Cyber Insurance vs Crime Insurance: Here’s What You’re Missing
True Story – The $83,000 That Vanished
It was supposed to be a routine reconciliation. Eleven days after the month’s end, the controller of a mid -sized construction firm noticed something alarming: an $83,000 ACH transfer had cleared the company’s account. No one had authorized it, and no one recognized the recipient.
When the company called the bank, the answer was blunt: too much time had passed. Because the fraudulent transfer wasn’t reported within the bank’s short reversal window, the funds were gone for good.
The bigger question was how the criminals got the account information in the first place.
• Was it a business email compromise (BEC), a phishing attack that exposed login credentials? The hacker could have gotten into the account info from by hacking their email or by hacking into their OneDrive, and then the cyber policy may respond.
• Or was it something more old -fashioned, the criminals just ripped the routing and account number from a simple check? In this case, a Crime policy may respond.
The loss could fall into a gray area between crime coverage and cyber coverage.
Depending on the policy language, neither or both could be triggered.
If you only have a cyber policy, then you’d have to pay a digital forensics firm to find out if someone is in your email. If results are inconclusive, you just spent $12K on top of the $83K you lost.
What Crime Insurance Covers:
Crime insurance protects against financial losses caused by theft or fraud. Think of it as protection for your money and securities. Common coverages include:
• Employee theft or embezzlement
• Forgery and check fraud
• Funds transfer fraud (e.g., tricked into wiring money)
• Social engineering scams
• Robbery or burglary of cash or securities
What Cyber Insurance Covers:
Cyber insurance is designed for your company’s network/computer-based risks.
Common coverages include:
• Data breaches (investigation, notification, credit monitoring, regulatory fines)
• Ransomware and cyber extortion
• Business interruption from system outages
• Liability if clients or partners sue after a breach
• Data restoration after malware or corruption
• Internet or email-based social engineering
Comparison: Crime Insurance vs. Cyber Insurance

Crime Insurance vs Cyber Insurance Comparison Chart
Insider threats — whether intentional (a disgruntled employee stealing data) or unintentional (an employee mishandling sensitive information) need to be considered as well.
• Crime insurance may respond if the insider embezzles money, securities, or commits fraud.
• Cyber insurance may respond if the insider causes a data breach, installs malware, or exposes client information.
• In many insider cases, both policies could be triggered: one for the financial theft, the other for the data and liability fallout.
What Questions Should Your Broker Be Asking You?
A good broker doesn’t just place coverage — they uncover risk. To make sure your policies align with your operations, your broker should be asking questions like:
• Transaction Size & Frequency: What is the typical size of your wire or ACH transfers? How often do they occur?
• Authorization Controls: Who has the authority to initiate or approve transfers? Is dual authorization required?
• Account Access: Who has online banking credentials? How are they stored and protected?
• Procedures & Training: What internal controls are in place to verify payment requests? Do employees receive phishing or fraud awareness training? Is the finance department getting specialized training?
• Incident Response: If a suspicious transfer or cyber event occurs, what’s your escalation process? Who do you call first?
These questions help identify where crime coverage and cyber coverage intersect and where gaps may exist.
What Happens If Both Policies Respond?
Sometimes, both policies could apply, especially in insider threat or blended cybercrime cases.
In these situations:
• Insurers decide which policy is primary and which is secondary.
• There may be delays or disputes if the wording isn’t clear.
• The best way to avoid gaps is to align both policies with your broker’s help.
The Bottom Line
• Crime insurance protects your money and securities from theft, fraud, and forgery.
• Cyber insurance protects your data, systems, and liability from internet internet-based attacks.
• Insider threats and blended attacks can trigger both policies, making it clear that neither is enough on its own.
Cybercrime doesn’t fit neatly into one boxbox, and neither should your insurance program.
If you’re unsure whether your current policies would respond to an $83,000 ACH theft, a ransomware attack, or an insider threat, it’s time to review your coverage.
Talk to your broker today about aligning your crime and cyber policies.
If you’d like a complimentary cybersecurity insurance gap review, please reach out to [email protected]
Joe Erle, Cyber Group Practice Leader


