#incident-response
Incident Response
Incident response procedures and communication protocols
Cyber Insurance for Small Businesses: The Coverage Gaps That Blindside Owners
Only 38% of small businesses carry cyber insurance, 44% of insured ones are underinsured, and nearly half of claims are denied or closed without payment. A guide to the ransomware sublimits, social engineering caps, and security-control requirements that determine whether a policy actually pays.
Cyber Insurance for Small Businesses in 2026: What It Costs, What It Covers, and Where Claims Get Denied
Small business cyber insurance runs roughly $400–$1,600 a year for a $1 million limit, while the average breach recovery costs $120,000 and downtime $53,000 an hour. A guide to first-party vs. third-party coverage, 2026 premium drivers, and the social-engineering sublimits and MFA requirements that most often sink claims.
Missouri's HB 974 Insurance Data Security Law: What Small Agencies Must Do Before January 1, 2026
Missouri's HB 974, signed July 2, 2025 and effective January 1, 2026, applies the NAIC Insurance Data Security Model Law to nearly every insurance licensee in the state — requiring a written security program, annual risk assessments, an incident response plan, vendor oversight, and breach notification to regulators within four business days.
CIRCIA's 72-Hour Cyber Incident Reporting Rule: A Small Business Guide
CIRCIA requires covered entities to report substantial cyber incidents to CISA within 72 hours and ransomware payments within 24 hours, with the final rule expected in fall 2026 and coverage reaching an estimated 300,000-plus organizations across 16 critical infrastructure sectors.
State Data Breach Notification Laws: A Small Business Compliance Guide
Every US state has its own data breach notification law, with individual-notice deadlines ranging from 30 days (California, Colorado, Florida, New York, Washington) to 60 days (Connecticut, Texas), and small businesses must comply with the law of every state where an affected person lives, not just their home state.
SEC Cybersecurity Incident Disclosure: Hitting the Four-Business-Day Clock on Item 1.05 in 2026
A 2026 operating guide to SEC Item 1.05 Form 8-K cybersecurity disclosure — when the four-business-day clock starts, how to make the materiality call without unreasonable delay, when the Attorney General can grant a delay, the Item 1.05 vs. Item 8.01 trap, and what Regulation S-K Item 106 requires in your annual 10-K.
The 2026 WISP Playbook for Tax Pros and Bookkeepers: Building an FTC Safeguards Rule-Compliant Data Security Program Without a CISO
A 2026 guide for solo tax preparers and small bookkeeping firms to build a Written Information Security Plan that satisfies the FTC Safeguards Rule's nine elements, the IRS PTIN attestation, and the 30-day breach notification requirement — using IRS Publication 5708 as the scaffold and a 90-day rollout.
Cyber Insurance for Small Businesses in 2026: MFA Requirements, Ransomware Coverage, and Premium Benchmarks
S&P forecasts a 15–20% rise in cyber insurance premiums for 2026 after a 126% jump in ransomware incidents. A guide to the controls underwriters now require, typical small business pricing ($1,000–$7,500 for $1M of coverage), and the exclusions behind the 40%+ claim denial rate.
Database Migration Incident Summary
A detailed account of a database migration error that affected 39 users, outlining the timeline of the incident and the measures taken for data recovery.