Don’t Succumb To Cyber Fraud

2

Proper insurance coverage can save your company time and money.

By Kevin DiPetrillo, Partner, PointeNorth Insurance Group

A standalone cyber policy, paired with employee awareness training and strong banking controls, can help your business prepare for a loss that could otherwise be financially devastating.

I recently acquired a new client who came to us after experiencing every business owner’s nightmare: A $95,000 loss from a cyber scam and no insurance recovery. The company believed it had the right protection. Its previous insurance agent had assured the owners that their cyber coverage would respond. Unfortunately, both the business and the agent misunderstood an important limitation in the policy.

How the fraud occurred
The scam began with a phone call. A criminal contacted the company’s controller and persuaded her to sign into a fraudulent website using her real business credentials. That single action gave the criminals access to the company’s checking account. They quickly transferred $95,000 out of the account before the bank alerted the business. The company froze its accounts immediately, but by then, the funds had already been wired through receiving accounts and could not be recovered.

This type of crime is known as social engineering fraud. Rather than trying to break through sophisticated computer defenses, criminals manipulate employees into giving them access, approving payments, or sharing sensitive information. Unfortunately, even well-run businesses can be vulnerable when a convincing request arrives by phone, email, or text.

Why insurance did not pay
The business did have cyber coverage, but it was included as an endorsement on its Commercial Package Policy rather than purchased as a standalone cyber insurance policy. That distinction matters.

Cyber endorsements added to business packages or business owners’ policies can provide a helpful starting point, but they are usually narrow in scope and carry lower coverage limits. They may also exclude — or severely limit — common events such as social engineering fraud, cyber extortion, ransomware, and certain technology failures.

In this case, the policy showed a $50,000 cyber limit. However, even if the claim had met the policy’s narrow definition of covered fraud, the applicable sublimit would have been only $5,000. The client’s best possible outcome would have covered only a small fraction of the $95,000 loss. Ultimately, the insurance paid nothing.

Ask better questions
Cyber insurance has evolved quickly, and policy language can vary significantly from one insurer to another. It is not enough to see the word “cyber” on a policy declaration page; business owners need to understand what events are covered, what limits apply, and what exclusions may affect a claim.

When reviewing your coverage, ask your agent to walk through realistic scenarios, such as:

  • An employee enters credentials on a fraudulent website.
  • A scammer impersonates a vendor and requests a payment change.
  • Your business is locked out of its systems by ransomware.
  • Criminals threaten to release customer or employee data.
  • A fraudulent wire transfer or ACH payment leaves your business account.

Ask a simple but important follow-up: “Would this specific loss be covered, and how much would the policy pay?” A knowledgeable agent should be able to explain the answer clearly, including any deductibles, exclusions, and sublimits.

Small businesses are targets
Small and midsize businesses are not too small to attract cybercriminals. The 2024 Verizon Data Breach Investigations Report found that 43 percent of cyberattack targets were businesses with fewer than 500 employees.

Criminals often focus on these organizations because they may have fewer technical safeguards, less formal employee training, and limited resources devoted to cybersecurity. At the same time, many owners underestimate the risk because they assume hackers only pursue large corporations.

The good news is that cyber insurance pricing has become more competitive in recent years. If you considered coverage before and decided it was too expensive — or assumed a small endorsement was enough — this is a good time to take another look.

A standalone cyber policy, paired with employee awareness training and strong banking controls, can help your business prepare for a loss that could otherwise be financially devastating.

KEVIN DIPETRILLO is a Partner at PointeNorth Insurance Group. With a degree in Risk Management from The University of Georgia, he has been helping businesses and High Net Worth households with their insurance needs for 25 years. Visit pointenorthins.com to see how the company can serve your needs.