Does your policy cover a BEC payment loss?
Usually, only if the wording expressly includes social engineering fraud, funds transfer fraud, or payment diversion.
A supplier bank-detail scam following an altered invoice may be covered. An employee must believe the invoice is genuine and send company money to a criminal account.
The wording often requires the deception to directly cause the payment.
A £1 million cyber insurance limit does not mean £1 million covers a fraudulent payment. The cash loss may sit within a smaller fraud sub-limit. That limit is sometimes between £25,000 and £250,000. It may also have its own excess.
The key point is simple. An employee often authorises a BEC transfer, but does so because of a lie. This differs from an unauthorised theft from the account.
Business email compromise (BEC) is one form of social engineering fraud. Policy labels matter less than the definition.
Social engineering cover may respond when a person is tricked into making an authorised payment. Funds transfer fraud may use narrower wording. It may cover an unauthorised bank instruction or a transfer caused by stolen credentials. Payment diversion cover may address a supplier bank-detail scam.
Standard cyber cover can still pay for incident response after a mailbox breach. It may also cover forensic work, legal advice, or notification costs. Yet it may not repay the diverted cash.
Check each insuring clause before you rely on the headline limit.
Why APP reimbursement rarely replaces BEC cover
APP reimbursement can help eligible microbusinesses. It does not replace insurance for most SMEs.
Does APP reimbursement cover my SME?
The UK's mandatory APP reimbursement rules cover eligible Faster Payments. They apply to consumers and eligible microbusinesses.
A larger SME may fall outside this definition. It should not plan on receiving reimbursement.
For this purpose, a microbusiness generally has fewer than 10 employees. It also has annual turnover or a balance-sheet total below €2 million.
The reimbursement cap is £85,000 for qualifying Faster Payments claims. Exceptions and investigations may still apply.
Which payments fall outside the rules?
Some payments fall outside the rules. These include payments outside Faster Payments and transfers by non-eligible businesses.
A loss may also fail the scheme's conditions. In that case, it may not receive mandatory reimbursement.
Bank recovery and insurance are separate routes. Quick action can protect both options.
For an England-based SME, treat APP reimbursement as a possible safety net. Do not treat it as a payment-fraud strategy. Check whether you are an eligible microbusiness. Then buy or renew cover based on the fraud sub-limit you could need. A £1 million cyber limit offers little help for a £150,000 invoice diversion if the social engineering sub-limit is £25,000.
Compare fraud wording, sub-limits and controls
Compare the fraud section, not the marketing headline. Focus on the loss definition, maximum payment, excess, and required payment controls.
| Fraud scenario | Likely policy treatment | Control most likely tested |
| Supplier changes bank details by email | Potentially covered under named social engineering or payment diversion cover | Documented callback using an independently found number |
| CEO requests an urgent confidential transfer | Potentially covered, subject to authority and dual approval | Second approver and out-of-band confirmation |
| Compromised mailbox changes an invoice | Cash loss may be limited; forensics may have separate cover | Multi-factor authentication and evidence preservation |
| Payroll account is redirected | May need specific wording; exclusions are common | Independent employee verification and payee controls |
| Ransomware demand is paid | Usually considered cyber extortion, not BEC cover | Insurer consent and incident-response process |
Is the fraud sub-limit enough?
The fraud sub-limit should match the largest plausible single payment. Include VAT, deposits, client money, and two payments leaving before discovery.
Check whether the limit applies to each claim. It may instead apply to all claims during the policy year.
The largest invoice is not always the real exposure.
Which controls can invalidate a claim?
Control conditions can limit a claim when staff ignore the promised process. The proposal or policy may set out that process.
The most common invoice-fraud failure involves a bank-detail change. Staff reply to the same compromised email chain. They should instead use an independently sourced number.
✅
Our recommendation
A USB security key adds a physical check to email sign-in. It suits finance staff where password theft is a concern. It can also help against fake Microsoft 365 login pages.
- Adds a physical second factor when staff access business email
- Reduces the value of a stolen password from a phishing page
- Helps protect supplier-bank-detail emails from account takeover
Check availability →
If a suspicious transfer occurs, contact your bank's fraud team at once. Ask it to recall, trace, and freeze the receiving account.
Notify the insurer that day. Keep emails, headers, invoices, and approval records. Then secure affected accounts with your IT provider.
This guidance matters less if your business makes no supplier, payroll, or client-money payments. It also differs for unauthorised card or bank-account theft. That is not the same as a person being tricked into approving payment. This is educational information, not legal, insurance, or claims advice.
A sound payment-control process starts before any claim. Require dual approval above a recorded threshold. The second approver should check the commercial reason for payment.
They should not simply approve it in the banking portal. New suppliers, changed bank accounts, and urgent requests need out-of-band confirmation.
Use a number from a verified contract, website, or past records.
Finance teams should split supplier-data maintenance, payment preparation, and payment release where practical. Keep a dated record of the callback, approval, and payee checks.
An insurer may ask for this evidence. It uses it to assess whether staff followed the required controls.
When comparing quotations, ask the insurer or broker for the exact clause. It must cover payment made after deception.
Terms such as “direct loss”, “voluntary parting”, “authorised payment”, and “fraudulent instruction” can change the result. A funds transfer clause may require an instruction without the insured's knowledge.
That clause may not respond after a finance employee approves payment. The employee may have acted after receiving a convincing fake email.
Check whether cover includes altered invoices, CEO fraud, payroll redirection, and compromised email accounts. Check whether the fraud sub-limit is per claim or aggregate.
Also check whether the excess, waiting period, or control conditions apply separately. They may differ from the main cyber policy.
Questions & answers
Does cyber insurance cover social engineering?
Only where the policy expressly includes social engineering or an equivalent fraud definition. Check the sub-limit, excess, and payment-control conditions.
Is BEC the same as social engineering?
BEC is a type of social engineering. It uses email to trick someone into sharing data or sending money.
A policy may cover one term while excluding the other.
Does a supplier callback have to be independent?
Yes. Use a number found outside the suspicious email or invoice. Replying to the sender may simply reach the criminal.
What is a social engineering sub-limit?
It is the most an insurer will pay for this fraud category. It is often far below the headline cyber limit.
Act before the next payment request
Combine suitable insurance with payment controls staff can follow under pressure. Compare the full policy wording with your largest regular payment.
What matters most:
- Social engineering and BEC losses need named cover or wording broad enough to include payment deception.
- A separate fraud sub-limit and excess may be far lower than the headline cyber insurance limit.
- Independent callbacks, dual approval, and multi-factor authentication can decide whether a claim succeeds.
- Call the bank, preserve evidence, and notify the insurer immediately after a suspicious transfer.
Will my bank refund a fraudulent business payment?
An eligible microbusiness may receive APP reimbursement for qualifying Faster Payments. The cap is usually £85,000.
Larger SMEs cannot assume mandatory reimbursement applies.
Learn more
Here are some additional resources on this subject: