Governance Excellence Series · Article 127

Cyber Insurance: Covering the Threat You're Least Likely to Actually Face

Social engineering drives most breaches, and it's often the category your policy covers the least. Check the sublimits directly

Governance Risk & Operations · 1 February 2028

Social engineering is now the dominant attack vector behind the large majority of Australian data breaches, and this specific category of loss is where many cyber insurance policies apply their tightest, least generous coverage. An association assuming its cyber policy broadly covers whatever a cyber incident throws at it may be relying on a policy least equipped to respond to the threat it is most likely to face.

The Specific Gap Most Boards Do Not Know Exists

Where an employee is deceived into transferring funds or disclosing credentials, without any actual system being technically compromised, some insurers classify the resulting loss as a crime loss rather than a cyber loss, placing it outside the policy's core insuring agreement entirely. Coverage for this specific scenario, social engineering fraud, is frequently only available as an optional add-on, and even where included, it commonly carries its own sublimit set considerably lower than the policy's overall aggregate coverage. An association could hold a policy with a headline limit in the hundreds of thousands or millions of dollars, while its actual protection against the most common real-world attack vector sits capped at a fraction of that figure. A cyber policy's headline coverage limit tells you very little about what it will pays on the specific type of loss your association is statistically most likely to experience. That answer sits in the sublimits and exclusions schedule, not the summary page.

The Application Answers That Can Quietly Void A Claim

Security control representations made when applying for cyber insurance, whether multi-factor authentication is enforced, whether backups are regularly tested, become material facts the insurer relies on when pricing the policy. If an incident occurs and those controls turn out to have been missing or inconsistently applied, despite being confirmed in the original application, insurers can and do deny the resulting claim on this basis. This connects directly to the cyber security governance discussed earlier in this series: the controls described in a cyber insurance application are not a one-time checkbox exercise, they are an ongoing commitment the association's actual practice needs to match for as long as the policy remains in force.

Cyber insurance is a genuine, valuable risk transfer tool, but only where an association actually understands what it covers, and equally important, what it specifically does not. The gap between the coverage a board assumes it has purchased and the coverage the policy will pays is exactly where an incident becomes a far more costly, uninsured problem than anyone expected.

This is one of the practical governance topics built into our Board Director course — alongside the papers, tools and frameworks that turn the principle into your board's actual practice. Explore the course →

— Annie

← Back to the Governance Excellence Series