Business email compromise is the single most frequent way small and mid-sized companies lose real money to cybercrime. Someone gets into an email account, watches the conversation, and redirects a payment. The frustrating part is that many owners discover their cyber policy responds to the breach but not to the missing funds.
BEC rarely involves dramatic hacking. A criminal obtains a password through phishing, credential stuffing, or a leaked database, then quietly logs into a mailbox and reads. They learn who approves payments, what a normal invoice looks like, and when big transactions happen. Sometimes they set inbox rules that hide their replies so the real account owner never sees the conversation.
When the moment arrives, they send a message that looks entirely normal. A vendor emails updated banking instructions. A title company sends closing wire details. The CEO asks the bookkeeper to push a payment through before a flight. The money leaves, and by the time anyone notices, it has been moved through several accounts.
Two variations matter for insurance purposes. In a true BEC, the criminal is inside your email system. In a spoofing or impersonation attack, they never touch your systems at all — they register a lookalike domain and simply pretend to be you or your vendor. Some policies treat these two scenarios very differently.
A cyber policy is not one coverage. It is a bundle of separate insuring agreements, each with its own limit and sometimes its own deductible. A BEC event can trigger several at once, and understanding which does what is the key to knowing whether you are protected.
That last bullet is where businesses get caught. The forensic and legal side of a BEC is usually covered generously, often at the full policy limit. The stolen funds themselves fall under a separate, much smaller crime-style coverage part that many policies include only by endorsement.
Carriers price funds transfer losses differently than data breach losses because the exposure is direct and immediate. A wire goes out, the money is gone, and there is no lengthy claims process to reduce the number. To manage that, insurers cap social engineering coverage well below the aggregate limit.
A common pattern on small business policies is a $1 million aggregate cyber limit with a $50,000 or $100,000 sublimit for social engineering fraud. Some policies offer $250,000. A handful of carriers will match the full limit for well-controlled accounts, but you generally have to ask and often have to answer additional underwriting questions about your payment verification procedures.
The mismatch matters because average BEC losses have climbed steadily. A construction firm paying a subcontractor, a law firm handling escrow, or a real estate brokerage coordinating a closing can easily wire six figures in a single transaction. If your sublimit is $50,000 and the wire was $180,000, the policy pays $50,000 and you absorb the rest. That is the single most common surprise in cyber claims for small businesses.
Even when the sublimit is adequate, social engineering coverage usually comes with conditions precedent — steps you must have taken for the coverage to apply. These are not fine print you can ignore, because adjusters check them.
The most common requirement is out-of-band verification. Before changing payment instructions or sending funds above a stated threshold, someone at your company must call the requester at a phone number already on file — not the number in the email. Some policies require dual authorization on transfers over a dollar amount. Others require that the request come from a known vendor with an existing relationship.
Policies also differ on whose deception is covered. A narrow form covers only impersonation of a company executive or employee. A broader form adds vendor and client impersonation, which is where the majority of real-world losses actually occur. If your policy only covers executive impersonation and your loss came from a spoofed supplier invoice, you may have no coverage for the funds at all. When you review the actual policy language, or run it through a policy checkup, this is one of the first clauses worth reading word for word.
Insurance is the backstop, not the control. Because the funds coverage is sublimited and conditional, the practical value of prevention is higher for BEC than for almost any other cyber risk. Three controls do most of the work.
Multi-factor authentication on every email account is the baseline. Most carriers now require it just to offer cyber coverage, and it stops the overwhelming majority of credential-based mailbox takeovers. Second, a written payment verification rule that applies to everyone, with no exception for urgent requests from the boss. Third, monitoring for suspicious inbox rules, which is often the first sign an account is compromised.
Also understand what happens after a wire goes out. Speed matters enormously. If you contact your bank within roughly 24 to 72 hours and file an IC3 complaint with the FBI, there is a genuine chance funds can be frozen or recalled. Recovery rates drop sharply after that window. Your cyber insurer's response hotline can often help coordinate this, which is another reason to call them before you call anyone else.
Any business that sends or receives payments by wire or ACH has BEC exposure, but some professions sit squarely in the crosshairs because criminals know large transfers are routine. Real estate brokerages and title agencies handle closing funds. Law firms manage trust and escrow accounts. CPA firms hold client banking details and often process payments on behalf of others.
Contractors and wholesalers are targeted too, because subcontractor and supplier payments are frequent and the invoice formats are easy to imitate. Medical and dental practices face a compounded version of the problem: a compromised mailbox may also contain protected health information, turning a funds loss into a HIPAA notification event with its own set of costs.
For these businesses, the question is not whether to carry cyber coverage but whether the social engineering sublimit is sized to the largest payment they might realistically send in a single day. That is a specific, answerable number, and it should drive the limit you buy.
Does a general liability policy or a BOP cover a fraudulent wire transfer?
Almost never. General liability responds to bodily injury and property damage claims from third parties, and a standard business owners policy excludes most electronic funds losses. Some BOPs offer a small cyber endorsement with a token limit, often $10,000 to $25,000, which is rarely enough for a real BEC loss. Standalone cyber insurance with an explicit social engineering coverage part is the reliable answer.
What is the difference between funds transfer fraud and social engineering coverage?
Funds transfer fraud typically covers losses where a criminal directly instructs your bank to move money without your knowledge. Social engineering covers losses where your own employee was tricked into authorizing the transfer voluntarily. Most real BEC losses are the second type, so a policy with funds transfer fraud but no social engineering coverage may leave the exact scenario you are worried about uninsured.
Will my claim be denied if my employee ignored our verification policy?
It depends on how the policy is worded. If callback verification is written as a condition precedent to coverage, skipping it can defeat the claim. If it is simply an underwriting representation, a single lapse is less likely to void coverage, though the insurer may still investigate. This is a meaningful difference in language and worth confirming before you bind.
Does cyber insurance cover the money if a client was tricked into paying a criminal instead of us?
Sometimes, under what is often called client or third-party social engineering coverage, but it is not standard. Many policies only cover funds you lose from your own accounts. If a customer wires a payment to a fraudster impersonating your business, you may face a dispute over who bears the loss, and only a broadened endorsement will respond.
Do I need to report a BEC even if no money was lost?
Yes, report it to your carrier. A compromised mailbox is a data event regardless of whether a payment went out, and if it contained personal information you may have notification obligations. Reporting also preserves your right to coverage if related losses surface later.
Pull your cyber policy and find two numbers: the social engineering sublimit and the largest single payment your business might send in a week. If the second number is bigger than the first, you have a gap worth closing, and it is usually inexpensive to raise. A Truscott coverage review will also flag the verification conditions and impersonation definitions that decide whether a BEC claim gets paid at all. Reach out for a review, or request a business quote to see what stronger business email compromise insurance limits would cost.
Cyber applications are now security questionnaires. Learn the controls underwriters ask about, how each one moves your price, and where applications most often get declined.
Cyber InsuranceMotor carriers run on dispatch software, ELD data, and email-based load booking, which makes them a live target for freight fraud and ransomware. Here is what cyber insurance covers for trucking and logistics operations.