Monday morning: a contractor’s bank details have been changed after a spoofed email. The payment has gone out, and the CRM still shows the genuine supplier record. Cyber insurance can help with response, downtime and certain fraud losses. But policy wording varies sharply. UK GDPR notification may be required within 72 hours where a breach risks people’s rights and freedoms.
Cyber cover protects CRM risks, not every loss
A cloud CRM does not transfer cyber risk to its supplier. The managing agent still controls access, payments and exports. It may face breach-response costs and UK GDPR duties after a compromised account or integration.
The provider normally protects its service infrastructure. The property manager remains responsible for user access, permissions, entered data and integration settings. Secure hosting cannot stop staff entering credentials on a fake Microsoft 365 page. It cannot stop approval of a fraudulent payment.
Map the data and access routes
Map tenant and leaseholder details, landlord bank details, ID documents and tenancy agreements. Include invoices, payment instructions, CRM users, email, accounting software and maintenance portals. Focus on accounts that can export data, change bank details or add administrators. Keep backups, audit logs and insurer contacts.
For a property manager, a cyber incident is not limited to a stolen CRM password. An account takeover can let an attacker download tenancy files or alter supplier contact details. It can create a new user or reach accounting data through a connected portal. A compromised Microsoft 365 mailbox can also support email spoofing fraud. Criminals can study genuine payment threads before sending convincing instructions.
The highest risk often sits between connected systems.
Effective cover should reflect these routes of loss. Data protection depends on CRM access controls, multi-factor authentication and Microsoft 365 email security. FIDO2 security keys give stronger phishing-resistant protection to finance staff and CRM administrators. These users often have high-risk permissions.
Payment-diversion cover depends on finance controls
Payment diversion is often insured only where it is expressly included. The stated checks must also have been followed. A high cyber limit may still have a low fraud sub-limit. It may have a separate excess or exclude changes approved from email alone.
Verify changes away from email
Call the known contact number held in the CRM or contract. Never call a number supplied in the amendment email. Use two people for material changes. Record the number used, person spoken to and approval. This evidence may be critical to recovery and a claim.
Email security is not enough
MFA should protect both the CRM and email. A compromised mailbox can reveal payment history and reset links. Security keys can strengthen protection for directors, finance teams and CRM administrators. They do not replace independent payment verification.
A payment check must work even when email is compromised.
📦
Available on Amazon
FIDO2 security keys can give finance and administrator accounts a stronger sign-in check than a password alone. They work best alongside, rather than as a replacement for, independent payment verification.
- Helps protect CRM administrator accounts from many password-phishing attempts
- Gives accounts staff a separate physical sign-in factor for payment systems
- Creates a clear, repeatable access control for underwriting evidence
Search on Amazon →
Compare policies by sub-limits and claim triggers
Compare what each section pays, not the headline limit or premium. Ask whether cover includes cloud outages, restoration costs and diverted client-money payments. Check fraud sub-limits, excesses, waiting periods and evidence requirements.
| Claim scenario | Ask the broker | Control to evidence |
| CRM or email breach | Are forensics, legal advice and notification costs within the full limit? | MFA, access logs and incident plan |
| Ransomware and restoration | Is data restoration included? Are immutable backups required? | Tested offline or immutable backups |
| Payment diversion | What are the fraud sub-limit, excess and verification condition? | Call-back, two approvals, payment segregation |
| Cloud supplier outage | Does contingent business interruption include named cloud providers? | Manual work-around and export access |
Check the waiting period
Business interruption cover has a waiting period before payment starts. It also has an indemnity period that limits how long losses can be claimed. Ask how long the firm can manage rent queries, maintenance jobs and reconciliation without the CRM.
Separate insurance can still matter
Cyber insurance does not replace professional indemnity, crime or property cover. Professional indemnity may address negligent management. Crime cover may respond to employee dishonesty under its own terms.
One policy rarely covers every financial loss.
Take this to a broker: List your CRM, email provider, payment systems and highest single payment. Include annual client-money flow, MFA status, backup method and the call-back process for bank-detail changes. Ask for each fraud sub-limit and excess in writing.
Read the insuring clauses alongside the exclusions. Do not assume one policy protects every financial consequence. Cyber cover may pay for forensics, notification, restoration and business interruption after a security event. Business email compromise cover may sit under a separate crime or social-engineering section. Payment diversion or client money fraud cover may also sit there.
These sections often have lower sub-limits for cyber fraud. They may require documented bank-detail change verification. Professional indemnity can apply where a client alleges negligent management. Property insurance usually concerns physical damage, not digital loss. Voluntary payments, known circumstances and control failures can also restrict recovery.
Your questions answered
These answers highlight the terms and controls most likely to affect cover.
Is cyber insurance worth having for a property manager?
Cyber insurance is worth considering if the firm holds personal data or relies on cloud systems. It also matters where staff release payments from emailed instructions. Its value depends on matching response, fraud and downtime cover to actual exposure.
Does a cloud CRM provider pay for our breach?
No. The provider’s contract may limit liability. Your firm remains responsible for accounts, data handling and payment controls.
Does cyber insurance cover a fraudulent payment?
Only some policies cover it. Cover usually sits under social engineering or funds-transfer fraud wording. Check the sub-limit, excess and independent call-back requirement.
Must we report every CRM breach to the ICO?
No. Report it without undue delay where feasible, and within 72 hours where the breach is likely to risk individuals’ rights and freedoms.
What lowers a cyber insurance premium in england?
MFA, tested backups and documented payment checks can improve an insurer’s view of risk. Turnover, claims history, data volume and payment values also affect the premium.
What is the difference between cyber and professional indemnity insurance?
Cyber insurance addresses defined cyber events. Professional indemnity addresses claims that professional advice or service caused client loss.
What should we do in the first day after an incident?
Notify the insurer promptly and preserve emails and logs. Stop further payments where possible. Do not delete evidence or promise compensation before advisers assess the event.
This guidance is less relevant where a business does not process personal data digitally. It is also less relevant where it does not process payment instructions or operational records digitally. It does not replace specialist advice for a live incident or disputed claim. It also does not replace advice on regulated client-money arrangements or UK GDPR legal duties.
The essential points:- Cloud CRM security does not remove a managing agent’s responsibility for accounts, access and payment controls.
- Check fraud sub-limits and verification conditions before treating a cyber policy as protection for diverted payments.
- Prepare MFA, backups, dual approval and a documented call-back process before requesting quotes or renewing.
- Notify quickly after a suspected breach. Preserve evidence for the insurer, legal advisers and the ICO assessment.
After a suspected breach, appoint one incident lead. Notify the insurer through the required claims channel before commissioning substantial external work. Immediate containment may be necessary first.
The insurer may provide a panel forensic firm, cyber lawyer and communications specialist. Their early findings help establish claim triggers and preserve evidence. They also help assess whether UK GDPR breach notification is required.
The forensic team can confirm what data was accessed. Legal advisers can assess risk to individuals and the ICO threshold. Communications support can prepare clear messages for tenants, landlords, suppliers or staff. This support is relevant where notification is necessary.
Keep a timed decision log. Include containment steps, payment recalls, affected systems and reasons for any decision not to report.
Further reading
If you want to learn more about this topic, these sources may interest you: