Media Mention | The Lane Report
Cybersecurity threats continue to evolve, but many middle-market organizations are still relying on security programs, response plans and governance structures that have not kept pace with their growth.
The objective is not to replicate the security program of a global enterprise. It is to identify the risks most likely to disrupt operations, compromise sensitive information or create regulatory exposure — and address them in a practical, prioritized way.
This is especially relevant for healthcare and healthcare technology companies, which must protect sensitive data while managing complex regulatory, customer and third-party security requirements. Technology companies also face heightened risk as they scale cloud environments, adopt artificial intelligence and rely on interconnected platforms, vendors and software ecosystems.
Key Takeaways
- Cybersecurity is a business risk, not just an IT issue. Executive leadership should help define priorities, assign accountability and connect security decisions to operational, financial and regulatory risk.
- Preparation reduces disruption. A documented and regularly tested incident response plan can help organizations make faster decisions, coordinate communications and begin recovery more effectively.
- Cyber resilience requires continuous improvement. Organizations should regularly reassess risks, test critical controls and update their security programs as technology, vendors and business operations change.
LBMC Cybersecurity Expert Featured in The Lane Report
In a recent feature published by The Lane Report, Jesse Chowning, Cybersecurity Manager at LBMC, discussed practical steps organizations can take to reduce cyber risk, prepare for incidents and strengthen long-term business resilience.
Read the full cybersecurity article in The Lane Report.
Cybersecurity Is a Business Risk
Cybersecurity should not be treated solely as an IT responsibility.
A significant incident can affect revenue, operations, customer relationships, regulatory obligations, insurance coverage and the organization’s reputation. Executive leadership should therefore participate in defining risk priorities, allocating resources and overseeing preparedness.
Cybersecurity decisions should be connected to:
- Business continuity
- Financial and operational risk
- Regulatory responsibilities
- Customer and contractual requirements
- Technology investments
- Third-party relationships
- The organization’s tolerance for disruption
A strong cybersecurity program gives leadership a clear view of the organization’s most significant risks and a defensible plan for addressing them.
When Should an Organization Reassess Cyber Risk?
Organizations should consider reassessing their cybersecurity posture after major business or technology changes, including:
- An acquisition, merger or period of rapid expansion
- Adoption of artificial intelligence or new cloud platforms
- A cyber insurance renewal
- New regulatory or customer security requirements
- A change in executive or technology leadership
- A security incident or near miss
- Entry into a new market
- Significant reliance on a new vendor or service provider
- Private equity investment or transaction preparation
These events can introduce risks that may not be addressed by existing policies, controls or response procedures.
Build and Test an Incident Response Plan
An incident response plan defines how an organization will identify, contain, investigate and recover from a cybersecurity incident.
The plan should establish:
- Decision-making responsibilities
- Internal and external communication procedures
- Legal, insurance and regulatory notification processes
- Technical containment and recovery steps
- Business continuity priorities
- Procedures for documenting lessons learned
Creating the plan is only the first step.
Leadership, IT, legal, communications, finance and other key stakeholders should participate in periodic tabletop exercises so they understand their responsibilities before an incident occurs.
A tabletop exercise can expose problems that are difficult to identify in a written plan, including unclear decision authority, communication delays, incomplete contact information and uncertainty about regulatory or insurance notification requirements.
Learn more about LBMC incident response planning and cybersecurity preparedness.
Strengthen Employee Cybersecurity Awareness
Employees remain an important part of an organization’s security environment.
Phishing, social engineering, credential theft and business email compromise often rely on human interaction rather than a purely technical vulnerability.
Effective awareness programs should go beyond annual training. Organizations should provide recurring education, conduct appropriate phishing simulations and give employees a clear process for reporting suspicious activity.
Training should also reflect the organization’s actual risks. Finance teams, executives, administrators and employees with access to sensitive information may require more targeted education than a general workforce program provides.
Use a Recognized Cybersecurity Framework
Recognized frameworks, including the NIST Cybersecurity Framework, can help organizations evaluate current capabilities, identify gaps and prioritize improvements.
A framework gives leadership and security teams a shared structure for discussing risk. It can also support more deliberate decisions about policies, technologies, personnel and third-party assistance.
Framework alignment does not require every organization to implement every possible control. The objective is to understand current maturity, identify material exposures and develop a roadmap that reflects the organization’s risks and resources.
Explore LBMC NIST compliance and cybersecurity framework services.
Treat Cyber Insurance as One Layer of Protection
Cyber insurance may help offset certain financial costs after a covered incident, but it is not a replacement for effective cybersecurity controls.
A resilient security program uses multiple layers of protection, including:
- Governance and executive oversight
- Employee education
- Multi-factor authentication
- Vulnerability management
- Data backup and recovery
- Incident response planning
- Third-party risk management
- Ongoing monitoring and testing
Organizations should review policy requirements and exclusions carefully. They should also confirm that their actual security practices align with the representations made during the insurance application process.
A disconnect between stated controls and operating practices may create complications when an organization files a claim.
Questions Middle-Market Leaders Should Ask
Organizations should look beyond whether a policy or control exists and determine whether it operates effectively in practice.
Key questions include:
- Has the incident response plan been tested with executive leadership?
- Are security responsibilities clearly assigned?
- Are critical backups regularly tested?
- Is multi-factor authentication consistently enforced?
- Are vendors evaluated based on the risk they introduce?
- Are vulnerabilities prioritized based on business impact?
- Do employees know how to report suspicious activity?
- Are cybersecurity decisions documented and reviewed?
- Do insurance application responses reflect current operating practices?
- Has the security program been updated after recent business or technology changes?
These questions can help organizations move from a checklist-based approach to a more resilient and defensible security program.
Cybersecurity Requires Continuous Improvement
Cybersecurity preparedness is not a one-time project.
New technologies, vendors, business processes and threat techniques continually change an organization’s risk environment. A security program that was appropriate two years ago may no longer reflect how the business operates today.
A practical improvement cycle should include:
- Assess current risks and capabilities.
- Prioritize gaps based on business impact.
- Assign owners and implementation timelines.
- Test whether controls operate as intended.
- Report progress to leadership.
- Reassess after significant changes.
Why Organizations Work with LBMC
LBMC helps organizations evaluate cybersecurity risk, strengthen governance, test preparedness and build practical security strategies that support business resilience. LBMC connects cybersecurity decisions with broader compliance, assurance, technology, transaction readiness and operational risk priorities.
LBMC’s cybersecurity team supports organizations across multiple industries with risk assessments, compliance readiness, incident response planning, control testing and remediation guidance.
About Jesse Chowning
Jesse Chowning is a Cybersecurity Manager at LBMC. He helps organizations evaluate cybersecurity risks, strengthen security practices and improve preparedness for evolving threats. Chowning applies his CISA and CCSK credentials and more than five years of audit and compliance experience to help clients achieve their risk management and compliance goals. His experience includes SOC 1, SOC 2, ISO 27001, SOX, HITRUST and PCI engagements. He guides clients through the full engagement lifecycle, from control walkthroughs and testing to findings remediation, reporting and executive presentations.
Frequently Asked Questions
What should a middle-market cybersecurity program include?
The appropriate program will depend on the organization’s risks and regulatory responsibilities. Common elements include governance, employee training, multi-factor authentication, vulnerability management, secure backups, incident response planning, third-party risk management and ongoing monitoring.
How often should an incident response plan be tested?
The appropriate frequency depends on the organization’s risk profile, regulatory requirements and pace of change. Organizations should also test the plan after significant technology changes, acquisitions, leadership transitions or material changes in business operations.
Is cyber insurance a substitute for cybersecurity controls?
No. Cyber insurance may help address certain financial consequences of a covered incident, but it does not prevent attacks or replace security governance, technical controls, employee education and incident response preparation.
What is the difference between a cybersecurity risk assessment and a penetration test?
A cybersecurity risk assessment evaluates risks across areas such as governance, policies, technologies, people, vendors and business processes. A penetration test is more narrowly focused on identifying and attempting to exploit technical vulnerabilities within an agreed scope. Many organizations need both, but they serve different purposes.
When should a company use the NIST Cybersecurity Framework?
The NIST Cybersecurity Framework can be useful when an organization needs a structured way to evaluate current capabilities, communicate risk to leadership and prioritize improvements. It can be adapted to organizations of different sizes and maturity levels.
Who should participate in a cybersecurity tabletop exercise?
Participation often includes executive leadership, IT, cybersecurity, legal, communications, finance, human resources and business operations. External legal counsel, insurance representatives or other advisors may also participate when appropriate.
What cybersecurity controls should companies review before a cyber insurance renewal?
Organizations should review the controls and practices referenced in the insurance application, which may include multi-factor authentication, backups, endpoint protection, vulnerability management, employee training, incident response and vendor oversight. Actual practices should be consistent with the responses provided to the insurer.
Discuss Your Cybersecurity Priorities
Concerned about security gaps, incident readiness, insurance requirements or the maturity of your cybersecurity program?
Schedule a 30-minute Cyber Risk Readiness Review with LBMC.
During the conversation, LBMC can help you:
- Clarify your most significant cybersecurity concerns
- Identify likely priority gaps
- Discuss regulatory, insurance or customer requirements
- Determine whether a risk assessment, tabletop exercise, framework review or insurance-readiness review may be appropriate
- Establish practical next steps






