Misconception 1: All 'Cyber' Policies Automatically Cover All Phishing Losses
The most common mistake is assuming that a general "cyber liability" policy covers every financial consequence of a phishing attack. In reality, policies are highly specific. For example, a plan might cover the cost of data recovery and notifying customers
about a breach, but exclude losses from fraudulent fund transfers unless you purchased a specific "social engineering" or "funds transfer fraud" rider. An employee tricked into wiring money to a scammer may not be covered under a basic plan. The term 'phishing' is the starting point, but insurers focus on the specific type of loss that follows, which can fall under different, and sometimes optional, coverage sections.
Misconception 2: Your Security Measures Are Good Enough for the Insurer
Buying a policy isn't a one-and-done transaction. Insurers have strict expectations for the security controls you must have in place. A claim can be denied if you can't prove that you met the standards declared in your application. For instance, if your application stated that multi-factor authentication (MFA) is used on all accounts, and the breach occurred on an account without it, the insurer may argue you misrepresented your security posture and rescind the policy. Underwriters now heavily scrutinize email security filters, documented incident response plans, and employee training programs. Simply having security tools isn't enough; you must prove they are implemented correctly and consistently.
Misconception 3: Ransomware Payments Are Always Covered
Phishing is a primary gateway for ransomware attacks. While many cyber policies offer coverage for extortion, payment is never guaranteed. Several factors come into play. First, the policy may have a sublimit for ransomware that is far lower than the actual demand. Second, the insurer must approve the payment; paying a ransom without consent can void your coverage. Third, payments are prohibited if they would violate federal laws, such as sanctions against terrorist organizations or specific criminal groups. Insurers assess each incident individually to determine if a ransom payment is legally permissible and necessary under the policy terms.
Misconception 4: Filing a Claim Is a Straightforward Process
After a phishing attack, business leaders are often shocked to find that the claims process is complex and requires immediate, precise action. Most policies have strict notification deadlines, sometimes as short as a few days, to report a potential incident. Waiting too long can jeopardize your claim. Furthermore, the policy will likely dictate which forensic, legal, and public relations vendors you can use. Hiring your own team without insurer approval can result in those costs not being reimbursed. The investigation will also focus on causation. If an employee action, like wiring funds, is deemed a voluntary transfer, the insurer might argue it wasn't a loss 'directly' caused by the unauthorized use of a computer, creating a loophole to deny the claim.
Misconception 5: Employee Mistakes Are Always Forgiven
Since phishing preys on human error, many leaders assume any employee mistake will be covered. However, many policies contain exclusions for certain insider-driven incidents. While a simple, accidental click might be covered, insurers distinguish between a mistake and negligence. If an employee repeatedly ignores security protocols or if the business has no documented training program, the insurer could argue the company failed to take reasonable care. Some policies specifically limit or exclude coverage for social engineering fraud where an employee is manipulated into taking an action, viewing it differently from a brute-force system hack.













