The coverage gap this creates

When fraud arrives through a trusted channel, the boundary between a cyber event and a crime event becomes less clear. Coverage for business email compromise (BEC) and funds transfer fraud varies across cyber policies and may be excluded, subject to lower sublimits, or require social engineering or fraudulent funds transfer extensions. This creates an important coverage consideration for sectors such as professional services, legal, and real estate, where payment diversion scams remain a significant source of financial loss. Analysis by law firm Jones Walker notes that the “voluntary parting” exclusion in standard crime and fidelity policies is the primary coverage barrier because coverage typically does not apply when a deceived employee knowingly authorises a transfer, and that social engineering sublimits of $100,000 to $250,000 are increasingly viewed as inadequate for AI-scale losses.