A single fraudulent wire instruction can drain a six-figure sum from your operating account in under an hour. The funds rarely come back. Cyber crime insurance exists to absorb that financial shock, yet most business owners confuse it with standard cyber liability or assume their bank will make them whole. Neither assumption holds up when a claim hits. This guide breaks down the six major crime coverages found in modern cyber and crime policy forms: computer fraud, funds transfer fraud, social engineering fraud, invoice manipulation, cryptocurrency theft, and telecom fraud. Each one responds to a different attack method, and the gaps between them are where businesses lose money. Understanding how these insuring agreements work, and where one stops and another starts, is the difference between a policy that pays and a policy that disappoints. Roughly 60% of all cyber insurance claims now stem from business email compromise and funds transfer fraud, making crime coverage the most likely section of your policy to be tested. If you are buying your first or second cyber policy, this is the coverage block that deserves the closest reading.
Understanding Cyber Crime Insurance and Why It Matters
Cyber crime coverage is a subset of a broader cyber insurance policy, but it functions more like a commercial crime form than a traditional liability policy. It pays first-party losses: money stolen from your accounts, not damages you owe a third party. The trigger is typically a theft event, not a data breach or a lawsuit.
Most mid-market companies carry some form of commercial crime coverage already, often bundled into a Business Owners Policy or purchased as a standalone fidelity bond. The problem is that those legacy forms were written before wire fraud, cryptocurrency wallets, and AI-generated voice clones became standard attack tools. A policy written in 2018 may not contemplate a 2026 threat.
The Difference Between Cyber Liability and Cyber Crime
Cyber liability responds to breach events: notification costs, regulatory defense, forensic investigations, and third-party lawsuits. Cyber crime responds to theft events: money leaving your account because someone manipulated a system or a person. These are two distinct insuring agreements, and they sit in different parts of the policy form.
A ransomware demand, for instance, may trigger both the cyber extortion coverage under your liability section and a funds transfer fraud claim if the attacker also redirected a wire. Treating them as interchangeable leads to coverage gaps. At Bloc Cyber, the practice of reviewing each insuring agreement at the form level exists precisely because these distinctions matter at claim time.
Why Standard Commercial Property Policies Fall Short
Commercial property policies cover tangible losses: fire, theft of physical inventory, equipment damage. Money lost through electronic manipulation does not fit neatly into those forms. Most commercial property policies exclude losses arising from voluntary parting of funds, which is exactly what happens when an employee is tricked into sending a wire to a fraudulent account.
Even standalone commercial crime forms often contain exclusions for losses involving electronic communications or computer systems unless a specific endorsement is added. The gap is real, and it is the primary reason dedicated cyber crime coverage exists as a separate product.

By: Caden Braly
Founder of Bloc Cyber Insurance
INDEX
Understanding Cyber Crime Insurance and Why It Matters
Core Coverage: Computer Fraud and Funds Transfer Fraud
Protecting Against Deception: Social Engineering and Invoice Manipulation
Emerging Threats: Cryptocurrency Theft and Telecom Fraud
Comparison: Standard Cyber vs. Enhanced Crime Coverage
Bloc Cyber and Its Licensed Producers Are Authorized to Place Cyber Coverage in All 50 U.S. States and The District of Columbia.
Cyber liability insurance covers the financial losses your business faces after a cyberattack or data breach. This page explains what the coverage includes, who needs it, what it costs, and how Bloc Cyber helps you get protected fast.
We start with a twenty-minute call to walk through your contracts, your draw process, your tech stack, and the last twelve months of attempted fraud. From there we go to market with ten-plus carriers, benchmark terms side-by-side, and present the options in plain language with recommended limits and retentions. Most intakes get indicative terms within one business day.
Forensic Investigations: Identifying the Source and Scope
Forensic investigators determine how the attacker got in, what data was accessed, whether exfiltration occurred, and whether the threat actor is still present in the network. Their report drives every downstream decision: which individuals must be notified, whether payment card brands must be alerted, and what remediation steps are necessary. Forensic engagements for mid-market companies commonly run between $30,000 and $150,000, depending on the complexity of the environment. The policy form may impose a separate sublimit on forensic costs or bundle them under a single breach response aggregate. Bloc Cyber reviews these sublimits at the insuring-agreement level before binding, so clients understand exactly how much forensic coverage they are purchasing and where the cap sits relative to their actual exposure.
Core Coverage: Computer Fraud and Funds Transfer Fraud
These two coverages form the backbone of any cyber crime insurance program. They address different attack vectors but often overlap in practice, which is why the policy language matters.
How Computer Fraud Coverage Protects Against Unauthorized Access
Computer fraud coverage typically responds when a third party gains unauthorized access to your computer system and directly causes a transfer of money, securities, or property. The key word is "directly." If a hacker breaks into your accounting software and initiates a wire, that is a direct cause. If a hacker steals your credentials and then calls the bank pretending to be you, some forms will argue the cause was not direct enough.
Courts have split on this issue repeatedly. The policy form's definition of "computer system" and "direct cause" will determine whether your claim is paid. A form-level review before binding, not after a loss, is the only way to know where you stand.
Understanding Funds Transfer Fraud and Electronic Instructions
Funds transfer fraud coverage responds when a third party issues fraudulent electronic instructions to your bank or financial institution, causing money to leave your account without your authorization. This is distinct from computer fraud because the attack targets the transfer mechanism itself, not your internal systems.
A common scenario: an attacker compromises your email, monitors invoice traffic for weeks, then sends a spoofed wire instruction to your bank using your email address. The bank processes the wire. Your funds transfer fraud coverage should respond here, but sublimits and retentions vary widely. Some forms cap this coverage at $100,000 or $250,000, well below the loss amounts that are growing more expensive per incident.

We start with a twenty-minute call to walk through your contracts, your draw process, your tech stack, and the last twelve months of attempted fraud. From there we go to market with ten-plus carriers, benchmark terms side-by-side, and present the options in plain language with recommended limits and retentions. Most intakes get indicative terms within one business day.
Protecting Against Deception: Social Engineering and Invoice Manipulation
Not every theft involves a hacker breaking into a system. Some of the most expensive losses occur when a human being is simply deceived into doing something they believe is legitimate.
Social Engineering Fraud: When Employees Are Tricked
Social engineering fraud coverage responds when an employee is manipulated into voluntarily transferring funds to a criminal. The classic example is the CEO impersonation email: "I need you to wire $85,000 to this account for a confidential acquisition. Do it now and do not discuss it with anyone." The employee complies. The money is gone.
This coverage is almost never included in the base cyber policy form. It is typically added by endorsement, and it frequently carries a sublimit lower than the main policy aggregate. A $1 million cyber policy might include only $100,000 in social engineering coverage unless you negotiate a higher limit at placement. The rise in identity theft-linked insurance fraud projected through 2025 and into 2026 reflects how profitable these schemes have become for criminals.
Invoice Manipulation: Protecting Your Accounts Receivable
Invoice manipulation is a variation of business email compromise where the attacker intercepts legitimate invoices and alters the payment instructions. Your customer pays the invoice in good faith, but the money goes to the attacker's account instead of yours. You are left with an unpaid receivable and a customer who believes they already paid.
Some policy forms treat this as a social engineering loss. Others classify it under funds transfer fraud or computer fraud depending on how the manipulation occurred. The distinction matters because each insuring agreement may carry different limits, retentions, and conditions. If your policy form does not specifically address invoice manipulation, you may find yourself arguing over which coverage applies while the claim sits unpaid.
We start with a twenty-minute call to walk through your contracts, your draw process, your tech stack, and the last twelve months of attempted fraud. From there we go to market with ten-plus carriers, benchmark terms side-by-side, and present the options in plain language with recommended limits and retentions. Most intakes get indicative terms within one business day.
| Coverage Element | Commercial General Liability | Cyber Insurance |
|---|---|---|
| Data breach notification costs | Not covered | Covered under first-party |
| Ransomware payment | Not covered | Covered (subject to sublimit) |
| Regulatory defense | Not covered | Covered under third-party |
| Business interruption from cyberattack | Not covered | Covered with waiting period |
| Funds transfer fraud | Not covered | Covered via cyber crime endorsement |
| Third-party lawsuit over data loss | Excluded or severely limited | Covered under third-party liability |
| Technology product failure | Not covered | Covered under Tech E&O |
Emerging Threats: Cryptocurrency Theft and Telecom Fraud
The threat environment keeps expanding, and policy forms are catching up at different speeds. Two areas that remain inconsistently covered are digital asset theft and telecom fraud.
Insuring Digital Assets and Crypto Wallets
If your business holds cryptocurrency, whether as a payment method, treasury asset, or customer funds, traditional crime forms do not cover it. Cryptocurrency is not "money" or "securities" under most policy definitions. A dedicated digital asset endorsement or a standalone crypto crime policy is required.
Coverage typically applies to theft from hot wallets through unauthorized access, but cold storage losses and private key compromise present underwriting challenges. The potential for quantum computing to disrupt cryptographic protections adds a forward-looking risk that underwriters are beginning to price. If your firm holds digital assets, confirm that the policy form explicitly names cryptocurrency in the covered property definition.
Telecom Fraud: Who Pays for Unauthorized Phone Charges?
Telecom fraud occurs when an attacker compromises your phone system, typically a PBX or VoIP platform, and routes thousands of dollars in long-distance or premium-rate calls through your account. The telecom carrier bills you. Your standard business insurance will not cover it.
Some cyber crime forms include telecom fraud as a named coverage; others exclude it entirely. The losses can be substantial: a compromised PBX running over a holiday weekend can generate $50,000 or more in fraudulent charges before anyone notices. Ask your broker whether the form includes telecom fraud and what the sublimit is.
We start with a twenty-minute call to walk through your contracts, your draw process, your tech stack, and the last twelve months of attempted fraud. From there we go to market with ten-plus carriers, benchmark terms side-by-side, and present the options in plain language with recommended limits and retentions. Most intakes get indicative terms within one business day.
FAQ: Does my general business insurance cover hacking?
Almost certainly not. Standard CGL and BOP policies contain electronic data exclusions. Even if your policy has a small "data breach" endorsement, it is typically capped at $50,000 to $100,000, which will not cover a meaningful incident. A standalone cyber liability form provides the breadth and limits required for a real claim.
Comparison: Standard Cyber vs. Enhanced Crime Coverage
| Coverage Element | Standard Cyber Liability | Enhanced Cyber Crime |
|---|---|---|
| Data breach response | Included | Not typically included |
| Regulatory defense | Included | Not typically included |
| Computer fraud | Sometimes included | Included with higher limits |
| Funds transfer fraud | Often sublimited | Full limit available |
| Social engineering | Rarely included in base form | Available by endorsement |
| Invoice manipulation | Varies by form | Explicitly addressed |
| Cryptocurrency theft | Excluded | Available by endorsement |
| Telecom fraud | Excluded | Available by endorsement |
The difference between these two columns is often a matter of endorsements and sublimits, not separate policies. A specialist agency like Bloc Cyber reviews these line items before binding so you know exactly what triggers each coverage and what falls outside the form.
We start with a twenty-minute call to walk through your contracts, your draw process, your tech stack, and the last twelve months of attempted fraud. From there we go to market with ten-plus carriers, benchmark terms side-by-side, and present the options in plain language with recommended limits and retentions. Most intakes get indicative terms within one business day.
| Coverage Element | Commercial General Liability | Cyber Insurance |
|---|---|---|
| Data breach notification costs | Not covered | Covered under first-party |
| Ransomware payment | Not covered | Covered (subject to sublimit) |
| Regulatory defense | Not covered | Covered under third-party |
| Business interruption from cyberattack | Not covered | Covered with waiting period |
| Funds transfer fraud | Not covered | Covered via cyber crime endorsement |
| Third-party lawsuit over data loss | Excluded or severely limited | Covered under third-party liability |
| Technology product failure | Not covered | Covered under Tech E&O |
Common Questions About Cyber Crime Insurance
Does my bank cover me if my business account is hacked?
Most commercial banking agreements place the liability for unauthorized electronic transfers on the account holder, not the bank, once the bank has followed its standard security procedures. Your bank is not your insurer. A dedicated funds transfer fraud policy is the appropriate risk transfer mechanism.
What is the difference between phishing and social engineering?
Phishing is a delivery method: a fraudulent email designed to steal credentials or install malware. Social engineering is broader and includes phone calls, text messages, and in-person deception. A phishing email that leads to credential theft may trigger computer fraud coverage, while a phone call that tricks an employee into wiring funds triggers social engineering coverage.
Is cyber crime insurance expensive for small businesses?
Premiums for small businesses with 10 to 100 employees typically range from a few hundred to a few thousand dollars annually, depending on revenue, industry, and the limits selected. Cyber insurance market conditions have stabilized heading into 2026, making coverage more accessible than it was during the hard market of 2022-2023.
Do I need this if I already have a general liability policy?
Yes. General liability excludes electronic theft, wire fraud, and virtually every scenario described in this guide. There is no overlap between a GL form and a cyber crime insuring agreement.
Will insurance pay if an employee makes a mistake?
It depends on the mistake. If an employee is deceived into sending a wire by a social engineering attack, the social engineering endorsement may respond. If an employee simply sends money to the wrong account due to carelessness, most forms will not cover the loss. The policy language around "voluntary parting" and "fraudulent inducement" controls the outcome.
We start with a twenty-minute call to walk through your contracts, your draw process, your tech stack, and the last twelve months of attempted fraud. From there we go to market with ten-plus carriers, benchmark terms side-by-side, and present the options in plain language with recommended limits and retentions. Most intakes get indicative terms within one business day.
FAQ: Does my general business insurance cover hacking?
Almost certainly not. Standard CGL and BOP policies contain electronic data exclusions. Even if your policy has a small "data breach" endorsement, it is typically capped at $50,000 to $100,000, which will not cover a meaningful incident. A standalone cyber liability form provides the breadth and limits required for a real claim.
The Bottom Line: Securing Your Business Assets
Cyber crime insurance is not a single coverage. It is a collection of insuring agreements, each written to respond to a specific theft scenario. Computer fraud, funds transfer fraud, social engineering, invoice manipulation, cryptocurrency theft, and telecom fraud all operate under different triggers, definitions, and limits within the same policy form. Buying a cyber policy without reading those individual grants is like locking your front door while leaving every window open.
The most common mistake mid-market buyers make is assuming that a bundled cyber policy covers all crime scenarios at full limits. It rarely does. Sublimits on social engineering, exclusions for digital assets, and narrow definitions of "direct cause" are the gaps that cost businesses real money when a claim is filed.
If you have not had your policy form reviewed at the insuring-agreement level, now is the time. A Bloc Cyber specialist can walk through each coverage grant, identify where the form stops, and show you what it will cost to close those gaps before a loss finds them.
Request a review and know exactly what your policy will and will not pay.
ABOUT THE AUTHOR
Caden Braly
— Founder, Bloc Cyber
I'm Caden Braly, founder of Bloc Cyber, the specialty cyber insurance arm of Braly Insurance. I built Bloc Cyber around one idea: businesses deserve coverage that actually responds when a cyberattack happens. I work closely with clients to understand their exposure, place the right policy through specialty carriers, and stand with them through the claim. My goal is simple — give every business straight answers and protection they can trust.
Full profile → caden@bloccyber.com LinkedIn
Industries We Protect
Cyber Coverage Built for Your Industry
Every industry faces a different cyber threat, from patient records in healthcare to wire fraud in construction. Bloc Cyber matches coverage to the risks your sector actually faces, drawing on specialty carriers that understand your business. Find your industry below to see how we protect it.
Healthcare
Banking
Retail / E-Commerce
Legal
Technology / SaaS
Education
Energy / Utilities
Manufacturing
Construction
Defense
Healthcare
HIPAA-grade protection for patient data
725
healthcare breaches disclosed in 2024
HIPAA-grade protection for patient data
▣ Ransomware on EHR systems
▣ PHI exfiltration
▣ Medical device exploits
▣ Business email compromise
Sub-sectors we place
Hospitals and health systems
Physician practices and specialty clinics
Dental practices and DSOs
Behavioral health and addiction treatment centers
Medical billing and revenue cycle management firms
Typical turnaround for indication of terms: 1 business day.
Banking
Coverage that meets FFIEC and NYDFS expectations
$5.9M
average cost of a financial sector breach
Common threats we underwrite against
▣ Wire fraud and BEC
▣ Credential stuffing
▣ Third-party vendor risk
▣ Ransomware
Sub-sectors we place
Community banks
Credit unions
Mortgage lenders and loan originators
Wealth management and RIAs
Payment processors and merchant acquirers
Typical turnaround for indication of terms: 1 business day.
Retail / E-Commerce
PCI-DSS aligned coverage for every checkout
42%
of retailers hit by ransomware in the last year
Common threats we underwrite against
▣ Magecart / card skimming
▣ POS malware
▣ Account takeover
▣ Supply-chain intrusion
Sub-sectors we place
Direct-to-consumer (DTC) brands
Shopify and marketplace sellers
Brick-and-mortar multi-location retailers
Restaurants and QSR franchises
Grocery and specialty food retail
Typical turnaround for indication of terms: 1 business day.
Legal
Privilege, client files, and trust-account safeguards
1 in 4
law firms reported a breach in 2024
Common threats we underwrite against
▣ Wire-transfer fraud
▣ Privileged data theft
▣ Email account compromise
▣ Ransomware
Sub-sectors we place
AmLaw / large firms
Boutique litigation firms
Personal injury and plaintiffs’ firms
Estate planning and trust attorneys
Title and real estate closing firms
Typical turnaround for indication of terms: 1 business day.
Technology / SaaS
SOC 2 and ISO-aligned risk transfer
$4.88M
avg. cost of a SaaS breach in 2024
Common threats we underwrite against
▣ Supply-chain attacks
▣ Cloud misconfiguration
▣ Token and key theft
▣ Zero-day exploits
Sub-sectors we place
B2B SaaS platforms
Managed service providers (MSPs) and MSSPs
Fintech startups
AI and machine learning companies
Cloud hosting and infrastructure providers
Typical turnaround for indication of terms: 1 business day.
Education
FERPA-aligned coverage for student and research data
80%
of K–12 districts hit by ransomware since 2022
Common threats we underwrite against
▣ Ransomware on district networks
▣ Student PII theft
▣ Fake invoice fraud
▣ DDoS on exam platforms
Sub-sectors we place
K-12 public school districts
Private and charter schools
Colleges and universities
EdTech platforms
Tutoring, test prep, and online learning providers
Typical turnaround for indication of terms: 1 business day.
Energy / Utilities
OT and IT coverage for critical infrastructure
24/7
operational-tech monitoring requirements
Common threats we underwrite against
▣ ICS/SCADA intrusion
▣ Nation-state actors
▣ Ransomware on OT
▣ Insider threat
Sub-sectors we place
Municipal utilities (water, electric, gas)
Oil and gas operators
Pipeline and midstream companies
Renewable energy (solar, wind) developers
Electric cooperatives and rural utilities
Typical turnaround for indication of terms: 1 business day.
Manufacturing
Business interruption protection for connected plants
25%
of all ransomware attacks target manufacturing
Common threats we underwrite against
▣ Ransomware halting production
▣ IP theft
▣ ICS exploits
▣ Vendor compromise
Sub-sectors we place
Industrial and heavy equipment manufacturers
Food and beverage processing
Pharmaceutical and medical device manufacturers
Automotive and parts suppliers
Aerospace component manufacturers
Typical turnaround for indication of terms: 1 business day.
Construction
Protection for project files, wires, and jobsite tech
$200K+
average wire-fraud loss in construction
Common threats we underwrite against
▣ Wire-transfer diversion
▣ BEC on project payments
▣ Stolen bid data
▣ Ransomware
Sub-sectors we place
General contractors
Commercial HVAC, electrical, and plumbing subs
Civil and infrastructure contractors
Homebuilders and residential developers
Architecture and engineering (A&E) firms
Typical turnaround for indication of terms: 1 business day.
Defense
CMMC, DFARS, and CUI-compliant risk transfer
CMMC
2.0 compliance required by 2026
Common threats we underwrite against
▣ CUI exfiltration
▣ Nation-state APTs
▣ Supply-chain compromise
▣ Cleared-personnel targeting
Sub-sectors we place
DoD prime contractors
CMMC-regulated subcontractors
Defense software and systems integrators
Aerospace and satellite contractors
Federal IT and cleared staffing firms
Typical turnaround for indication of terms: 1 business day.
Coverage
A policy you can actually read.
Structured in three clean blocs.
01
First-Party
Your direct losses when an incident hits your business.
✓
Incident response & forensics
✓
Business interruption
✓ Data restoration
✓ Cyber extortion / ransomware
✓ Funds transfer fraud
✓ Reputational harm
02
Third-Party
Your liability to clients, partners, and regulators.
✓
Network security liability
✓
Privacy liability (HIPAA, GDPR, state laws)
✓ Regulatory defense & fines
✓ PCI-DSS fines and assessments
✓ Media liability
✓ Breach notification costs
03
Specialty
Advanced coverages for complex risks and contracts.
✓
Technology E&O
✓
Social engineering fraud
✓ Contingent business interruption
✓ Systems failure
✓ Bricking & hardware replacement
✓ CMMC / regulatory-specific endorsements
Typical limits placed
$1M / $1M starter
$5M / $10M mid-market
$25M+ layered towers
Custom retentions
Common Questions
Cyber Liability Insurance, Explained
What does cyber insurance cover?
Cyber insurance covers the financial losses from a data breach or cyberattack. This includes breach response, legal fees, customer notification, ransomware, business interruption, and regulatory fines, depending on your policy.
Does my business really need cyber insurance?
Yes. Any business that stores customer data, processes payments, or relies on connected systems faces cyber risk. Small and mid-sized companies are frequent targets because they often have fewer defenses.
How much does cyber insurance cost?
Cost depends on your industry, revenue, data volume, and security practices. We market your risk to multiple carriers to find strong coverage at a competitive price. Request a quote for an exact figure.
What is the difference between first-party and third-party cyber coverage?
First-party coverage pays for your own losses, like data recovery and lost income. Third-party coverage pays for claims from others harmed by a breach on your systems.
How fast can I get a quote?
Most clients receive a quote in under 24 hours after we review the details of their business and exposure.
What should I do first after a cyberattack?
Contact us right away. We help you start breach response, connect you with forensic and legal support, and guide your claim so you contain the damage quickly.
Insights
Field notes from the placement desk.
What carriers are asking right now.
Start a quote
Tell us about your business.
We’ll come back with terms.
We’ll review your stack, your contracts, and your exposure — then place the program against the right markets. Most intakes get indicative terms back within one business day.
01
Quick intake
We only ask what the carriers actually need.
02
Benchmark
Side-by-side terms from 10+ specialty cyber carriers.
03
Bind
Plain-language policy review, e-signed and in force.




