For commercial bankers in Arkansas and across the country, closing a new business loan is a real cause for celebration.
Rightfully so. For both banker and client alike.
In this age of rampant cyberattacks, however, some new loans carry unforeseen and dangerous cyber risks — risks that can quickly turn a new loan into a liability for the lending bank.
After all, cyberattacks have become an ever-present feature of today's business landscape. Consider this excerpt from Hiscox's Cyber Readiness Report 2026 — which doesn't exactly paint a rosy picture:
It’s more likely than not that a US company will suffer a cyber-attack. In fact, in the past 12 months, more than half (56%) of US small businesses experienced at least one cyber-attack and the average number of attack attempts per business was 2.38. (emphasis added)
Yes, getting hacked — if you're a U.S. small business — is "more likely than not" at this point.
Of course, small businesses aren't just small businesses. For banks, small businesses are borrowers. And a cyberattack can greatly hinder that borrower's ability to pay back their loan. Indeed, 25% of businesses surveyed by Hiscox "indicated that solvency or viability of their company was materially threatened" following a cyberattack.
Banks, then, often find it in their best interest to ensure commercial borrowers are not precariously exposed to cyber incidents. As Richard Thurston, writing for BankInfoSecurity, put it: When you're a bank, "bad cybersecurity is bad for business." Which is why business clients with weak cyber defenses may pay up to 10 extra basis points for a loan.
The danger of cyberattack on business clients, and what that means for the bank's own health, is not lost on JPMorgan Chase. In the mega-bank's 2024 Form 10-K filing with the SEC, the word "cyber" — as in "cyber attack," "cyber incident," and "cyber breach" — was used right at 100 times.
Here's what JPMorgan Chase had to say about the risk of cyberattack on the lender-borrower relationship:
Clients and customers are also sources of cybersecurity risk to (JPMorgan Chase) and its information assets, particularly when their activities and systems are beyond (our) own security and control systems.
(We engage) in periodic discussions with...clients, customers and other external parties concerning cybersecurity risks including opportunities to improve cybersecurity (emphasis added).
And many other banks, not just JPMorgan Chase, are finding it increasingly necessary to mind their cybersecurity p's and q's when considering a business for a new loan.
But why? Why are Arkansas banks so concerned about the cyberattack exposure of their commercial borrowers?
At least three primary reasons are noteworthy....
Of course, banks themselves are often targets of cyberattacks. But that's not what we're discussing here.
The question here and now is: How does an attack on a bank's business client impact that bank?
And there are at least three compelling answers, including:
Higher risk of loan default
Collateral deterioration
Interconnectivity of bank, clients, and third parties
As seen, following a cyber incident, commercial borrowers may struggle to pay back some or all of their loan.
Indeed, cyberattacks frequently cost SMBs in the hundreds-of-thousands of dollars to resolve and remediate. More precisely, $255K on average. As an IT services provider ourselves, one that remediates cyber incidents for SMBs, we receive the panicked day-after-an-attack phone calls from NWA small businesses. And we don't necessarily need statistics to tell us how costly cyberattacks are. We hear the disturbing numbers from the owners themselves.
Naturally, an unexpected $255K expense can break a small business.
And impede their ability to pay back business loans.
When cybercriminals infiltrate business systems, they often do more than steal data, demand ransoms, and/or manipulate invoices. They also sometimes lock down systems or otherwise disrupt business, so that the victim can't operate at max capacity or, in some cases, virtually at all. Which may mean...
It can get downright ugly, in fact.
But from a banker's point of view, this isn't just deterioration of business capacity and image; it's deterioration of loan collateral. After all, the loan process hinges on the would-be borrower's ability to pledge business assets as collateral. And a bank's ability to redeem that collateral without significant loss of value is a crucial source of security for the bank in the borrower-lender relationship.
Cyberattacks can devalue this collateral, however. Forcing banks to assume greater financial risk.
"Interconnectivity." That's JPMorgan's word — not ours. But it's a good word here.
Cyber risks are not isolated in our modern economy — because businesses are not isolated. Rather, modern businesses are part of a larger supply chain or, at least, a digitally-interconnected web of employees, clients, and third-parties.
What often goes unacknowledged is this: A cyber breach in one part of a supply chain gives cybercriminals a foothold in other parts and with other members of that supply chain. Imagine, if you're a banker, that a bad actor infiltrates the email system of one of your business clients. Not only does that attacker gain access to your client's data/systems, which is bad enough, but they may also gain access to a treasure trove of information — names/job titles, transactions, details, etc. — about your bank that lives in or on this client's inbox, drives, and the like.
This is worth a read. Look at how JPMorgan Chase described this "interconnectivity" threat in its 2024 Form 10-K Filing:
As JPMorganChase’s interconnectivity with clients, customers and other external parties continues to expand, JPMorganChase increasingly faces the risk of operational failure or cyber attacks with respect to the systems of those parties. Security breaches affecting JPMorganChase’s clients or customers, or systems breakdowns or failures, security breaches or human error or misconduct affecting other external parties, may require JPMorganChase to take steps to protect the integrity of its own operational systems or to safeguard confidential information, including restricting the access of customers to their accounts (emphasis added).
Today, a cyberattack on one member is a cyberattack on the entire supply chain.
From greater chances of loan default, collateral deterioration, and the "interconnectivity" of banks with their clients, it's clear that it greatly behooves commerical banks to be concerned about their clients' cyberattack readiness.
But how can bankers spot vulnerable business clients? What are the warning signs?
Let's take a look.
Now, first, there would be more than 10 warning signs of a looming cyberattack on a commercial borrower.
But the point here is to equip business bankers with a checklist of readily apparent signs.
After all, bankers usually aren't IT experts — and so they need to be able to deduce cyberattack preparedness through a series of simple questions and/or readily visible signs.
Here's 10 of them...
Imagine someone claims to be a master chef but doesn't own any cutlery. Or maybe someone says they're passionate about golf — but there are no clubs anywhere around their house.
If something is true, you expect to see the rudimentary signs of it.
And if a business claims to be protected from cyberattack, it's hard to take that claim seriously if they don't at least:
You're unlikely to find two measures more fundamental and essential to protecting a business today.
So, simply ask that commercial borrower if they're practicing the "first aid" of cybersecurity — specifically, using strong passwords and multi-factor authentication. If not, they're not even getting to first base.
Here's a cybersecurity tip sheet we prepared for small businesses, and it can also be used by bankers to evaluate whether their business-loan clients are practicing basic cybersecurity hygiene.
When you start talking about the ubiquity of cyberattacks, and their impact on local businesses, does your potential borrower seem surprised, incredulous, or confused — or maybe all three?
Remember, SMBs today are "more likely than not" to sustain an attack. Consequently, it doesn't exactly instill confidence — does it? — when a potential commercial borrower isn't even aware there's a problem.
Have a simple convo with the would-be client about cyberattacks.
If they're not aware of the problem, and its extent, that's a sign of ill-preparedness.
Almost every business has a "close call" story.
Maybe it's the invoice that almost got paid to the wrong account. Or the email that almost got clicked — the one with the urgent request from the "CEO." Or the login attempt from a country nobody in the office has ever visited.
These near-misses are warning shots. And how a business responds to a warning shot tells you a lot about how seriously they take the threat.
So ask the potential borrower: Has anything like this ever happened to you?
If the answer is yes — and it often will be — the follow-up question matters even more: What did you do about it?
If the answer is "nothing much," that's the real red flag. A close call that didn't prompt so much as a password reset, a staff reminder, or a second look at their defenses isn't a close call anymore.
It's probably a preview of more to come.
While not true of every business, for many businesses today, no data = no business.
Client files. Financial records. Years of correspondence. Inventory and production data. For plenty of small businesses, if that information disappeared tomorrow, so would the business itself.
So when evaluating a potential borrower, it's worth asking a simple question: How — and how often — do you back up your data?
There's an industry rule of thumb here, and it's not complicated: Backups should run at least daily, following the "3-2-1" rule — 3 copies of your data, on 2 different types of media, with 1 copy stored off-site (cloud counts).
Of course, different businesses have different backup needs. But at a minimum, businesses should:
Back up their mission-critical data at least daily
If a potential borrower isn't meeting these minimum standards, your concerns are quite legitimate.
Speaking of backups, having one is only half the equation. The other half is knowing what happens when disaster actually strikes.
Ask the potential borrower: If your systems went down tomorrow, what's the plan to get back up and running — and how long would it take? A backup nobody can explain, after all, isn't much of a safety net.
The biggest threat to a business often isn't the hacker's knowledge. It's the employee's lack of knowledge.
Phishing emails, fake invoices, urgent texts from "execs" — these scams don't need to beat a firewall.
They just need one distracted employee to take the bait.
So ask the potential borrower: How do you train your staff to spot these threats? And how often? If the answer is a shrug, a one-time onboarding mention, or "we tell people to be careful" — that's not training.
That's just...wishful thinking.
Untrained employees are a hacker's favorite entry point into business systems.
If strong passwords and multi-factor authentication are cybersecurity "first aid," software patching is right behind them.
Unpatched software — that is, software that isn't regularly updated — is an open invitation to cybercriminals. Every patch exists because a vulnerability has been found. Skip the patch, and that vulnerability stays wide open.
Simply ask: How often is your software updated?
A business that can't answer, or hasn't updated in months, is running yesterday's defenses against today's threats.
Outdated hardware, too, can be a concern. And one you may be able to visibly see.
Older computers and servers often can't run the latest security software at all because the manufacturer has stopped supporting them, which means no more security patches ever again .
So look around during your next visit. Aging computers, old server towers humming away in a closet, systems running software that looks like it's from another decade...
...these are visible clues that a business's technology, and its defenses, haven't kept pace.
A cybersecurity risk assessment is exactly what it sounds like: a systematic look at where a business is vulnerable — weak passwords, unpatched systems, untrained staff, missing backups — so those gaps can be identified and fixed before someone with sinister intentions finds them first.
Ask the potential borrower: When was your last cybersecurity risk assessment? If they've never had one, or can't recall the last time, that's a sign they don't actually know their own exposure. And you can't fix what you haven't identified.
Worth noting: a proper risk assessment often requires the help of an MSP or cybersecurity provider.
Most small businesses simply don't have the in-house expertise to conduct one themselves.
Some businesses have a clear, deliberate approach to technology. Others just, well, wing it.
In a "willy-nilly" IT environment, there's no consistent standard. Employees are largely left to fend for themselves.
Signs of this DIY approach include:
Bring your own device (BYOD): Employees use personal phones, laptops, and tablets to access business systems and data — devices that likely aren't monitored, secured, or updated by any IT standard.
Provide your own antivirus: Rather than a company-managed security solution, employees are expected to install (or not install) their own protection however they see fit.
No standardized software: Different employees use different tools for the same job — one person's on Dropbox, another's on Google Drive, another's emailing files back and forth.
No IT policies in writing: There's no documented standard for passwords, device use, data handling, or software approval — just informal habits and assumptions.
None of this is necessarily malicious. It's often just neglect — technology that grew organically, without anyone stepping back to build a system around it.
But ad hoc IT means ad hoc security.
And a patchwork of personal devices and self-managed tools is awfully hard to monitor, let alone protect.
Different businesses, different approaches to IT and cybersecurity.
In some SMBs, no one is thinking about either one — at all.
In others, the responsibility falls to one person — often someone without IT expertise. Maybe it's someone in accounting or HR. Maybe it's simply the youngest member of the team, the assumed "tech person" by default rather than by training. Needless to say, this person is often overwhelmed to the point of inaction.
So ask the potential borrower: Who, specifically, is responsible for your cybersecurity? Better yet, ask to speak to the person in charge of cybersecurity — and evaluate how the potential borrower responds.
Of course, at some point, a small business — either because of their dependence on data and technology, or because of their growth and size — needs to start thinking about professional IT. Here, the MSP (managed service provider) becomes invaluable — taking cybersecurity off the plate of an accountant, an HR manager, or an overwhelmed office "techie," and putting it in the hands of a dedicated team built for exactly this purpose.
If a business has outgrown the DIY approach but hasn't made that shift, that's a sign worth noting.
Maybe your bank is considering a loan to a NWA-based business, but you first need to ensure the potential borrower is prepared for a cyberattack?
Or maybe you have a client that has already sustained a cyberattack — and is in need of remediation?
Either way, TekTrendz is here to help.
We've been helping NWA businesses with their IT and cybersecurity needs since 2007 — and we're standing by to help banks and bankers protect their investments even as we help their clients protect their businesses.