Lesson 2 of 5 · Cyber Insurance

Key Exclusions

The main exclusions and conditions in a cyber policy: social engineering fraud, minimum security standards, physical damage and bodily injury, and prior known events, and how endorsements can change the position.

Fact-checked 8 October 20265 practice questions in the game

Why exclusions matter here

Exclusions are the events, circumstances or types of loss that a policy does not cover. They matter more than usual in cyber insurance because one incident often straddles the line between covered and excluded. A cyber policy carries the standard exclusions common to general insurance and also cyber-specific ones that arise from digital risk.

Social engineering and funds transfer fraud

In social engineering fraud nobody breaks into a system. An employee is tricked into voluntarily transferring funds, for example by an email that appears to come from a senior executive or by a manipulated vendor invoice. This loss is often excluded from the base cyber policy, or covered only up to a sub-limit, unless an endorsement is bought.

The Social Engineering Fraud and Funds Transfer Fraud covers are distinct covers that are often sold together. They respond to loss from business email compromise, impersonation of a senior executive and manipulated vendor invoices, exposures that matter most to businesses moving large sums by wire. They usually carry a sub-limit and conditions such as verifying payment instructions.

By contrast, forensics and legal defence are standard covers, and ransom payments are usually covered subject to the insurer's consent and the policy limits.

Minimum security standards

Cyber policies often require minimum security standards as a condition of cover: multi-factor authentication (MFA), firewalls and patching are the usual examples. Where the insured did not maintain them and that contributed to the loss, the insurer may decline the claim. A rejection because MFA was not enabled rests on this minimum security standards warranty.

The same thinking lies behind the treatment of known critical vulnerabilities left unpatched, which some policies exclude and others restrict through conditions or sub-limits.

Physical damage and prior known events

Bodily injury and physical property damage caused by a cyber attack are generally excluded from cyber policies. If a hacked industrial control system causes a factory explosion, the physical damage is outside the cyber policy. It may fall under property or liability insurance instead, but many of those policies now carry cyber exclusions of their own, so the wording of each needs checking.

The prior known events exclusion removes incidents or circumstances the insured knew of before the policy began. Insurance covers the unknown, not a loss already in progress. Failing to disclose such matters is a separate breach of the duty of good faith, so a known breach that was kept quiet creates two problems, not one.

Rules at a glance

Social engineering fraudOften excluded or sub-limited in the base policy; added by endorsementCyber policy wording; varies by policy
Minimum security standardsCondition of cover; breach that contributed to the loss may defeat the claimCyber policy warranty or condition
Bodily injury and physical property damageGenerally excluded from cyber policiesCyber policy exclusion; check property and liability wordings
Prior known eventsIncidents or circumstances known before inception are excludedCyber policy exclusion
Illustration

An invoice that looked right

Illustration: the accounts team of an exporter in Ludhiana receives an email, apparently from a regular supplier, giving new bank details. A payment is sent to the new account before anyone telephones the supplier to check. No system was hacked; the funds were transferred voluntarily on a false instruction. Under a base cyber policy this loss is often excluded or sub-limited. If the exporter had bought a social engineering fraud endorsement, the claim would be looked at under it, up to its sub-limit, and the insurer would ask whether the condition on verifying payment instructions was met.

Worked example

A sub-limit at work

  1. Assumptions, for arithmetic only: policy limit ₹5,00,00,000; social engineering fraud endorsement with a sub-limit of ₹25,00,000; a fraudulent transfer of ₹40,00,000; all conditions of the endorsement met.
  2. The loss falls under the endorsement, so the sub-limit applies and not the overall policy limit.
  3. Amount payable = the lower of ₹40,00,000 and ₹25,00,000 = ₹25,00,000, before any other term of the policy.
  4. Amount borne by the insured = ₹40,00,000 − ₹25,00,000 = ₹15,00,000.

Result. Although the policy limit is ₹5,00,00,000, this loss is capped at the ₹25,00,000 sub-limit and the insured bears ₹15,00,000.

Key points

  • Social engineering fraud is often excluded from, or sub-limited in, the base policy unless added by endorsement.
  • Social Engineering Fraud and Funds Transfer Fraud covers are distinct, often sold together, and usually carry a sub-limit and verification conditions.
  • Ransom payments are usually covered subject to the insurer's consent and the policy limits.
  • Failure to maintain required security standards, where it contributed to the loss, may lead the insurer to decline the claim.
  • Bodily injury and physical property damage from a cyber attack are generally outside a cyber policy.
  • Incidents or circumstances known before the policy began are excluded, and non-disclosure is a separate breach of good faith.

Common misunderstandings

  • A cyber policy does not cover every loss that begins with an email: voluntary transfers induced by fraud are often excluded or sub-limited unless endorsed.
  • Physical damage from a hack is not a cyber claim: it is generally excluded, and the property or liability policy may carry its own cyber exclusion.
  • Security requirements are not a formality: they are often conditions of cover, so the wording has to be checked for how they apply.
  • Buying a policy after discovering a breach does not bring that breach into cover: prior known events are excluded.

Questions people ask

Are ransom payments excluded?

Usually not. They are usually covered, subject to the insurer's consent and the policy limits.

Does a missing security control always defeat a claim?

The verified position is narrower: where the insured did not maintain the required standards and that contributed to the loss, the insurer may decline the claim. The exact effect depends on the policy wording.

Are social engineering fraud and funds transfer fraud the same cover?

No. They are distinct covers that are often sold together.

What this lesson relies on

  • Cyber insurance policy wording — exclusions, minimum security conditions, social engineering fraud and funds transfer fraud endorsements

This lesson was reviewed independently against these sources on 8 October 2026. Rules change: check the current regulation, scheme document or policy wording before relying on any figure. This is education, not advice.

Free learning from the Trustner Group. Trustner Academy is an education initiative of the Trustner Group, whose companies work across insurance broking and investment services, with offices in Bangalore, Guwahati, Kolkata, Hyderabad and Mumbai. Everything here is for learning only — it is not advice, a recommendation or an offer of any product. Scenarios are illustrative. Rules and figures change; check the current regulation, scheme document or policy wording before acting on anything.