Social engineering scams are built around one simple trick: getting a person to do something they normally wouldn’t. A fake email arrives. Someone pretends to be a supplier. Money gets sent to the wrong account. And suddenly, the business is dealing with a loss that didn’t start with hacked software.
Why Social Engineering Gets Complicated
The tricky bit is that the victim may have technically made the payment themselves. There was no stolen password in the usual sense. No ransomware locked the company’s files. An employee simply believed a convincing message and followed the instructions.
Insurers treat this differently from a standard cyberattack. A basic cyber policy might cover costs tied to a data breach, while a social engineering endorsement is designed for losses caused by someone manipulating an employee.
Check for a Specific Social Engineering Cover
• A separate endorsement may be required, and assuming the basic cyber cover includes it is a risky bet.
• Payment fraud is the big sticking point because the employee may have authorised the transfer, even though the instruction came from a scammer.
• There can be a lower payout limit here, which matters if the fraudulent transfer is large.
The Fine Print Can Decide the Claim
Some policies require specific controls before they’ll pay. The insurer may expect employees to verify payment changes through a separate communication channel. If those steps weren’t followed, the claim could face trouble.
What Should You Look For?
• Coverage for fraudulent transfers, because that’s often where the financial loss actually happens.
• A social engineering sub-limit that is large enough for your typical payment size, not just a number that looks reassuring on the first page.
• Verification requirements matter too. If your policy expects a callback before changing bank details, your team needs to actually do it.
Honestly, this is one area where broader coverage isn’t automatically better. A policy can sound impressive and still leave a major gap if social engineering fraud is carved out or capped at a small amount.
So, Is It Covered?
Yes, social engineering can be covered by cyber insurance, but you shouldn’t assume it is included automatically. The policy needs to provide the right type of protection, and the claim still has to meet its conditions.