Social engineering coverage pays when a criminal deceives your employee into voluntarily sending money — and on most cyber policies it is capped at a sublimit that is a fraction of the full policy limit. A business carrying a one-million-dollar cyber policy often has only $100,000 to $250,000 of coverage for the loss it is statistically most likely to suffer.
Business email compromise is not a systems failure. No firewall is breached, no malware is deployed, and no data is stolen — an employee with full authority simply sends a real wire to a criminal’s account because an email told them to. That distinction is exactly why insurers treat it differently: the full cyber limit responds to a network intrusion, while a deception loss gets a small carve-out with its own cap and its own conditions. This article walks through how a business email compromise loss actually unfolds, why carriers sublimit it, where crime and cyber policies overlap on the same missing dollars, and the verification controls that both prevent the loss and persuade an underwriter to raise the cap.

- What is social engineering coverage?
- What does a business email compromise loss actually look like?
- Why do cyber policies sublimit social engineering?
- Don’t the bank or the crime policy cover a fraudulent wire?
- What verification controls prevent the loss — and improve your terms?
- How do you get the sublimit raised?
- What should a business do at its next renewal?
What is social engineering coverage?
Social engineering coverage — sometimes labeled fraudulent instruction, funds transfer fraud by deception, or cyber deception coverage — is the insuring agreement that responds when an employee is tricked into voluntarily transferring money or property to a criminal. The operative word is *voluntarily*. The employee had the authority to send the payment, followed what looked like a legitimate instruction, and used the company’s own systems exactly as designed.
That places social engineering in a strange position on a commercial insurance program. It looks like a cyber loss, because the deception arrives by email. It looks like a crime loss, because money was stolen. But most cyber liability policies were built around network intrusions — breach response, data restoration, liability to third parties — and most crime policies were built around dishonest employees and forged checks. A deception loss sits in the seam between them, and carriers on both sides responded the same way: cover it, but cap it.
Avanti Group’s framing for every coverage decision applies here with unusual force: understand the risk you are keeping versus the risk you are transferring. With social engineering, most businesses are keeping far more than they think.
What does a business email compromise loss actually look like?
The anatomy is remarkably consistent, and the FBI’s Internet Crime Complaint Center has ranked business email compromise among the costliest cybercrime categories it tracks for years running, with reported losses in the billions of dollars annually.
It starts quietly. A criminal compromises or convincingly spoofs an email account — often not yours, but a vendor’s. They read the mailbox for weeks. They learn who approves payments, what invoices look like, which projects are mid-stream, and how people sign their emails.
Then comes the instruction. A message arrives in your accounts payable inbox that matches every pattern your team expects: the right vendor, the right project, the right dollar range, the right tone. It says the vendor has changed banks, and the attached invoice — real work, real amount — carries new wiring instructions.
Your employee updates the record and sends the payment. Nothing looks wrong for days or weeks, until the real vendor calls asking why the invoice is past due. By then the money has typically moved through several accounts and out of reach. Recovery windows on wire transfers are measured in hours, not weeks.
For a Midwest business the pattern is not exotic. The payment chains that define this region’s economy — contractors paying subcontractors on draw schedules, ag operations settling with suppliers and cooperatives, real estate closings moving six-figure wires on a deadline — are precisely the routine, high-dollar, deadline-driven transfers this fraud is engineered to imitate.
Why do cyber policies sublimit social engineering?
A sublimit is a lower cap inside the policy that applies to a specific category of loss — and on most cyber forms, social engineering carries one of the smallest. Where the policy might carry a $1 million aggregate limit, the social engineering insuring agreement commonly caps out at $100,000 or $250,000, sometimes less. The reasons are structural, not arbitrary.
First, frequency. Deception attacks are cheap to run and scale infinitely — a criminal needs a convincing email, not a technical exploit. Carriers price accordingly.
Second, the voluntary-parting problem. Insurance responds most cleanly to things done *to* you. A social engineering loss is something your own authorized employee did, through the proper channel, with the proper authority. From an underwriting seat, the loss is inseparable from the strength of your internal controls — so the carrier caps its exposure to the part of the risk it cannot see.
Third, control dependence. Whether a fake vendor email costs you $80,000 or nothing depends almost entirely on whether anyone picked up the phone to verify. Carriers sublimit what your own procedures largely determine.
This is the same structural logic covered in the companion piece on ransomware sublimits, coinsurance, and exclusions: the headline limit is not the coverage. The coverage is the schedule of insuring agreements underneath it — which is why reading sublimits, exclusions, and conditions before the loss, not after, is the entire game. A sublimit discovered at claim time is coverage that looked fine on paper and failed when it actually mattered.
Don’t the bank or the crime policy cover a fraudulent wire?
Usually not the bank. Under Uniform Commercial Code Article 4A — adopted in Iowa as part of Iowa Code chapter 554 — a payment order your business actually authorized is generally your loss, even when the authorization was procured by fraud, so long as the bank followed commercially reasonable security procedures. The law treats a deceived-but-authorized wire very differently from a forged one. Businesses routinely assume the bank will make them whole; the statute mostly says otherwise.
The crime policy is a real but partial answer. Commercial crime forms respond to employee theft and computer fraud, and many now offer their own social engineering endorsement — typically with its own modest sublimit. Which policy pays for the same missing dollars depends on exactly how the money left, and the boundaries between crime, employee dishonesty, and social engineering coverage are covered in detail in that companion article. The short version: a deception loss can implicate both the crime and cyber policies, both will likely sublimit it, and the two sublimits do not stack by default. Coordinating them is program design, not luck.
What verification controls prevent the loss — and improve your terms?
Verification controls are the procedures that confirm a payment instruction through a second, independent channel before money moves — and they are the single strongest lever on both the risk itself and the coverage available for it. The core set underwriters ask about:
– Out-of-band callback verification. Any new payee or any change to banking instructions gets confirmed by phone, using a number already on file — never a number supplied in the email requesting the change. – Dual authorization on wires and ACH changes above a defined dollar threshold, so no single deceived employee can complete the transfer alone. – A cooling-off standard for banking changes — vendor bank-detail changes take effect on a fixed schedule, not on the timeline the email demands. Urgency is the fraud’s fuel. – Email authentication and flagging — marking external mail, and flagging lookalike domains registered near your own or your vendors’ names.
Here is the part that connects controls to coverage: many social engineering insuring agreements make verification a *condition* of coverage. If the form requires callback verification and your employee skipped it, the sublimited coverage you did buy may not respond at all. The procedure is not just loss prevention — on many forms, it is the coverage trigger.
How do you get the sublimit raised?
The same way every account earns better terms: by giving the underwriter a reason. Carriers raise social engineering sublimits — sometimes substantially — for accounts that can document the controls above, because documented controls convert an unknowable risk into a priced one. This is account positioning: packaging your risk so an underwriter wants it, rather than shopping the same unexamined risk harder.
Timing matters too. Avanti’s read of the market as of mid-2026 is that cyber has softened substantially — in the firm’s words, nearly everyone should be remarketed, because better coverage at the same or better rate is the norm right now rather than the exception. A soft cyber market is exactly when sublimits, coverage conditions, and endorsement language are negotiable. Walking into that market without asking about the social engineering cap is one of the classic renewal mistakes: renewing the headline limit while the sublimit that matches your likeliest loss rolls over untouched.
What should a business do at its next renewal?
Start with the number, not the premium. Pull the cyber policy and the crime policy, find the social engineering and funds transfer fraud insuring agreements, and write down three things: the sublimit on each, the verification conditions attached to each, and the size of the largest wire your business sent in the past year. If the third number is larger than the first two, that gap is risk you are keeping — and current market conditions mean you are probably keeping it unnecessarily.
This is precisely the kind of seam-between-policies exposure the Business Risk Diagnostic™ exists to surface. The Diagnostic maps how money actually moves through your business — who can send it, on whose instruction, with what verification — against how your cyber and crime coverage would actually respond, before any quote enters the conversation. It is the difference between buying a limit and understanding your commercial program — and with deception losses, understanding is most of the protection.
Frequently Asked Questions
What is a typical social engineering sublimit on a cyber policy?
Commonly $100,000 to $250,000, regardless of the full policy limit — and sometimes as low as $50,000 on smaller programs. Some carriers will raise the sublimit meaningfully, or offer full-limit endorsements, for accounts that document callback verification and dual authorization. The only way to know your number is to read the insuring agreement schedule, not the declarations page headline.
Does the bank have to reimburse a fraudulent wire transfer?
Generally not, if your business authorized the wire — even under deception. Under UCC Article 4A, adopted in Iowa Code chapter 554, an authorized payment order is typically the customer’s loss when the bank followed commercially reasonable security procedures. Banks can sometimes claw back funds if notified within hours, which is why immediate reporting matters, but reimbursement is the exception rather than the rule.
Is business email compromise covered by cyber insurance or crime insurance?
Potentially both, and fully by neither. Cyber policies address it through a social engineering or fraudulent instruction insuring agreement; crime policies address it through a social engineering endorsement. Both are usually sublimited, and the two do not stack automatically. Which one responds depends on how the loss occurred and how the two policies are coordinated — which is a program-design decision made before the loss.
Can a claim be denied if an employee skipped the verification procedure?
Yes. Many social engineering insuring agreements make verification — such as a callback to a known number before changing banking details — a condition of coverage. If the form requires it and it was skipped, the carrier may deny even the sublimited amount. Training and enforcing the procedure protects both the money and the coverage.
What controls do underwriters want to see before raising a social engineering sublimit?
The consistent short list: out-of-band callback verification for new payees and banking changes, dual authorization above a dollar threshold, a mandatory waiting period on vendor bank-detail changes, external-email flagging, and documented employee training. Accounts that can evidence these controls routinely secure higher sublimits and better conditions — especially in a soft cyber market.
