How Dependent Is Your Business on Technology and Information?
Originally published: August 2026 | Last reviewed/revised: August 2026
You don’t have to operate a technology company to have cyber risk.
If your business uses email, computers, smartphones, online banking, electronic payments, cloud-based software, customer information or an internet connection, a cyber incident could affect your operations or finances.
Cyber risk also isn’t limited to someone “hacking” your computer. An employee can click a malicious link. A criminal can impersonate a customer or vendor and convince someone to send money to the wrong account. A laptop can be stolen. A cloud service can become unavailable. Information can accidentally be sent to the wrong person. Ransomware can make critical systems unusable.
Good cyber risk management combines technology, employee awareness, procedures, planning and, where appropriate, insurance.
For each question, select:
Yes | No | Not Sure
There are no “right” answers. The objective is to identify issues that may deserve additional thought.
1. Have you identified the technology and electronic information your business couldn’t operate without?
Consider email, accounting software, customer records, scheduling systems, point-of-sale systems, online banking, cloud services, websites, phones and specialized applications.
Why it matters:
It’s difficult to protect or plan around a dependency you haven’t identified. Many businesses discover how dependent they are on technology only after it becomes unavailable.
Something to consider:
Make a list of your critical systems, services and data. Ask what would happen if each were unavailable for a day, a week or longer.
2. Do you use multi-factor authentication wherever it’s available, particularly for important accounts?
Multi-factor authentication, often called MFA, requires another form of verification in addition to a password.
Why it matters:
A stolen password may not be enough for a criminal to access an account protected by properly implemented MFA.
Something to consider:
Prioritize MFA for email, online banking, accounting systems, cloud services, remote access and administrator accounts. Don’t rely on passwords alone when stronger authentication is available.
3. Are important business systems and data backed up regularly, and have you tested whether those backups can actually be restored?
Why it matters:
A backup that can’t be restored isn’t much of a backup. Ransomware, hardware failure, accidental deletion and other events can make data unavailable or destroy it.
Something to consider:
Maintain backups appropriate to your operations, protect them from the same event that could affect your primary systems, and periodically test the restoration process.
4. Do you control who has access to important systems, information and administrative privileges?
Consider employees, former employees, contractors, vendors and outside IT providers.
Why it matters:
The more people who have unnecessary access, the greater the opportunity for mistakes, misuse or compromised credentials.
Something to consider:
Give people access only to the systems and information they need. Promptly remove access when someone leaves or changes responsibilities, and tightly restrict administrator privileges.
5. Do you keep computers, software, browsers, network equipment and other technology reasonably current with security updates?
Why it matters:
Cybercriminals frequently exploit known vulnerabilities for which updates or security patches already exist.
Something to consider:
Use automatic updates where appropriate and establish responsibility for maintaining systems that require manual attention. Don’t overlook routers, firewalls and other network equipment.
6. Are employees taught how to recognize phishing, suspicious links, fraudulent requests and other common cyber threats?
Why it matters:
Technology can reduce cyber risk, but people remain an important part of the defense. Criminals frequently attack the employee rather than the computer system.
Something to consider:
Provide practical cybersecurity awareness training and periodically remind employees about current threats. Training should include what to do when something looks suspicious and how to report a possible mistake quickly.
7. Does your business independently verify requests to change payment instructions, bank information or other important financial details?
Consider an email that appears to come from a vendor requesting payment to a new bank account, an executive asking for an urgent wire transfer, or a customer providing revised payment instructions.
Why it matters:
A criminal may not need to penetrate your computer systems to steal from your business. Sometimes all that’s necessary is a convincing email, text message or phone call.
Something to consider:
Establish procedures requiring employees to verify unusual or changed financial instructions using a trusted method independent of the original request. For example, call a known telephone number rather than the number contained in the email requesting the change.
8. Do you understand what sensitive or confidential information your business collects, stores or has access to?
Consider customer information, employee records, Social Security numbers, payment information, health information, tax records, passwords and confidential information belonging to other businesses.
Why it matters:
You can’t adequately protect information if you don’t know you have it or where it’s stored.
Something to consider:
Identify what sensitive information you possess, why you need it, where it’s stored, who can access it and how long it needs to be retained. Information you don’t need may create risk without providing any business benefit.
9. Do you know what legal, contractual or industry requirements apply to the information your business handles?
Requirements can vary depending on the type of information, industry, customers and jurisdictions involved.
Why it matters:
A data breach can create obligations beyond repairing computer systems. Notification requirements, contractual obligations, regulatory issues and other expenses may follow.
Something to consider:
Understand the requirements that apply to the information you collect and the contracts you sign. Appropriate legal, IT or other professional assistance may be necessary for businesses handling regulated or particularly sensitive information.
10. Have you considered the cyber risks created by vendors and other third parties?
Consider cloud providers, payroll companies, payment processors, software vendors, managed IT providers and other organizations that access your systems or hold information on your behalf.
Why it matters:
Your business can be affected by a cyber incident that occurs at another organization.
Something to consider:
Know which vendors have access to important systems or information and what you depend upon them to provide. Where appropriate, consider their security practices, contractual responsibilities, backup capabilities and procedures for notifying you of an incident.
11. Could your business continue operating if its computers, email, internet connection or cloud services were unavailable?
Why it matters:
Cyber risk isn’t only about privacy. A technology outage or cyberattack can interrupt operations, reduce revenue and create additional expenses even when no sensitive information has been stolen.
Something to consider:
Identify which operations could continue manually or through alternative systems. Develop contingency procedures for critical functions and consider how long the business could operate without normal technology.
12. Do you have a plan for what to do if you suspect a cyberattack, data breach or fraudulent financial transaction?
Why it matters:
The first hours following an incident can matter. Delays can allow additional damage to occur and can make recovery more difficult.
Something to consider:
Know who should be contacted and in what order. Depending on the incident, this could include your IT provider, financial institution, cyber insurer, attorney, law enforcement or other specialists.
If cyber insurance is involved, contact the insurer or its designated incident-response service promptly. Taking significant action without involving the insurer may affect the assistance or coverage available under some policies.
13. Have you considered how employees use personal devices, remote connections and public or home networks for business?
Consider laptops, smartphones, tablets, home computers, remote access and employees working while traveling.
Why it matters:
Business information and systems can leave the protection of the traditional workplace.
Something to consider:
Establish reasonable rules for remote access, personal devices, passwords, software, storage of business information and reporting lost or stolen devices.
14. Have you considered what would happen if a cyber incident caused your business to lose revenue or incur significant additional expenses?
Possible costs can include lost income, forensic investigation, data restoration, legal services, customer notification, credit monitoring, public relations, additional staffing and temporary technology.
Why it matters:
The cost of a cyber incident isn’t limited to replacing a computer or restoring a file.
Something to consider:
Think about both the direct expenses and the interruption that could follow a serious cyber event. Cyber insurance may provide several different types of first-party and liability coverage, but policies vary considerably in what they cover and how they respond.
15. Do you periodically review your cybersecurity practices as your business and technology change?
Why it matters:
Cyber risk changes quickly. New employees, software, vendors, devices and business practices can create exposures that didn’t exist when security procedures were originally established.
Something to consider:
Review important systems, access privileges, backups, vendors, security procedures and insurance periodically and whenever significant changes occur.
What Did You Learn?
This isn’t a test, and there is no passing score.
A business doesn’t have to possess thousands of customer records to have meaningful cyber risk. Dependence on email, online banking or a single cloud-based application may be enough for a cyber incident to cause significant financial harm.
Pay particular attention to your No and Not Sure answers.
Then ask yourself:
- What technology and information does my business depend upon?
- What could happen if someone gained unauthorized access to it?
- What would happen if it suddenly became unavailable?
- How could someone use technology or deception to steal money from the business?
- Do we know what we would do if an incident occurred tomorrow?
Cyber risk can’t be eliminated. The objective is to make incidents less likely, reduce their potential severity, prepare the business to respond when something does happen, and decide which financial risks should be retained or insured.
Cyber Insurance Is More Than Data Breach Coverage
Cyber insurance is sometimes thought of simply as insurance for businesses that possess large amounts of personal information. Modern cyber policies can address considerably more than notification following a data breach.
Depending on the policy, coverage may be available for expenses associated with incident response, forensic investigation, data restoration, cyber extortion, business interruption, privacy liability, regulatory proceedings and certain forms of cybercrime or social engineering.
Coverage varies significantly among insurers and policies. Sublimits, waiting periods, deductibles, security requirements and exclusions can materially affect how a policy responds.
Insurance also shouldn’t substitute for reasonable cybersecurity practices. Insurers increasingly ask about controls such as multi-factor authentication, backups, employee training and procedures for verifying financial transactions when evaluating whether and on what terms they will provide coverage.
Explore Other Business Risks
Cyber & Privacy Risk is one part of a broader risk management program.
Return to the Plapp Insurance Services Business Risk Self-Assessment Series directory to see other available assessments and additional topics as they’re added.
Important Information
Please keep in mind that this assessment does not:
- Identify every risk your business faces.
- Determine whether your current insurance is adequate.
- Recommend particular insurance policies or limits.
- Replace professional insurance, legal, accounting, safety, IT or other advice.
It is designed to help you ask better questions.
