Here is the loss. Your bookkeeper gets an email from a supplier you've paid for six years. New remittance instructions, new account number, polite and unremarkable. She updates the vendor record and pays the next invoice. Three weeks later the real supplier calls asking where their money is.
Nobody hacked anything. Nobody forged a signature. A real employee with real authority made a real transfer. That is exactly why the two policies you'd expect to cover it may both deny it.
The coverage that responds is a specific, separately-elected insuring agreement — usually called social engineering fraud, deception fraud, or fraudulent instruction — and it carries its own sub-limit and its own conditions. If it isn't named on your declarations page, assume you're self-insuring the loss.
The scheme is always the same underneath — convince a trusted person to move money — but it arrives in four recognizable forms:
Contractors get hit disproportionately on the first one, because construction payment chains involve many vendors, large progress payments, and email-based invoicing across parties who rarely meet in person.
A commercial crime policy is a stack of separate insuring agreements. The three people assume will catch this each contemplate something that didn't happen:
| Insuring agreement | What it contemplates | Why the wire loss may fall outside |
|---|---|---|
| Computer fraud | A criminal directly entering or altering your computer systems to cause a transfer | Nobody entered your system — they sent an email |
| Funds transfer fraud | A fraudulent instruction sent to your bank without your knowledge | The instruction to the bank came from you, knowingly |
| Forgery or alteration | A falsified signature or financial instrument | No instrument was forged |
| Employee dishonesty | Theft by your own employee for their own gain | Your employee was deceived, not dishonest |
Whether a given policy responds anyway has been litigated repeatedly, with results that differ by jurisdiction, by policy wording, and by fact pattern — which is a polite way of saying you do not want your recovery to depend on it. Carriers resolved the ambiguity in the only way carriers do: by writing an explicit endorsement, and by tightening the base wording so the ambiguity is gone in the other direction.
A cyber liability policy is built around the data-and-network event: breach response and notification, regulatory defense, liability to affected parties, network business interruption, ransomware and extortion. Those are real and valuable coverages, and none of them is "we sent money to a criminal."
Direct financial loss from a fraudulently induced transfer sits in an optional insuring agreement — funds transfer fraud, cybercrime, social engineering, fraudulent instruction, the naming is not standardized — and when it is included, it very often comes at a sub-limit well below the policy aggregate. A $1M cyber policy with a $25,000 social engineering sub-limit is a completely ordinary thing to be holding without knowing it.
Do this today: pull the declarations page and look for the insuring agreement by name, then look at the number next to it. Not the policy aggregate — the number next to that line.
This is the part that matters most and gets read least.
Most social engineering endorsements include a condition precedent requiring verification before you execute a transfer request or a change in payment instructions: someone must confirm the request through a different channel than the one it arrived on — typically a phone call to a number already on file for that vendor, not a number supplied in the request itself.
Skip that step and the carrier can deny the claim even though the endorsement is on the policy and the loss is precisely what it describes. This is the single most common reason a business with the right coverage collects nothing.
So treat it as an operating procedure, not policy boilerplate. Write it down. Post it at the AP desk. Make it the rule that nobody — including the owner — is allowed to override by saying it's urgent, because "it's urgent" is the fraud.
| Coverage | Typical sub-limit | Illustrative annual premium* |
|---|---|---|
| Social engineering endorsement on a crime policy | $100,000–$250,000 | ~$400–$2,000 |
| Funds transfer fraud on a cyber policy | $25,000–$250,000 | Often bundled; higher sub-limits cost extra |
| Standalone crime policy (small business, full form) | $250,000–$1M | ~$800–$3,500 |
*Illustrative only — not filed rates. Pricing varies by revenue, transaction volume, industry, prior loss history, and the payment controls you can document.
Two things about that table are worth sitting with. First, the premium is small relative to a single event — a five-figure annual spend does not exist here, and a six-figure loss absolutely does. Second, controls buy limit. Carriers will offer meaningfully higher sub-limits and better pricing to a business that can demonstrate dual authorization and documented out-of-band verification, and some won't offer a serious limit at all without them. The underwriting question and the prevention question have the same answer.
Social engineering coverage sits at the intersection of two policies and belongs to neither by default, which is exactly why it gets missed when a business buys insurance one line at a time from different sources. The clean structure for most Southeast small businesses is a crime policy carrying employee dishonesty plus a social engineering endorsement, alongside a cyber policy handling breach response and network interruption — with someone checking that the two don't leave a seam between them. Insider theft and outsider deception are genuinely different exposures and you need both covered; neither endorsement substitutes for the other.
Bettr Coverage is an independent commercial insurance agency serving Georgia and the wider Southeast. Social engineering is the coverage most often missing from an otherwise well-built program, usually because the crime policy and the cyber policy came from two different places and nobody read them side by side. We pull both declarations pages, confirm whether the insuring agreement exists and at what sub-limit, read the verification condition out loud so your AP process actually matches it, and size the limit against the largest transfer your business realistically makes in a week. One agency, one relationship, the whole program reviewed together — which is how seams like this one get found before a claim rather than after.
Most owners can't — and the number is usually far below the wire they'd actually lose. Bettr Coverage reviews your crime and cyber policies side by side, free.
Get a free coverage reviewA loss where an employee is deceived into voluntarily transferring money — fake vendor bank changes, executive impersonation, compromised mailboxes, payroll diversion. Nothing is hacked and nothing is forged, which is precisely what creates the coverage gap.
Often not without a specific endorsement. Computer fraud, funds transfer fraud, and forgery all contemplate unauthorized acts, and this transfer was authorized by your own employee. Look for a social engineering or deception fraud endorsement by name.
Not automatically. Cyber is built around breach and network events. Direct financial loss from a fraudulent instruction is a separate optional insuring agreement, usually at a sub-limit well below the policy aggregate. Verify it's on your declarations page.
Roughly a few hundred to about $2,000 a year for a $100,000–$250,000 sub-limit added to a crime policy, depending on revenue, transaction volume, and the payment controls you can document. Better controls get better limits and better pricing.
Most endorsements require verifying a transfer or payment-change request through a channel other than the one it arrived on — a call to a number already on file. Skip it and the carrier can deny even though the endorsement is on the policy. It's the most common reason covered businesses collect nothing.
No. Employee dishonesty covers theft by your own staff for their own gain. Social engineering covers an outsider deceiving a loyal employee. Different insuring agreements, and neither substitutes for the other — most businesses need both.
Never change vendor banking from an email; call a known number. Require dual authorization above a threshold. Train on urgency, secrecy, and payment-method changes. MFA and email authentication on all mailboxes. And if it happens, notify the bank and law enforcement within hours, not days.
For general information only. Not a quote, contract of insurance, or legal advice. Cost ranges and sub-limits are illustrative, not filed rates, and vary by revenue, transaction volume, industry, controls, and loss history. Insuring agreement names, definitions, sub-limits, exclusions, and verification conditions differ materially by carrier and policy form — read your own declarations page and endorsements. Coverage litigation outcomes referenced are general and jurisdiction-dependent. Coverage subject to policy terms and carrier appetite.