A good incident response plan should dovetail with the cyber policy, meaning the response plan should list the A good incident response plan should dovetail with the cyber policy, meaning the response plan should list the "pre-approved" providers that can be used during any breach response effort. (Credit: Shutterstock)

As of late, an unfortunate reality is that it's no longer "if" a cyber incident will occur, but a matter of "when."

A survey of information technology professionals conducted by cybersecurity company Kaspersky found 91% of their companies have been affected by attacks in the last year, while 45% admit they're under-prepared. No one is immune — companies of any size and in any industry can fall victim to a cyberattack. Incidents in health care, financial institutions and retail may be more widely publicized, but we're now seeing an increase in attacks across all sectors, including manufacturing, real estate and construction. Consequently, it's vital for executives, management personnel, legal and IT leaders in all industries to understand and help combat cyber risks so they are better protected for the "when."

Want to continue reading?
Become a Free PropertyCasualty360 Digital Reader

Your access to unlimited PropertyCasualty360 content isn’t changing.
Once you are an ALM digital member, you’ll receive:

  • Breaking insurance news and analysis, on-site and via our newsletters and custom alerts
  • Weekly Insurance Speak podcast featuring exclusive interviews with industry leaders
  • Educational webcasts, white papers, and ebooks from industry thought leaders
  • Critical converage of the employee benefits and financial advisory markets on our other ALM sites, BenefitsPRO and ThinkAdvisor
NOT FOR REPRINT

© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.