Cyber crime insurance, and why a stolen payment is a different claim from a hack

Cyber crime insurance answers for money that left the business because somebody was deceived, which is a different event from a system being broken into. No malware, no breach, no forensic investigation: an email that looked exactly like a supplier, a bank detail that had been quietly changed, and a payment made by a person doing their job properly. It is the loss small firms most often actually suffer, and the one a basic cyber policy is least likely to pay.

Why it sits in its own section

Traditional cyber cover was built around data and systems. A payment made voluntarily on a false instruction damages neither, so the loss falls outside the first party costs section and outside the liability section. Insurers answered by writing a separate crime or social engineering section, with its own limit, its own excess and its own conditions. If the schedule does not name that section, assume the loss is not covered rather than assuming it is.

The conditions that decide the claim

Almost every crime section requires verification of a change to payment details by a means other than the one that requested it, usually a telephone call to a number you already held. Some require dual authorisation above a stated amount. These are conditions, not suggestions: a firm that paid on an emailed change without ringing the number it already had will usually find the claim argued. Writing the verification step into the finance process is what makes the cover real.

What counts as cyber crime for a policy

Funds transfer fraud, where a payment is diverted. Invoice fraud, where a genuine supplier's invoice is intercepted and altered. Impersonation of a director or a client. Theft of the firm's own funds through compromised banking credentials. Extortion where a ransom is demanded, though that usually sits in the cyber section rather than the crime one. Theft of a client's money held by you is often a separate fidelity question and worth asking about explicitly.

Reporting, and what has to happen quickly

A diverted payment is sometimes recoverable if the bank is told within hours, so the first call is to the bank, then to the police through Action Fraud, then to the insurer. Most wordings require prompt notification and cooperation with any recovery attempt. Where personal data was also taken, the data protection reporting duty runs in parallel and on its own short clock.

Questions people ask about cyber crime insurance

Is social engineering covered by a standard cyber policy?

Frequently not. It is usually a named section that has to be added, with a sub limit smaller than the main one. Check the schedule for the words crime, social engineering or funds transfer fraud.

What if my client was defrauded using my compromised email?

That is a liability question rather than a first party one, and it may fall to the liability section of a cyber policy or to professional indemnity depending on the wording. It is one of the clearest reasons to hold both and to check how they interlock.

Does the bank not refund it?

Reimbursement rules for authorised push payment fraud have improved for consumers and small businesses, but recovery is not guaranteed and depends on the circumstances and on how quickly it was reported. Insurance answers for what is not recovered.

Do I have to report it to the police?

Report fraud and cyber crime through Action Fraud. Most policies require it, and a crime reference number is usually part of the claim file.

Sources

Related answers

See what insurers printCompare by trade