

If your business holds sensitive data (customer records, payment details, health information, employee files) or can be tricked into sending money, then yes, and the reason changed recently. AI-driven attack tools removed the labor cost that once made small businesses uneconomical targets: the same automated reads and convincing fraud now run against everyone, and route effort toward whoever looks easiest. Being small was a defense when attacking you took an expert's time. It no longer does.
For twenty years the honest answer for many small businesses was that obscurity worked: attackers had limited hours and aimed them at bigger prizes. AI broke that math. Phishing that references your real vendors writes itself; reconnaissance that once took days of expert probing runs as automated tooling against everything with an address on the internet; a cloned voice is a commodity. When targeting is free, the sorting criterion stops being value and becomes openness. And smaller businesses, on average, look more open.
MGM Resorts was reportedly cracked through a phone call to its own help desk. Change Healthcare fell to a single compromised login and stalled claims processing across American healthcare for weeks, at a cost its parent company put in the billions. Thousands of organizations were breached in one wave through a flaw in the MOVEit file-transfer tool. The lesson for a smaller business is not “even the big ones fail.” It is that the defenses that failed were far better than yours, and the techniques that beat them are now automated and cheap.
Hold health information and you have HIPAA obligations; take cards and you sit under PCI rules; keep employee files and you hold Social Security numbers with state breach-notification duties attached. For data-holding businesses the incident is never just an IT event. It is a legal event with regulators, notification deadlines, and liability to every person in your records. That legal tail is exactly what third-party cyber coverage carries, and it is the part no backup strategy addresses.
Defense buys the odds down; it never buys them to zero. The residual risk (the deepfake that fools a careful employee, the vendor flaw no patch existed for) is transferred, not eliminated, and that transfer is the policy. The practical sequence for an owner: run a public read of your own posture (it is free and takes seconds), fix what is cheap to fix, and have your existing policies read against modern incident patterns before assuming anything is covered. Most stacks we read carry at least one exclusion the owner had never been told about.
An IT vendor reduces some risks and adds one: their access and their tools become your attack surface, and their contract almost certainly disclaims liability for your losses. Vendor management is a reason to carry cyber coverage with dependent-business-interruption extensions, not a substitute for it.
Automated targeting does not “bother.” It enumerates. The FBI's Internet Crime Report logged $16.6 billion in reported losses in one year across businesses of every size, and reported is the operative word.
Two free ones: run the exposure scan on your own website to see what an attacker's first pass sees, and send your current policies for a read that tells you, cited to the page, what they would actually do after an incident.
Ninety days before it, you get one market read for your industry, from me. Nothing else happens without you.
Sixty seconds of questions, or upload your current policies. ARIA shows what it finds, cited to the page, with no obligation attached.
In writing, within 48 hours, free. If the read shows your current program is right, I will tell you to stay put, in writing. You lose nothing either way.
Nothing binds until a licensed Risk Strategist signs the placement
ARIA · live across every page