Risk Management Considerations for Unregulated SMBs in NY

When we talk with business owners and executives about cybersecurity, one question comes up more than almost any other. It usually sounds something like this: “We’re not a bank or a hospital. We don’t answer to government regulators. How much security do we actually need?”

It’s a fair question, and it deserves a straight answer. But it’s built on an assumption that deserves a closer look: that the level of protection a business needs is determined by whether a regulator is watching. In our experience, that assumption leaves a lot of companies carrying far more risk than they realize.

Cybersecurity Is a Risk Management Decision

Every leadership team makes decisions about risk. You decide how much inventory to carry, which customers get credit terms, what insurance coverage makes sense, and how much cash to keep in reserve. In each case, you weigh the likelihood of something going wrong against the cost of preventing it, then decide what level of exposure you’re comfortable with.

Cyber risk belongs in the same conversation. The goal isn’t to eliminate every possible threat, which no business can do. The goal is to understand your exposure and make a deliberate choice about how much of it to accept, reduce, or transfer.

The problem with the “we’re not regulated” mindset is that it skips that process. It treats the absence of a compliance requirement as evidence of low risk. Those are two very different things.

Cybersecurity Regulations Follow the Threat, Not the Other Way Around

Compliance frameworks exist because businesses were getting hurt. Regulations like HIPAA and the security requirements placed on government contractors were written in response to real breaches and real losses. They set a minimum standard for industries where the consequences were severe enough to force the issue.

That minimum is useful, but it was never meant to be the finish line. Regulations also take years to write and update, while the methods criminals use change constantly. A company that is fully compliant today can still be exposed to threats the rules haven’t caught up with.

So, the more useful question isn’t whether you’re required to protect your business. It’s whether the risks those regulations were designed to address apply to you. For nearly every business, they do.

Why Unregulated Businesses Are Attractive Targets for Cyber Attacks

Cybercriminals run their operations like a business. They want the highest return for the least effort, and that makes organizations with weaker defenses more appealing, not less.

A regulated company has usually been forced to invest in security. A company outside those industries often hasn’t, and attackers know it. The assumption that “we’re too small” or “we’re not the type of company they go after” is precisely what makes these businesses easy wins. The data bears this out. According to Verizon’s 2026 Data Breach Investigations Report, among ransomware cases where the victim’s size was known, about 96% of victims were small and midsize businesses.

It also helps to understand that most attacks aren’t personal. Criminals use automated tools to scan for vulnerable systems and send phishing emails by the thousands. They aren’t selecting targets by industry. They’re looking for an open door. As Verizon puts it, “it’s not so much about industry or the revenue of the victims but the fact that the victims had credentials that were compromised (38%) or unpatched vulnerabilities in edge devices (29%) that resulted in them being victimized.” In other words, a stolen password or an overdue update is often all it takes.

What Your Business Has That Cyber Criminals Want

Many leaders assume they don’t have much worth stealing. In practice, almost every organization has at least one of the following.

Money in motion. If your business sends and receives invoices, pays vendors, or processes wire transfers, you are a target for business email compromise. These schemes are simple and effective. An attacker gains access to an email account, or imitates a trusted vendor, and sends a convincing request to update payment details. By the time anyone notices, the money is gone and rarely recoverable.

Operations that can be stopped. Ransomware doesn’t need your data to be valuable to anyone else. It only needs your systems to be valuable to you. If an attack locks up your accounting, order management, or scheduling systems, the business stops. Every hour of downtime means lost revenue, missed commitments, and strained customer relationships.

Information about people. Customer records, vendor contracts, pricing, employee files, and payment details all have value, either for resale or for use in further fraud. Employee data in particular is easy to overlook. The IBM Cost of a Data Breach Report 2026 found that employee personal information was compromised in 35% of breaches, at an average cost of $188 per record. As you’ll see below, that same employee data is also what brings many businesses under New York State’s data security law.

Connections to others. Your business is linked to customers, suppliers, and partners, and attackers increasingly use smaller companies as a way into larger ones. Verizon found that breaches involving a third party rose 60% in a single year and now account for nearly half of all breaches. Being the weak link in someone else’s supply chain carries its own consequences, including lost contracts.

The Regulations and Standards You May Already Be Subject to

Even businesses outside heavily regulated industries often have obligations they aren’t aware of.

The New York SHIELD Act

This is the one most New York businesses overlook. The SHIELD Act applies to any organization, in any industry and anywhere in the world, that owns, licenses, or maintains computerized private information of New York residents. If you have employees or customers in New York, it very likely applies to you.

“Private information” includes Social Security numbers, driver’s license numbers, biometric data, and online account credentials. As of March 2025, it also includes medical and health insurance information. That change matters for more businesses than you might expect, since routine HR records like leave paperwork and benefits enrollment can now fall under the law.

The Act requires covered businesses to maintain reasonable administrative, technical, and physical safeguards. In plain terms, that means things like employee training, network monitoring, encrypting sensitive data, and disposing of data securely. “Reasonable” may sound like a low bar, but many organizations still fall short of it. IBM found that 53% of breached organizations hadn’t encrypted their sensitive data, and another 10% weren’t sure whether they had.

Amendments signed in December 2024 also tightened what happens after a breach. Businesses must now notify affected New York residents within 30 days of discovering the incident. There is no longer an allowance for delaying notice while you investigate or restore your systems. Only a request from law enforcement can pause the deadline. It’s also worth knowing that a breach includes unauthorized access, not just theft. If someone views records they shouldn’t, the clock starts.

The New York Attorney General enforces the law and can impose penalties of up to $5,000 per violation of the safeguard requirements and up to $250,000 for failures to notify.

Payment Card Standards

If you accept credit cards, you’re contractually bound to the Payment Card Industry Data Security Standard (PCI DSS) through your payment processor.

Your Customers’ Requirements

Organizations in government, healthcare, finance, and larger enterprises are increasingly asking their vendors to complete security questionnaires and meet specific standards. Some write these requirements directly into contracts. A business that can demonstrate strong security has an advantage when competing for and keeping those accounts. One that can’t may lose them.

Your Cyber Insurance Policy

Insurers have become far more selective. Many now require controls such as multi-factor authentication, advanced endpoint protection, and tested backups before they’ll issue or renew a policy. Gaps can lead to higher premiums, reduced coverage, or a denied claim when you need it most.

The Real Cost of “It Won’t Happen to Us”

Consider a common scenario. An employee in accounts payable receives an email from a familiar vendor asking to update their banking information. The email looks legitimate because it comes from the vendor’s actual account, which was compromised weeks earlier. The next payment goes to the attacker.

Or consider a ransomware attack that begins late on a Friday. By Monday morning, your systems are encrypted, your staff can’t work, and you’re facing a ransom demand. Now you also have 30 days to determine whose information was accessed and notify them, all while trying to get the business running again.

Ransomware at least announces itself. Many breaches don’t. In the payment fraud example, the vendor’s email account had been compromised for weeks before anyone noticed, and that’s typical. According to IBM, organizations took an average of 183 days just to identify a breach and 247 days to fully contain it. Measured against a 30-day notification deadline, early detection matters as much for compliance as it does for security.

The costs add up quickly: lost revenue during downtime, recovery and forensic expenses, legal and notification costs, potential penalties, insurance complications, and the harder-to-measure damage to customer trust. Most of that cost has nothing to do with the ransom or the fine. IBM found that two categories, investigating the breach and the business lost while it’s being resolved, together made up 63% of the average breach cost. Recovery also takes longer than most leaders expect: fewer than 1 in 20 breached organizations fully recovered in under 50 days.

Essential Protections to Mitigate Cyber Risk

Reducing cyber risk doesn’t require a massive overhaul. It requires consistent attention to a handful of fundamentals:

These fundamentals pay for themselves. IBM’s research found that identity and access management lowered the average cost of a breach by $225,622, employee training by $196,259, and a managed security services program by $152,929. Speed matters just as much: breaches that took more than 200 days to identify and contain cost an average of $5.65 million, compared to $4.32 million for those resolved faster.

It’s no coincidence that these same measures are what regulators, insurers, and customers look for when they ask whether you have reasonable safeguards in place. Investing in good security and meeting your obligations turn out to be the same effort.

The Risk Management Question Worth Asking

For most businesses, the question isn’t whether you’re required to invest in cybersecurity. Every organization accepts some level of cyber risk. The real question is whether you know how much you’re carrying, and whether that decision is being made deliberately or by default.

The businesses that fare best are the ones that understand their exposure clearly and decide how to handle it with intention. The ones that struggle are often those that assumed the risk didn’t apply to them.

At M.A. Polce, we’ve spent more than 28 years helping organizations across New York optimize and protect their operations, from small, local businesses to the government agencies that communities throughout the state depend on. Security is at the center of every engagement, and we hold ourselves to the same standards we set for our clients, which is why we maintain SOC 2 Type II certification.

If you’re not sure where your business stands, a conversation with our team is a simple place to start. We’ll help you understand your exposure, what you may already be required to do, and which steps would make the biggest difference, with no obligation to take it further. Call us at 315-338-0388 or contact us here, and a member of our team will follow up within one business day.

Date Published
Share This Content

Subscribe to Our Resource Center

Join M.A. Polce’s mailing list to be the first to receive essential company news and valuable industry insights.

You May Also Like:

Share with Your Network

Download the "How Strong is Your Cybersecurity Culture?" Checklist!