Manav.id
Vertical · 4 min read

Your cyber limit is not your wire fraud limit

Your cyber limit is not your wire fraud limit

The policy limit on the certificate and the amount that will be paid for a diverted wire are different numbers, sometimes by a factor of forty. The second number is in a schedule most people do not read.

Does a $10M cyber policy cover a $10M wire fraud?

Almost never. Social engineering fraud typically carries a sub-limit far below the policy limit, and most wire fraud falls into that bucket rather than computer fraud — because an authorised employee was deceived into making the transfer, which is exactly what the sub-limit anticipates.

Key takeaways
  • Social engineering sub-limits are commonly a small fraction of the policy limit and are the applicable limit for most wire fraud losses.
  • The sub-limit exists because insurers cannot verify the manual controls that would prevent the loss.
  • Raising it requires evidence per transaction, which also means accepting a warranty that the control operated.

Where the number actually is

What the certificate showsPolicy aggregate $10,000,000Network security liability $10,000,000Business interruption $5,000,000Cyber extortion $5,000,000What applies to a diverted wireComputer fraud $1,000,000Social engineering fraud $250,000Less the deductibleThis is the numbervs

The headline limit applies to the policy generally. Specific coverages carry their own limits in a schedule, and social engineering fraud is typically one of the lowest.

CoverageIllustrative limit
Policy aggregate$10,000,000
Network security and privacy liability$10,000,000
Business interruption$5,000,000
Cyber extortion$5,000,000
Computer fraud$1,000,000
Social engineering fraud$250,000

These are illustrative, not typical of any particular policy. The pattern — social engineering as the lowest line — is common across the market.

Why most wire fraud lands there

Computer fraud coverage generally contemplates an unauthorised system intrusion causing a transfer. Social engineering coverage contemplates an authorised person being deceived into making one.

A diverted vendor payment is the second. An employee with authority made the transfer, through the normal process, because they were deceived. That is the sub-limited bucket, and that is the majority of these losses.

Why the sub-limit exists

Not arbitrarily. Insurers sub-limit what they cannot underwrite, and they cannot underwrite a control they cannot verify.

Given those four, a low sub-limit is a rational response. Arguing it is unfair misses the mechanism; changing it requires changing the second bullet.

What treasury should establish at renewal

  1. The actual social engineering sub-limit, in writing, not the policy limit.
  2. Whether it is per occurrence or annual aggregate. Aggregate is materially worse if there is more than one incident.
  3. The deductible or retention applying to it specifically.
  4. Whether it covers transfers to vendors, to employees, and internal transfers — wordings vary and gaps hide here.
  5. Any conditions precedent on verification, and precisely what would satisfy them.

Item four catches a common surprise: some wordings respond to vendor impersonation and not to an instruction that appears to come from an executive, or vice versa.

The exposure arithmetic

Simple and worth doing before the conversation with the broker.

  Largest single payment in the last 12 months     $2,400,000
  95th percentile payment                            $840,000
  Median payment above the approval threshold        $118,000

  Social engineering sub-limit                       $250,000
  Applicable deductible                               $50,000

  Net recovery on a $840,000 diverted payment        $200,000
  Uninsured exposure                                 $640,000

Most organisations have not computed this. Presenting it to a board is usually what starts the conversation about the control.

What raising it requires

An underwriter increasing exposure in this category needs a reason. The realistic package has four parts.

The fourth is the trade and it should be made deliberately. A higher sub-limit conditioned on a control you cannot consistently apply is worse than a lower one with no condition — which is exactly the trap the current questionnaire regime creates.

Compute your own exposure

  Largest single payment, last 12 months      $2,400,000
  95th percentile payment                       $840,000
  Median above the approval threshold           $118,000

  Social engineering sub-limit                  $250,000
  Applicable deductible                          $50,000

  Net recovery on an $840,000 diversion         $200,000
  Uninsured exposure                            $640,000

Most organisations have not done this arithmetic. Presenting it to a board is usually what starts the conversation about the control.

Objections and honest limits

“We will negotiate the sub-limit up.” With what? Every client brings the same training statistics. Raising it requires evidence, and accepting a condition you can actually sustain.

“A higher limit is always better.” Not if it is conditioned on a control you cannot consistently apply. A conditioned higher limit can be worse than an unconditioned lower one.

What to establish at renewal

  1. The actual social engineering sub-limit. In writing, not the policy limit.
  2. Per occurrence or annual aggregate. Aggregate is materially worse.
  3. The deductible applying specifically to it. Frequently different.
  4. Which transfer types are covered. Vendor, employee, internal — wordings vary and gaps hide here.
  5. What satisfies any verification condition. Get the answer before the loss.

Terms used here

Sub-limit
A cap applying to one coverage within a policy, frequently far below the headline limit.
Computer fraud
Cover contemplating an unauthorised system intrusion causing a transfer.
Social engineering fraud
Cover contemplating an authorised person being deceived into making a transfer — where most wire fraud lands.

Frequently asked questions

Why is the sub-limit so much lower than the policy limit? Insurers sub-limit what they cannot underwrite. The preventive control is a human process whose operation cannot be verified at underwriting or at claim.

Why does wire fraud fall under social engineering rather than computer fraud? Computer fraud generally contemplates an unauthorised intrusion. A deceived but authorised employee making a transfer is the social engineering bucket.

What should treasury check at renewal? The actual sub-limit, whether it is per occurrence or aggregate, the specific deductible, which transfer types it covers, and what satisfies any verification condition.

Is a higher conditioned sub-limit always better? No. A higher limit conditioned on a control you cannot consistently apply is worse than a lower unconditioned one. Make the trade deliberately.

Why does wire fraud fall under social engineering? Because an authorised employee made the transfer through the normal process, having been deceived. That is the sub-limited bucket.

Is the sub-limit unfair? It is a rational response to a control the insurer cannot verify. Changing it requires making the control measurable.

Where this fits in Manav

Manav produces the artefact underwriting and claims both lack: a per-transaction receipt an adjuster can verify without contacting the insured, and a measurable coverage rate across a defined scope.

See the evidence a claim needs →

Sources and further reading