Cybersecurity is no longer just about installing the right tools and hoping they keep attackers out.
Today’s businesses rely on cloud platforms, software vendors, managed service providers (MSPs), employees, insurance carriers, and countless other pieces of an increasingly connected technology ecosystem. That creates tremendous opportunity—but it also creates risk that can become complicated very quickly when something goes wrong.
On this episode of the Cyber Brisket Podcast, Engler IT President Chris Engler sits down with Justin Reinmuth, President of TechRUG, the Technology Risk Underwriting Group, to discuss the changing risk landscape for MSPs and the businesses they support.
Their conversation explores everything from AI and software development to cyber liability insurance, supply chain attacks, incident response planning, financial fraud, and an important question every organization should be asking:
When a cyber incident happens, who is actually responsible?
AI Is Changing More Than Technology—It Is Changing Liability
Artificial intelligence is allowing businesses and IT providers to accomplish things that would have required specialized development teams only a few years ago.
That convenience can create an unexpected problem.
An MSP that traditionally manages networks, computers, security, and cloud services may suddenly begin using AI tools to create custom applications or software for clients. While that may feel like a natural extension of technology services, from an insurance perspective, it can represent an entirely different category of work.
Justin’s advice is simple: notify your insurance provider when your services change.
An insurance policy was created based on representations about the type of work a company performs. If an IT provider begins offering software development but its professional liability or errors and omissions policy does not clearly cover that activity, the provider could discover a significant coverage gap after a claim occurs.
The larger lesson applies beyond MSPs.
AI makes it incredibly easy to expand what your organization can do. But before adding a new AI-powered service, businesses should also consider the legal, security, contractual, and insurance risks that come with it.
Innovation should move quickly—but risk management needs to move with it.
The Supply Chain Has Become Part of Your Cybersecurity Strategy
Businesses rarely operate entirely within systems they control.
Microsoft, Google, cloud platforms, software vendors, payment providers, cybersecurity companies, and dozens of other technology partners may play a role in day-to-day operations.
That creates supply chain risk.
Even if your own organization follows strong cybersecurity practices, a vulnerability or breach involving an outside provider can potentially affect you.
The important question becomes: Who accepts that risk?
Chris and Justin discuss the importance of understanding vendor agreements, limitations of liability, indemnification language, and end-user agreements.
Businesses often click “accept” on terms and conditions without considering what those agreements mean if a major outage or security incident occurs.
For MSPs, transparency is especially important. Clients need to understand where the MSP’s responsibility ends and where the responsibility of Microsoft, Google, another vendor—or the client itself—begins.
Cybersecurity cannot eliminate every possible incident.
A physical security company can install cameras, alarms, card readers, and locks, but it cannot guarantee nobody will ever break into a building. Cybersecurity works similarly.
The goal is to dramatically reduce risk while preparing for what happens if defenses are eventually tested.
Cyber Insurance and Cybersecurity Need to Work Together
One of the strongest messages from the episode is that businesses should not think of cybersecurity and cyber insurance as competing solutions.
They complement each other.
Security controls are designed to reduce the likelihood and impact of an incident. Cyber liability insurance can provide another layer of financial and operational protection when an incident still occurs.
Justin describes risk management as requiring both sides of that equation.
A company can invest heavily in security and still face a zero-day vulnerability, vendor compromise, employee mistake, or sophisticated attack.
Likewise, simply purchasing cyber insurance without implementing appropriate cybersecurity controls is not a strategy.
Businesses need both prevention and preparation.
Having an Incident Response Plan Is Not Enough
- What happens during the first few hours of a cyberattack?
- What happens during the first few hours of a cyberattack?
- Who contacts the insurance carrier?
- Who makes decisions about shutting down systems?
- Who communicates with employees or customers?
- What does the MSP handle?
- What does the company’s cyber insurance provider handle?
If those questions are being answered for the first time during an attack, the organization is already at a disadvantage. Chris and Justin compare incident response planning to the fire drills schools conduct every year. Schools do not wait until the building is burning to decide where everyone should go. Businesses should approach cybersecurity the same way.
Creating an incident response plan is only the first step. The organization also needs to test it.
A plan sitting untouched in a folder provides limited value. Running an annual tabletop exercise or simulated incident helps leadership understand where confusion, communication gaps, and unclear responsibilities exist before a real emergency occurs.
Cyber Insurance Reporting Requirements Matter
Another potential problem discussed during the episode involves reporting security incidents to cyber insurance carriers. A business may notice unusual activity, contact its IT company, resolve the immediate problem, and move on. But the insurance policy may require certain incidents or circumstances to be reported within a specific timeframe. That becomes especially important because attackers do not always reveal themselves immediately. They may gain access, remain inside an environment, observe communication patterns, and wait before taking further action. An event that initially seemed insignificant could later become connected to a larger loss. Businesses should understand the notification requirements within their own cyber insurance policies and work with professionals who specialize in cyber coverage rather than assuming every insurance policy operates the same way.
Subrogation Could Create New Risks for MSPs
Another major topic is subrogation. The concept sounds complicated, but the basic idea is straightforward.
Suppose a company suffers a cyberattack and its insurance carrier pays the claim. If the carrier later determines that another party—such as an MSP or technology vendor—caused or contributed to that loss, the insurer may attempt to recover some of the money it paid from that party.
That makes contracts, clearly defined responsibilities, documentation, and appropriate insurance coverage increasingly important. As more businesses purchase cyber insurance, Justin expects these types of disputes to become an increasingly important consideration for technology providers.
A $500,000 Lesson in Verification
One of the most powerful examples in the conversation involved a business that transferred approximately $500,000 after attackers compromised one of its vendors.
The attackers reportedly spent significant time observing communications and learning how payments were handled. They then used convincing information and fraudulent payment instructions to redirect money.
Technology alone cannot solve every version of this attack.
A simple process can make an enormous difference:
Verify significant financial requests using a second, trusted communication method.
If payment instructions arrive through email, do not verify them by calling the number included in that same suspicious email.
Use a phone number already stored in your contacts, an independently verified number, or another established communication channel.
With AI making phishing messages, impersonation, and potentially even voice or video deception more convincing, these verification procedures are becoming even more valuable.
Cybersecurity Standards May Be Inconvenient—But There Is a Reason for Them
Multi-factor authentication. Security awareness training. Software updates. Endpoint protection.
Employees do not always love them.
But cybersecurity controls exist because experience has repeatedly demonstrated what can happen when organizations operate without them.
The small inconvenience of approving an MFA request or installing an update is nothing compared with days or weeks of business disruption following a serious attack.
Organizations should resist the temptation to create security exceptions simply because someone finds a particular control inconvenient.
Attackers are actively looking for exactly those weaknesses.
What Comes Next?
Looking several years into the future, Justin predicts that increasing concerns about centralized systems and supply chain attacks could eventually push some organizations toward more decentralized technology.
Cloud computing has created incredible efficiency, but concentrating thousands of organizations onto common platforms can also magnify the impact when those platforms experience major problems.
That does not necessarily mean businesses should abandon the cloud.
Instead, the conversation raises an important strategic question:
Have we become so dependent on a small number of interconnected systems that resilience now needs to become as important as convenience?
The answer will likely continue evolving as AI, cloud technology, cybersecurity, and insurance change together.
Key Takeaways
- Cyber liability insurance and cybersecurity should work together. Neither should be treated as a complete solution by itself.
- Tell your insurance provider when your services change. AI is allowing companies to enter new areas of business that may not be covered under existing policies.
- Understand your supply chain. Your cybersecurity risk includes the vendors and platforms your organization depends on.
- Know where responsibility begins and ends. Contracts, insurance coverage, and vendor agreements matter when incidents occur.
- Build and test an incident response plan. Do not wait for a real attack to determine who does what.
- Understand insurance reporting requirements. Seemingly minor security events may need to be reported.
- Verify financial requests independently. Never rely exclusively on the same communication channel through which a payment change was requested.
- Do not weaken security for convenience. MFA, updates, employee training, and other safeguards exist because the consequences of avoiding them can be far greater.
- Resilience matters. As businesses become more interconnected, reducing dependence on any single point of failure will continue to be an important conversation.
Cybersecurity is ultimately about managing risk—not pretending risk can be completely eliminated.
The businesses best positioned for what comes next will combine strong technology, clearly defined responsibilities, proper insurance, tested response plans, and employees who understand their role in protecting the organization.
