Print PDF version
Business Protection Bulletin
Construction Insurance Bulletin
Cyber Security Awareness
Employee Matters Bulletin
Employment Resources Bulletin
Life and Health Bulletin
Personal Protection Bulletin
Risk Management Bulletin
Workplace Safety Bulletin
Please contact me about a quick, no-obligation insurance review.
!
!
!
! !
!
!

Captcha AntiSpam Security

Visual verification
!
Please type in the code shown in the image.
CAPTCHAs are used to prevent automated software from performing actions which degrade the quality of service of a given system, whether due to abuse or resource expenditure.
Submit

Easy Ways To Participate In The Stop.Think.Connect.™ Campaign

Your business faces significant cybersecurity threats each day. October is National Cybersecurity Awareness Month, and the Stop.Think.Connect.™ Campaign helps your team and business address cyber threats and remain safe. Consider these easy ways you and your staff can participate in this awareness month and protect your business.

For related insurance topics, see Chapter 11 Restructuring Insurance.

Toss Anything Suspicious

Evaluate every email attachment and all the links in your email, instant messages and online posts. If the attachments or links look suspicious, delete them immediately. Cybercriminals can insert damaging information into attachments and links and then gain access to your system. For security, evaluate and then toss suspicious content.

Strengthen Passwords

Passwords for every account should be long, strong and complex. The best passwords include a combination of letters, numbers and symbols. Give every account a different password that you change often, too, and never share or write down usernames or passwords.

Improve Authentication

Add a second layer of security to your password with strong authentication. It’s a one-time code that’s designed to verify that you actually own the accounts you want to access. Multi-factor authentication is available on most email, financial and social media accounts and improves security.

Clean Machines

All computers and mobile devices should be cleaned regularly to remove potentially harmful information. In addition to removing cookies and cleaning the history and cache, update security software, the operating system and the web browser on devices that connect to the internet.

Make Backup a Priority

Backing up all your data both electronically and physically should become a habit that happens frequently throughout the day. This habit prevents costly data loss that can occur because of cyber theft, malware, viruses, computer malfunctions, or human error.

Guard your Devices

Train your staff to protect their devices from theft or unauthorized access. Computers, mobile phones and tablets should never be left unattended even for a minute. Also, lock devices when they’re not in use. If you run events or camps, review Soccer - Camp Insurance for relevant coverage considerations.

Report Suspicious Activity

Sometimes, you may experience a problem with your computer, question if a link is safe or receive phishing requests. Instead of blaming the problem on technology gremlins or ignoring it, report all suspicious activities to the IT Department. The professionals can fix the issue, offer sound advice for future safety and protect your business.

Share with Care

Only share essential information online. Personal and confidential details should not be sent through online channels. Use strict privacy settings, too, as another layer of information protection.

This October, celebrate National Cybersecurity Awareness Month in several easy ways. Partner with the Stop.Think.Connect.™ Campaign as you protect your business from cybersecurity threats. If you need further help, talk to an agent.

Frequently Asked Questions

How often should I change passwords for business accounts?

Change passwords regularly and immediately after any suspected compromise; use unique passwords per account and enable multi-factor authentication when possible.

What is the simplest way to spot a phishing email?

Look for unexpected requests, mismatched sender addresses, misspellings, urgent language, or links that don’t match the sender’s domain; when in doubt, verify with the sender through a separate channel.

How often should I back up business data?

Back up critical data frequently—ideally daily or in real time for high-value systems—and keep at least one offline or offsite copy to protect against ransomware and physical damage.

Who should employees contact if they notice suspicious activity?

Employees should report suspicious activity to the IT department or a designated security contact immediately so the issue can be investigated and contained.

Insomis 909-547-6212 Website
 

Tips That Help You Avoid Being Tracked Online

Overview

Every time employees search online, advertisers and other third parties can collect data that builds profiles used for targeted ads and, in some cases, for more intrusive monitoring. Organizations that care about employee privacy and basic cybersecurity can adopt simple, practical controls to reduce tracking and limit exposure to data collection.

Key takeaways

  • Use a combination of private browsing tools, anti-tracking extensions, and cookie management to reduce profiling.
  • Encryption (VPNs, HTTPS) and device-level privacy settings help protect data in transit and on mobile devices.
  • Regularly review account and app permissions and read terms to understand what data is being collected.

How it works

Websites, ad networks and analytics firms place small files or code—cookies, pixels and trackers—on browsers and apps to record page visits, search terms, and other interactions. That data is aggregated to target ads or, in some scenarios, to profile users for business intelligence or risk analysis.

VPNs and encrypted connections hide content and IP addresses from eavesdroppers on the network, while browser privacy modes and tracker-blocking extensions limit the signals third parties can collect. For businesses that host customer data or run online services, specialized protections and insurance options can help manage the risks; for more information on coverage tailored to online services, see On-line Database Information Retrieval Service Insurance.

What it may cover (and what it may not)

Technical controls like VPNs, private browsing and anti-tracking add layers of privacy but do not make activity invisible to all parties. Your internet service provider, corporate network administrators and some site operators can still log traffic metadata even when cookies are blocked.

For businesses that process customer transactions or operate online storefronts, reducing tracking and hardening systems are part of a broader risk management program; companies also commonly evaluate protections such as those described under E-Commerce Security Insurance to address data-breach and online-fraud exposures.

Common mistakes to avoid

Relying on a single tool is a common error—private browsing alone does not encrypt your traffic or stop network logging, and a VPN without proper configuration can leak DNS requests. Combining multiple tools gives better protection.

Another mistake is ignoring app permissions and default cookie settings. Many mobile apps request access to contacts, location and other sensors; failing to review those permissions increases exposure even if browser tracking is reduced.

Questions to ask an agent

When evaluating commercial protections or insurance, ask which types of incidents are covered and whether policies include response services, forensic investigation and notification assistance. Clarify what exclusions apply and whether coverage extends to third-party vendors or cloud services.

Also ask about recommended technical controls and whether the provider offers resources to help implement privacy measures across the organization rather than only after a loss.

Next steps

Start by implementing layered defenses: use a trusted VPN on company devices, enable private browsing modes for casual sessions, and install reputable anti-tracking browser extensions such as Privacy Badger or Ghostery.

Review account privacy settings on major services, remove unnecessary app permissions on mobile devices, and establish a routine for clearing cookies and limiting third-party tracking. If your business hosts customer data or runs online services, consider formal risk-transfer and security programs and On-line Database Information Retrieval Service Insurance or E-Commerce Security Insurance as part of that strategy.

If you need help evaluating options or coverage, review them with an insurance professional or talk to an agent to get guidance tailored to your organization.

Frequently Asked Questions

Does incognito or private browsing hide my activity from my employer?

No. Private browsing prevents the browser from saving history and cookies locally, but network-level logs and employer monitoring tools can still record visited sites.

Will a VPN hide everything I do online?

A VPN encrypts traffic between your device and the VPN server, hiding content from local observers, but the VPN provider can see your traffic and some tracking may persist via browser fingerprints and third-party cookies.

Are anti-tracking extensions safe to use on company devices?

Reputable anti-tracking extensions can reduce third-party tracking and improve privacy, but evaluate them for compatibility with business applications and check any enterprise deployment policies before wide installation.

How often should I clear cookies and review permissions?

Regularly—at least quarterly for business devices—and immediately after installing new apps or browser extensions to ensure permissions and tracking settings remain appropriate.

Insomis 909-547-6212 Website
 

Tips to Combat Email Phishing Attacks

As many as one in five office workers fall prey to phishing incidents, but 14 percent of office workers don’t recognize phishing attacks. Learn more about phishing and how to combat attacks on your personal or company email.

Businesses that sell or process transactions online should consider additional protections such as E-Commerce Security Insurance to help manage cyber risk.

What is Phishing?

Phishing is a scam cybercriminals use to gain access to sensitive information, often via email. The attacker sends an email that appears official but contains spyware, malware, or other malicious content. If you click a link or download an attachment, criminals can access confidential data like bank account numbers, Social Security numbers, and other personal information. In many cases you may not notice the compromise immediately.

How to Recognize a Phishing Email

  1. Sender Address — Before opening any email, check the sender’s address. It may look similar to an official address but include small changes such as a different domain (for example, using .net instead of .com) or a spelling error like "micrsoft" instead of "microsoft."

  2. Graphics — Attackers often imitate company graphics, but logos, colors, or layout may be slightly off.

  3. Spelling and Grammar Errors — Legitimate organizations usually use professionally written content. Emails with obvious spelling or grammar mistakes are a red flag.

  4. Links — Links are a common phishing tool. Hover over any link (without clicking) to verify the destination matches the sender and looks legitimate.

  5. Threats — Phishing messages often use fear or urgency, claiming you will lose money, face charges, or suffer other severe consequences unless you act immediately.

Steps That Protect Your Email

You can't stop cybercriminals from targeting you, but you can take steps to reduce your risk and limit damage if an attack succeeds.

If your business handles deliveries or mail as part of operations, you may also want to review relevant protections such as Mail Haulers Insurance.

  • Install spam filters and virus scans.

  • Learn to recognize phishing emails.

  • Only open email links from verified and trusted sources.

  • Delete any emails that look suspicious.

  • Train coworkers and associates to recognize phishing threats.

  • Purchase cyber insurance that protects you if you are a victim of phishing.

Regular security reviews and audits can help identify weaknesses and improve training; consider resources such as Security Audit Insurance to support those efforts.

You can’t stop cybercriminals from targeting your email, but applying these tips can help protect your personal and company data.

Frequently Asked Questions

How can I verify if an email is legitimate?

Check the sender address carefully, hover over links to view their real destination, and look for spelling or formatting errors before clicking anything.

What should I do if I clicked a suspicious link?

Disconnect from the network if possible, run a full antivirus scan, change passwords from a secure device, and report the incident to your IT team or service provider.

Can phishing affect personal accounts as well as work accounts?

Yes. Phishing targets personal email, social media, banking, and workplace accounts, so apply the same cautious practices across all accounts.

Are there insurance options that help after a phishing incident?

Some cyber insurance policies can cover costs related to phishing attacks, such as incident response and data recovery, depending on the policy terms.

Insomis 909-547-6212 Website
Copyright 2026. All rights reserved.