What brokers can actually negotiate on impersonation risk
The coverage gap for executive impersonation is well understood on both sides of the table. What is missing is the thing a broker needs to argue with: a demonstrable difference between this client and the next one.
What can a broker actually negotiate on deepfake impersonation risk?
Very little today, because there is nothing to show. Brokers such as Marsh and Aon create leverage through differentiators an underwriter can price. On impersonation risk every client brings the same two things — training completion rates and a policy document — which is why sub-limits have not moved.
- Broker leverage requires a differentiator the underwriter can price. On impersonation risk, most clients look identical.
- Standard social engineering wordings turn on whether the insured was induced to transfer voluntarily, which impersonation claims usually are.
- A control that produces evidence per transaction is the first thing in this category that can be shown rather than described.
Part of Cyber insurance and risk transfer
How a broker creates leverage
Through differentiation. A broker's argument is that this client's risk is better than the class, evidenced by something the underwriter can price.
| Risk area | Available differentiator |
|---|---|
| Ransomware | Backup testing evidence, EDR coverage, segmentation, recovery time |
| Data breach | Encryption coverage, data minimisation, breach response retainer |
| Business interruption | Redundancy architecture, tested failover, dependency mapping |
| Executive impersonation | Training completion rates and a policy document |
The last row is why sub-limits in this category are sticky. There is nothing to bring to the negotiation that the next client does not also have.
Why the wording is unhelpful
Social engineering fraud coverage typically responds where an insured was induced by a fraudulent communication to transfer funds voluntarily.
That is precisely what an impersonation attack produces. The employee was induced, they did transfer voluntarily, and the transfer was authorised through normal channels. The claim falls into the sub-limited bucket rather than the main computer fraud cover.
This is not an insurer being difficult. It is the wording working as drafted, for a loss type that behaves exactly as the sub-limit anticipated.
What would move an underwriter
Underwriters price what they can verify at claim time. Three things they can verify, in increasing order of value.
- Scope. Which payments are subject to the control, defined by threshold and by trigger event rather than by policy language.
- Coverage rate. What proportion of in-scope payments actually carried the control over the last twelve months.
- Exception shape. Where the control was not applied, and what the exception path looks like.
The third is counter-intuitively the most persuasive. A broker presenting a measured exception rate with a documented reason is presenting a client that understands its own operations — which is rarer than a client presenting a clean yes.
The negotiation, in order
| Ask | Realistic? |
|---|---|
| Raise the social engineering sub-limit | Possible with evidence, on a specific defined scope |
| Reduce the deductible on impersonation losses | Sometimes easier than moving the sub-limit |
| Remove the sub-limit entirely | Unlikely in the current market |
| Affirmative wording for synthetic media impersonation | Increasingly available; worth asking |
| Premium credit for the control | Possible, usually small; the coverage terms matter more |
Brokers generally report that deductible and scope movement comes before sub-limit movement. That is a useful sequencing insight for a client deciding what to ask for.
The honest state of play
There is no established actuarial basis yet for pricing this differently. Insurers do not have loss experience separating organisations with per-transaction evidence from those without, because very few organisations have it.
So the argument today is structural rather than statistical: this control removes the mechanism by which the loss occurs, and that should be worth something. Some underwriters find that persuasive; others reasonably want data first.
A broker should present it as what it is. Overstating the market's readiness damages credibility on a claim that is otherwise sound.
What a client should prepare
- A written definition of which payments are in scope for the control, by threshold and trigger.
- Twelve months of measured coverage, with exceptions categorised.
- A sample receipt, with an explanation of what a claims adjuster could verify from it.
- A statement of what the organisation will commit to maintaining, since that is what a warranty would be drafted against.
Item four matters. If a term is granted, it will come with a condition, and the client should have decided in advance what they can actually sustain.
What would actually move an underwriter
| Evidence | Why it prices |
|---|---|
| Scope | Which payments carry the control, by threshold and trigger — not by policy language |
| Coverage rate | What proportion of in-scope payments actually carried it over twelve months |
| Exception shape | Where it was not applied, and why |
The third is counter-intuitively the most persuasive. A measured exception rate with documented reasons presents a client that understands its own operations, which is rarer than a client presenting a clean yes.
Objections and honest limits
“The wording is being unfair.” It is not. Social engineering cover responds where the insured was induced to transfer voluntarily, which is exactly what an impersonation attack produces. The claim falls into the sub-limited bucket because it behaves as the sub-limit anticipated.
“This control is actuarially proven.” It is not, and saying so damages credibility. Insurers have no loss experience separating organisations with per-transaction evidence from those without, because very few have it. The argument today is structural, and should be presented that way.
Brokers generally report that deductible and scope movement comes before sub-limit movement, and that affirmative wording for synthetic media impersonation is increasingly available. That is a useful sequencing insight for a client deciding what to ask for.
What a client should bring to renewal
- A written scope definition. Which payments are in scope, by threshold and trigger.
- Twelve months of measured coverage. With exceptions categorised by reason.
- A sample receipt and what an adjuster could verify from it. Make it concrete.
- What you will commit to maintaining. If a term is granted it comes with a condition. Decide in advance what you can sustain.
Terms used here
- Sub-limit
- A cap applying to one coverage inside a policy, frequently far below the headline limit. Social engineering is typically among the lowest.
- Affirmative wording
- Language explicitly confirming a peril is covered, as opposed to relying on silence.
- Condition precedent
- A requirement that must be satisfied for cover to respond. Failing to demonstrate it can defeat a claim independent of the loss.
Frequently asked questions
Why are social engineering sub-limits so sticky? Because clients cannot differentiate themselves. Training completion rates and a policy document are what everyone brings, so there is nothing to price.
Why does the wording put impersonation in the sub-limit? Cover typically responds where the insured was induced to transfer voluntarily, which is exactly what an impersonation attack produces.
What moves first in a negotiation? Brokers generally report deductible and scope movement before sub-limit movement. Affirmative synthetic media wording is increasingly available.
Is there actuarial support for pricing this control? Not yet. Insurers lack loss experience separating organisations with per-transaction evidence from those without. The argument today is structural.
Is there actuarial support for this control? Not yet. Insurers lack loss experience separating evidenced from attested controls. The argument is structural, and overstating it damages the case.
Where this fits in Manav
Manav produces the artefact a broker currently lacks: a per-transaction receipt an adjuster can verify without contacting the insured, and a measurable coverage rate across a defined scope.
Sources and further reading
- NAIC — cyber insurance market report
- Published broker market commentary on cyber coverage terms.
- FBI IC3 2025 Internet Crime Report
- FCC — protecting consumers from SIM swap and port-out fraud