Today's fraud schemes often blur the line between cybercrime and traditional theft. Cyber insurance typically covers system breaches like data theft and ransomware, while commercial crime insurance typically covers funds transfer fraud, social engineering, and employee theft. Many businesses need both policies to address potential coverage gaps.
Most business owners think cybercrime and theft are separate risks. Increasingly, they aren't.
Many modern fraud schemes begin with a compromised email account or stolen credentials and end with a financial loss, fraudulent wire transfer, or stolen inventory. Criminals are less likely to force their way in than they are to exploit trust and routine business processes.
Criminals frequently gain access to email systems and patiently monitor activity until the right opportunity appears.
For example, they may intercept vendor communications and redirect a legitimate payment to a fraudulent account. Or they may use stolen shipping documents to pose as a carrier and pick up goods before anyone realizes something is wrong.
In both cases, the fraud starts digitally but results in a real-world financial loss.
Cyber insurance typically covers losses involving data breaches, ransomware, and network security incidents.
Commercial crime insurance often provides coverage for exposures such as:
The challenge is that many losses involve elements of both. Depending on policy language, coverage may fall under a crime policy, cyber policy, or a combination of the two. That's why it's important to understand coverage details, not just policy limits.
Artificial intelligence is helping criminals create increasingly convincing emails, phone calls, and impersonation attempts.
As a result, businesses should not rely solely on traditional verification methods. Strong internal controls and employee awareness remain critical, regardless of insurance coverage.
Insurance helps address losses after they occur, but prevention can stop them from happening in the first place.
Every business owner assumes fraud won't happen to them, right up until it does. Insurers see claims daily from businesses that did everything right and got hit anyway.
Businesses should:
Fraud can affect businesses of any size or industry. The more payments, invoices, and transactions a company handles, the more opportunities criminals have to exploit routine activity.
Insurance finances a loss. Prevention is what keeps you from filing one.
The commercial insurance specialists at B. F. Saul Insurance help businesses understand how crime and cyber insurance policies work together, identify potential coverage gaps, and build a stronger defense against today's fraud risks.
Contact our team to review your commercial crime and cyber coverage.
Q. What is commercial crime insurance?
A. Commercial crime insurance can protect businesses against financial losses from theft, fraud, or dishonesty, including employee theft, funds transfer fraud, and social engineering scams. It's typically purchased separately from a general liability or property policy, since those policies don't usually cover intentional criminal acts against the business.
Q. What does commercial crime insurance cover?
A. Commercial crime insurance can cover employee theft, forgery, funds transfer fraud, and social engineering scams where someone is tricked into sending money or goods to a fraudster. Coverage limits and exact terms vary significantly by policy, so two businesses with the same stated limit may have different protection.
Q. What is the difference between commercial crime insurance and cyber insurance?
A. Commercial crime insurance typically covers losses from theft and fraud, including funds transfer fraud and social engineering. Cyber insurance typically covers losses connected to a system breach, such as data theft or ransomware. When a loss involves both, like a phishing email that leads to stolen funds, either policy may apply depending on its wording.
Q. Is a certificate of insurance proof of adequate coverage?
A. No. A certificate of insurance confirms a policy exists and states a coverage limit, but it doesn't specify what that limit applies to. A million dollars in crime coverage could apply to employee dishonesty or to social engineering fraud. Confusing the two is how a gap goes unnoticed until a carrier denies a claim. Confirm the specifics directly with the policyholder's advisor.
Q. Does cyber insurance cover AI-related fraud like deepfakes?
A. Coverage for AI-related fraud, including deepfake voice scams, is still developing. Most cyber insurance policies don't yet specifically address AI-enabled fraud, though a growing number of carriers offer AI-specific endorsements or standalone policies. Businesses should expect policy language in this area to become more defined as claims increase.