{
 "slug": "social-engineering-sub-limit-trap-10m-cyber",
 "topic_id": "TOPIC-068",
 "cluster": "Cyber Insurance & Risk Transfer",
 "tier": "Tier B",
 "title": "Your cyber limit is not your wire fraud limit",
 "summary": "A large cyber tower can carry a small sub-limit for the loss type most likely to occur. Treasury discovers this at claim time rather than at renewal.",
 "lede": "The policy limit on the certificate and the amount that will be paid for a diverted wire are different numbers, sometimes by a factor of forty. The second number is in a schedule most people do not read.",
 "date": "2024-09-03",
 "category": "Vertical",
 "author_id": "constance-ibe-whitmore",
 "tags": [
  "sub-limits",
  "cyber policy",
  "wire fraud",
  "treasury",
  "coverage gap",
  "risk management"
 ],
 "image_title": "Cyber Limit Versus Wire Limit",
 "schema": "Article",
 "key_takeaways": [
  "Social engineering sub-limits are commonly a small fraction of the policy limit and are the applicable limit for most wire fraud losses.",
  "The sub-limit exists because insurers cannot verify the manual controls that would prevent the loss.",
  "Raising it requires evidence per transaction, which also means accepting a warranty that the control operated."
 ],
 "body": [
  {
   "type": "h2",
   "text": "Where the number actually is"
  },
  {
   "type": "diagram",
   "kind": "compare",
   "alt": "The headline limit and the applicable one",
   "caption": [],
   "nodes": "Illustrative figures. The pattern — social engineering lowest — is common.",
   "left": {
    "title": "What the certificate shows",
    "items": [
     "Policy aggregate $10,000,000",
     "Network security liability $10,000,000",
     "Business interruption $5,000,000",
     "Cyber extortion $5,000,000"
    ]
   },
   "right": {
    "title": "What applies to a diverted wire",
    "items": [
     "Computer fraud $1,000,000",
     "Social engineering fraud $250,000",
     "Less the deductible",
     "This is the number"
    ]
   }
  },
  {
   "type": "p",
   "html": "The headline limit applies to the policy generally. Specific coverages carry their own limits in a schedule, and social engineering fraud is typically one of the lowest."
  },
  {
   "type": "table",
   "head": [
    "Coverage",
    "Illustrative limit"
   ],
   "rows": [
    [
     "Policy aggregate",
     "$10,000,000"
    ],
    [
     "Network security and privacy liability",
     "$10,000,000"
    ],
    [
     "Business interruption",
     "$5,000,000"
    ],
    [
     "Cyber extortion",
     "$5,000,000"
    ],
    [
     "Computer fraud",
     "$1,000,000"
    ],
    [
     "<strong style=\"font-weight:600\">Social engineering fraud</strong>",
     "<strong style=\"font-weight:600\">$250,000</strong>"
    ]
   ]
  },
  {
   "type": "p",
   "html": "These are illustrative, not typical of any particular policy. The pattern — social engineering as the lowest line — is common across the market."
  },
  {
   "type": "h2",
   "text": "Why most wire fraud lands there"
  },
  {
   "type": "p",
   "html": "Computer fraud coverage generally contemplates an unauthorised system intrusion causing a transfer. Social engineering coverage contemplates an authorised person being deceived into making one."
  },
  {
   "type": "p",
   "html": "A diverted vendor payment is the second. An employee with authority made the transfer, through the normal process, because they were deceived. That is the sub-limited bucket, and that is the majority of these losses."
  },
  {
   "type": "h2",
   "text": "Why the sub-limit exists"
  },
  {
   "type": "p",
   "html": "Not arbitrarily. Insurers sub-limit what they cannot underwrite, and they cannot underwrite a control they cannot verify."
  },
  {
   "type": "ul",
   "items": [
    "The preventive control is a human process — callbacks, dual approval, verification",
    "Its operation cannot be confirmed at underwriting or at claim",
    "Loss frequency in the category is high and rising",
    "Severity is unbounded, since the limiting factor is what the company can transfer"
   ]
  },
  {
   "type": "p",
   "html": "Given those four, a low sub-limit is a rational response. Arguing it is unfair misses the mechanism; changing it requires changing the second bullet."
  },
  {
   "type": "h2",
   "text": "What treasury should establish at renewal"
  },
  {
   "type": "ol",
   "items": [
    "The actual social engineering sub-limit, in writing, not the policy limit.",
    "Whether it is per occurrence or annual aggregate. Aggregate is materially worse if there is more than one incident.",
    "The deductible or retention applying to it specifically.",
    "Whether it covers transfers to vendors, to employees, and internal transfers — wordings vary and gaps hide here.",
    "Any conditions precedent on verification, and precisely what would satisfy them."
   ]
  },
  {
   "type": "p",
   "html": "Item four catches a common surprise: some wordings respond to vendor impersonation and not to an instruction that appears to come from an executive, or vice versa."
  },
  {
   "type": "h2",
   "text": "The exposure arithmetic"
  },
  {
   "type": "p",
   "html": "Simple and worth doing before the conversation with the broker."
  },
  {
   "type": "code",
   "text": "  Largest single payment in the last 12 months     $2,400,000\n  95th percentile payment                            $840,000\n  Median payment above the approval threshold        $118,000\n\n  Social engineering sub-limit                       $250,000\n  Applicable deductible                               $50,000\n\n  Net recovery on a $840,000 diverted payment        $200,000\n  Uninsured exposure                                 $640,000"
  },
  {
   "type": "p",
   "html": "Most organisations have not computed this. Presenting it to a board is usually what starts the conversation about the control."
  },
  {
   "type": "h2",
   "text": "What raising it requires"
  },
  {
   "type": "p",
   "html": "An underwriter increasing exposure in this category needs a reason. The realistic package has four parts."
  },
  {
   "type": "ul",
   "items": [
    "A defined scope: which payments carry the control, by threshold and trigger",
    "Measured evidence that it operated over the prior period",
    "An artefact a claims adjuster can verify without contacting you",
    "A willingness to accept a condition that the control was applied"
   ]
  },
  {
   "type": "p",
   "html": "The fourth is the trade and it should be made deliberately. A higher sub-limit conditioned on a control you cannot consistently apply is worse than a lower one with no condition — which is exactly the trap the current questionnaire regime creates."
  },
  {
   "type": "h2",
   "text": "Compute your own exposure"
  },
  {
   "type": "code",
   "text": "  Largest single payment, last 12 months      $2,400,000\n  95th percentile payment                       $840,000\n  Median above the approval threshold           $118,000\n\n  Social engineering sub-limit                  $250,000\n  Applicable deductible                          $50,000\n\n  Net recovery on an $840,000 diversion         $200,000\n  Uninsured exposure                            $640,000"
  },
  {
   "type": "p",
   "html": "Most organisations have not done this arithmetic. Presenting it to a board is usually what starts the conversation about the control."
  },
  {
   "type": "h2",
   "text": "Objections and honest limits"
  },
  {
   "type": "p",
   "html": "<strong style=\"font-weight:600\">“We will negotiate the sub-limit up.”</strong> With what? Every client brings the same training statistics. Raising it requires evidence, and accepting a condition you can actually sustain."
  },
  {
   "type": "p",
   "html": "<strong style=\"font-weight:600\">“A higher limit is always better.”</strong> Not if it is conditioned on a control you cannot consistently apply. A conditioned higher limit can be worse than an unconditioned lower one."
  }
 ],
 "faq": [
  {
   "q": "Why is the sub-limit so much lower than the policy limit?",
   "a": "Insurers sub-limit what they cannot underwrite. The preventive control is a human process whose operation cannot be verified at underwriting or at claim."
  },
  {
   "q": "Why does wire fraud fall under social engineering rather than computer fraud?",
   "a": "Computer fraud generally contemplates an unauthorised intrusion. A deceived but authorised employee making a transfer is the social engineering bucket."
  },
  {
   "q": "What should treasury check at renewal?",
   "a": "The actual sub-limit, whether it is per occurrence or aggregate, the specific deductible, which transfer types it covers, and what satisfies any verification condition."
  },
  {
   "q": "Is a higher conditioned sub-limit always better?",
   "a": "No. A higher limit conditioned on a control you cannot consistently apply is worse than a lower unconditioned one. Make the trade deliberately."
  },
  {
   "q": "Why does wire fraud fall under social engineering?",
   "a": "Because an authorised employee made the transfer through the normal process, having been deceived. That is the sub-limited bucket."
  },
  {
   "q": "Is the sub-limit unfair?",
   "a": "It is a rational response to a control the insurer cannot verify. Changing it requires making the control measurable."
  }
 ],
 "sources": [
  {
   "t": "NAIC — cyber insurance market report",
   "u": "https://content.naic.org/cipr-topics/cyber-risk"
  },
  {
   "t": "Published market commentary on cyber coverage structure."
  },
  {
   "t": "FBI IC3 2025 Internet Crime Report",
   "u": "https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf"
  },
  {
   "t": "Treasury association guidance on payment fraud exposure assessment."
  }
 ],
 "related": [
  {
   "slug": "marsh-vs-aon-top-insurance-brokers-evaluate-emerging",
   "title": "What brokers can negotiate on impersonation risk",
   "category": "Comparison"
  },
  {
   "slug": "funds-transfer-fraud-ftf-endorsement-prove-compliance",
   "title": "Proving out-of-band verification",
   "category": "Vertical"
  },
  {
   "slug": "cyber-insurance-actuarial-crisis-deepfake-warranties",
   "title": "Underwriting on questionnaire answers",
   "category": "Definitional"
  },
  {
   "slug": "ucc-article-4a-corporate-wire-exposure-calculator",
   "title": "Modelling corporate wire exposure under UCC 4A",
   "category": "Compliance"
  }
 ],
 "image": "https://cdn.twc.sh/images/igcache/Cyber%20Limit%20Versus%20Wire%20Limit/1500_900/blog.jpg",
 "wordcount": 833,
 "url": "/blog/social-engineering-sub-limit-trap-10m-cyber.html",
 "reading_time": "4 min read",
 "hub": {
  "slug": "topics/cyber-insurance",
  "title": "Cyber insurance and risk transfer"
 },
 "answer": "Almost never. Social engineering fraud typically carries a sub-limit far below the policy limit, and most wire fraud falls into that bucket rather than computer fraud — because an authorised employee was deceived into making the transfer, which is exactly what the sub-limit anticipates.",
 "answer_q": "Does a $10M cyber policy cover a $10M wire fraud?",
 "glossary": [
  {
   "term": "Sub-limit",
   "def": "A cap applying to one coverage within a policy, frequently far below the headline limit."
  },
  {
   "term": "Computer fraud",
   "def": "Cover contemplating an unauthorised system intrusion causing a transfer."
  },
  {
   "term": "Social engineering fraud",
   "def": "Cover contemplating an authorised person being deceived into making a transfer — where most wire fraud lands."
  }
 ],
 "checklist": {
  "title": "What to establish at renewal",
  "id": "renewal",
  "desc": "Five items.",
  "steps": [
   {
    "name": "The actual social engineering sub-limit.",
    "text": "In writing, not the policy limit."
   },
   {
    "name": "Per occurrence or annual aggregate.",
    "text": "Aggregate is materially worse."
   },
   {
    "name": "The deductible applying specifically to it.",
    "text": "Frequently different."
   },
   {
    "name": "Which transfer types are covered.",
    "text": "Vendor, employee, internal — wordings vary and gaps hide here."
   },
   {
    "name": "What satisfies any verification condition.",
    "text": "Get the answer before the loss."
   }
  ]
 },
 "cta": {
  "title": "Where this fits in Manav",
  "html": "Manav produces the artefact underwriting and claims both lack: a per-transaction receipt an adjuster can verify without contacting the insured, and a measurable coverage rate across a defined scope.",
  "href": "../docs.html",
  "label": "See the evidence a claim needs"
 }
}