Crime vs. Cyber Crime Insurance

Crime vs. Cyber Crime Insurance

Comparing crime vs. cyber crime Insurance is not always easy. Both policies may cover computer fraud, funds transfer fraud, or social engineering, however, the same loss can be treated very differently under each form.

 

An erroneous email, a hacked account, or a fraudulent wire does not necessarily tell you which policy will respond. Coverage may depend on who sent the instruction and whether an employee authorized the transfer. It may also depend on whose funds were lost and which insuring agreements were included.

 

In this article, we will explain what each policy is designed to cover. We will also look at where the two may overlap. Most importantly, we will explain how your firm can identify gaps before a fraudulent payment occurs.

 

What Does Commercial Crime Insurance Cover?

 

Commercial crime insurance is designed to protect your business against specific forms of theft and fraud. While employee theft remains one of its most important functions, current crime policies can extend beyond dishonest acts committed by employees.

 

Depending on the policy form, crime insurance may cover employee theft, forgery, or alteration. It may also cover money or securities stolen from your premises or while in transit. Other available agreements may address computer fraud, funds transfer fraud, social engineering, money orders, and counterfeit currency.

 

Not every commercial crime insurance policy automatically includes every one of these coverages, however. Each insuring agreement may have its own limit, retention, definitions, exclusions, and conditions.

 

Employee theft coverage generally applies when an employee intentionally takes covered property. Forgery or alteration coverage addresses a different exposure. It may respond when someone forges or changes a check, draft, or similar financial instrument.

 

Computer fraud and funds transfer fraud address different ways money can leave your firm. The exact triggers vary by policy. However, these provisions often focus on unauthorized computer activity or an instruction sent without your knowledge or consent.

 

That distinction is important. An outsider instructing the bank is one type of loss, while an employee authorizing a fraudulent request is another.

 

Because the transaction itself often determines which insuring agreement may apply, a crime vs. cyber crime insurance review must go beyond the name shown on the policy.

 

What Does Cyber Crime Insurance Cover?

 

Unlike commercial crime insurance, cyber crime coverage usually appears within a broader cyber insurance policy. That policy may also address data breaches, cyber extortion, data restoration, business interruption, and privacy liability. Each coverage remains subject to the terms of the policy.

 

For example, computer fraud coverage may require intentional and unauthorized activity within a computer system in order for the policy to respond. It may also require that the activity directly cause money or property to be transferred.

 

Funds transfer fraud, on the other hand, may involve someone impersonating you and sending instructions directly to your bank. When this happens, some cyber crime insurance forms require that the instructions were sent without the insured’s knowledge or consent in order for coverage to apply.

 

Social engineering addresses a different situation altogether. Here, a criminal deceives a legitimate employee into sending money or changing payment information. While the employee may have authority to make the payment, they act based on false information.

 

These definitions are not identical across the market, which is why the coverage name alone cannot determine how a claim will be handled. That distinction is central to any crime vs. cyber crime insurance review.

 

Where Crime vs. Cyber Crime Insurance May Overlap

 

Computer fraud, funds transfer fraud, and social engineering are the main areas of overlap between a commercial crime insurance policy and a cyber insurance policy. A carrier may provide these coverages under a crime policy, a cyber policy, or both. Additionally, the coverage may appear within the primary policy form or through an endorsement to the policy.

 

Social engineering is a particularly important example. A loss can begin with an email or compromised account. However, that alone does not make it a cyber claim.

 

Consider a criminal who gains access to a vendor’s email account. The criminal monitors an existing conversation and sends new banking information at the right moment. An employee receives the message, updates the vendor record, and releases the payment.

 

If the criminal instructed the bank directly, then funds transfer fraud may apply. The analysis changes, however, if an employee authorized the payment. That claim may fit more closely within social engineering coverage. Computer fraud might also be considered if unauthorized activity directly caused the transfer.

 

Further, social engineering is not limited to cyber insurance. Some carriers offer it through their commercial crime program as a separate endorsement.

 

The important takeaway here is that while a single incident may be reviewed under more than one policy, it does not mean that the commercial crime and cyber insurance policies will both respond. The policy terms will determine which policy provides the appropriate coverage. A complete crime vs. cyber crime insurance review should identify both coverage overlaps and gaps in coverage.

 

A Common Gap: When an Employee Authorizes Payment

 

One difficult fraud scenario begins with a legitimate employee making what appears to be a legitimate payment.

 

For example, a criminal may impersonate an executive, vendor, client, or other trusted party of your firm. The criminal then provides wiring instructions to an employee, which appear legitimate. The message may be spoofed or sent from a compromised account.

 

The employee believes the request is valid and authorizes the transfer. That transfer authorization becomes the basis of the coverage analysis.

 

Computer fraud and funds transfer fraud may require an unauthorized actor to cause the transfer. Funds transfer fraud may also require an instruction sent without the insured’s knowledge or consent.

 

Those requirements may not be satisfied when an employee instructs the bank. Notwithstanding the fact that a criminal actor may have caused the decision, the employee nonetheless intended to transfer the funds.

 

Some commercial crime policies also contain voluntary parting language. This may restrict coverage when the insured knowingly transfers property, even when deception caused the transfer.

 

Social engineering coverage may restore protection for certain losses, subject to the specific wording. Within a crime vs. cyber crime insurance review, this is often the most important gap to examine.

 

Your firm should confirm where that protection is provided in its insurance policies. You should also review the policy limits, sublimits, retention, verification requirements, and treatment of client funds.

 

The Policy Limit is Only the Starting Point

 

A cyber insurance policy with a $1 million limit may not provide $1 millions of coverage for social engineering or other financial fraud coverage. The same is true of a commercial crime policy.

 

The reason for this is that financial fraud coverage often carries a separate sublimit. That amount may be much lower than the overall policy limit. A separate retention may also apply.

 

A crime vs. cyber crime insurance comparison should start with the insuring agreements. Confirm whether each policy addresses computer fraud, funds transfer fraud, and social engineering. Similar names do not guarantee similar coverage.

 

Next, determine the limit available for each type of fraud in each policy. It’s important that you do not rely only on the overall policy limit.

 

Verification requirements also need close attention. Some forms require the insured to verify a payment request through a separate method of communication in order for coverage to apply. The policy may specify how that verification must occur.

 

The consequence of failing to verify varies by form. It could reduce the available limit or eliminate coverage for the loss altogether.

 

Additionally, be sure to check how each policy treats client funds. If both could apply, then review the “other insurance” provisions in each policy. Those terms may determine which insurer responds first, and to what extent.

 

Commercial crime insurance and cyber insurance forms may also have different reporting requirements. Prompt notice to the carrier following a suspected fraudulent transfer may help preserve coverage and improve the chances of stopping or recovering the transferred funds.

 

A Claims Scenario: The Vendor Payment

 

Imaging a consulting firm that regularly pays its technology vendor by electronic transfer. One morning, the firm’s controller receives an email that appears to come from the usual vendor contact.

 

The message explains that the vendor has changed banks. It also provides new payment instructions for an outstanding $180,000 invoice.

 

The controller accepts the email as legitimate and updates the vendor record and releases the payment. Several days later, the actual vendor reports that the invoice remains unpaid. The controller suspects the original email was fraudulent and files a claim with both the company’s commercial crime and cyber insurance carriers.

 

As part of the claim adjusting process, each insurer will examine how the email message was sent and who instructed the bank. They may also ask whether an email account was compromised. The firm’s verification procedures may matter here as well.

 

The insurers will also review the respective policy’s social engineering coverage, the applicable policy sublimits, and the coordination between the two policies.

 

The ultimate outcome of the claim will depend on the facts and the policy language. Your firm should understand these distinctions before it experiences a loss.

 

Reducing the Risk Before Money Leaves

 

Insurance should only ever be one part of the equation when it comes to protecting your firm. Robust risk management processes and procedures are also a must. That includes having strong payment controls in place which can help stop a fraudulent instruction from becoming a financial loss in the first place.

 

For example, your firm should independently verify every change to payment instructions. Additionally, employees should only ever use contact information that was already on file. Further, they should not rely on a telephone number provided in a new email request that is not separately verified.

 

Also, large funds transfers should require approval from at least two authorized employees of your firm. When practical, different employees should enter and approve changes to payment information.

 

Further, your firm should use multifactor authentication for email and financial systems, and written procedures should address urgent payment requests. Additionally, employee training should always reflect the firm’s actual workflow.

 

Your firm’s robust risk management controls can help support the insurance underwriting process. More importantly, they give employees permission to slow down when a request does not feel right.

 

Matching Coverage to the Way Your Firm Moves Money

 

There is no universal answer about where financial fraud coverage should sit. The right structure depends on how your firm operates.

 

Start by identifying who within your company can authorize payments and how your firm receives instructions. Then determine whether your firm controls client funds. Your verification procedures should also be part of the review.

 

The goal is not to buy duplicate coverage for the sake of having two policies. It is to understand how a loss could occur. At least one policy should address that loss clearly and at an adequate limit.

 

At BR Risk Group™ Specialty Insurance Services, LLC, we review crime and cyber coverage together. We compare the definitions, sublimits, retentions, verification requirements, and other insurance provisions that may determine coverage.

 

If you are unsure how your policies would respond to a fraudulent payment, now is the time to find out. Visit brriskgroupins.com, email info@brriskgroupins.com, or call 877 208 2455 to speak with BR Risk Group™ Specialty Insurance Services, LLC.

 

 

 

Disclaimer: This content is for informational purposes only and should not be considered as legal or financial adviceCoverage varies by carrier and form; always review your specific policy and endorsements.

 

 

 

 

 

Leave a Reply

Your email address will not be published. Required fields are marked *