Skip to content

Cyber Insurance News

The Leading Source for Cybersecurity Insurance News, Insights and Data

Mid-Size Bank Cybersecurity: Underinsured and Overexposed

Posted on November 13, 2024November 13, 2024 By Martin Hinton 3 Comments on Mid-Size Bank Cybersecurity: Underinsured and Overexposed

Cybersecurity is no longer an abstract threat; it’s an immediate and pervasive danger keeping the CEO of mid-sized River City Bank, Steve Fleming, up at night. Hackers relentlessly target both large institutions for big payoffs and small to mid-sized businesses as easy prey, making cyber resilience essential for any organization. With cyberattacks expected to cause $10.5 trillion in damages by 2025—a 300% increase from 2015—every sector faces devastating potential losses, underscoring the need for robust defenses and rapid response plans.

The Jones Walker 2024 Community and Mid-Size Banks Cybersecurity Survey reflects this widespread vulnerability, highlighting key gaps in cybersecurity practices across the banking sector. This report reveals that while community and mid-size banks are beginning to address these threats, inadequate preparedness, over-reliance on third-party vendors, and underutilization of cyber insurance are leaving them at risk for potentially devastating breaches.

“Banks are highly regulated, but many third-party vendors are not. It is critical that banks conduct thorough due diligence on their vendors and ensure robust contractual protections are in place.”

Rob Carothers, Jones Walker

The survey offers a detailed picture of the vulnerabilities facing small and mid-sized banks in the United States. The survey highlights critical gaps in cyber preparedness, particularly concerning third-party vendor risks, cyber insurance, and the adoption of emerging technologies.

Our survey analysis follows; you can find the whole report here.

Inadequate Preparedness and Prevention Efforts

One of the report’s main findings is that, despite high regulatory standards, small and mid-sized banks often prioritize compliance over proactive prevention. Although 61% of respondents felt somewhat prepared for cyber threats, only 42% felt highly prepared. Furthermore, just over a third of banks use encryption for sensitive data, a fundamental cybersecurity measure. The survey highlights the importance of implementing and regularly testing incident response plans (IRPs). Still, it notes that less than two-thirds of banks have specific response teams with clear roles, leaving significant room for improvement in cybersecurity readiness.

 A dark, black-and-white pencil drawing depicts a small bank interior with a sense of eerie tension. Bank tellers stand behind counters, while customers in the lobby show signs of fear, looking on in alarm. A swirling digital storm of binary code and jagged, lightning-like patterns fills the air, blending into the physical space of the bank. Sharp circuitry lines and fragmented digital shapes, resembling shattered glass, seem to consume the scene, casting deep shadows and creating a haunting, dystopian atmosphere. The ominous storm appears to creep into every corner, transforming the once-ordinary bank into a surreal, threatening environment.
Underutilization of Outside Counsel and Cyber Insurance

The survey indicates a troubling trend: only 57% of banks engage cybersecurity attorneys, leaving gaps in their legal protection and preparedness. Banks also underutilize cyber insurance, with less than half having policies reviewed for adequate coverage. With insurance companies becoming more sophisticated in matching policies to potential cyber risks, this gap represents a missed opportunity for many banks to mitigate the financial impacts of a cyberattack. As cyber threats become more complex, expert legal and advisory support can be instrumental in helping banks navigate breaches and minimize reputational damage.

Third-Party Vendor Risks

Another pressing issue is the widespread reliance on third-party vendors, with 99% of banks surveyed outsourcing some or all of their cybersecurity needs. These vendors often handle critical data, yet only 71% of banks enforce contracts that hold vendors accountable for security failures. Even fewer, a mere 23%, require vendors to indemnify the bank in the event of a data breach. Banks remain vulnerable to breaches that originate with these external providers without rigorous oversight and robust contractual protections, making third-party vendor management an area that demands more focus.

Hesitancy Toward Emerging Technology

Community and mid-sized banks are cautious about implementing new technologies, including artificial intelligence (AI), despite the potential cybersecurity benefits. Larger banks have embraced AI, using it to enhance fraud detection and improve resilience against cyber threats, while smaller banks lag. This disparity increases smaller institutions’ risk exposure as attackers shift focus to more vulnerable targets. When deployed responsibly, AI tools can help level the playing field by automating security processes, enabling faster threat detection, and reducing the burden on limited in-house resources.

Emphasis on Cyber Resilience Over Static Security

The report advocates for a shift from traditional security postures to a cyber resilience framework. This approach focuses on continuous improvement and adaptation to new threats rather than striving for a static level of cybersecurity. Building resilience involves anticipating future risks, strengthening incident response strategies, and promoting a culture of security awareness across all levels of an organization. This proactive mindset is particularly vital for smaller banks, which must work harder to maintain trust in an era of rising cybercrime and increasingly complex regulatory environments.

 “As security threats are constantly evolving, focusing on a culture of cyber resilience….will help to minimize the disruption and negative impacts caused by any future cyber event.”

Lara Sevener, Jones Walker
Recommendations and Best Practices

Jones Walker’s report concludes with recommendations for community and mid-sized banks to protect their assets and customer data better. These include:

Enhancing Prevention and Preparedness: Shift focus from reactive compliance to proactive measures, such as regular cybersecurity training, updated encryption protocols, and thorough incident response testing.

Increasing Third-Party Vendor Oversight: Banks should enforce stronger contractual obligations, conduct due diligence, and ensure vendors have solid cybersecurity policies.

Engaging Experienced Cybersecurity Counsel: Utilizing outside advisors can help banks refine their cybersecurity strategies and navigate complex regulations, which can ultimately reduce their exposure to legal risks.

Adopting Emerging Technologies: By cautiously implementing AI and other advanced tools, banks can strengthen their cybersecurity defenses and stay competitive.

Image of Jones Walker logo

The report serves as both a cautionary tale and a call to action, urging community and mid-sized banks to bolster their cybersecurity frameworks. While many have made strides, significant work remains to ensure they can withstand the evolving landscape of cyber threats.

This survey focused on community and mid-size banks across the United States, each with assets under $50 billion. In July 2024, the survey gathered responses from 125 banking executives with cybersecurity responsibilities within their institutions.

Other News: The Nightmare of a Ransomware Attack, Community Bank Version (Opens in a new browser tab)

Other News: City of Sheboygan hit by apparent ransomware attack.

Martin Hinton

Martin Hinton is the Executive Editor and Publisher of Cyber Insurance News and Information. With over three decades of journalism experience across six continents, his work encompasses investigative reporting, documentaries, and coverage of cultural, political, and business news. To learn more about his career, click on his name to visit his LinkedIn page.

Cyber Insurance, Cyber Insurance Financial Institutions Tags:Bank Cybersecurity, cyber insurance, cyber liability insurance, Cybersecurity, Mid-Size Bank Cybersecurity, Ransomware

Post navigation

Previous Post: Email Security Insights: Key Trends and Solutions – Report
Next Post: Mulberri and Qualys Team Up to Offer Cyber Insurance Discounts to SMEs

Related Posts

  • AWS Takes Next Step in its Cyber Insurance Program with Leading Cyber Brokers & Carriers Cyber Insurance
  • Can Microsoft Exchange Server Be A “Pre-Existing Condition” For Cyber Insurers?   Cyber Insurance
  • 2025 Center for Internet Security, MS-ISAC Report Examines Concerning K-12 Cybersecurity Threats Cyber Insurance
  • The Price of Complacency: Only 2% of Companies Fully Implement Cyber Resilience – PWC Survey Cyber Insurance
  • Feds Have Failed to Take Basic Step in Analyzing USG Role in Catastrophic Cyber Events: GAO  Cyber Insurance
  • Tokio Marine Pushes Personal Cyber Insurance Cyber Insurance

Comments (3) on “Mid-Size Bank Cybersecurity: Underinsured and Overexposed”

  1. Ralph Pasquariello says:
    November 18, 2024 at 8:30 pm

    Martin, Excellent article with great content. Spot on, especially with medium and small banks. There is no excuse for neglect with all the available information available today.

  2. Craig Sekowski says:
    November 18, 2024 at 8:39 pm

    Great article, and it is on point! Our team has performed many CyberInsurance Audits and found that many banks, especially Independent Banks, are underresourced when addressing their CyberInsurance preparedness.

  3. Ralph Pasquariello says:
    November 18, 2024 at 8:40 pm

    Martin, Excellent article with great content. Spot on, especially with medium and small banks. There is no excuse for neglect with all the available information available today. We have had many small businesses come to us in the past 6 months

Comments are closed.

Get the Cyber Insurance Newsletter

Receive weekly updates on the top news on cyber insurance.

Cyber Insurance News

Cyber Insurance News
In this clip from our latest podcast episode, Dan Candee, CEO of Cork Protection, dives into a critical topic that hits close to home: Cybersecurity for Main Street businesses.

🛡️ With a background in enterprise-level cybersecurity on Wall Street and a personal connection to small business through his family, Dan shares why Cork focuses on protecting small and mid-sized businesses from rising cyber threats.

🚨 "The threat actors are getting better, and they're coming after Main Street more and more."

👉 Discover why Main Street is being underserved in today's digital threat landscape and how Cork is filling that gap with a unique value proposition.

🔗 Learn more about Cork: corkinc.com
🎧 Full Podcast Episode: www.youtube.com/@CyberInsuranceNews/podcasts

📣 Don't forget to LIKE, SUBSCRIBE, and hit the 🔔 notification bell so you never miss a powerful conversation.

#Cybersecurity #SmallBusiness #MainStreet #DanCandee #CorkProtection #TechForGood #SMBs #PodcastClip #CyberThreats #BusinessSecurity
Cybersecurity for Main Street: Dan Candee on Protecting Small Businesses | CEO of Cork Protection
SMB Cyber Threats - In this episode of the Cyber Insurance News Podcast, host Martin Hinton talks with Dan Candee, CEO of Cork Protection, about the rising tide of cyber threats targeting small and mid-sized businesses (SMBs). Dan shares his journey from Main Street entrepreneur to cybersecurity leader, offering real-world insight into the threat landscape, financial vulnerabilities, and how AI and managed service providers (MSPs) can help fortify business resilience.

We explore:
• Why Main Street is more vulnerable than Wall Street
• Common SMB cybersecurity blind spots (like ACH fraud)
• The evolving role of managed service providers
• How Cork Protection blends cybersecurity and cyber insurance
• Real-world attack case studies and practical advice for SMBs

Whether you’re a small business owner, MSP, or cyber pro, this episode unpacks how to prepare, prevent, and protect your organization in today’s digital world.

📌 Topics: cybersecurity, cyber insurance, social engineering, SMB protection, ransomware, AI in security, MSPs

🎙 Guest: Dan Candee, CEO of Cork Protection
📢 Host: Martin Hinton, Executive Editor, Cyber Insurance News

👉 Don’t forget to like, comment, and subscribe for more insights on cyber insurance and digital defense!

#CyberSecurity #CyberInsurance #SMB #AI #CyberPodcast #BusinessResilience #smallbusiness #sme
00:00 Introduction - Dan Candee and Cork Protection
02:27 The Importance of Cybersecurity for Small Businesses
05:29 Understanding Cyber Threats and Their Impact
08:26 The Role of Managed Service Providers in Cybersecurity
11:24 24Financial Protection and Cyber Insurance Solutions
14:01 Leveraging AI in Cybersecurity
16:53 Navigating Cyber Insurance Policies
19:56 Empowering Small Businesses with Knowledge
21:52 The Future of Cybersecurity and Community Resilience
26:05 MSP/ MSSP The Lingo decoded
29:05 Finals Thoughts and a bit of Hope!
SMBs Are Cyber Targets | Dan Candee on Cyber Resilience & AI | Cyber Insurance News Podcast EP#6
Cyberattack on Small Business is on the rise—and AI is making it worse. In this episode of the Cyber Insurance News Podcast, host Martin Hinton sits down with William Altman of CyberCube to unpack how AI is enabling threat actors to more efficiently target and exploit small businesses.

🔐 From credential stuffing to brute force attacks, William explains how cybercriminals use AI to bypass login portals and MFA solutions—putting millions of small business owners at risk.

🎙️ Timestamps:
0:00 - Introduction
6:26 - William Altman on AI and threat actors
6:50 - Credential stuffing, brute force & reused credentials
10:00 - What small businesses can do right now
14:20 - The future of AI in cybercrime

🎧 Don’t miss this crucial update on the cybersecurity landscape for small businesses. Subscribe and stay informed.

#cyberattack #smallbusiness #AI #cybersecurity #CyberCube
Cyberattack on Small Business: How AI Supercharges Cyber Threats | William Altman @CyberCube"
Load More... Subscribe

Categories

  • 8-K
  • AI & Cyber Insurance
  • AI & Cybersecurity
  • Critical Infrastructure cyber insurance and security
  • Cyber Cat Bonds/Cyber Catastrophe Bonds
  • Cyber Insurance
  • Cyber Insurance APAC
  • Cyber Insurance Best Practices
  • Cyber Insurance Captive
  • Cyber Insurance Carriers & Brokers
  • Cyber Insurance Claims
  • Cyber Insurance EU
  • Cyber Insurance Financial Institutions
  • Cyber Insurance for Government
  • Cyber Insurance for Healthcare
  • Cyber Insurance for Schools
  • Cyber Insurance for SMEs/SMBs
  • Cyber Insurance For Startups
  • Cyber Insurance for Utilities
  • Cyber Insurance Geographic Markets
  • Cyber Insurance Industry Groups
  • Cyber Insurance Investments and M&A
  • Cyber Insurance Jobs
  • Cyber Insurance Laws & Regulations
  • Cyber Insurance Litigation
  • Cyber Insurance Market Size
  • Cyber Insurance MENA
  • Cyber Insurance News & Information Podcst
  • Cyber Insurance People
  • Cyber Insurance Policies & Strategies
  • Cyber Insurance Premiums
  • Cyber Insurance Reports
  • Cyber Insurance Settlements
  • Cyber Insurance Sunday – Upload
  • Cyber Insurance Systemic Risks
  • Cyber Insurance Tech
  • Cyber Insurance Threats
  • Cyber Insurance UK
  • Cyber Insurance Underwriting
  • Cyber Insurance Wholesaler
  • Cyber Regulations
  • Cyber War Exclusions
  • Cybersecurity
  • Cybersecurity and Credit Ratings
  • Cybersecurity for SMBs
  • Cybersecurity in Education
  • Cybersecurity Investment
  • cybersecurity jobs
  • cybersecurity M&A
  • Cybersecurity people
  • Cybersecurity Report
  • Cybersecurity Training
  • Department of Homeland Security
  • EU Cybersecurity
  • Insurance Linked Securities/ILS
  • Insurance Loss Warranty contract/ILW
  • Managed Service Providers
  • National Association of Insurance Commissioners' (NAIC) model cybersecurity law
  • Non-criminal Claims/Non-Malicious Claims
  • Opinion/Commentary
  • Personal Cyber Insurance
  • Personal CyberSecurity
  • Ransomware Insurance
  • Reinsurance
  • Risk Modeling
  • SEC Cyber Disclosure Rule
  • Small Business
  • Supply Chain Cybersecurity And Insurance

Send Ideas, Requests & Comments




    Tags

    AI AI in Cybersecurity Artificial Intelligence At-Bay Beazley CFC Chubb Cloud Security Coalition Corvus Cowbell Cowbell Cyber crowdstrike cyber attack Cybercrime CyberCube cyber insurace cyber insurance cyberinsurance cyber insurance for small businesses Cyber Insurance Market Cyber liability Insruance cyber liability insurance cyberliabilityinsurance Cyber Resilience Cyber Risk Cyber Risk Management cyber security Cybersecurity cybersecurity insurance Cyber threats Data Breach Data Breaches Howden Lloyds Marsh Microsoft personal cyber insurance phishing Ransomware Ransomware Insurance Resilience Risk Management SecurityScorecard small business
    • Cyber Insurance Books
    • Cyber Insurance Reports & Documents
    • Cyber Insurance Acronyms/Terms
    • Cyber Insurance Companies: Carriers, Brokers & Vendors
    • Industry Response: Potential Federal Insurance Response to Catastrophic Cyber Incidents
    • Ransomware Insurance
    • How Much Is Cyber Insurance?
    • Considerations for Buying Cyber Insurance
    • Cyber Liability Insurance Near Me
    • Cyber Insurance Quote
    • Newsletter
    • Legal Analysis & Full Text of 2023 SEC Rule: Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure
    • Glossary
    • About Cyber Insurance News
    • Privacy Policy

    • Ransomware Crisis Worsens in 2023: Calls for Urgent Action to Ban Payments – Report Ransomware Insurance
    • SMBs Get Easier Access to Cyber Insurance with SaaS Alerts and FifthWall Solutions Cyber Insurance
    • Scammers Eye $85 Trillion: Are Cybersecurity and Cyber Insurance Critical for Seniors? Cyber Insurance
    • What Do Cyber Insurance and Exploding Steam Boilers during the 1800s Have in Common?  Cyber Insurance Best Practices
    • BlackCloak Secures $17M in Funding to Bolster Personal Cybersecurity Personal Cyber Insurance
    • Blackpanda Secures US$6.7 Million Investment to Enhance Cyber Emergency Response Services in Asia Cybersecurity Investment
    • Cytora and DynaRisk Partner to Empower Insurers with Advanced Cyber Risk Assessment Tools Risk Modeling
    • Indian PM Cybercrime Collaboration Needed Cyber Insurance for Government

    Related Cybersecurity Sites

    http://www.whatiscyberliability.com

    https://www.whatiscyberinsurance.com

    http://www.ddosattacktutorial.com

    http://www.ransomwareremovaltool.com

    Our Privacy Policy: https://cyberinsurancenews.org/privacy-policy/

    Copyright © 2024 Cyber Insurance News.

    Powered by PressBook Premium theme