Cyberattacks are inevitable

Several years ago, I had the opportunity to speak at a veterinary conference during a lunch session. The room was filled with about 185 attendees, all eager to enjoy their meal and take a break from continuing education, while “the insurance guy” disrupted their appetites with tales of loss and destruction! With only 45 minutes of time to present, I focused my talk on the “top 5 biggest risk exposures in vetmed.” I always saved Cyber for last back then, because it’s universally relevant—whether you own a hospital or not—and can lead to enormous financial nightmares. It’s definitely a compelling topic over a meal!

At the start, I like to get a sense of the audience’s engagement level and also identify how many business owners are present. So, I asked and a little over half raised their hands that they were practice owners. That was a strong response, which was more than I anticipated and one that justified the $2,500 sponsorship fee for lunch. Later as my talk progressed, I was emphasizing how cyber liability can devastate small business owners (SMBs), reputation, finances, time, etc.  I further pressed by stating:

“Earlier, I asked how many of you owned a hospital—about half did. No need to raise your hands again, but I want you to realize that right now, as you sit here enjoying lunch, none of you likely have solid protections if you get hacked or ransomed and the fallout could destroy everything you have worked so hard for. Perhaps one day in the near future, when a large corporate veterinary group gets hit with a major cyber-attack, will the vet industry finally stop and take notice to realize how vulnerable we all are.”

At that moment, I saw a hand go up. I love interaction during my talks, so I called on the lady who raised her hand. She explained, “I’m an associate veterinarian for NVA. We got hit on Saturday by a cyber-attack and have been shut down. Over 700 of our hospitals have lost a month’s worth of accounts receivable.” Even after my earlier points, I was stunned by the scale of the attack and the fact that backups were only performed once a month. Mentioning them here is by no means a criticism of NVA, quite the opposite. The list of large businesses that experienced major intrusions include Coca-Cola, Adobe, Microsoft and Capital One just to name a few. The fact that NVA got hit so hard and it was being disclosed in real-time gave a stark illustration of my point:  if large businesses with millions of dollars budged annually in cybersecurity can be compromised, small veterinary practices are simply low-hanging fruit. And since a small veterinary practice doesn’t have a large budget for major cyber security infrastructure like a big business, at the very least transfer as much risk as economically viable.

Fast forward: before COVID, small business owners (SMBs) were targeted about 25% of the time in cyber incidents, based on reported intrusions and ransomware cases. I believe the real number is higher, considering many breaches go unnoticed or unreported. When COVID hit, even though veterinary hospitals remained essential, many other businesses couldn’t operate normally. Remote work became the norm, and while large companies had the resources to keep their systems protected, most small businesses struggled just to stay afloat. Protecting all their systems adequately was often beyond their means—most simply didn’t have the budget or bandwidth.

Today, SMBs are targeted more than ever, and the evidence is clear:

  • 75% of cyber incidents now target SMBs—up from 25% pre-pandemic.
  • Of these incidents, 70% are ransomware.
  • The average time to detect a breach is 194 days.
  • In 2024, cloud intrusions increased by 75%.
  • 88% of breaches are caused by human error.
  • In 2024, 1.7 billion individuals were compromised.
  • The most targeted SMBs are Professional Services.
  • The average financial impact of a breach to SMBs in 2024 was $2.64 million.

Additionally, with the rapid evolution of AI, the ability of malicious actors to exploit firewalls, anti-virus, and anti-malware is accelerating at an unprecedented rate. During a 2025 appearance at Harvard Business School, Perplexity AI CEO Aravind Srinivas was asked about his company’s future plans. To everyone’s shock, he said, “We don’t think three years ahead, mainly because AI is so fast-moving and constantly changing. It’s kind of pointless to plan that far ahead. We focus on quarterly planning.” hbs.edu

The message is clear: AI is advancing faster every day and SMBs, especially veterinary hospital owners, are more exposed to cyber risk than ever before. The time has never been more critical for veterinary hospitals owners to do something about protecting their businesses from cyber-attacks. It’s imperative to focus on robust protection strategies now, not later. Cyberattacks are inevitable, but financial ruin is not.

For more information on Cyber Liability Insurance visit us at: Cyber coverage for veterinary hospitals.