Social engineering is one of those cyber risks that sounds covered until you read the policy closely. A person gets fooled by a fake email or a convincing phone call, money leaves the company account, and everyone naturally asks the same thing: will cyber insurance pay for it?

Why Social Engineering Gets Tricky

The problem starts with how the loss happens. A hacker may never break into your network. Instead, they persuade an employee to approve a payment or share sensitive information. From an insurer’s view, that can look very different from a direct system breach.

Check the Actual Wording

Look for terms such as social engineering fraud, fraudulent instruction, funds transfer fraud, or impersonation fraud. The wording matters because one policy might respond when an employee is tricked by a fake supplier email, while another may require evidence that the company’s computer system was actually compromised.

• A separate endorsement, which is often where social engineering coverage quietly lives.

• A lower sublimit than the main cyber policy, so a large loss can leave a noticeable gap.

• Employee verification requirements may apply too, and skipping the required callback could affect a claim.

How to Tell If You’re Actually Covered

Start with the exclusions. Then read the coverage section and any endorsements attached to the policy. Don’t stop after seeing the phrase “cyber fraud.”

Pay attention to how the policy defines a covered event. Some policies require an employee to be deceived. Others focus on an unauthorized transfer. Some require a third-party impersonation element. Those differences sound minor until you’re trying to recover real money.

Watch for These Gaps

• If the policy only covers unauthorized access, a payment that an employee willingly approves may fall outside that wording.

• A social engineering endorsement can be valuable, but check its limit before assuming the full cyber limit applies.

• Verification rules matter, especially when the policy sets a specific process that employees must follow.

So, is social engineering excluded from cyber insurance? Not always. In fact, many policies can provide protection when the right coverage or endorsement is included.