By Pat Wilderotter
HOAs are not multi-million-dollar corporations like McDonalds, Starbucks, Marriott Hotels, Yahoo and countless other companies. Why are HOAs vulnerable?
Hackers recognize that HOA board members are typically volunteers. Associations typically possess valuable financial information including homeowners contact information, banking and payment information, assessment payment records, operating and reserve accounts, etc. Couple that with associations having few safeguards to protect their digital records and they are an easy target for hackers. Even when the association is using a management company, boards often can direct the management company to transfer funds to a fraudulent vendor’s invoice that they received and to move funds from the operating account to a reserve fund that has been unknowingly hacked…etc.
The most common cyber attacks involved fraudulent email communications. Hackers can gain access to an email account or impersonate the management company, a vendor or a board member.
Ransomware attacks are one of the fastest growing cyber threats. Hackers infiltrate computer systems, encrypt critical data and demand payment to restore access.
Data Breaches target stored personal information. Members of the HOA’s names, addresses, credit card information, etc. are now compromised. The affected individuals have to be notified with the association having to provide credit monitoring services, legal services to help re-establish an individual’s identity, etc.
Social engineering is when hackers manipulate individuals into providing sensitive information or authorizing financial transactions. Phishing is a type of social engineering where internet users are “tricked” through deceptive emails etc. to reveal sensitive information, unknowingly installing viruses, etc. and often are aimed at a large group of recipients. Additionally, we know that 1 in 6 hackers are now turning to AI to create phishing emails and deepfakes.
Boards traditionally look to cover the property, liability, D&O and crime exposures for their association. Crime policies historically did not offer coverage for cyber attacks. We are now in the computer/digital age where insuring protection from hackers is as important as property and liability coverages. Board members have a fiduciary responsibility to protect the association’s assets. Whether buying separate cyber insurance or seeing what coverages can be added to their crime policy, each association’s insurance renewal should include cyber insurance coverage. Cyber coverage is not expensive but is now a necessary part of the association’s risk management responsibilities. For example, $250,000 of coverage with a $2,500 deductible can cost from $600 - $700 annually.
Boards and managers should request insurance coverage for potential cyber attacks if they do not currently have coverage or are not offered coverage at their renewal. Cyber insurance can help to cover financial and recovery loss, ransomware payouts, notification services, credit monitoring services etc. In 2025, the average U.S. data breach cost 10.2 million. High dollar costs that the association will have to incur if they do not have adequate cyber insurance.
About the Author: Pat Wilderotter is past-president of the Rocky Mountain Chapter of CAI. She is one of 150 agents in the US to hold the designation of CIRMS (Community Insurance and Risk Management Specialist). Pat heads the HOA team at CCIG where she is an executive VP and Partner.