Cyber Insurers Quietly Remove Coverage for Social Engineering and Fraudulent Instruction Claims

Stu Sjouwerman | Mar 23, 2023

Cyber Insurance Social EngineeringAs cyber insurers become more experienced in what kinds of claims are being presented, and the threat action details therein, specific types of coverages are no longer being included.

I’ve written quite a few times about specific cyber insurance claim cases that required going to court to settle. And in most of them, the courts sided with the insurer because the wording in the cyber insurance policy made certain it was covering specific use cases. According to a recent article in JD Supra, cyber insurers are either eliminating the coverage entirely or are “have quietly added policy language that, in essence, makes it incredibly challenging, and in some instances impossible, to secure any actual recovery for the claim.”

In addition, they are adding in specific verbiage that any kind of fraud involving change of payment instructions must include that the policyholder “independently verify” the request – that is, use another medium instead of simply taking the word of an email purporting to be someone with authority to make the request in the first place.

What we’re seeing isn’t greed or bad faith on the part of the cyber insurer; in fact quite the contrary – they aren’t in the business of simply handing out checks, so they need to either put in specific requirements or remove/reduce coverages for cases where the risk is just too high because – yep, you guessed it – users come into the equation.

In the end, this is really the problem – even with all the security tech in the world in place, all it takes is a little social engineering and a user that’s not paying attention and you have yourself a successful case of fraud, and it’s subsequent cyber insurance claim.

The answer here isn’t to put more emphasis on the cyber insurer; instead the focus should be on preventing such attacks from being successful – accomplished by educating the user with Security Awareness Training designed to teach them about scam tactics and their role in the organization’s cyber security stance.

Access the World’s Largest Security Awareness Library

Explore over 1,000 interactive modules, videos, and games designed to sharpen user instincts and secure AI interactions. Get instant access to our Free Training Preview and find the perfect content to fortify your security culture.

Get Your Free Training Preview

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.