

An employee at the engineering firm Arup wired roughly $25 million after a video call with what looked and sounded exactly like the company's CFO. Every face on that call was an AI deepfake. That case was reported worldwide, and the tools that made it possible are cheaper and better every month. The question is no longer whether your business is a target. Everyone with a bank account is. The question is what your insurance actually does the morning after.

We don't invent urgency. These are public, documented numbers, which is exactly why they should worry you more than a marketing statistic ever could.
The FBI's Internet Crime Report logged $16.6 billion in reported losses for 2024, and reported is the operative word. Most incidents never reach a report.
The Arup case: a finance employee joined a video call where the CFO and colleagues were all AI reconstructions, then followed their instructions. No malware. No breach. Just a convincing face.
The old tell, clumsy English, is gone. Machine-written fraud now references your real vendors, your real projects, and your real org chart, at scale, for pennies.
In 2023, attackers reportedly talked their way past MGM Resorts' IT help desk by impersonating an employee they found online. Slot floors, hotel keys, and reservations went down for days; the company disclosed an impact of roughly $100 million. Not a line of code. A convincing voice.
In 2024, ransomware entered Change Healthcare through a single compromised credential reportedly lacking multi-factor authentication. Claims and prescription processing stalled across the country for weeks; its parent company has put the total cost in the billions, and the breach ultimately touched data on roughly 190 million people.
In 2023, a previously unknown flaw in the MOVEit file-transfer software was exploited before a patch existed. Government agencies, airlines, banks, and universities were breached in one wave, through software many of them barely knew they were running.
Here is what those three stories mean for a business without a security operations center: the defenses that failed were better than yours. What kept smaller companies safe was never superior security. It was that attacking them wasn't worth an expert's time. AI removed that cost. The same techniques now run as automated tooling against everyone, and the effort flows to whoever looks easiest.
If your business holds sensitive data (customer records, payment details, health information, employee files), you are not too small to be a target. You are the target profile: real money, regulated data, and no one watching the wire at 2 a.m.
The same models that write software can read software, and security researchers have repeatedly shown them finding flaws in it. What used to take a skilled specialist weeks of probing can increasingly be automated, run at scale, and pointed at anything with an address on the internet. Your website, your remote-access portal, your vendor integrations, the forgotten server nobody has patched since the person who set it up left.
This is why the boards of the world's largest corporations now treat AI-enabled attack as a standing agenda item: the skill floor for attackers has collapsed. The person probing your systems no longer needs to be good. Their tools are.
Here is the honest conclusion, and it is the one that matters for a business your size: you cannot patch your way to zero. Defense buys down the odds; it never buys them out. The residual risk, the deepfake that fools a careful employee, the flaw found before the patch existed, is exactly the category of risk that is transferred, not eliminated. That is what insurance is for, and it only works if the forms were built for this decade's threats instead of the last one's.
Standard property and general liability forms commonly exclude cyber events outright. The coverage that answers lives in a cyber policy, if you carry one, and if its limits were built for a company your size rather than checked as a box.
Worse: when an employee is deceived into sending money (the deepfake call, the perfect phishing email), many forms treat it as “voluntary parting” of funds and exclude it unless a specific social-engineering endorsement was added. It is one of the most consequential gaps we find, and the owner almost never knows it is there.
And a ransomware outage is a business-interruption event: the waiting period and sublimits in the cyber form decide whether three dark weeks are an insurance claim or a near-death experience. A $50,000 sublimit against a three-week outage is decoration.
None of this is knowable from the premium line. It is only knowable by reading the forms, which is precisely what we do, and cite to the page, before you ever pay us anything.
ARIA can now evaluate the controls, dependencies, and operating risks that shape how your business responds before, during, and after a loss. About 3 minutes. A Business Preparedness Score, public website security signals, and the three actions that matter first.
Ninety days before it, you get one market read for your industry, from me. Nothing else happens without you.
Send your declarations pages and get back a cited read: what answers, what's excluded, and what a company your size should be carrying against the threat that looks like your CFO.
In writing, within 48 hours, free. If the read shows your current program is right, I will tell you to stay put, in writing. You lose nothing either way.
Nothing binds until a licensed Risk Strategist signs the placement
ARIA · live across every page