Skip Navigation
  • Careers
  • Report a Claim
  • Contact Us
Risk Strategies Logo
  • Industries

    • Agriculture
    • Architects & Engineers
    • Aviation
    • Cannabis
    • Construction
    • Dental
    • Education
    • Entertainment
    • Financial Services
    • Fine Art
    • Healthcare
    • Law Firms
    • Marine & Yacht
    • Nonprofit & Human Services
    • Private Equity
    • Public Sector
    • Real Estate
    • Relocation
    • Transportation
    • Waste & Recycling
    • Wineries
  • Solutions

      • Captives
      • Casualty
      • Cyber
      • Environmental
      • International
      • Management Liability
      • Property
      • Surety
      • Employee Benefits Overview
      • Benefit Administration and Technology
      • Benefits Compliance Support
      • Data & Analytics
      • Human Capital Advisory Services
      • International Benefits
      • Absence Management & Ancillary Programs
      • Voluntary & Lifestyle Benefits
      • Medicare
      • Financial & Wealth Overview
      • Life Insurance
      • Private Client Services Overview
      • Homeowners
      • Flood
      • Collections
      • Umbrella & Excess Liability
      • Auto
      • Collector & Exotic Car
      • Boat & Yacht
      • Travel Medical & Trip Insurance
      • Family Office
      • Cyber Insurance - Family Office
      • Cyber Insurance - Individuals
      • Specialty Coverages
      • Private Client Risk Resource Center
    • Reinsurance
      • Risk Management Services Overview
      • Analytics
      • Claims Management & Advocacy
      • Loss Control
      • Safety Consulting Services
      • Pro Safety Training Courses
      • Workers’ Comp: Premium Review & Recovery
  • Consulting

    • Consulting Overview
    • Actuarial Services
    • Healthcare Claim Audit Services
    • Health and Welfare
    • Mergers and Acquisitions
    • Pharmacy Consulting
    • Retirement Benefits
  • News and Insights

    • All Insights
    • Blog
    • Emergency Resource Centers
    • Employee Benefits Compliance Center
    • Events
    • Media Coverage
    • State of the Market Reports
    • Press Releases
    • Private Client Resources
    • Webinars
  • Company

    • About Us
    • Annual Report
    • Careers
    • Culture and Values
    • Diversity, Equity & Inclusion
    • Environmental, Social, & Governance
    • General Terms of Business
    • Leaders
    • Local Expertise
    • Mergers & Acquisitions
    • Recognition & Awards
    • Risk Strategies Foundation
    • Transparency and Disclosures
  • Join Us
    • Careers
    • Mergers & Acquisitions
  • Industries
    • Agriculture
    • Architects & Engineers
    • Aviation
      • Aviation Business Insurance - Manned Risk
      • Non-Owned Aviation
      • Unmanned Aerial System and Drones
    • Cannabis
    • Construction
      • Alternative Solutions
      • Financing & Pre-Construction
      • Insurance Solutions
      • Risk Management
      • Surety
    • Dental
      • Insurance for Dental Professionals
      • Dental Malpractice Insurance
      • BOP Insurance - Dental Practices & DSOs
      • Dental School Graduates
      • Dental Associates & Hygienists
      • Dental Practice Owners
      • Dental Service Organizations (DSOs)
    • Education
      • Employee Benefits for Education
      • Property, Casualty & Liability for Education
      • Student Health & Wellness
        • Student Health Brokerage and Consulting
        • Student Health Plan Administration
        • Student Health Insurance Plans
        • Solutions for Student Athletes
        • Student Health & Wellness Tools
        • Special Risk Insurance
    • Entertainment
      • Film & Television
      • Advertising Production Wrap Ups
      • Advertising/PR
      • Event Cancellation & Non-Appearance
      • Music & Touring
      • Theatrical Production & Live Performance 
      • Venue Insurance
    • Financial Services
      • Asset Managers
      • Banks & Non-Bank Lending
      • Collections
      • Consumer Financial Services
      • Financial Tech
      • Insurance Companies
    • Fine Art
      • Artists
      • Artist Endowed Foundations
      • Auction Houses
      • Fine Art Packers / Shippers / Warehouses
      • Galleries
      • Museums
      • Private Art Dealers / Advisors
      • Private Collectors
    • Healthcare
      • Employee Benefits - Healthcare
      • Managed Care / Stop Loss
      • Medical Malpractice
      • Property & Casualty - Healthcare
      • Reinsurance
    • Law Firms
    • Marine & Yacht
      • Boat & Yacht For Individuals
      • Commercial & Recreational Marine Businesses
        • Marine Businesses
        • Sailing Organizations - Burgee Program
      • Jackline Insurance Solutions for Cruisers
      • Mega Yachts
      • One-Design Insurance Program
      • Crew Medical Insurance
      • Sailors Health Insurance Program
      • US Sailing Insurance Solutions
    • Nonprofit & Human Services
    • Private Equity
      • Crypto Companies
    • Public Sector
      • Public Safety Organizations & Municipalities
    • Real Estate
      • Commercial
      • Community Associations
      • Hospitality
      • Residential / Habitational
      • REITs
      • Retail
      • Specialty Programs
    • Relocation
      • Domestic Household Goods
      • Expat Renters & Living Insurance
      • Relocation Claims Service
      • International Household Goods
      • Supplemental Movers Coverage
      • Temporary Living Insurance
      • Vacant Home
    • Transportation
      • Business Auto Insurance
      • Last Mile Delivery
      • While Under Dispatch Insurance
      • Forwarding & Brokering
      • Workers' Compensation
    • Waste & Recycling
    • Wineries
  • Solutions
    • Commercial Insurance
      • Captives
      • Casualty
        • Analytics
        • Auto Liability & Physical Damage
        • Captives & Alternative Risk Financing
        • Claims Advocacy & Loss Control
        • Excess Liability
        • General Liability
        • Product Recall
        • Workers' Compensation
      • Cyber
        • Cyber Resolute
        • Cyber Risk Assessment and Analytics
        • Cyber Risk Response & Claims Advocacy
        • Cyber Insurance - Family Office
        • Cyber Insurance - Individuals
      • Environmental
        • Contractors Pollution Liability
        • Environmental Excess
        • Environmental Liability Transfer
        • Environmental Liability - Healthcare
        • Environmental Liability - Higher Education
        • Pollution Legal Liability
        • Environmental Liability - Private Equity
        • Professional Environmental Liability Insurance
        • Real Estate Development
        • Remediation Cost Cap
        • Secured Creditor Protection for Lenders
        • Underground Storage Tanks
      • International
      • Management Liability
        • Management Liability - Entertainment
        • Management Liability - Financial Institutions
        • Management Liability - Healthcare
        • Management Liability - Real Estate
      • Property
        • Builder's Risk
        • Property Claims Services
        • Inland Transit and Ocean Cargo
        • Natural Hazard Catastrophe Modeling
        • Political Violence and Terrorism
        • Property Damage & Business Interruptions Valuations
        • Property Loss Prevention and Control
      • Surety
    • Employee Benefits
      • Employee Benefits Overview
      • Benefit Administration and Technology
      • Benefits Compliance Support
      • Data & Analytics
      • Human Capital Advisory Services
      • International Benefits
      • Absence Management & Ancillary Programs
      • Voluntary & Lifestyle Benefits
      • Medicare
    • Financial & Wealth
      • Financial & Wealth Overview
      • Life Insurance
    • Private Client Services
      • Private Client Services Overview
      • Homeowners
      • Flood
      • Collections
      • Umbrella & Excess Liability
      • Auto
      • Collector & Exotic Car
      • Boat & Yacht
      • Travel Medical & Trip Insurance
      • Family Office
      • Cyber Insurance - Family Office
      • Cyber Insurance - Individuals
      • Specialty Coverages
      • Private Client Risk Resource Center
    • Reinsurance
    • Risk Management Services
      • Risk Management Services Overview
      • Analytics
      • Claims Management & Advocacy
      • Loss Control
      • Safety Consulting Services
      • Pro Safety Training Courses
      • Workers’ Comp: Premium Review & Recovery
  • Consulting
    • Consulting Overview
    • Actuarial Services
    • Healthcare Claim Audit Services
    • Health and Welfare
    • Mergers and Acquisitions
    • Pharmacy Consulting
    • Retirement Benefits
  • News and Insights
    • All Insights
    • Blog
    • Emergency Resource Centers
      • Cybersecurity
      • Earthquake
      • Hurricane
      • Pandemic
      • Riot & Civil Unrest
      • Severe Storms
      • Violence & Active Shooter
      • Wildfire
      • Winter Weather
    • Employee Benefits Compliance Center
    • Events
    • Media Coverage
    • State of the Market Reports
    • Press Releases
    • Private Client Resources
    • Webinars
  • Company
    • About Us
    • Annual Report
    • Careers
    • Culture and Values
    • Diversity, Equity & Inclusion
      • BeHEARD Series
      • DE&I Structure
      • Employee Resource Groups
    • Environmental, Social, & Governance
    • General Terms of Business
    • Leaders
    • Local Expertise
    • Mergers & Acquisitions
    • Recognition & Awards
    • Risk Strategies Foundation
    • Transparency and Disclosures
      • General Terms of Business
      • Conflict of Interest Policy
      • Compensation Disclosure
      • Enterprise Risk Management
  • Join Us
    • Careers
      • Benefits & Wellness
      • Investing in Growth & Leadership
      • Life at Risk Strategies
      • Next Steps
    • Mergers & Acquisitions
      • Partnership Benefits
      • Why Join Us?
      • Onboarding & Integration
  • Careers
  • Report a Claim
  • Contact Us

You are about to leave Risk Strategies website and view the content of an external website.

You are leaving risk-strategies.com

By accessing this link, you will be leaving Risk Strategies website and entering a website hosted by another party. Please be advised that you will no longer be subject to, or under the protection of, the privacy and security policies of Risk Strategies website. We encourage you to read and evaluate the privacy and security policies of the site you are entering, which may be different than those of Risk Strategies.

OK
  • News and Insights
  • Blog
Subscribe

Subscribe via Email

  • News and Insights
  • Blog
July 20, 2023

Cyber Insurance and Social Engineering Attacks

Cyber
5 min read
Allen Blount, National Cyber & Technology Product Leader
  • Facebook
  • X (Twitter)
  • LinkedIn
  • Email
Cyber Insurance and Social Engineering Attacks Can Be Costly
  • Facebook
  • X (Twitter)
  • LinkedIn
  • Email

Criminals often use “social engineering” to groom victims and deceive them into transferring funds or sensitive data. If employees don’t recognize the hallmarks of a social engineering scam, they can easily expose your organization to substantial risk. These types of attacks can lead to a costly response and remediation process. So, insurers want to see specific precautions before issuing a cyber insurance policy.  

What is social engineering? 

Social engineering is a particularly pernicious and common form of cyberattack, only partly reliant on technology. The hacker or scammer uses whatever intelligence they can find about you and your organization to trick you into sharing information or diverting funds.  

You may not think you have any pertinent personal details floating around on the internet. However, hackers can work with the smallest scrap of information. For example, they can check a company’s LinkedIn page for a low-level employee or recent hire. Then, they reach out with seemingly authentic communications via email or LinkedIn. 

These messages might look official at first glance. An email might appear to be from the billing department, asking you to fill out something. Perhaps, it instructs you to wire money for a client or share details like Social Security numbers for administrative purposes.  
 
Sometimes, a criminal will use a pretext, such as introducing themselves as a fellow attendee at a recent conference. These scams typically convey urgency, manipulating you to respond reflexively — often citing names of executives in your organization. 

Social engineering works so well because it starts with a nugget of truth. The sender references something specific that grabs your attention and causes you to overlook warning signs. 

Social engineering escalated as more people began working from home 

Social engineering scams are not new and have been rising at an alarming rate for years. However, the March 2020 COVID-19 lockdown emboldened cybercriminals even more. It became much easier for a bad actor to say, “I am a new hire in accounting, and my boss asked me to reach out.”  
 
Most employees want to be helpful, particularly to someone who has just started a job. So, they need training on how to discern between an innocent outreach and potential trouble.  

In a distributed workforce, employees may not be able to stroll down the hall to validate an email or call. As a result, accounts payable employees are expediting payments for fraudulent invoices. A false sense of urgency can lead to overriding company controls. 

Real scams and hacks 

  • A professional services firm issued a wire transfer payment of almost $400,000 to a cybercriminal. An email that appeared to be from a legitimate subcontractor provided “new account information” for the payment. On closer inspection, the email address contained an incorrect letter — a subtle clue the firm didn’t catch. The firm’s out-of-pocket expenses exceeded $100,000 after applying the policy limit and deductible.  
  • A community association issued a wire transfer payment of nearly $100,000 based on fraudulent emails. The association had commissioned a boat manufacturer to build a boat and believed the emails were from the manufacturer. Instead, a hacker had gained access to the boat company’s computer network. This enabled the cybercriminal to send new, fraudulent payment account information from a legitimate boat company email address. The association issued payment to the fraudulent account. 

How to protect your business from social engineering attacks 

Relying solely on coverage from crime policies and cyber insurance is not a viable strategy given the prevalence of social engineering attacks. At minimum, you need to implement these risk mitigation measures: 

Secondary Authentication 

Before responding to requests for wire transfers or changes in payment instructions, use a secondary method for authenticating the request. For example, your accounting team could call the internal stakeholder, vendor, or client at a pre-established phone number to confirm the legitimacy of the transaction and wiring instructions. If you can’t verify or if you remain uncertain, do not act on the request. 
 
Best practices call for creating an internal process that requires signoff from multiple parties before initiating any wire transaction or implementing changes in payment instructions. 

Training and Communication 

Training employees is the number one line of defense against social engineering attacks. Implement a regular stream of security awareness training. Also, periodically test your employees with fake social engineering emails and calls to identify training gaps. Cyber Resolute policyholders have access to discounted training resources on the eRisk Hub. As well, Cyber Resolute policyholders can recover the costs of proactive services via supplemental coverage.  

Practice vigilance at all levels 

Ask all employees to check the email address if they receive a suspicious or legitimate-looking email requesting sensitive information. It might have a known contact’s name in the address, but does it follow the company’s or vendor’s email format?  

When employees receive a suspicious email, they need to report it immediately to the IT department. Once IT becomes aware of a circulating email scam, alert all employees to be on the lookout for similar correspondence. Provide instructions for what to do if they receive it: don’t click anything, mark as spam, delete. 

Cyber insurance and social engineering 

When it comes to cyberattacks, companies of all sizes are only as strong as their weakest link. The best information security controls cannot prevent an employee from mistakenly clicking on a hyperlink or engaging with a fraudster. Following the best practices above can help reduce the probability of a social engineering claim and reduce your total cost of risk. 

To get cyber insurance, you will need to demonstrate that you have trained your full workforce on how to identify potential social engineering scenarios. If you’re applying for cyber coverage, insurers will ask you to document your procedures and prove you are following cybersecurity best practices. 
 

Want to learn more? 

Connect with the Risk Strategies Cyber Risk team at cyber@risk-strategies.com. 

About the author 

Allen Blount leads the Cyber Team at Risk Strategies, where he guides clients on navigating cyber risks such as social engineering attacks. He specializes in both cyber insurance and tech E&O (errors and omissions). Before his insurance career, he practiced law.  

The contents of this article are for general informational purposes only and Risk Strategies Company makes no representation or warranty of any kind, express or implied, regarding the accuracy or completeness of any information contained herein. Any recommendations contained herein are intended to provide insight based on currently available information for consideration and should be vetted against applicable legal and business needs before application to a specific client. 

Related Posts

See all posts

Cyber Risk
5 min read
April 02, 2025

The Future of Risk: Cyber Threats Affecting Businesses in 2025

Editor’s note: The way businesses approach risk is undergoing a fundamental shift. This article is …
Read article
Cyber
5 min read
March 26, 2025

Understanding the 23andMe Data Breach and Ensuring Cybersecurity

- UPDATE - From breach to bankruptcy: 23andMe’s data fallout continues Little more than 18 months …
Read article
Cyber Risk
7 min read
March 04, 2025

The Future of Risk: Systemic Risks to Watch in 2025

The days of treating risks as isolated incidents are over. As we move deeper into 2025, business …
Read article
Risk Strategies Logo
  • Report a Claim
  • Contact
  • Terms of Use
  • Cookie Policy
  • Privacy Policy
  • Consumer Health Data Privacy Notice
  • Accessibility
  • Health Plan Transparency Compliance
  • Accessibility
  • Cookie Policy
  • Health Plan Transparency Disclosure
  • Privacy Policy
  • Terms of Use
©2025 Risk Strategies. All rights reserved.

Connect with Us

  • LinkedIn
  • X
  • Instagram
  • Facebook