Governance Risk & Operations · 1 February 2028
Social engineering is now the dominant attack vector behind the large majority of Australian data breaches, and this specific category of loss is where many cyber insurance policies apply their tightest, least generous coverage. An association assuming its cyber policy broadly covers whatever a cyber incident throws at it may be relying on a policy least equipped to respond to the threat it is most likely to face.
The Specific Gap Most Boards Do Not Know Exists
Where an employee is deceived into transferring funds or disclosing credentials, without any actual system being technically compromised, some insurers classify the resulting loss as a crime loss rather than a cyber loss, placing it outside the policy's core insuring agreement entirely. Coverage for this specific scenario, social engineering fraud, is frequently only available as an optional add-on, and even where included, it commonly carries its own sublimit set considerably lower than the policy's overall aggregate coverage. An association could hold a policy with a headline limit in the hundreds of thousands or millions of dollars, while its actual protection against the most common real-world attack vector sits capped at a fraction of that figure. A cyber policy's headline coverage limit tells you very little about what it will pays on the specific type of loss your association is statistically most likely to experience. That answer sits in the sublimits and exclusions schedule, not the summary page.
The Application Answers That Can Quietly Void A Claim
Security control representations made when applying for cyber insurance, whether multi-factor authentication is enforced, whether backups are regularly tested, become material facts the insurer relies on when pricing the policy. If an incident occurs and those controls turn out to have been missing or inconsistently applied, despite being confirmed in the original application, insurers can and do deny the resulting claim on this basis. This connects directly to the cyber security governance discussed earlier in this series: the controls described in a cyber insurance application are not a one-time checkbox exercise, they are an ongoing commitment the association's actual practice needs to match for as long as the policy remains in force.
- Confirm specifically whether social engineering and business email compromise fraud are covered under your policy's core insuring agreement or only as a separate, lower-sublimit add-on, given this is now the dominant real-world attack vector.
- Read the full policy document, including the exclusions schedule, rather than relying solely on a broker's summary, since policy wordings have changed in ways summaries do not always reflect.
- Ensure the security controls represented in your cyber insurance application are and continuously maintained, since a gap between what was declared and what exists is a documented, common reason claims are denied.
- Confirm the retroactive date on your policy, since a breach originating before that date will generally not be covered regardless of when it is discovered.
- Ask your broker directly how many cyber claims they have helped manage, and specifically how sublimits for social engineering and business interruption apply, rather than focusing the conversation only on overall limits and premium cost.
Cyber insurance is a genuine, valuable risk transfer tool, but only where an association actually understands what it covers, and equally important, what it specifically does not. The gap between the coverage a board assumes it has purchased and the coverage the policy will pays is exactly where an incident becomes a far more costly, uninsured problem than anyone expected.
This is one of the practical governance topics built into our Board Director course — alongside the papers, tools and frameworks that turn the principle into your board's actual practice. Explore the course →
— Annie