More than half of small U.S. businesses surveyed by the Ponemon Institute were found to have experienced at least one data breach in the entire span of their operations, but only a third notified customers of the situation.

"Smaller companies are targeted by data thieves, but they often don't know how to respond when sensitive information they keep on customers and employees is lost or stolen," says Eric Cernak, vice president for Hartford Steam Boiler in a statement. "Failing to act in a timely and effective way can harm the reputation of businesses and even risk legal penalties in many states." 

Cernak later told PC360, "The top three reasons why small businesses aren't reporting breaches are because many do not know that state laws regulating their disclosure exist, some companies erroneously think that the laws only apply past a threshold of amount of data stolen, and they may believe that if they don't report the incident, no one will find out." 

Recommended For You

Want to continue reading?
Become a Free PropertyCasualty360 Digital Reader

Your access to unlimited PropertyCasualty360 content isn’t changing.
Once you are an ALM digital member, you’ll receive:

  • Breaking insurance news and analysis, on-site and via our newsletters and custom alerts
  • Weekly Insurance Speak podcast featuring exclusive interviews with industry leaders
  • Educational webcasts, white papers, and ebooks from industry thought leaders
  • Critical converage of the employee benefits and financial advisory markets on our other ALM sites, BenefitsPRO and ThinkAdvisor
NOT FOR REPRINT

© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.