Cybersecurity threats are one of the fastest-growing areas of concerns for businesses across almost every industry and in companies of almost every size, according to Nicholas Koch of Troxell, a Springfield-based insurance company.
“You only hear about the large companies, but the regular person would be shocked at how often cyber incidents are happening in every community,” Koch said.
The success and sophistication of cyber criminals seeking to hack into business records and operations – and sometimes demanding large sums of money – is leading to a growing interest in cyber insurance as companies seek protection against cyber threats. Businesses and individuals are targeted daily in emails, texts and links that tempt users to click on or download something malicious. Sometimes the threats appear to come from a coworker or friend or someone in your contacts, and it is unclear at first glance whether the message or file is legitimate and personally intended for you.
“Many successful cyber events begin with what appears to be a routine email,” Koch said.
Attackers may pretend to be a vendor sending an invoice that needs to be paid, or they might pose as someone in the same company who mentions a confidential – but fake – transaction or a need to change someone’s bank information for direct deposit. Employees who trust the source and provide such information can provide an opening for the attacker to hack into a company’s files and steal information or money.
In some of the worst cases, attackers freeze all a company’s files and demand ransom payments to unlock the files. Cyber insurance can cover repayment of ransom, according to consultant Kurtis Minder, who has assisted “quite a few” Illinois businesses that have been hacked.
“Some of these [Illinois] cases were solved without paying a ransom; others elected to pay,” Minder said.
Cyber insurance has other benefits. First-party insurance coverage addresses losses and expenses of the affected business, while third-party coverage, Koch said, “may help address claims made by customers, vendors or regulators alleging damages related to a cyber incident or data breach.”
“A cyber incident can lead to lost income, business interruption, legal expenses, notification costs and damage to customer trust,” Koch said. “The value of the policy is not only the insurance coverage but also access to specialized response teams and resources immediately after an event occurs.”
Koch and Minder classify cyber insurance as a risk management tool, but Koch says it still is not as common as liability insurance.
“Understanding cyber insurance helps business owners evaluate their exposure and determine whether they have a plan in place to help respond to and recover from these types of events,” Koch said.
Minder said whether a company needs cyber insurance is “highly variable” depending on the business, adding it generally makes sense, but not for all businesses.
Beyond insurance to protect your company if an attack does occur, Koch and Minder recommend strong cyber security practices and policies to help prevent being targeted in the first place. For one, do not use your business email for anything other than business purposes, Minder said. That means not signing up for external newsletters and social media accounts with your business email, which can provide an inside track for hackers.
Other good “cyber hygiene” practices include updating software with patches that often provide security enhancements, using multi-factor authentication, and not reusing passwords. And, as Minder said simply in a 2022 TED Talk, “Stop clicking on things.”
It can be difficult to take legal action against hackers and scammers because duped people often unwittingly and voluntarily chose to give away money or information. In addition, most attackers are based in foreign countries where they won’t be extradited or prosecuted, Minder said.
Businesses must be on the alert for both scammers and hackers, Koch said. “A hacker typically gains unauthorized access to systems or accounts through technical means, while a scammer may rely on deception, such as impersonating a vendor or executive, to convince someone to voluntarily send money,” he said.
A newer factor is artificial intelligence. Minder said he is seeing hackers increasingly use AI “to better understand the data they have stolen, synthesizing large data sets to find the most valuable artifacts, like financial data, personal information, etc. [And] we are now seeing the threat actors using AI to develop and execute the actual attacks.”
Ed Wojcicki has a degree in journalism, worked 26 years for print publications and now freelances from Springfield.
This article appears in August SBJ 2026.

