SPECIALTIES

Cyber Crime Insurance

A single fraudulent wire instruction can drain a six-figure sum from your operating account in under an hour. The funds rarely come back. Cyber crime insurance exists to absorb that financial shock, yet most business owners confuse it with standard cyber liability or assume their bank will make them whole. Neither assumption holds up when a claim hits. This guide breaks down the six major crime coverages found in modern cyber and crime policy forms: computer fraud, funds transfer fraud, social engineering fraud, invoice manipulation, cryptocurrency theft, and telecom fraud. Each one responds to a different attack method, and the gaps between them are where businesses lose money. Understanding how these insuring agreements work, and where one stops and another starts, is the difference between a policy that pays and a policy that disappoints. Roughly 60% of all cyber insurance claims now stem from business email compromise and funds transfer fraud, making crime coverage the most likely section of your policy to be tested. If you are buying your first or second cyber policy, this is the coverage block that deserves the closest reading.

Understanding Cyber Crime Insurance and Why It Matters

Cyber crime coverage is a subset of a broader cyber insurance policy, but it functions more like a commercial crime form than a traditional liability policy. It pays first-party losses: money stolen from your accounts, not damages you owe a third party. The trigger is typically a theft event, not a data breach or a lawsuit.


Most mid-market companies carry some form of commercial crime coverage already, often bundled into a Business Owners Policy or purchased as a standalone fidelity bond. The problem is that those legacy forms were written before wire fraud, cryptocurrency wallets, and AI-generated voice clones became standard attack tools. A policy written in 2018 may not contemplate a 2026 threat.

The Difference Between Cyber Liability and Cyber Crime

Cyber liability responds to breach events: notification costs, regulatory defense, forensic investigations, and third-party lawsuits. Cyber crime responds to theft events: money leaving your account because someone manipulated a system or a person. These are two distinct insuring agreements, and they sit in different parts of the policy form.


A ransomware demand, for instance, may trigger both the cyber extortion coverage under your liability section and a funds transfer fraud claim if the attacker also redirected a wire. Treating them as interchangeable leads to coverage gaps. At Bloc Cyber, the practice of reviewing each insuring agreement at the form level exists precisely because these distinctions matter at claim time.

Why Standard Commercial Property Policies Fall Short

Commercial property policies cover tangible losses: fire, theft of physical inventory, equipment damage. Money lost through electronic manipulation does not fit neatly into those forms. Most commercial property policies exclude losses arising from voluntary parting of funds, which is exactly what happens when an employee is tricked into sending a wire to a fraudulent account.


Even standalone commercial crime forms often contain exclusions for losses involving electronic communications or computer systems unless a specific endorsement is added. The gap is real, and it is the primary reason dedicated cyber crime coverage exists as a separate product.

By: Caden Braly

Founder of Bloc Cyber Insurance

Bloc Cyber and Its Licensed Producers Are Authorized to Place Cyber Coverage in All 50 U.S. States and The District of Columbia.


Cyber liability insurance covers the financial losses your business faces after a cyberattack or data breach. This page explains what the coverage includes, who needs it, what it costs, and how Bloc Cyber helps you get protected fast.

We start with a twenty-minute call to walk through your contracts, your draw process, your tech stack, and the last twelve months of attempted fraud. From there we go to market with ten-plus carriers, benchmark terms side-by-side, and present the options in plain language with recommended limits and retentions. Most intakes get indicative terms within one business day.

Forensic Investigations: Identifying the Source and Scope

Forensic investigators determine how the attacker got in, what data was accessed, whether exfiltration occurred, and whether the threat actor is still present in the network. Their report drives every downstream decision: which individuals must be notified, whether payment card brands must be alerted, and what remediation steps are necessary. Forensic engagements for mid-market companies commonly run between $30,000 and $150,000, depending on the complexity of the environment. The policy form may impose a separate sublimit on forensic costs or bundle them under a single breach response aggregate. Bloc Cyber reviews these sublimits at the insuring-agreement level before binding, so clients understand exactly how much forensic coverage they are purchasing and where the cap sits relative to their actual exposure.

Core Coverage: Computer Fraud and Funds Transfer Fraud

These two coverages form the backbone of any cyber crime insurance program. They address different attack vectors but often overlap in practice, which is why the policy language matters.

How Computer Fraud Coverage Protects Against Unauthorized Access

Computer fraud coverage typically responds when a third party gains unauthorized access to your computer system and directly causes a transfer of money, securities, or property. The key word is "directly." If a hacker breaks into your accounting software and initiates a wire, that is a direct cause. If a hacker steals your credentials and then calls the bank pretending to be you, some forms will argue the cause was not direct enough.


Courts have split on this issue repeatedly. The policy form's definition of "computer system" and "direct cause" will determine whether your claim is paid. A form-level review before binding, not after a loss, is the only way to know where you stand.

Understanding Funds Transfer Fraud and Electronic Instructions

Funds transfer fraud coverage responds when a third party issues fraudulent electronic instructions to your bank or financial institution, causing money to leave your account without your authorization. This is distinct from computer fraud because the attack targets the transfer mechanism itself, not your internal systems.


A common scenario: an attacker compromises your email, monitors invoice traffic for weeks, then sends a spoofed wire instruction to your bank using your email address. The bank processes the wire. Your funds transfer fraud coverage should respond here, but sublimits and retentions vary widely. Some forms cap this coverage at $100,000 or $250,000, well below the loss amounts that are growing more expensive per incident.

We start with a twenty-minute call to walk through your contracts, your draw process, your tech stack, and the last twelve months of attempted fraud. From there we go to market with ten-plus carriers, benchmark terms side-by-side, and present the options in plain language with recommended limits and retentions. Most intakes get indicative terms within one business day.

Protecting Against Deception: Social Engineering and Invoice Manipulation

Not every theft involves a hacker breaking into a system. Some of the most expensive losses occur when a human being is simply deceived into doing something they believe is legitimate.

Social Engineering Fraud: When Employees Are Tricked

Social engineering fraud coverage responds when an employee is manipulated into voluntarily transferring funds to a criminal. The classic example is the CEO impersonation email: "I need you to wire $85,000 to this account for a confidential acquisition. Do it now and do not discuss it with anyone." The employee complies. The money is gone.


This coverage is almost never included in the base cyber policy form. It is typically added by endorsement, and it frequently carries a sublimit lower than the main policy aggregate. A $1 million cyber policy might include only $100,000 in social engineering coverage unless you negotiate a higher limit at placement. The rise in identity theft-linked insurance fraud projected through 2025 and into 2026 reflects how profitable these schemes have become for criminals.

Invoice Manipulation: Protecting Your Accounts Receivable

Invoice manipulation is a variation of business email compromise where the attacker intercepts legitimate invoices and alters the payment instructions. Your customer pays the invoice in good faith, but the money goes to the attacker's account instead of yours. You are left with an unpaid receivable and a customer who believes they already paid.


Some policy forms treat this as a social engineering loss. Others classify it under funds transfer fraud or computer fraud depending on how the manipulation occurred. The distinction matters because each insuring agreement may carry different limits, retentions, and conditions. If your policy form does not specifically address invoice manipulation, you may find yourself arguing over which coverage applies while the claim sits unpaid.

We start with a twenty-minute call to walk through your contracts, your draw process, your tech stack, and the last twelve months of attempted fraud. From there we go to market with ten-plus carriers, benchmark terms side-by-side, and present the options in plain language with recommended limits and retentions. Most intakes get indicative terms within one business day.

Coverage Element Commercial General Liability Cyber Insurance
Data breach notification costs Not covered Covered under first-party
Ransomware payment Not covered Covered (subject to sublimit)
Regulatory defense Not covered Covered under third-party
Business interruption from cyberattack Not covered Covered with waiting period
Funds transfer fraud Not covered Covered via cyber crime endorsement
Third-party lawsuit over data loss Excluded or severely limited Covered under third-party liability
Technology product failure Not covered Covered under Tech E&O

Emerging Threats: Cryptocurrency Theft and Telecom Fraud

The threat environment keeps expanding, and policy forms are catching up at different speeds. Two areas that remain inconsistently covered are digital asset theft and telecom fraud.

Insuring Digital Assets and Crypto Wallets

If your business holds cryptocurrency, whether as a payment method, treasury asset, or customer funds, traditional crime forms do not cover it. Cryptocurrency is not "money" or "securities" under most policy definitions. A dedicated digital asset endorsement or a standalone crypto crime policy is required.


Coverage typically applies to theft from hot wallets through unauthorized access, but cold storage losses and private key compromise present underwriting challenges. The potential for quantum computing to disrupt cryptographic protections adds a forward-looking risk that underwriters are beginning to price. If your firm holds digital assets, confirm that the policy form explicitly names cryptocurrency in the covered property definition.

Telecom Fraud: Who Pays for Unauthorized Phone Charges?

Telecom fraud occurs when an attacker compromises your phone system, typically a PBX or VoIP platform, and routes thousands of dollars in long-distance or premium-rate calls through your account. The telecom carrier bills you. Your standard business insurance will not cover it.


Some cyber crime forms include telecom fraud as a named coverage; others exclude it entirely. The losses can be substantial: a compromised PBX running over a holiday weekend can generate $50,000 or more in fraudulent charges before anyone notices. Ask your broker whether the form includes telecom fraud and what the sublimit is.

We start with a twenty-minute call to walk through your contracts, your draw process, your tech stack, and the last twelve months of attempted fraud. From there we go to market with ten-plus carriers, benchmark terms side-by-side, and present the options in plain language with recommended limits and retentions. Most intakes get indicative terms within one business day.

FAQ: Does my general business insurance cover hacking?

Almost certainly not. Standard CGL and BOP policies contain electronic data exclusions. Even if your policy has a small "data breach" endorsement, it is typically capped at $50,000 to $100,000, which will not cover a meaningful incident. A standalone cyber liability form provides the breadth and limits required for a real claim.

Comparison: Standard Cyber vs. Enhanced Crime Coverage

Coverage Element Standard Cyber Liability Enhanced Cyber Crime
Data breach response Included Not typically included
Regulatory defense Included Not typically included
Computer fraud Sometimes included Included with higher limits
Funds transfer fraud Often sublimited Full limit available
Social engineering Rarely included in base form Available by endorsement
Invoice manipulation Varies by form Explicitly addressed
Cryptocurrency theft Excluded Available by endorsement
Telecom fraud Excluded Available by endorsement

The difference between these two columns is often a matter of endorsements and sublimits, not separate policies. A specialist agency like Bloc Cyber reviews these line items before binding so you know exactly what triggers each coverage and what falls outside the form.

We start with a twenty-minute call to walk through your contracts, your draw process, your tech stack, and the last twelve months of attempted fraud. From there we go to market with ten-plus carriers, benchmark terms side-by-side, and present the options in plain language with recommended limits and retentions. Most intakes get indicative terms within one business day.

Coverage Element Commercial General Liability Cyber Insurance
Data breach notification costs Not covered Covered under first-party
Ransomware payment Not covered Covered (subject to sublimit)
Regulatory defense Not covered Covered under third-party
Business interruption from cyberattack Not covered Covered with waiting period
Funds transfer fraud Not covered Covered via cyber crime endorsement
Third-party lawsuit over data loss Excluded or severely limited Covered under third-party liability
Technology product failure Not covered Covered under Tech E&O

Common Questions About Cyber Crime Insurance

Does my bank cover me if my business account is hacked?

Most commercial banking agreements place the liability for unauthorized electronic transfers on the account holder, not the bank, once the bank has followed its standard security procedures. Your bank is not your insurer. A dedicated funds transfer fraud policy is the appropriate risk transfer mechanism.

What is the difference between phishing and social engineering?

Phishing is a delivery method: a fraudulent email designed to steal credentials or install malware. Social engineering is broader and includes phone calls, text messages, and in-person deception. A phishing email that leads to credential theft may trigger computer fraud coverage, while a phone call that tricks an employee into wiring funds triggers social engineering coverage.

Is cyber crime insurance expensive for small businesses?

Premiums for small businesses with 10 to 100 employees typically range from a few hundred to a few thousand dollars annually, depending on revenue, industry, and the limits selected. Cyber insurance market conditions have stabilized heading into 2026, making coverage more accessible than it was during the hard market of 2022-2023.

Do I need this if I already have a general liability policy?

Yes. General liability excludes electronic theft, wire fraud, and virtually every scenario described in this guide. There is no overlap between a GL form and a cyber crime insuring agreement.

Will insurance pay if an employee makes a mistake?

It depends on the mistake. If an employee is deceived into sending a wire by a social engineering attack, the social engineering endorsement may respond. If an employee simply sends money to the wrong account due to carelessness, most forms will not cover the loss. The policy language around "voluntary parting" and "fraudulent inducement" controls the outcome.

We start with a twenty-minute call to walk through your contracts, your draw process, your tech stack, and the last twelve months of attempted fraud. From there we go to market with ten-plus carriers, benchmark terms side-by-side, and present the options in plain language with recommended limits and retentions. Most intakes get indicative terms within one business day.

FAQ: Does my general business insurance cover hacking?

Almost certainly not. Standard CGL and BOP policies contain electronic data exclusions. Even if your policy has a small "data breach" endorsement, it is typically capped at $50,000 to $100,000, which will not cover a meaningful incident. A standalone cyber liability form provides the breadth and limits required for a real claim.

The Bottom Line: Securing Your Business Assets

Cyber crime insurance is not a single coverage. It is a collection of insuring agreements, each written to respond to a specific theft scenario. Computer fraud, funds transfer fraud, social engineering, invoice manipulation, cryptocurrency theft, and telecom fraud all operate under different triggers, definitions, and limits within the same policy form. Buying a cyber policy without reading those individual grants is like locking your front door while leaving every window open.


The most common mistake mid-market buyers make is assuming that a bundled cyber policy covers all crime scenarios at full limits. It rarely does. Sublimits on social engineering, exclusions for digital assets, and narrow definitions of "direct cause" are the gaps that cost businesses real money when a claim is filed.


If you have not had your policy form reviewed at the insuring-agreement level, now is the time. A Bloc Cyber specialist can walk through each coverage grant, identify where the form stops, and show you what it will cost to close those gaps before a loss finds them. Request a review and know exactly what your policy will and will not pay.

ABOUT THE AUTHOR

Caden Braly

— Founder, Bloc Cyber

I'm Caden Braly, founder of Bloc Cyber, the specialty cyber insurance arm of Braly Insurance. I built Bloc Cyber around one idea: businesses deserve coverage that actually responds when a cyberattack happens. I work closely with clients to understand their exposure, place the right policy through specialty carriers, and stand with them through the claim. My goal is simple — give every business straight answers and protection they can trust.

Full profile → caden@bloccyber.com LinkedIn

Industries We Protect

Cyber Coverage Built for Your Industry

Every industry faces a different cyber threat, from patient records in healthcare to wire fraud in construction. Bloc Cyber matches coverage to the risks your sector actually faces, drawing on specialty carriers that understand your business. Find your industry below to see how we protect it.

Healthcare

HIPAA-grade protection for patient data

725

healthcare breaches disclosed in 2024

HIPAA-grade protection for patient data

Ransomware on EHR systems

PHI exfiltration

Medical device exploits

Business email compromise

Sub-sectors we place

Hospitals and health systems
Physician practices and specialty clinics
Dental practices and DSOs
Behavioral health and addiction treatment centers
Medical billing and revenue cycle management firms


Typical turnaround for indication of terms: 1 business day.

The Bloc system

One foundation.
Ten industry-specific builds.

The Bloc mark is built from stackable planes — each one a different angle on the same core structure. That’s how we place coverage: one underwriting discipline, tuned and re-tuned for every industry we serve.

Coverage

A policy you can actually read.
Structured in three clean blocs.

01

First-Party

Your direct losses when an incident hits your business.

Incident response & forensics

Business interruption

 Data restoration

 Cyber extortion / ransomware

 Funds transfer fraud

Reputational harm

02

Third-Party

Your liability to clients, partners, and regulators.

Network security liability

Privacy liability (HIPAA, GDPR, state laws)

 Regulatory defense & fines

 PCI-DSS fines and assessments

 Media liability

Breach notification costs

03

Specialty

Advanced coverages for complex risks and contracts.

Technology E&O

Social engineering fraud

 Contingent business interruption

 Systems failure

 Bricking & hardware replacement

CMMC / regulatory-specific endorsements

Typical limits placed

$1M / $1M starter

$5M / $10M mid-market

$25M+ layered towers

Custom retentions

Common Questions

Cyber Liability Insurance, Explained

  • What does cyber insurance cover?

    Cyber insurance covers the financial losses from a data breach or cyberattack. This includes breach response, legal fees, customer notification, ransomware, business interruption, and regulatory fines, depending on your policy.

  • Does my business really need cyber insurance?

    Yes. Any business that stores customer data, processes payments, or relies on connected systems faces cyber risk. Small and mid-sized companies are frequent targets because they often have fewer defenses.

  • How much does cyber insurance cost?

    Cost depends on your industry, revenue, data volume, and security practices. We market your risk to multiple carriers to find strong coverage at a competitive price. Request a quote for an exact figure.

  • What is the difference between first-party and third-party cyber coverage?

    First-party coverage pays for your own losses, like data recovery and lost income. Third-party coverage pays for claims from others harmed by a breach on your systems.

  • How fast can I get a quote?

    Most clients receive a quote in under 24 hours after we review the details of their business and exposure.

  • What should I do first after a cyberattack?

    Contact us right away. We help you start breach response, connect you with forensic and legal support, and guide your claim so you contain the damage quickly.

Insights

Field notes from the placement desk.
What carriers are asking right now.

Construction Cyber Risk: Project Data, Wire Transfers and Connected Sites
4 August 2026
Explore construction cyber risks including draw fraud, email compromise, bid theft, connected equipment threats, ransomware, and delay losses.
Defense Contractor Cyber Risk: Protecting Controlled Unclassified Information
4 August 2026
Understand defense contractor cyber risks, including CUI compliance, CMMC, flow-down clauses, supply chain threats, and contract penalties.
Retail Cyber Risk: Payment Data, Loyalty Systems and Seasonal Exposure
4 August 2026
Explore retail cyber risks including POS breaches, loyalty account attacks, peak season downtime, PCI penalties, and franchise network threats.

Start a quote

Tell us about your business.
We’ll come back with terms.

We’ll review your stack, your contracts, and your exposure — then place the program against the right markets. Most intakes get indicative terms back within one business day.

01

Quick intake

We only ask what the carriers actually need.

02

Benchmark

Side-by-side terms from 10+ specialty cyber carriers.

03

Bind

Plain-language policy review, e-signed and in force.