Cyber risks are a major threat to businesses today. A new survey from insurance provider QBE found that two-thirds of U.S. businesses had experienced a cyberattack in the past 12 months. The findings highlight the importance of implementing strong internal controls that specifically target this risk. Here's a closer look at the survey's findings and practical ways to identify your vulnerabilities and strengthen your cybersecurity practices.
Recent Trends
QBE surveyed 400 U.S. businesses with 100 to 2,000 employees between March 31, 2026, and April 17, 2026. The online survey revealed the following findings about reported cybersecurity events in the past year:
- 58% were caused by, or related to, a supplier,
- 58% led to a loss of revenue, and
- 25% resulted in a business interruption for more than one business day.
Many respondents expressed concern about future threats, and 75% plan to increase their cybersecurity budget in the coming year. "This research underscores the importance of stronger defenses as companies navigate an evolving risk environment that includes emerging technologies," concluded Ian Walsh, Vice President and U.S. Product Leader at QBE North America.
Identifying Cyber Risks
No business is immune to cyberthreats, but some are more vulnerable than others. The first step in protecting at-risk assets is to inventory them. Many businesses possess sensitive customer or employee data that hackers might want to steal, including:
- Personally identifiable information, such as phone numbers, physical and email addresses, and Social Security numbers,
- Protected health information, and
- Payment card data.
Businesses are required to have effective controls over this data to comply with obligations under federal and state laws and industry standards.
Hackers may also try to access your network to steal intellectual property, such as customer lists, proprietary software, formulas, strategic business plans, and financial data. These intangible assets may be sold or used by competitors to gain market share.
Strengthening Controls
Once you've identified the assets that are vulnerable to cyberattacks, you need to take practical steps to make your data more secure. Cybersecurity is part of your business's overall internal environment. Consider these best practices:
Vet your partners. Cyberattacks are often perpetrated through a business's suppliers and vendors. That's because attackers look for the easiest point of entry — whether that's a small provider with limited resources or a widely used platform that gives them access to many businesses at once.
When you rely on outside vendors, you're trusting them with parts of your business. Before you start working with a business partner, ask simple questions: How do they protect your data? What happens if they're breached? Who will be able to access your information? Reputable vendors should be comfortable providing answers. Also check for basic safeguards, including written security policies or independent audits.
Limit your business partners' access to data to only the information they truly need. Also review your existing suppliers and vendors periodically, because a trusted partner today can become a risk if their practices change.
Limit employee access. Your employees should have access only to the systems and data they need to do their jobs. Limiting access reduces the risk of sensitive information being exposed, either accidentally or through a cyberattack.
Evaluate which devices need internet access and take steps to secure remote connections, such as requiring strong passwords or multi-factor authentication. Educate employees about cybersecurity risks and install encryption on devices that access company data. You should also review access rights periodically and promptly remove access when employees leave the organization.
Keep software up to date. Protecting against cyberthreats is an ongoing challenge, not a one-time event. Establish a documented process to ensure software updates and patches are applied consistently and promptly across your organization. Patches and updates often reveal vulnerabilities, and hackers can exploit these gaps before you have time to install the fix.
Cover your assets. Another popular security measure is cyber insurance. Professional and general business liability insurance policies typically don't cover losses arising from a cybersecurity incident. Cyber insurance can cover a variety of risks, depending on the scope of the policy, and typically protects against liability or losses that come from unauthorized access to your electronic data and software.
Instead of purchasing a standalone cyber insurance policy, you might be able to add a cyber-liability endorsement to your errors and omissions policy. Not surprisingly, the coverage under an endorsement isn't as extensive as the coverage in a standalone policy.
Seek outside help. Cybersecurity is an important task that few organizations can handle exclusively in-house. Consider seeking outside resources to reinforce your current IT policies and procedures.
However, cyber risks are more than an IT concern. Weaknesses in cybersecurity can lead to lost revenue, business disruptions, and reputational damage. These risks should be managed through a strong system of internal controls. Gaps in access controls, vendor oversight, or system updates can signal broader weaknesses in your control environment.
A financial statement audit can help you get a better handle on your internal control system. From an auditor's perspective, cybersecurity is part of the broader risk assessment process. Your auditor can help assess whether your cybersecurity controls are properly designed, consistently applied, and regularly reviewed.
Be Proactive, Not Reactive
Taking a more structured, controls-based approach to cybersecurity helps protect your data and strengthens your overall business resilience. Contact Hood & Strong to gain an independent perspective on your internal controls and identify potential gaps before they lead to costly disruptions.