skip to main content
Travelers Logo
  • About
  • Careers
  • Agents
  • Investors
  • Sustainability
  • Contact Us
  • For Individuals
    • Overview
    • Products
      • Car
      • Home
      • Renters
      • Condo
      • Landlord
      • Boat & Yacht
      • Flood
      • Motorcycle
      • Travel
      • Pet
      • Weddings
      • Umbrella
      • All Products
    • Prepare & Prevent
      • Insurance 101
      • Home Central
      • Travelers Garage
      • Managing Through COVID-19
    • Affinity Group Discount
    • Online Service
    • Pay Your Bill
      • Get a Quote
      • Find an Agent
      • File a Claim
      • Pay Your Bill
  • For Business
    • Overview
    • Products & Solutions
      • Overview
      • Boiler & Machinery
      • Commercial Auto & Trucking
      • Cyber
      • Environmental Liability
      • Excess Casualty & Umbrella
      • General Liability
      • Global Insurance
      • Inland Marine
      • Management & Professional Liability
      • Ocean Marine
      • Property
      • Business Owner's Policy
      • Surety Bonds
      • Workers Compensation
        • Find an Agent
        • File a Claim
        • Pay Your Bill
    • Industries
      • Overview
      • Agribusiness
      • Architects, Engineers & Surveyors
      • Auto & Truck Dealers
      • Business & Professional Services
      • Construction
      • Education
      • Energy & Renewable
      • Equipment Dealers
      • Financial Institutions
      • Food Services
      • Health & Related Services
      • Hospitality & Recreation
      • Manufacturing
      • Marine Industries
      • Museums & Fine Art
      • Non-Profit
      • Oil & Gas
      • Public Entities
      • Real Estate
      • Retail
      • Technology
      • Transportation
      • Wholesale & Distribution
        • Find an Agent
        • File a Claim
        • Pay Your Bill
    • Services
      • Overview
      • Risk Control
      • Claim
      • Premium Audit
      • Online Customer Tools
      • Risk Management Information Services
      • Travelers Client Advantage
        • Find an Agent
        • File a Claim
        • Pay Your Bill
    • Small Business
      • Overview
      • Automobile Insurance
      • Business Owner's Policy
      • Data Breach
      • Employment Practices Liability
      • Professional Insurance
      • Umbrella Insurance
      • Workers Compensation Inurance
        • Find an Agent
        • File a Claim
        • Pay Your Bill
    • Large Business
      • Overview
      • Casualty
      • Cyber
      • Management & Professional Liability
      • Property
        • Find an Agent
        • File a Claim
        • Pay Your Bill
    • Multinational Business
    • Prepare & Prevent
      • By Topic
      • By Industry
      • Navigating Your Business Through COVID-19
        • Find an Agent
        • File a Claim
        • Pay Your Bill
      • Find an Agent
      • File a Claim
      • Pay Your Bill
  • Claim Center
    • Claim Center
    • Should I File a Claim?
    • File a Claim
    • Roadside Assistance
    • Find a Service Provider
    • Check Your Claim Status
    • Manage Your Claim Experience
      • Understanding the Claim Process
      • Claim Guide Library
      • Workers Compensation Resources
    • Claim Capabilities
      • Get a Quote
      • Find an Agent
      • File a Claim
      • Pay Your Bill
  • Prepare & Prevent
    • For Individuals
    • Home Central
      • Buying & Selling
      • Home Maintenance
      • Home Renovation
      • Home Safety
      • Moving
      • Smart Home
    • Travelers Garage
      • Buying & Selling
      • Car Maintenance
      • Distracted Driving
      • Safe Driving
      • Teen Driving
      • Boating
    • Insurance 101
    • Weather
    • For Business
    • Industries
      • Construction
      • Manufacturing
      • Nonprofit
      • Small Business
      • Technology
    • Topics
      • Business Continuity
      • Cyber
      • Driver and Fleet Safety
      • Facilities Management
      • Internet of Things
      • Product and Services Liability
      • Supply Chain Management
      • Workplace Safety
    • Travelers Risk Index
      • Get a Quote
      • Find an Agent
      • File a Claim
      • Pay Your Bill
  • About Travelers
    • Overview
      • Awards & Recognition
      • Careers
      • Community
      • Diversity & Inclusion
      • Sustainability
      • History
      • Investors
      • Media Resources
      • News
      • Travelers Championship
      • Travelers Institute
      • Get a Quote
      • Find an Agent
      • File a Claim
      • Pay Your Bill
    • Get a Quote
    • Find an Agent
    • File a Claim
    • Pay Your Bill
Main Navigation
  • For Individuals
      • Insurance for Individuals
      • Products
        • Car
        • Home
        • Renters
        • Condo
        • Landlord
        • Boat & Yacht
        • Flood
        • Motorcycle
        • Travel
        • Pet
        • Weddings & Events
        • Umbrella
        • More
      • Prepare & Prevent
        • Insurance 101
        • Home Central
        • Travelers Garage
      • Affinity Group Discount
      • Online Service
      • Pay Your Bill
    • Get a home quote now

      It's easy to get a free quote for home insurance from Travelers in just a few minutes.

       

      Get a home quote now
  • For Business
      • Products & Solutions
        • Commercial Auto & Trucking
        • Cyber
        • General Liability
        • Management & Professional Liability
        • Property
        • Business Owner's Policy
        • Surety Bonds
        • Workers Compensation
        • More
      • Industries
        • Construction
        • Energy & Renewable
        • Financial Institutions
        • Healthcare
        • Manufacturing
        • Real Estate
        • Technology
        • Transportation
        • More
      • Prepare & Prevent
      • Services
        • Risk Control
        • Claim
        • Premium Audit
        • More
      • Pay Your Bill
      • Small Business
      • Large Business
      • Multinational Business
      • For Business Overview
    • Tips for Managing Risks Related to a Remote Workforce

      Tips for Managing Risks Related to a Remote Workforce

      With the current reality of more employees working from home through the pandemic, is your business ready for all the implications?

      Learn more
  • Claim Center
      • Claim Center
      • Should I File a Claim?
      • File a Claim
      • Roadside Assistance
      • Find a Service Provider
      • Check Your Claim Status
      • Manage Your Claim Experience
        • Understanding the Claim Process
        • Claim Guide Library
        • Workers Compensation Resources
      • Claim Capabilities
    • Send us your receipts, photos, invoices and more with just a push of a button.

      Securely share information with your Claim team.

      Send us your receipts, photos, invoices and more with just a push of a button.

      Upload a File
  • Prepare & Prevent
      • For Individuals
      • Home Central
        • Buying & Selling
        • Home Maintenance
        • Home Renovation
        • Home Safety
        • Moving
        • Smart Home
      • Travelers Garage
        • Buying & Selling
        • Car Maintenance
        • Distracted Driving
        • Safe Driving
        • Teen Driving
        • Boating
      • Insurance 101
      • Weather
      • For Business
      • Industries
        • Construction
        • Energy
        • Manufacturing
        • Nonprofit
        • Small Business
        • Technology
      • Topics
        • Business Continuity
        • Cyber
        • Driver and Fleet Safety
        • Facilities Management
        • Internet of Things
        • Product and Services Liability
        • Supply Chain Management
        • Workplace Safety
      • Travelers Risk Index
    • Managing Through COVID-19

      Managing Through COVID-19

      Resources to help you adapt to the realities of COVID-19.

      Learn more
  • Home
  • Prepare & Prevent
  • Business
  • Cyber
  • Anatomy of a Main Street Hack

Anatomy of a Main Street Hack

By Travelers Risk Control
small business owner checking cyber security measures small business owner checking cyber security measures

National news headlines routinely feature high-profile data breaches and hacking events, with large corporations working around the clock to contain the damage to their business, their customers and their reputations. But research shows that cyber criminals and hackers are also attacking smaller “Main Street” companies who are often less prepared to prevent and respond to an attack.

The Symantec Internet Security Threat Report found that 60% of all targeted attacks struck small- to mid-sized companies. These relatively small breaches can still affect a significant amount of records and be a catastrophic event for unprepared small- to mid-sized businesses, says Tim Francis, Travelers’ Cyber Insurance Lead.

“Large companies have increasingly begun to think about cyber hacks and to have a plan in place to deal with them,” explains Francis. “Meanwhile, small- and mid-sized businesses often lack access to cyber security expertise, including others that can help them secure their systems or help with a breach should it occur.”

In the world of cyber security, it is not if but when a company will experience a data breach. “But if you know how and why, you can do things to mitigate those risks,” Francis says. “You need a plan in place to deal with it effectively.”

Here is a look at how small- to mid-sized companies are vulnerable, what is at stake, and methods to help protect against hacking and data breaches.

The Motive

Using hacking kits available online, cyber criminals target small- to mid-sized businesses to exploit known weaknesses in the software in which their databases or websites are built, extract valuable data, and demand payment to restore a company’s website or database. The thieves are in search of Personally Identifiable Information (PII), Protected Health Information (PHI), and Payment Card Industry Information (PCI), all of which can be bought and sold on the black market.

The Cost

Regulations geared at consumer protection are helping to increase the cost of a breach response and to raise public awareness of risks, says Mark Greisiger, President of NetDiligence, which provides data breach crisis services. When this sensitive data is exposed, companies face growing costs from forensics, legal counsel, notification and credit monitoring, according to the 2014 NetDiligence Claims Study. The average per-record cost increased from $307 in the 2013 NetDiligence study to $956 in 2014, with an average breach claim of $733,000.

The Hack

In an age of “point-and-click computer hacking,” cyber thieves are no longer necessarily part of sophisticated crime units, says Francis. One of the more popular attacks is the SQL injection, which was rated the #1 attack in 2013¹ and still accounts for a significant number of data breaches. It exploits vulnerabilities in an application’s software, when user inputs (i.e., fields for user name and password) are incorrectly filtered, allowing a hacker to execute commands.

The Response

Following an attack, companies are responding to data breaches by turning to a breach coach to walk them through their response and to retain experts, such as a forensics team, to investigate how and when the breach happened, what was accessed, whether or not the data was encrypted or protected, and who it affected.

After a breach involving PII, PHI, or PCI, there are strict timelines for notifying customers, including those issued by state, federal and other organizations. Companies can face potential litigation from government entities and class action lawsuits. There are also public relations concerns, as a breach can threaten a company’s brand and reputation.

Prevention Strategies

“Risk Managers need to accept that their company’s network or data is never 100% secure,” says Greisiger of NetDiligence, who advises developing a response in advance and protecting against known vulnerabilities. Here are four common weak spots that can lead to a data breach:

  1. Overly Relying on IDS or ‘Intrusion Detection Software’ – These systems are intended to alert companies to attempted cyber attacks, but Greisiger warns that frequent “false alarms” may result in IT staff failing to recognize an actual attack.
  2. Failure to Encrypt Private Data – In the event of a data breach, encryption can provide an extra layer of protection, making it harder for a criminal to use or sell.
  3. Poor Patch Management – All networks and databases require constant updates to patch vulnerabilities that cyber criminals can exploit to access data.
  4. Vendor Mismanagement – Third-party vendors are often in care, custody and control of systems or data, sometimes with little oversight.

“What we find is the more that companies can prepare for the potential that an event may take place, the better off they will be when that event takes place,” Francis explains. Francis adds that cyber insurance can protect companies before an event takes place by helping supply them with risk management tools and advice and access to other professionals in the data security community that can help with their information security.

In addition to preventive measures, companies can benefit from performing a table top exercise to help plan their response to a data breach.

Sources:
1 Open Web Application Security Project
Learn More About Travelers Cyber Insurance Options

More Prepare & Prevent

team responding to a data breach

Responding to a Data Breach Takes a Team

Small and mid-sized businesses may be the most vulnerable, and least prepared, to handle a data breach. Without employees trained to handle questions a breach can bring, the effects on the business can be catastrophic.

System protected from cyber extortion

11 Steps to Help Protect Your Business from Cyber Extortion

Extortion as a result of a cyber attack is becoming more and more common for all business types and sizes.

Digital forensic detective investigating a data breach in a server room

How Digital Forensics Detectives Investigate a Data Breach

Digital forensic detectives help businesses with data breach investigations to properly collect evidence and help prevent further damage.

Top Stories
cyber risk pressure test

Is Your Data Secured?

Help protect your data from cyber attacks. Find gaps with The Cyber Risk Pressure Test.

  • Take the test

Related Content

  • How Does a Data Breach Happen?
  • What Is a Data Breach Coach?
  • Cyber Security Training for Employees

Find an Agent

Need an Agent?

Get the personal service and attention that an agent provides.

Find a local agent in your area:


cyber lock

Get Prepared with Cyber Insurance

Travelers can help with cyber insurance solutions for your business.

  • Learn more

person holding a computer and showing different cyber risks

Is Your Business Protected from Cyber Risk?

As technology becomes more complex, so do the threats businesses face.

  • Learn about cyber insurance solutions

See All Cyber Content


Travelers logo

Travelers and The Travelers Umbrella are registered trademarks of The Travelers Indemnity Company in the U.S. and other countries.
© 2023 The Travelers Indemnity Company. All rights reserved.

  • Travelers on Facebook
  • Travelers on YouTube
  • Travelers on Twitter
  • Travelers on LinkedIn
  • Travelers on Instagram

Products & Services

  • For Individuals
  • For Businesses
  • Claim Services
  • Prepare & Prevent

Our Company

  • About Travelers
  • Careers
  • Investors
  • Sustainability
  • Travelers Institute

Connect

  • Customer Support
  • MyTravelers®
  • For Agents
  • Find an Agent

Legal & Compliance

  • Terms of Service
  • Privacy & Security
  • Cookie Settings
  • Accessibility
  • Producer Compensation Disclosure