Most companies discover how their cyber policy works after they need it. By then the decisions that determine whether a funds transfer claim pays have already been made, usually in the first few hours.
Call the carrier before you call anyone else technical
Nearly every policy requires notice as soon as practicable and requires you to use panel vendors for forensics and legal. Hiring your own firm first, without approval, is one of the most common ways coverage gets reduced. If you already have a responder engaged, say so on the notice call and let the carrier approve the engagement.
What the carrier will ask for
- A timeline: when the compromise started, when it was detected, and what was done at each step.
- Sign-in and audit logs showing attacker sessions, rules created, and data accessed.
- Evidence of the fraudulent instruction: the emails, the altered banking details, and the thread they arrived in.
- Proof of your internal verification process for payment changes, and whether it was followed.
- Your multi-factor authentication posture at the time of the incident, per account, not per policy document.
Why funds transfer claims get denied
Three reasons dominate. First, the application said multi-factor authentication was enforced on all email accounts and it was not. Misrepresentation on the application is grounds to rescind. Second, the loss falls under a sublimit that is far smaller than the headline policy limit, which is standard for social engineering coverage. Third, the internal callback procedure the company described to the underwriter existed on paper but was skipped for this payment.
Evidence you destroy by accident
Deleting the attacker mail, wiping the mailbox, or rebuilding the laptop feels like cleanup. To an adjuster it looks like spoliation. Preserve everything, including the malicious messages, until forensics says otherwise. Audit log retention in Microsoft 365 depends on licensing, so speed protects the claim.
Before the next renewal
Underwriters now price on controls, not intentions. Phishing-resistant multi-factor authentication, conditional access, endpoint controls, and tested backups all move the premium. A documented gap analysis helps you answer the application accurately, which is the cheapest coverage protection available. Our cybersecurity assessments produce exactly that evidence, and the free cybersecurity risk scorecard gives you a prioritized starting point.
If a claim is forming right now, read what to do when your business email is compromised and call 864-224-0008.

