A finance team receives an email that appears to come from a long-standing supplier. The banking details have changed, the payment deadline is tight, and the requested transfer is authorised. Days later, the supplier calls to ask why its invoice remains unpaid. The funds are gone.
Cyber insurance versus crime insurance becomes a critical question at precisely this point. Both classes may be relevant to technology-enabled fraud, but they are designed to answer different losses. Assuming one will automatically respond to the other can leave a business carrying a material uninsured exposure when a claim occurs.
For businesses with substantial payment flows, confidential data, operational technology or third-party network dependencies, the distinction deserves careful attention. The sensible approach is not to buy the cheapest policy labelled “cyber” or “crime”. It is to map how money, data and authority move through the organisation, then test the insurance programme against credible failure scenarios.
Cyber insurance versus crime insurance: the core difference
At its simplest, cyber insurance is principally concerned with the consequences of a cyber incident affecting systems, data, network security and operations. Crime insurance is principally concerned with direct financial loss caused by defined dishonest or fraudulent acts.
The line is not always neat. A fraudulent email, for example, is a cyber-enabled event. Yet the central financial loss may be the money voluntarily transferred by an employee after being deceived. Whether that loss falls within cyber cover, crime cover, a specific social-engineering extension, or none of them, depends on the policy structure and the facts.
Cyber insurance often responds to the cost of managing and recovering from an incident. Crime insurance often addresses the stolen assets themselves, subject to the insuring clauses and conditions. A well-designed corporate programme may require both, coordinated so that there are no avoidable gaps or disputes between policies.
What cyber insurance commonly addresses
Cyber policies vary considerably, but are commonly designed around first-party incident costs and third-party liability arising from a security failure, privacy event or technology disruption. For a manufacturer, logistics operator or professional-services firm, the impact can extend well beyond the immediate IT issue.
A cyber policy may include elements such as forensic investigation, legal and crisis-management support, notification costs, credit-monitoring services where appropriate, data restoration, cyber extortion response and business interruption resulting from a covered network event. It may also provide cover for liabilities to affected third parties, defence costs and certain regulatory investigations or penalties where insurable by law.
The business interruption component requires particular scrutiny. A ransomware event that stops warehouse management systems, production scheduling, booking platforms or project documentation can generate lost gross profit, additional working costs and contractual pressure. The trigger, waiting period, indemnity period, method of calculating loss and treatment of dependent service providers can materially affect the value of the cover.
Cyber cover can also be relevant when a third-party cloud provider, software platform or managed service provider suffers an outage or breach. However, contingent business interruption cover is not universal, and some policies narrowly define the technology providers or events that qualify. Businesses that rely on a small number of critical platforms should not assume this exposure has been fully addressed.
What cyber insurance may not solve
A cyber policy is not simply a balance-sheet guarantee for every loss involving an email, computer or mobile device. Many wordings distinguish between a malicious compromise of the insured’s systems and a payment made because an employee was manipulated by an external fraudster.
Some policies offer social-engineering or funds-transfer fraud extensions, often with a separate sub-limit, strict verification requirements or a narrow definition of impersonation. The amount available may be far below the organisation’s largest plausible payment. Others may exclude contractual liabilities, reputational damage that does not produce an insured financial loss, or losses arising from an inadequate pre-existing control.
This does not make cyber insurance less valuable. It means the policy must be read alongside the organisation’s payment procedures, supplier-onboarding controls and crime protection.
What crime insurance commonly addresses
Commercial crime insurance, sometimes referred to as fidelity guarantee or crime cover, is intended to protect the business against direct loss of money, securities or other property caused by specified criminal acts. It is especially relevant where an organisation handles high-value payments, inventory, stored-value instruments, client funds or decentralised purchasing authority.
Depending on the wording, crime cover may address employee dishonesty, theft by third parties, forgery or alteration, counterfeit currency, computer fraud, funds-transfer fraud and client-property exposures. The exact terminology and scope differ between insurers, and the policy may be written on a discovery or loss-sustained basis. That distinction matters where fraudulent activity is concealed for an extended period.
Employee dishonesty remains a significant exposure, including in businesses with trusted, long-serving staff. A person with access to procurement systems, payment platforms or inventory records may be able to conceal misconduct before it is detected. Crime insurance is not a substitute for segregation of duties and auditing, but it can be an important financial backstop when controls fail.
Crime cover can also be more directly aligned with certain external fraud losses than a standard cyber policy. However, the way the payment occurred is usually decisive. Did a criminal access the payment system and initiate the transfer? Was an instruction forged? Or did an authorised employee make the payment after receiving a convincing but false instruction? These are materially different events in insurance terms.
The social-engineering gap
Business email compromise sits at the intersection of cyber and crime risk. An attacker may impersonate a director, supplier, legal adviser or project partner, using lookalike domains, compromised accounts and carefully timed requests to defeat normal caution.
The most difficult cases involve a voluntary transfer. The employee had authority, the payment was processed correctly within the system, but the instruction was fraudulent. Traditional crime wordings may exclude voluntary parting with property, while cyber wordings may treat the payment as outside the main insuring clause unless a specific extension applies.
This is why a social-engineering extension should be reviewed in detail rather than accepted as a reassuring label. Consider its limit, excess, aggregation wording, proof requirements, call-back procedures, treatment of supplier-bank-detail changes and whether it applies to instructions received by email, telephone or messaging applications. A £-equivalent limit may be inappropriate for a Singapore business with regional project payments in several currencies, so limits should reflect actual exposure rather than a standard package amount.
Comparing the policies in a real incident
Consider a regional engineering contractor whose document-management system is compromised. The attacker accesses tender files and supplier correspondence, deploys ransomware and sends altered bank details to the accounts team. Operations are disrupted for five days, the business pays external specialists to investigate, and a payment is sent to the criminal’s account.
The forensic costs, system restoration and eligible interruption loss may fall for consideration under cyber insurance. Any liabilities connected with exposed personal or confidential information may also be relevant to that policy.
The misdirected supplier payment may instead require assessment under crime insurance or a social-engineering extension. If the fraud involved unauthorised access and direct manipulation of the banking platform, a computer-fraud or funds-transfer provision may be relevant. If the accounts team acted on an apparently genuine request, the voluntary-transfer wording becomes central.
There may be multiple policies to notify. Early notification is generally prudent, but businesses should follow the notification provisions in each policy and preserve evidence. Do not negotiate recovery arrangements, admit liability or incur significant response costs without considering the policy requirements and taking appropriate legal or claims advice.
Build cover around the way your business operates
The starting point is a practical risk review, not a policy comparison sheet. Finance, IT, operations, legal and procurement should be able to identify the payment types that could cause the greatest loss, the systems that cannot be unavailable, and the information whose disclosure would create contractual, regulatory or commercial harm.
Four questions usually reveal where more work is needed:
- What is the largest single payment that could be redirected through supplier or executive impersonation?
- Which operational systems would cause immediate revenue loss or project delay if unavailable?
- Can a third party’s outage, breach or error interrupt the business?
- Who can create, approve and amend payment instructions, supplier records and user access?
The answers should inform policy limits, sub-limits and retentions. They should also guide controls. Dual authorisation, independent verification of bank-detail changes, privileged-access management, phishing training, offline backups, incident-response planning and supplier due diligence all reduce the likelihood and severity of loss. Insurers may also make some controls conditions of cover or factors in underwriting.
For organisations operating across Southeast Asia, local entities, currencies and contractual obligations add further complexity. A programme should be checked for territorial scope, insured entities, local-policy requirements, cross-border data issues and whether a loss in one subsidiary could erode a shared group limit. The same care is needed for contractors handling client information, marine and logistics operators dependent on tracking systems, and healthcare or hospitality businesses holding significant personal data.
Read the programme as a whole
Cyber and crime insurance should not be reviewed in isolation from directors’ and officers’ liability, professional indemnity, property damage and business interruption, marine cargo or other covers within the wider programme. An incident can create several kinds of loss at once, and inconsistent definitions or exclusions can create unwelcome uncertainty.
Coverage always depends on the quotation, schedule, policy wording, endorsements, exclusions, limits and the facts of the claim. Limits and sub-limits should be tested against realistic loss scenarios, including the cost of external response specialists and the possibility that a fraud event coincides with operational disruption.
Kloon Risk Management approaches this review as a business-continuity exercise: understanding the exposures first, then arranging cover that reflects how the business actually trades. The most useful insurance conversation is held before the urgent call from finance, when there is still time to verify that the policy, controls and claims process will work together.
For further information, call +65 6241 3767, contact us on WhatsApp, or email enquiry@kloonrisk.com.
