy doesn’t describe what those tools do, that gap has become the basis for a legal claim.

In Coalition’s analysis of privacy claims, 77% of wrongful collection claims arose from activity on a business’s own website. The claimants are remarkably concentrated. Out of more than 400,000 law firms in the United States, four of them represented the claimants in 72% of all web privacy claims, usually through templated demand letters aimed at a quick settlement before any lawsuit is filed.11

Website scans in the same study show how wide the gap is. Only 19% of websites deploy a consent banner. Only 29% of privacy policies named the specific tracking technology running on the site, and half carried a generic line about tracking instead. Among the lowest-traffic sites, only 37% had updated their privacy policy in the past year.12

However, there is reassurance in the same scans. Tracking tools cluster where the traffic is, and most of the lowest-traffic sites ran no tracking technology at all.13 If your site is simple, it may already be clean.

Closing the door: find out what’s running on your website and make sure your privacy policy names it clearly. Then, talk to your agent. Cyber policies differ in how they treat privacy claims, and it’s a specific question worth asking.

What AI changed

Owners hear constantly that cybercriminals are using AI. Far fewer have been told what it looks like on their own screen.

For example, fake CAPTCHA campaigns are surging. CrowdStrike recorded a 563% rise in incidents using fake versions of that prompt during 2025.14 The page looks routine, but the instruction that follows installs and executes malware. In the same data, attacks by adversaries using AI rose 89% year over year.15

According to IBM, more than one in four organizations that suffered a malicious attack reported it was driven by AI, a 56% increase over the previous year.16 Lagging AI governance also creates vulnerabilities. Among small and midsize businesses, 87.3% now use AI, while only 45.6% have written guidelines for how employees may use it.17 A short written policy naming the approved tools and the data that never goes into them is a practical first step toward closing that gap.

Questions to ask your agent

Cyber coverage varies more than most business policies, so the details are worth asking about directly. Five questions to bring to your Highstreet agent:

  1. What kinds of cyber incidents does this policy cover, and what does it exclude? Ask specifically about ransomware, funds transfer fraud, business email compromise and data breaches. Then, identify the gaps.
  2. If money leaves our account because an employee was tricked, is that covered? This is the most likely loss for smaller operations, and the answer is not automatically yes. Ask how the policy treats a transfer an employee authorized.
  3. What support do we get during an incident, and how quickly does it start? Ask whether the policy brings in forensic investigators, legal counsel, negotiators and communications help. Then find out who makes the first call.
  4. How does the policy handle claims about data collected on our website? Privacy claims work differently from breach claims. Ask how yours are treated, and what the policy expects of your site.
  5. How much coverage does a business our size need? Ask for guidance on limits and deductibles, and whether a standalone policy or an addition to your existing coverage fits better.

Coverage terms and availability vary. Talk to your local Highstreet agent for details.

Businesses with a plan are better prepared

One finding in this year’s small business survey stands out: Businesses that have already been through a cyberattack are measurably better prepared than businesses that have not. Nearly three-quarters of breached companies have a documented incident response plan they follow, against 51.5% of companies that have never had an incident. That means companies with no incident behind them are five times more likely to have no plan at all.18

Everything those businesses learned the hard way is recognizable in advance. The doors we’ve discussed show up again and again in claims data and closing them can start with a phone call to your Highstreet agent. Our team is available to walk through your unique exposures. We’ll help you find the openings in your business and the coverage that fits.

1 Coalition (2026). 2026 Cyber Claims Report.

2 National Cybersecurity Alliance (2026). 2026 Small Business Cybersecurity Awareness & Practices Survey.

3 Coalition (2026). 2026 Cyber Claims Report.

4 Coalition (2026). 2026 Cyber Claims Report.

5 Coalition (2026). 2026 Cyber Claims Report.

6 Coalition (2026). 2026 Cyber Claims Report.

7 Coalition (2026). 2026 Cyber Claims Report.

8 CrowdStrike (2026). 2026 Global Threat Report.

9 National Cybersecurity Alliance (2026). Cybersecurity Awareness Month 2026 tip sheet.

10 National Cybersecurity Alliance (2026). 2026 Small Business Cybersecurity Awareness & Practices Survey.

11 Coalition (2025). The State of Web Privacy.

12 Coalition (2025). The State of Web Privacy.

13 Coalition (2025). The State of Web Privacy.

14 CrowdStrike (2026). 2026 Global Threat Report.

15 CrowdStrike (2026). 2026 Global Threat Report.

16 IBM (2026). Cost of a Data Breach Report 2026.

17 National Cybersecurity Alliance (2026). 2026 Small Business Cybersecurity Awareness & Practices Survey.

18 National Cybersecurity Alliance (2026). 2026 Small Business Cybersecurity Awareness & Practices Survey.

  • Tags:
  • Article
  • Cyber resilience
  • Workspace compliance