A $575 Million Deal Just Told You Something About Cyber Risk
Updated: Sep 4
By Toby Hartman, MM Insurance Associates
I've been watching the insurance industry's biggest players make moves this year, and one deal from this week caught my attention more than most. Munich Re, one of the largest reinsurers in the world, just agreed to pay $575 million for a company called At-Bay. At-Bay does not insure Fortune 500 companies. It insures small and mid-sized businesses, the kind of contractors, shops, and service companies I work with every day.
When a company that size makes a bet that large on protecting small businesses from cyber risk, it tells me something. The exposure is real, it is growing, and it is not going away.
Cyber Risk Is Not Just About Credit Cards or Medical Records
Here is the conversation I have with clients all the time. Someone tells me, "I do not take credit cards online and I do not handle medical records, so cyber insurance is not for me." I understand why people think that. But that is not how most cyber claims happen anymore. More businesses are running on digital tools now than ever before, whether that is cloud accounting, an AI chatbot on the website, email based invoicing, or just a shared file system. Every one of those is a door a criminal can walk through, and it has nothing to do with whether you store health records.
Let me walk you through some real examples of the kinds of claims that come in, because they are more common and more ordinary than people expect.
Five Cyber Claim Examples Small Business Owners Should Understand
1. The wire transfer that looked completely normal
A law firm received what looked like a legitimate cashier’s check from a new client’s insurance company to settle a debt. The bank told them to wait ten days before sending the funds along, which they did. The check turned out to be fraudulent, and the client was a scammer running a con from the start. The firm had already wired the full $89,000. Because they carried funds transfer fraud coverage, their policy covered the loss.
2. The invoice that went to the wrong account
A family run grain farm had an employee whose email got compromised through a phishing message disguised as a routine login alert. The criminal sat quietly inside that inbox watching for financial activity, then intercepted a supplier invoice and redirected the payment to a fraudulent account. The farm did not lose data. They lost money on a transaction that looked completely routine, right up until it was not.
3. The ransomware attack that locked everyone out
A small marketing and PR firm showed up to work one day and could not open a single file on their system. A ransom note appeared shortly after. They had bought a cyber policy only a couple of months earlier. Their insurer connected them with incident response specialists who identified the ransomware and worked with their IT team to get them back online. The firm was down for a couple of days instead of being shut down for good.
4. The breach that started with a vendor, not the business itself
A workforce analytics company that many employers use to manage employee data was hacked, exposing names, birth dates, and Social Security numbers for employees of the businesses that used its service. Those businesses did not get hacked directly. They got pulled into the fallout, and some faced lawsuits anyway, because they were the ones who had entrusted their employees’ information to a vendor. If you send employee or customer data to any outside software or service, this is your exposure too.
5. The chatbot that made a promise the business could not keep
More small businesses are putting AI chatbots on their websites to handle customer questions. Legal guidance published this year is clear: if your chatbot tells a customer the wrong return policy, an incorrect price, or promises something your product cannot do, your business is on the hook for that, not the AI company that built the tool. "The AI made a mistake" is not a defense under consumer protection law.
A Practical Cyber Coverage Conversation
None of these businesses thought of themselves as a target. A law firm, a farm, a marketing agency, and any business using a vendor or a chatbot. That is exactly the point. Cyber risk today is not about the size of your business or the type of data you keep on file. It is about how much of your business runs through email, software, and digital payments, and for almost everyone reading this, that answer is more than it used to be.
If you are not sure what your policy actually covers, or whether you have any cyber coverage at all, that is a conversation worth having before something happens, not after. I would rather walk you through it now and send you a proposal to look at than have you find out the hard way what your gap is.
Start a cyber coverage conversation with MM Insurance Associates through our customer portal.
Related reading: what AI adoption does to your insurance, your vendors, and your renewal.




Comments