Check Your Cyber Insurance After Fraud
Your business has lost money to fraud and may hold a policy that helps.
Updated 2026-09-29 · Independent resource. Legal review pending.
Check whether a policy exists first
Before anything else, find out whether your business holds a cyber or crime insurance policy, and who manages it. Many SMEs carry this cover through a broader business policy without realising it.
Ask your insurance broker, or the person who handles company insurance, to pull the policy document. Look specifically for wording on funds transfer fraud, social engineering fraud, or a cyber crime endorsement.
Understand what cover may include
Coverage for this type of loss varies a great deal between policies, and some do not include it at all. A policy might cover funds transfer fraud, where a scammer tricks staff into sending money, separately from a general cyber incident.
Social engineering fraud, such as a faked email from a director or supplier, is sometimes covered under its own clause with its own limit. Read the wording carefully, since the definitions decide whether your loss fits.
Notify the insurer promptly
Most policies set a window for reporting a loss, and late notification can affect a claim. Contact the insurer or broker as soon as the fraud is discovered, even before every detail is confirmed.
A short initial notice that a fraud has occurred is usually enough to open the claim. You can add documents and detail as the investigation continues.
Gather what the insurer will ask for
Insurers typically want a police report, the full email or message trail, bank correspondence about the transfer, and a timeline of events. If your IT team or an external specialist looked into how the fraud happened, include their notes too.
Keeping these records organised from day one makes the claims process faster and reduces back and forth with the insurer.
What to do next
A lawyer is not only useful for chasing the money that was sent. A lawyer can also review the policy wording and help you understand what is actually covered.
They can coordinate a claim alongside other recovery steps too, such as a bank dispute or tracing the funds through a civil claim. This keeps the insurance claim and the recovery effort moving together, rather than as two separate processes that lose time.
Report the fraud to the police and, for a recent transfer, call the National Scam Response Centre (NSRC) on 997. Read more about how business email compromise happens and see the recovery options available once a report is filed.
If the claim or the loss is complex, a first legal assessment can help you weigh the options clearly. Bringing the policy document and your incident records to that conversation saves time on both fronts.
If you are unsure whether your policy covers this kind of loss, send us a short message and we will help you think through the next step.
Common questions
How do we find out if we have cyber insurance cover?
Ask your insurance broker or whoever manages company insurance to pull the actual policy document, not just the summary. Look specifically for wording on funds transfer fraud, social engineering fraud, or a cyber crime endorsement, since general business policies do not always include this cover automatically.
How quickly should we notify the insurer?
As soon as the fraud is discovered, even before every detail is confirmed. Most policies set a window for reporting a loss, and notifying late can affect whether a claim is accepted, so a short initial notice is safer than waiting until the picture is complete.
Can a lawyer help with an insurance claim, not just recovering the money?
Yes. A lawyer can review the policy wording, help you understand what is actually covered, and coordinate the claim alongside other recovery steps such as a bank dispute. This is often more useful early, while the insurer's reporting window is still open.
Read next
A BEC Incident Response Checklist
A practical checklist for responding to business email compromise, covering the first hours through the following weeks.
Read thisHandle a Data Breach After BEC
If a compromised inbox during a business email compromise incident may have exposed personal data, here is how to assess and respond.
Read thisHow to Recall a Corporate Wire Transfer
How a business can request a recall on a corporate wire transfer sent on a fraudulent instruction, and what your bank needs from you.
Read thisHow to Respond to CEO Fraud
A step by step response when a CEO fraud instruction is discovered, whether the transfer already left or not.
Read thisIf you are unsure whether your policy covers this kind of loss, send us a short message and we will help you think through the next step.