Are there overlaps between Crime and Cyber coverage?

Brett Sadoff
Brett Sadoff

Brett Sadoff is a nationally recognized insurance executive with nearly three decades of experience specializing in professional lines and cyber risk at AIG, Hiscox and At-Bay.

Direct answer

Absolutely—but the more important issue is not the overlap. It is the potential gap between the policies. The easiest way to think about it is:

Classic Crime

Someone steals:

your money

Typical exposures include:

  • employee theft
  • forgery
  • counterfeit instruments
  • fraudulent transfers
  • social engineering, where covered
  • theft of securities

Classic Cyber

Someone compromises:

your systems, data or network

Typical exposures include:

  • ransomware
  • malware
  • system intrusion
  • data breach
  • privacy liability
  • business interruption
  • restoration costs
  • cyber extortion

Modern policies increasingly cross into each other’s territory, particularly around cyber-enabled financial fraud.

The classic overlap: Business Email Compromise

Suppose your CFO receives an email that appears to come from the CEO:

“Wire $2.5 million to this acquisition account immediately.”

The CFO sends the money.

There may have been:

  • no ransomware
  • no malware
  • no data destruction
  • no direct compromise of the insured’s network

But $2.5 million is gone.

Is it Crime?

Potentially.

Cyber?

Potentially.

Social Engineering Fraud?

Very likely the relevant coverage question.

An important distinction

Consider two different scenarios.

Scenario A — Hacker takes control

A hacker penetrates banking credentials and transfers:

$3 million

without an employee authorizing the transaction.

That is generally closer to:

Funds Transfer Fraud / Computer Fraud

Scenario B — Employee is deceived

A hacker impersonates the CEO and convinces an employee to voluntarily wire:

$3 million

That is generally closer to:

Social Engineering Fraud

The distinction matters because the available limits can be very different.

A company might carry:

$10M Crime Limit

but only:

$250K Social Engineering Sublimit

The headline crime limit therefore may tell you very little about the protection available for the actual loss.

Vendor invoice manipulation

Suppose a hacker compromises a vendor’s email account and tells your accounts-payable team:

“We’ve changed banks. Please send future payments to this new account.”

You wire $800,000.

Now the coverage questions become:

  • Was your network compromised?
  • Was the vendor’s network compromised?
  • Who suffered the direct loss?
  • Was the transfer authorized?
  • Was this social engineering?
  • Was it computer fraud?
  • Does Cyber respond?
  • Does Crime respond?
  • Were verification procedures required?

That is why Cyber and Crime should be viewed as a coordinated financial-loss program, not simply as two independent insurance policies.

Coverage Matrix

LossCyberCrime
RansomwarePrimaryGenerally no
Data breachPrimaryGenerally no
Network restorationPrimaryGenerally no
Cyber business interruptionPrimaryGenerally no
Employee theftGenerally noPrimary
Forgery / counterfeitLimited / generally noPrimary
Unauthorized electronic transferSometimesOften primary
Social engineeringSometimesSometimes
Business email compromisePotentiallyPotentially
Vendor impersonationPotentiallyPotentially
Client funds theftHighly wording-dependentHighly wording-dependent

“Potentially” is the important word.

The form governs.

Thanks — your question is in. If it's public, the best ones become a page here. If it's private, an editor will follow up by email. Short answers take longer than they look.

Submit A Question

Ask publicly The best questions become new pages here, anonymized.

Questions may be published in anonymized form. No mailing list, no quotes, no follow-up sales.

Ask privately Confidential — for a policy-specific read, answered by an editor, never published.

Kept confidential — used only to answer you, never sold, shared, or published. This is the only path where anything is attached.