An Eight-Person Team, One Tuesday Morning, Total Lockout
A small e-commerce business in Jaipur learned the hard way what many small business owners still underestimate: ransomware doesn't discriminate by company size. Run by a team of eight with no dedicated IT department, the business arrived one Tuesday morning to find every customer order file, every payment record, and every bit of inventory data locked behind an encryption wall, with a ransom demand attached.
This is the reality that has pushed cyber risk insurance into mainstream conversation for small and mid-sized businesses. Insurance can help cover the financial fallout of an attack, from ransom negotiations to recovery costs and legal exposure. But the Jaipur incident also highlights a gap that insurance alone cannot close: prevention. A policy pays out after the damage is done. It does not stop the ransomware from landing on a shared drive in the first place.
What Cyber Risk Insurance Actually Covers (and What It Doesn't)
Cyber risk insurance policies are designed to soften the financial blow of a breach. Depending on the policy, coverage can include costs tied to data recovery, business interruption, customer notification, and sometimes even ransom payments. For a small business without an IT department, that financial cushion can be the difference between reopening and shutting down permanently.
What insurance typically does not do is prevent the attack. It doesn't patch outdated software, segment a vulnerable network, or train an employee not to click a malicious link. Underwriters are increasingly requiring businesses to demonstrate baseline security practices before issuing a policy or before honoring a claim, which means the businesses that treat insurance as their only line of defense may find themselves underinsured or, worse, without coverage at all when it matters most.
For a small operation like the one in Jaipur, that distinction matters enormously. Eight employees running an e-commerce business likely don't have the budget or staff for a security operations center. But that doesn't mean meaningful prevention is out of reach.
Prevention Still Comes First
Security researchers have long pointed out that ransomware attacks often unfold over a compressed window, sometimes with attackers moving from initial access to full encryption in as little as 72 hours. Understanding that timeline is critical because it shapes how a small business should respond, both before and during an incident. A closer look at how to protect against ransomware's 72-hour threat breaks down the stages of a typical attack and the response window businesses actually have once an intrusion begins.
Several practical, low-cost measures can meaningfully reduce the odds of a ransomware incident like the one in Jaipur:
- Use a VPN for remote and administrative access. Encrypting connections between employees and business systems reduces the exposure of login credentials and internal data, particularly for teams without dedicated IT oversight.
- Segment the network. Keeping payment systems, inventory databases, and general office traffic on separate network segments limits how far ransomware can spread if one device is compromised.
- Train employees on phishing recognition. Many ransomware infections begin with a single clicked link or opened attachment. Basic, recurring training for a small team costs little and closes one of the most common entry points.
- Maintain offline, tested backups. Regular backups that are not connected to the main network give a business a path back to normal operations without needing to pay a ransom.
- Apply software updates promptly. Outdated systems remain one of the easiest targets for attackers scanning for known vulnerabilities.
None of these measures require an enterprise budget. They require consistency, which is often more achievable for a small team than a large, bureaucratic one.
What This Means For You
If you run a small business, the lesson from Jaipur isn't that cyber risk insurance is unnecessary. It's that insurance should be the last layer of defense, not the only one. Pair a policy with concrete prevention steps: encrypted connections, segmented systems, trained staff, and reliable backups. Insurance protects your finances after an incident. Prevention protects your business from having that incident happen at all.
Small businesses are attractive targets precisely because attackers assume there's little in the way of defense. Closing that gap doesn't require a large IT budget, just deliberate, ongoing effort.
Key Takeaways
- Cyber risk insurance covers financial fallout, not the attack itself; treat it as a safety net, not a shield.
- Understand the compressed timeline of a typical ransomware attack so you know how to respond quickly if one occurs.
- Implement basic protections now: VPN use for remote access, network segmentation, phishing training, and offline backups.
- Review your insurance policy's requirements, insurers increasingly expect proof of basic security hygiene before or during a claim.
- Don't wait for a Tuesday morning wake-up call. Small, consistent security habits are often more effective than any single tool or policy.




