Simpson & McCrady, LLC

Simpson & McCrady, LLC For over 100 years, our focus has been on the sophisticated and complex risk management needs of our Colvin McCrady and William H.

Simpson & McCrady is guided by our steadfast dedication to client needs. Our allegiance to clients is driven by our keen foresight and unwavering vigilance on their behalf. Simpson & McCrady looks forward to celebrating 100 years of unprecedented service and growth. The agency assumed its current name in 1985 when partners L. Simpson combined their agencies. Since the beginning of this partnership

, the agency has continued to evolve and now represents a wide variety of companies and over 5,000 clients. While many of our clients are located in Western Pennsylvania, we have clients in over 48 states and numerous foreign countries. As we continue to grow and adapt to our clients’ changing needs, we will never lose focus of our commitment to service and quality insurance products and solutions. As a firm dedicated to serving the places we live and work, Simpson & McCrady remains actively engaged in supporting various philanthropic organizations throughout the community.

08/14/2026

Where does your organization stand? A 90-day roadmap by maturity.

Not every organization is starting from the same place on AI governance. Identify your current stage below, then focus your next 90 days on the actions listed for that tier.

Stage 1: Early-Stage. AI is in use, but governance is absent or informal. You're here if employees are using AI tools without centralized tracking, no one owns AI risk formally, and there's no written policy on acceptable use.

Your priorities: build an AI inventory (a spreadsheet is a fine starting point), name one risk owner, draft an acceptable use policy, and fold AI-specific scenarios into your incident response plan.

Stage 2: Developing. Governance exists, but it operates in silos. You're here if you have an inventory and a named owner, but security and governance aren't aligned and you haven't adopted a recognized framework.

Stage 3: Advanced. Governance is established. The goal now is continuous and defensible. You're here if security and governance are aligned and a framework is in place, and the challenge is keeping the program audit-ready.

Your priorities: define what triggers a formal reassessment, build executive-level reporting so leadership has a real dashboard view, and run the 48-hour test. Could your organization produce a complete AI risk artifact within 48 hours if a regulator or insurer asked for one? If not, that's the gap to close.

Our team wrote an article with more details on how to update your cyber coverage with the rapidly changing AI landscape, no matter what stage your company lands in.

Wherever you land on this, it's worth a conversation with your broker about whether your coverage reflects where you actually are.

Which stage is closest to where your organization sits today?

08/12/2026

Does a nonprofit board's D&O policy cover a data breach?

No. And this is a common we see with nonprofit and human services clients across Western Pennsylvania.

D&O insurance protects board members and executives from claims about decisions they made, mismanagement of funds, employment disputes, breach of fiduciary duty. A cyber incident is a different kind of exposure entirely, and it needs its own policy.

Here's why this matters more for nonprofits than most people assume. A human services organization handling client records. A school with student data. A community development nonprofit processing donor payment information. All of them sit on sensitive data, and most of them are running on tighter margins than the businesses that typically carry standalone cyber coverage.

The good news: cyber liability for nonprofits is more accessible and more affordable than most executive directors expect. The bad news: the boards that find this out after a breach are the ones who assumed D&O had it covered.

If your organization hasn't looked at its cyber coverage separately from its D&O policy, that's a conversation worth having before renewal, not after an incident.

08/05/2026

There are six ways AI has quietly rewritten your cyber risk profile.

Ransomware is faster now. AI automates the discovery of vulnerabilities and the brokering of access, shrinking the time between breach and extortion demand.

Data breaches are sharper too. AI-powered reconnaissance lets attackers zero in on your most valuable data: PHI, PII, financial records.

Social engineering doesn't look like spam anymore. These emails reference real org charts, real vendors, real names.

Technology E&O exposure has grown right alongside it. A supply chain attack on one AI vendor can ripple out to every client who relies on that platform.

Business email compromise now has an audio and video dimension. Deepfakes are convincing enough to impersonate an executive in real time.

And a newer category is emerging: standalone AI liability. Carriers are starting to add AI-specific exclusions to E&O and cyber policies. That means some organizations deploying AI tools may have real gaps in coverage nobody has flagged yet.

Our team has written a memo to summarize the ways AI has changed the risk landscape, governance, and coverage for your business.

The regulatory ground is moving just as fast. The EU AI Act is already live. NIST's AI Risk Management Framework is becoming the de facto US standard for 2026, and insurers are starting to reference it in underwriting. ISO 42001 is on track to become the market-expected certification by 2027.

AI hasn't just changed how attacks happen. It's changing what your policy needs to cover and what regulators expect you to prove.

Has your organization reviewed its cyber coverage against any of this yet?

Good conversations happen when nobody's trying to sell anything.That was the mixer at Leech Tishman's office this week. ...
08/03/2026

Good conversations happen when nobody's trying to sell anything.

That was the mixer at Leech Tishman's office this week. A few members of the S|M team spent the evening with attorneys, wealth managers, and other Pittsburgh professionals who spend their days advising the same business owners and families we do.

No pitch decks. No agenda beyond actually knowing the people you're supposed to be collaborating with when a client needs more than one kind of advisor in the room.

This is the part of the job that doesn't show up in a renewal proposal but matters just as much. The professionals who know their clients personally, can anticipate their needs before they arise, and can recommend them to trusted brokers, attorneys, and advisors. This is the beauty of the Pittsburgh network.

Thanks to the Tishman team for hosting!

07/31/2026

What happens when a volunteer gets hurt at your nonprofit's fundraiser?

Most executive directors assume general liability handles it. Sometimes it does. Often it doesn't, and the gap shows up at the worst possible moment.

Volunteers occupy a strange middle ground in insurance terms. They're not employees, so workers' comp typically doesn't apply. They're not quite the general public either, since they're actively working an event on your behalf. Depending on how your policy defines "volunteer" and what activities are covered, an injury during setup, teardown, or the event itself can land in a coverage gray area.

We see this most with human services organizations and nonprofits across Pittsburgh running galas, food drives, and community events with a mix of staff and volunteers doing the same physical work side by side.

The fix is usually straightforward. Volunteer accident coverage is inexpensive, and a clear review of how your GL policy actually defines volunteer activities closes most of the gap. What it requires is someone actually asking the question before the event, not after someone's on the ground.

If your organization runs volunteer-heavy events and hasn't had this specific conversation with your broker, it's worth fifteen minutes before your next one.

07/29/2026

What does a D&O policy actually cover for a nonprofit board in Pennsylvania?

Most board members assume it covers any lawsuit involving the organization. It doesn't. D&O covers claims against the board and leadership for decisions they made, things like a wrongful termination claim, a dispute over how grant funds were allocated, or a claim that the board failed in its oversight duties.

It does not cover bodily injury, property damage, or a lot of employment claims that people assume fall under it. Those need separate coverage entirely.

We work with nonprofits and human services organizations across the Pittsburgh region, and the gap we see most often isn't a missing policy. It's a policy that was purchased years ago and never revisited as the organization grew. A $500,000 limit that made sense for a $2M budget organization doesn't make sense once that same organization is running $8M in programs and government contracts.

Boards also tend to assume that D&O and EPLI are the same thing. They're related, but they're not interchangeable, and a lot of exposure lives in the space between them.

If your board hasn't reviewed its management liability coverage in the last two years, that's the conversation worth having before the next renewal, not during it.

What's the last thing your board asked about coverage that nobody had a great answer to?

Is your cyber insurance still built for the threats your business actually faces?Google's threat intelligence team just ...
07/27/2026

Is your cyber insurance still built for the threats your business actually faces?

Google's threat intelligence team just published a report worth every business owner's attention. Here's what they found already happening, not theoretical, happening now.

AI helped discover a real zero-day vulnerability, one that was used to plan a mass exploitation campaign against thousands of organizations at once.

State-sponsored hackers are writing malware that disguises itself with decoy code to slip past traditional security tools. One malware family used 32 benign-looking code queries just to look harmless.

A new strain of Android malware operates with no human supervision. It navigates a phone's interface on its own and blocks its own removal.

Phishing emails now reference real vendors, real coworkers, real projects, because AI did the research first.

Even the AI tools your business relies on have become a target. A criminal group compromised widely-used AI software, stole cloud credentials, and sold them to ransomware groups.

Here's what this means if you're running a manufacturing company, a nonprofit, or a growing tech firm in Western Pennsylvania: the assumption "we're too small to be a target" doesn't hold anymore. Attackers don't always come at you directly. They compromise a tool thousands of companies use, and gain access to all of them at once. Deepfake voice cloning is now part of the wire fraud playbook too, not a hypothetical.

The barrier to running a sophisticated attack has dropped. The time between a breach and real damage has shrunk. Coverage and controls that felt adequate two years ago may not reflect today's environment.

We wrote a longer piece on how business owners should be thinking about risk, coverage, and governance in light of all this. Click on the link below for in-depth analysis:

https://simpsonmccrady.com/artificial-intelligence-has-changed-the-cyber-threat-landscape-here-is-how-you-should-be-thinking-about-risk-coverage-and-governance/

What's changed most in your business's risk exposure over the past two years?

Source: Google Threat Intelligence Group (GTIG), "Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access" — May

07/24/2026

If your home is worth more than $1.5 million, your homeowners policy is probably underinsuring it.

Not because your carrier is careless. Because standard homeowners policies are built around replacement cost formulas that work fine for a median-priced house and fall apart fast once you're talking about custom construction, high-end finishes, or a rebuild in today's labor and materials market.

We see this constantly with high-net-worth families across Pittsburgh and the surrounding area. The policy looks fine on paper. The dwelling coverage number hasn't been revisited since the home was purchased or last appraised. Construction costs have moved considerably since then.

A few other places standard coverage quietly falls short at this level: scheduled jewelry and valuables with real appraisals behind them, umbrella limits sized to actual net worth rather than a round number, and coverage for a second home or family property that doesn't automatically extend the same protections as the primary residence.

This is the case for working with a carrier built for this, not a generic policy stretched to fit. As a Cornerstone agency, this is the conversation we have with families every day, and it usually starts with one question: when was the last time someone actually walked through your coverage line by line, not just renewed it.

If it's been a few years, that's worth doing before your next renewal, not after a claim.

07/22/2026

A machine goes down on a Tuesday morning at a manufacturing plant outside Pittsburgh. Repair takes six weeks. The property policy covers the machine.

Nobody thought to ask what covers the six weeks.

This is a common coverage gap with manufacturers in Western Pennsylvania: property insurance protects the asset, but it doesn't protect the revenue you lose while that asset sits broken. Equipment breakdown coverage and business interruption are two different policies doing two different jobs, and a lot of manufacturers assume one includes the other.

Equipment breakdown covers the mechanical or electrical failure itself, boiler explosions, motor burnout, control panel failures. Business interruption covers what happens to your income while you're not producing. You need both, and they need to be sized to match how long a real repair actually takes for your specific equipment, not a generic industry average.

This conversation happens often enough with manufacturing clients to know the honest answer: most policies underestimate downtime. A CNC machine with a six-month lead time on replacement parts is a very different exposure than a conveyor belt you can fix in a day.

If you haven't reviewed your business interruption limits against your actual equipment lead times recently, that's worth twenty minutes at your next renewal conversation.

07/17/2026

Most business owners think ransomware is a big-company problem. It isn't.

Small and mid-sized businesses now get hit more often than large enterprises, mainly because attackers know the security budget usually isn't there.

Here's the part that catches people off guard even after they've bought a cyber policy: paying the ransom doesn't guarantee you get your data back, and it doesn't mean the attacker won't sell it anyway.

We have conversations with firms across Western Pennsylvania who assume their general liability policy covers a breach. It typically doesn't. Cyber liability is its own coverage, and the gaps we see most often are business interruption limits that are too low and no coverage at all for social engineering fraud.

A few questions worth asking at your next renewal:

1. Does your policy cover business interruption if a ransomware attack shuts down operations for two weeks?

2. Are wire fraud and social engineering scams covered, or just network breaches?

3. Do you have an incident response plan, or is the carrier's hotline the plan?

If it's been more than a year since you looked at this coverage, the market and the threats have both moved.

What's changed at your renewal this year on the cyber side?

Address

310-330 Grant Street, Suite 1320
Pittsburgh, PA
15219

Opening Hours

Monday 8:30am - 5pm
Tuesday 8:30am - 5pm
Wednesday 8:30am - 5pm
Thursday 8:30am - 5pm
Friday 8:30am - 5pm

Telephone

+14122612222

Alerts

Be the first to know and let us send you an email when Simpson & McCrady, LLC posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Simpson & McCrady, LLC:

Shortcuts

Featured

Share