The cyber insurance hard market made it clear that organizations need baseline controls to qualify for coverage, but those expectations continue to evolve as threats become more sophisticated and underwriting increasingly validates real-world risk beyond application responses.

Join CBIZ for a practical discussion on ransomware prevention, recovery planning, and risk transfer through the lifecycle of a cyber claim. Learn how ransomware and social engineering fraud events unfold, where attackers commonly focus, and how cyber insurance policies influence response decisions, vendor coordination, recovery efforts, and claims outcomes.

Attendees will gain insight into why tested backups, incident response plans, tabletop exercises, remote-access controls, and evidence-based underwriting preparation are critical for both prevention and recovery. The session will also explore how insurers use proprietary tools, scans, and claims data to assess risk, revealing why a strong application alone may not tell the full story.

Presenters

Tiffany Garcia, National Industry Leader, Government, CBIZ
Damian Cracciolo, Vice President, National Practice Leader, CBIZ 
Perry Tsao, Chief Claims Officer, Elpha Secure

Key Learning Objectives

  • Understand how a ransomware or social engineering fraud cyber claim may unfold from discovery through recovery and resolution.
  • Recognize where threat actors commonly focus, including remote access, exposed login pages, credential-based attacks, control weaknesses, and the human element.
  • Identify why tested backups, incident response plans, and tabletop exercises are critical for recovery, underwriting, and loss prevention.
  • Evaluate how carrier risk analysis can go beyond the cyber insurance application, including proprietary scans, control validation, and claim trend insights.
  • Explore how technical controls, business continuity planning, insurance coverage, and claims coordination work together during a cyber event.
  • Prepare for stronger underwriting conversations by aligning evidence of control maturity with real-world loss mitigation priorities.
  • Understand practical outcomes and decision points, including ransom payment considerations, data recovery limitations, and the importance of pre-event readiness.