The Oldest Scams Get a Digital Makeover
Social engineering isn't a new concept; it's the art of manipulating people to gain access to information or assets. What has changed is the scale and sophistication of these attacks in the digital age. Instead of just targeting one company's on-site
server, attackers now exploit the human element to gain a foothold in vast, interconnected cloud systems. Common tactics include phishing, where deceptive emails trick employees into revealing credentials, and business email compromise (BEC), where criminals impersonate executives to authorize fraudulent wire transfers. Research shows that the overwhelming majority of cyberattacks involve some form of social engineering, proving that people, not just software, are often the primary vulnerability.
How the Cloud Changes the Game
Migrating to the cloud fundamentally alters a company's risk profile. While cloud providers offer robust infrastructure security, the responsibility for securing access falls heavily on the user. This creates a new, expanded playground for social engineers. Instead of a single office network, businesses now have a sprawling attack surface spread across various cloud services like Microsoft 365 or Google Workspace. A single compromised password can give an attacker the keys to multiple kingdoms. Attackers specifically target cloud administration consoles and developers with high-level privileges, knowing that one successful deception can lead to a massive data breach or financial loss. The very nature of the cloud, with its reliance on third-party vendors and APIs, introduces new points of failure that savvy criminals are quick to exploit.
The Dangerous Gaps in Your Insurance
Many business leaders assume their standard cyber insurance policy has them covered. However, this is often not the case. Traditional cyber policies were designed to cover direct breaches of a company’s own systems. A social engineering loss, however, often involves an employee voluntarily transferring funds or data under false pretenses. Some policies specifically exclude losses from such voluntary actions. Furthermore, if an incident originates from a vulnerability in a third-party cloud provider's system, coverage might be denied under what’s known as a contingent business interruption exclusion. Without a specific endorsement or dedicated coverage for social engineering, businesses can find themselves uninsured for one of today's most common and costly threats.
What True Cloud-Era Coverage Looks Like
To properly mitigate these risks, businesses must seek out insurance that explicitly addresses social engineering in a cloud context. This is often available as an add-on, or endorsement, to a cyber or commercial crime policy. Effective coverage should insure against losses from fraudulent instruction, whether it comes from an attacker impersonating a vendor, a client, or a company executive. Look for policies that don't have restrictive clauses about how the fraudulent communication was received, as modern attacks use everything from email to AI-generated deepfake phone calls. A critical component is also ensuring your policy covers losses stemming from third-party failures, closing the contingent coverage gap that affects so many cloud-reliant businesses. Reviewing your policy to ensure it accounts for stolen credentials and compromised cloud accounts is no longer optional; it's essential.











