The Opening Story
The email came from his own CFO. Same signature block, same tone, same phrasing the man had used for years. It asked accounting to wire $74,000 to a vendor account for a project already underway.
Accounting wired it. Nobody questioned it, because there was nothing to question. The request looked exactly like every other request.
It wasn't the CFO. Someone had been sitting inside that email thread for weeks, reading, learning how the company talked to itself, waiting for a payment large enough to be worth taking and ordinary enough not to be noticed.
The owner called me the same day. He had cyber liability coverage. He'd bought it specifically because he worried about exactly this kind of thing.
The claim was denied.
The Insight
Cyber liability and social engineering fraud are two different coverages, and most owners find that out the way this one did.
Cyber liability responds when someone breaches your systems — ransomware, data theft, a hack. Something was done to you without your participation.
Social engineering fraud responds when someone tricks your people into voluntarily sending money. Nothing was breached. No firewall failed. An employee did exactly what they were asked to do by someone who had convincingly impersonated a person they trusted.
Carriers separate these on purpose. The second is a crime coverage, it usually sits as an endorsement rather than a base form, and it frequently carries a sublimit well below your main cyber limit — $50,000 or $100,000 against a policy that reads $1M on the declarations page.
If nobody walked you through that distinction when you bought the policy, you likely don't have the second one.
The Protection Checkpoint
Three things to check this week:
Pull your cyber policy and search for "social engineering" or "fraudulent instruction." If the phrase doesn't appear, the coverage isn't there.
If it does appear, find the sublimit. It's rarely equal to your policy limit, and the gap is what you'd absorb.
Install a callback rule. Any payment instruction that arrives by email — new account, changed account, urgent — gets verified by phone to a number you already had on file. Not a number in the email. This costs nothing and stops nearly all of it.
Ask John
A question I get asked constantly:
"Our bank says they'd reverse a fraudulent wire. Doesn't that cover us?"
Almost never. Reversal depends on catching it inside a very short window, and these transfers are usually moved through several accounts within hours. Banks will help you try. They don't guarantee recovery, and they aren't liable for an instruction your own employee authorized. That's the whole reason the coverage exists.
The Bottom Line
He didn't lack insurance. He lacked the specific endorsement that matched the specific way he was going to be attacked.
That distinction is the difference between a bad week and a $74,000 hole in your operating account.
Reply to this email with your industry and I'll tell you the two coverages most commonly missing in it.
John Crist
Prestizia Insurance
Author, The Prestizia Protection Playbook