Connect coverage, controls, response, and recovery
Criminals exploit trust, urgency, authority, and familiar business processes. Email compromise, vendor impersonation, executive requests, altered invoices, and AI-generated voice or video can bypass ordinary approval habits. Cyber, crime, fidelity, and funds-transfer provisions should be reviewed together because definitions, triggers, verification duties, and sublimits differ.
Risks to review
- Vendor, executive, employee, customer, or bank impersonation
- Altered payment instructions and fraudulent invoices
- AI-generated voice, video, identity, or document deception
- Coverage gaps between cyber, crime, and financial institution agreements
Information to prepare
- Payment approval, callback, dual-control, and account-change procedures
- Email security, multifactor authentication, access, and vendor controls
- Maximum transaction values, payment volume, and banking relationships
- Prior fraud attempts, incidents, controls, and employee training
Frequently asked questions
Is social-engineering fraud automatically covered by cyber insurance?
Do not assume it is. Coverage may be excluded, endorsed, sublimited, or addressed under a crime policy. Actual definitions and verification requirements control.
What control is most useful when payment instructions change?
Independent verification using a trusted contact method is an important control. Procedures should also address dual approval, access, limits, and escalation.
Coverage descriptions are general. Availability, eligibility, limits, waiting periods, deductibles, exclusions, sublimits, services, and policy terms vary. Actual policy documents control.
