← All posts

Cyber Insurance After an Email Breach: What Carriers Expect

September 16, 2026

Prompt notice, approved vendors, forensic evidence, and the difference between funds transfer fraud and social engineering coverage.

We work incidents alongside carriers, brokers, and breach counsel every week. The claims that go smoothly look very similar to each other.

Notify before you remediate

Most policies require notice "as soon as practicable", and many require the carrier to approve vendors before work begins. Companies that spend three days quietly cleaning up and then file a claim routinely find that costs incurred before notice are not reimbursed — and that the evidence needed to prove the loss was destroyed during cleanup.

Expect a panel

Carriers maintain panels of approved forensics, legal, and restoration firms. You can usually request a specific provider, but ask first. We are engaged both directly by insureds and as an approved vendor on carrier-led matters, and either way the approval conversation happens on day one.

Know which coverage part applies

Email-enabled loss splits into categories that pay very differently:

  • Funds transfer fraud — an unauthorized transfer using compromised systems
  • Social engineering / fraudulent instruction — an authorized employee tricked into paying, often with a sublimit far below the main policy limit
  • Breach response — forensics, notification, credit monitoring, legal
  • Business interruption — rarely triggered by BEC alone

A wire sent by a trusted employee following convincing instructions frequently lands in the social engineering bucket with a lower sublimit. Read yours before you need it.

Evidence carriers actually ask for

Sign-in and audit logs covering the compromise window, mailbox access records, the malicious rule with its creation timestamp, the fraud thread with full headers, bank recall correspondence, the IC3 filing, and a timeline of your response actions. Preserve all of it before remediation.

Controls that affect renewal

MFA coverage — increasingly phishing-resistant MFA for privileged users — EDR deployment, tested immutable backups, email authentication, and documented payment verification. These now drive both eligibility and pricing. Our assessment work is often used to answer these application questions with evidence rather than estimates.


Business email compromised right now? Call 1-844-LYRA-REC — our incident commanders answer live 24/7 and start containment on the first call. See our business email compromise response page for the first-hour checklist.

cyber insuranceclaimsBECfunds transfer fraud

24 / 7 Recovery

When the worst day hits, every minute matters.

Our breach team is standing by — call, email, or submit a request and we respond within minutes.