The 2026 Cyber Resilience Field Guide
A practical cyber resilience guide for businesses, insurance agencies and MSPs covering cybersecurity, cyber insurance, AI risk and incident response.
THOUGHT LEADERSHIP
10/1/20267 min read
Cybersecurity Awareness Month began in 2004 as a public-private effort led by the U.S. government and the National Cybersecurity Alliance. The idea was refreshingly practical: give people useful information that could make the internet safer.
Facebook was eight months old. Gmail was six months old. The iPhone did not exist.
Twenty-two years later, the campaign still arrives every October. The National Cybersecurity Alliance's 2026 theme may be its best yet: Don't Make It Easy for Them.
The official advice remains beautifully simple. Use strong passwords and a password manager. Turn on multifactor authentication. Recognize and report scams. Update your software.
Do those things. Then look a little wider.
A modern business runs through email, cloud software, vendors, bank accounts, mobile devices, artificial intelligence and outside technology providers. The insurance policy written to protect that business depends increasingly on how those systems are secured.
The result is a broader cyber conversation.
Cybersecurity helps reduce the likelihood and severity of an incident. Cyber insurance transfers part of the financial risk that remains. Contracts establish responsibility. Incident response planning determines what happens when preparation becomes action.
As Andy Runyan, UKON's Head of Cybersecurity Risk Services, puts it: “This is a risk mitigation conversation first, risk transference conversation second. The two work together.”
Cybersecurity Awareness Month 2026
The latest research makes the direction unusually clear.
31% of breaches now begin with exploitation of a software vulnerability. According to Verizon's 2026 Data Breach Investigations Report, vulnerability exploitation surpassed stolen credentials as the leading breach entry point for the first time in the DBIR's 19-year history.
48% of breaches now involve a third party. Verizon reports that third-party involvement increased 60% from the prior year as businesses became more dependent on outside vendors and interconnected supply chains.
45% of employees frequently use unapproved AI tools at work, up from 15% a year earlier, according to Verizon. AI has entered the workplace faster than many companies have established rules for using it.
58% of Coalition's 2026 cyber insurance claims involved business email compromise or funds-transfer fraud. Some of the most consequential cyber losses still begin with an ordinary message and a believable request.
$4.99 million is the global average cost of a data breach in IBM's 2026 Cost of a Data Breach Report. IBM also found AI-driven attacks increased 56% from the prior year.
The lesson is remarkably old-fashioned: Know what you have. Know who has access. Know what protects you. Know what your insurance covers. Know whom to call.
TL;DR: What We Know in 2026
Five Conversations Worth Having
1. What protects us today?
Start with the technology.
Does the business use multifactor authentication? Are computers and servers monitored? Are backups tested? Is software patched? Who has administrator access? Which vendors can reach important systems?
These are security questions. They are increasingly insurance questions, too.
The National Cybersecurity Alliance's guidance for Cybersecurity Awareness Month starts with four fundamentals anyone can understand: strong passwords, multifactor authentication, scam awareness and software updates.
Your MSP or technology provider should be able to help you understand the security environment. Your insurance professional should understand how material controls relate to underwriting and coverage.
For a business owner, the practical question is simple: Could we explain our current security environment accurately today?
2. What changed this year?
Businesses rarely stand still. A company adds software. Hires employees. Changes payroll providers. Moves data into the cloud. Opens another location. Gives a vendor access. Starts using AI.
Each change can alter the company's cyber risk.
AI deserves particular attention in 2026. Verizon found frequent use of unapproved AI tools increased from 15% to 45% of employees. IBM found AI-driven attacks increased 56%, with AI-enabled breaches costing more than the global breach average.
The insurance market is changing with the technology. Businesses are beginning to deploy AI agents capable of communicating, retrieving information, making decisions and taking actions across connected systems. Emerging insurance solutions are beginning to address exposures associated with agentic AI as well.
That leaves a useful question: Does our insurance understand the technology we are actually using?
Your technology provider should know what has changed. Your insurance professional should know when those changes materially affect the risk being insured.
3. What happens if someone gets in?
Every business should have an incident response plan.
It should identify who makes decisions, whom employees contact, how systems are contained, how the MSP or technology provider becomes involved, when legal and insurance resources are contacted and how the business continues operating.
Your MSP can help build and test the technical portion of that plan.
Your cyber carrier may also care that one exists. Some insurers now ask specifically about incident response planning during underwriting, and requirements vary by carrier and policy.
The reason is practical.
Coalition's 2026 Cyber Claims Report, based on claims across more than 100,000 policyholders, found that initial ransomware demands increased 47% in 2025 and averaged more than $1 million.
There is another number worth remembering.
86% of affected Coalition policyholders refused to pay.
Preparation creates options.
Coalition also recovered $21.8 million in stolen funds for policyholders in 2025 and found that faster reporting increased the likelihood of recovering stolen money.
Runyan, who spent years coaching before entering cybersecurity risk, uses a simpler analogy: “If I were playing the best team in the league for the championship, would I practice? Draw up a playbook? It's the same for cybersecurity risk. People who've suffered a ransomware event or BEC describe it as the worst day in the history of their business. Why wouldn't I practice and prepare for that?”
A useful question for any leadership team is: If we discovered a cyber incident at 9:17 tomorrow morning, would everyone know what happens next?
If the answer is uncertain, ask your MSP about an incident response plan. Then make sure the plan includes the insurance, legal and response resources that may become important during an actual claim.
4. Have we actually read the insurance?
A cyber policy is part of the company's financial resilience. Depending on the policy and circumstances, cyber insurance can help fund forensic investigation, legal counsel, incident response, data restoration, business interruption, cyber extortion, privacy liability and other costs following an incident.
The details matter. Limits matter. Sublimits matter. Exclusions matter. The accuracy of the application matters.
The business underneath the policy changes constantly. Software changes. Revenue changes. Security controls change. Vendors change. AI enters workflows.
That makes the months before renewal valuable.
Ask: What does our policy cover? What has changed since we bought it? Does the application still describe our business accurately?
Those are considerably easier questions to answer before a claim.
5. Do the people protecting us know one another?
This may be the simplest question in the guide.
For many small and midsize businesses, two outside advisers already see different parts of the same risk. The MSP understands the technology. It sees systems, access, controls, backups and much of the day-to-day security environment. The insurance professional understands the policy. They see coverage, limits, underwriting requirements, renewal timing and the financial risks being transferred.
In practice, those conversations often happen separately.
Runyan describes a pattern UKON sees regularly: “The CFO is having a risk-transference conversation with the agent. The CIO is having a risk-mitigation conversation with the MSP. People aren't at the table together, and they need to be.”
That separation matters more as insurers ask increasingly technical questions and MSPs assume broader responsibility for cybersecurity.
Sophos' 2026 research found that MSPs estimate 46% of their customers already look to them for CISO-level cybersecurity leadership, while 84% expect demand for those services to increase over the next 12 months.
UKON President and COO Reid Wellock sees cyber insurance becoming part of that broader responsibility: “Cyber insurance is no longer a side conversation for MSPs. It is a critical part of risk management and client confidence.”
A business benefits when these advisers compare notes before renewal and before a claim.
Ask one question: Has our insurance professional ever spoken directly with our MSP?
If the answer is no, October is a fine time to introduce them.
The Five-Minute Review
You do not need another 40-page cybersecurity plan to begin.
Take five minutes. Write down five answers.
Who manages our cybersecurity?
What materially changed in our technology or business this year?
When did we last test our ability to recover from an incident?
When does our cyber insurance renew, and when did we last review it?
Have our technology and insurance advisers ever spoken to one another?
An uncertain answer is useful. It tells you where to start.
Know Before You Need To
Cybersecurity Awareness Month began because people needed a clearer way to understand a changing digital world.
They still do.
The technology is considerably more sophisticated now. So are the threats. Artificial intelligence has accelerated both sides. Vulnerabilities can be discovered and exploited faster. Vendors connect more deeply into the businesses they serve. Insurance underwriting increasingly reflects the security environment underneath the policy.
The fundamentals remain reassuringly practical.
Use MFA. Update software. Protect access. Test backups. Know your vendors. Understand how AI is being used. Read the cyber policy. Keep the application accurate.
Then introduce the people responsible for the technology to the people responsible for the insurance.
A business does not need to predict the next cyberattack. It should know what happens if one arrives.
Know before you need to.
THE CYBER INSURANCE PARTNER
Protect, retain, and grow with Cyber Peace of Mind.
Powering cyber practices for agencies and MSPs


Frequently asked questions
What is cyber resilience?
Cyber resilience is a business's ability to prepare for a cyber incident, respond effectively and continue or restore critical operations. It brings cybersecurity, incident response, insurance and business continuity into the same risk conversation.
What should a business review during Cybersecurity Awareness Month?
Start with the four practices recommended by the National Cybersecurity Alliance: strong passwords, multifactor authentication, scam awareness and software updates. Then review system access, vendors, backups, AI use, incident response and cyber insurance. Confirm that the company's technology environment and insurance information still agree.
What does cyber insurance cover?
Coverage varies by policy. Cyber insurance can include costs associated with forensic investigation, incident response, legal counsel, business interruption, data restoration, cyber extortion, privacy liability and certain forms of cybercrime. A licensed insurance professional should review the specific policy.
Why should an insurance professional speak with a client's MSP?
The MSP can provide current information about the client's technology and cybersecurity controls. The insurance professional understands the underwriting and coverage implications of that information. Direct communication can improve the accuracy of insurance applications and identify material changes before renewal.
Why should an MSP understand a client's cyber insurance?
Cyber insurance applications increasingly ask detailed questions about controls the MSP may manage. Understanding those requirements can help the MSP provide accurate technical information while keeping insurance advice with the client's licensed insurance professional.
What should a business ask about artificial intelligence and cyber insurance?
Identify which AI systems employees or automated agents use, what information those systems can access and what actions they can take. Material AI use should be discussed with both the technology provider and insurance professional so security controls and coverage can be evaluated against the actual environment.
Resources
National Cybersecurity Alliance: Cybersecurity Awareness Month 2026
Verizon: 2026 Data Breach Investigations Report
Coalition: 2026 Cyber Claims Report
IBM: 2026 Cost of a Data Breach Report
Sophos: 2026 MSP Perspectives Report
This guide is provided for educational purposes and does not constitute legal, cybersecurity or insurance advice. Coverage varies by policy, insurer and individual circumstances. Businesses should consult qualified technology, legal and licensed insurance professionals regarding their specific needs.
Pittsburgh, PA · Denver, CO · Bogotá, Colombia · info@ukon.com
© UKON 2026. All rights reserved. Privacy Policy & Cookie Policy


