Are there overlaps between Crime and Cyber coverage?
Absolutely—but the more important issue is not the overlap. It is the potential gap between the policies. The easiest way to think about it is:
Classic Crime
Someone steals:
your money
Typical exposures include:
- employee theft
- forgery
- counterfeit instruments
- fraudulent transfers
- social engineering, where covered
- theft of securities
Classic Cyber
Someone compromises:
your systems, data or network
Typical exposures include:
- ransomware
- malware
- system intrusion
- data breach
- privacy liability
- business interruption
- restoration costs
- cyber extortion
Modern policies increasingly cross into each other’s territory, particularly around cyber-enabled financial fraud.
The classic overlap: Business Email Compromise
Suppose your CFO receives an email that appears to come from the CEO:
“Wire $2.5 million to this acquisition account immediately.”
The CFO sends the money.
There may have been:
- no ransomware
- no malware
- no data destruction
- no direct compromise of the insured’s network
But $2.5 million is gone.
Is it Crime?
Potentially.
Cyber?
Potentially.
Social Engineering Fraud?
Very likely the relevant coverage question.
An important distinction
Consider two different scenarios.
Scenario A — Hacker takes control
A hacker penetrates banking credentials and transfers:
$3 million
without an employee authorizing the transaction.
That is generally closer to:
Funds Transfer Fraud / Computer Fraud
Scenario B — Employee is deceived
A hacker impersonates the CEO and convinces an employee to voluntarily wire:
$3 million
That is generally closer to:
Social Engineering Fraud
The distinction matters because the available limits can be very different.
A company might carry:
$10M Crime Limit
but only:
$250K Social Engineering Sublimit
The headline crime limit therefore may tell you very little about the protection available for the actual loss.
Vendor invoice manipulation
Suppose a hacker compromises a vendor’s email account and tells your accounts-payable team:
“We’ve changed banks. Please send future payments to this new account.”
You wire $800,000.
Now the coverage questions become:
- Was your network compromised?
- Was the vendor’s network compromised?
- Who suffered the direct loss?
- Was the transfer authorized?
- Was this social engineering?
- Was it computer fraud?
- Does Cyber respond?
- Does Crime respond?
- Were verification procedures required?
That is why Cyber and Crime should be viewed as a coordinated financial-loss program, not simply as two independent insurance policies.
Coverage Matrix
| Loss | Cyber | Crime |
|---|---|---|
| Ransomware | Primary | Generally no |
| Data breach | Primary | Generally no |
| Network restoration | Primary | Generally no |
| Cyber business interruption | Primary | Generally no |
| Employee theft | Generally no | Primary |
| Forgery / counterfeit | Limited / generally no | Primary |
| Unauthorized electronic transfer | Sometimes | Often primary |
| Social engineering | Sometimes | Sometimes |
| Business email compromise | Potentially | Potentially |
| Vendor impersonation | Potentially | Potentially |
| Client funds theft | Highly wording-dependent | Highly wording-dependent |
“Potentially” is the important word.
The form governs.
