Connect with us

Hi, what are you looking for?

Technology

Cyber Insurance Won’t Cover Your Business From an Iranian Attack. An 831(b) Micro-Captive Plan Can

Cyber Insurance Won’t Cover Your Business From an Iranian Attack. An 831(b) Micro-Captive Plan Can

Since the first wave of the U.S.-Israel strikes on Iran at the end of February, cyberattacks launched by Iranian-linked groups targeting the U.S. have escalated. And not even the biggest of the big guys are safe.

Take Stryker as an example. After being hit by a wiper attack tied to the Iran-aligned hacker group, the medical technologies behemoth lost about $6 billion in market value, saw shares plunge 9%, and had operations disrupted among 56,000 employees across 61 countries.

If a company of that size can be brought to its knees by a state-backed cyberattack, what happens when a small- and medium-sized business (SMB) is struck?

“Depending on the size of the company, you’re looking at roughly a 30–60% chance of going out of business within 6–12 months after a serious breach,” said Michael Scheumack, chief innovation officer at IdentityIQ. “Not because the business isn’t viable, but because they run out of cash while trying to clean up the aftermath and keep customers from walking out the door.”

In Q3 2025, small businesses had real quarterly revenue of $143,110 per business, on average, according to data from the Small Business Index. They would potentially need as much as twenty times that amount to recover from just one successful cyberattack.

“A small company could see up to $3 million in loss — lost revenue, reputational damage, the notices that have to be sent out to anybody that was impacted by the data breach and legal fees,” Scheumack said.

Why SMBs Are Vulnerable to State-Backed Cyberattacks

For a cybergang linked to Iran, China, Russia, North Korea or any other foreign adversary, bankrupting a small American business may be less dramatic than wiping out Stryker, but it’s still a worthwhile feat. SMBs are vital critical drivers of the U.S. economy, contributing about 44% of the total GDP. Plus, for a sophisticated cybergang SMBs are usually low-hanging fruit.

“SMBs are targeted because they sit in the middle of critical supply chains but lack the infrastructure maturity of larger enterprises,” said Joe Scheidler, CEO and co-founder at Helios, who has served in senior roles in the U.S. government including at the White House, the Office of the National Cyber Director and the U.S. Department of State. “They often have weaker controls, less dedicated security personnel and fragmented data systems, which means slower detection and response.”

Almost all (94%, according to the latest CrowdStrike State of SMB Cybersecurity Survey) of SMB leaders say they’re “somewhat” or “very” knowledgeable about cyber threats. With awareness that high, it’s no wonder cyber insurance is a multibillion-dollar industry growing astronomically year over year — projected to be valued at $223.47 billion by 2034 (it was at $26.25 billion in 2025), according to Fortune Business Insights.

In a hostile geopolitical climate where foreign state-linked cybercriminals are skulking in the shadows of cloud services and corporate databases, an SMB better have a cyber insurance policy, right? Well, actually, no; not if they want to be covered should Iran or any other foreign adversary-linked cybergroup succeed in attacking them.

Why Cyber Insurance May Exclude State-Backed Cyberattacks

Insurance providers began explicitly excluding acts of cyberwarfare following the 2017 NotPetya cyberattack. Linked to Russian military intelligence, the attack caused over $10 billion in global damage. The insurance claims of affected business’ claims were initially denied by insurers due to “act of war” exclusions. But companies like Merck & Co. fought back and won. Courts determined that cyber warfare is distinct from traditional warfare. That caused insurers to hemorrhage money and quickly tie up the loophole by expanding traditional war exclusions to include state-backed cyberattacks.

So now if your business suffers a cyberattack tracing to a foreign state and you suffer a loss as a result, your cyber insurance policy will most likely deny your claim and you’ll be out of luck and, potentially, out of business.

So what are an SMB’s options for comprehensive cyber insurance that will cover losses endured from a state-backed cyberattack? There is really only one: an 831(b) Micro-Captive Plan, which is effectively a self-insurance program that you can customize to meet your needs. If you want cyber insurance that covers you in the event of an attack, including one that could be considered an act of war by a state-backed actor, you can build that into the plan.

“Think of it like an HSA for the business when qualifying events happen like a data breach,” said Dustin Carlson, president of SRA 831(b) Admin, which provides 831(b) Plans to business owners who gross approximately $2 million or more annually.

831(b) Micro-Captive Plans, like HSAs, provide special tax exemption benefits.

“The insured is able to use a section of the tax code 831(b) to defer taxes on a portion of their revenue,” Carlson said. “It’s effectively a tax-deferred account.”

AI Cyberattacks Add Another Layer of Risk

It may sound hyperbolic to describe an 831(b) Plan as an absolute necessity for a SMB to ensure it survives a cyberattack, but that is, unfortunately, where we are at, and amid AI’s unstoppable evolutions, the risks only grow exponentially. In 2025 there was an 89% increase in cyberattacks by AI-enabled adversaries, according to Crowdstrike’s 2026 Global Threat Report, aptly titled “Year of the Adversary”.

“AI is causing technology advances to increase at an exponential rate right now, and it’s creating a new world in cybersecurity,” Scheumack said.

Part of that new world means new exclusions by cyber insurance providers. In February, the Insurance Services Office (ISO) Businesses introduced two new optional endorsements — CG 40 47 and CG 40 48 — that create generative AI insurance exclusions under commercial general liability (CGL) policies. These exclusions enable insurers to deny claims tied to cyberattacks that look to have been generated by AI.

So, if you’re assembling an 831(b) Micro-Captive Plan to protect your business from cyberattack-related loss, be sure to get coverage not only for losses linked to state-backed attacks or “acts of war”, but also to those that may be traced back to generative AI, as insurers can now exclude them. And try to do this all soon, because cyber risk, already severe, is rapidly reaching doomsday levels.

“[Cyberattacks] occur globally at around every 29 seconds right now,” said Chris Millington, the global solutions lead for data and cyber resilience at Hitachi Vantara. “In the next two to three years that will be down to every three to four seconds.”

 

 

 

 

 






Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like