Active extortion or breach? Call +1 212 457 9797 · Beware impersonation — we e-mail only from @dilendorf.com

Cyber Insurance for Family Offices: Where the Policy Stops Paying

Cyber Insurance for Family Offices: Where the Policy Stops Paying

Dilendorf Law Firm · Cybercrime · September 26, 2026 · By Max Dilendorf

A family office may wire several million dollars in a month. One impersonated email can move a large share of that sum before anyone notices.

In 2025 the FBI Internet Crime Complaint Center recorded $20.877 billion in reported losses, and business email compromise accounted for about $3.05 billion of that total (FBI IC3, 2025 Annual Report, pp. 6, 8). Over the same period insurers tightened cyber terms, leaving policyholders with fewer options, stricter standards, and more exclusions (GAO, Rising Cyberthreats Increase Cyber Insurance Premiums).

Cyber insurance can help offset the cost of responding to an attack, but whether a policy pays depends on words negotiated before the loss (GAO-21-477).

How a cyber policy is built

A standalone cyber policy has two halves. First-party coverage pays the insured’s own costs, and third-party coverage responds to claims brought by others (FTC, Cyber Insurance).

The Federal Trade Commission lists forensics, notification counsel, business interruption, and cyber extortion among first-party items, and settlements, regulatory inquiries, and judgments among third-party items (FTC, Cyber Insurance).

Theft of funds by impersonation usually falls under a commercial crime policy instead, through computer fraud, funds transfer fraud, or social engineering insuring agreements with separate definitions and limits (Ernst & Haas Mgmt. Co. v. Hiscox, Inc., No. 20-56212 (9th Cir. Jan. 26, 2022)).

A third layer is what regulators call silent cyber. The New York Department of Financial Services defines it as the risk that an insurer must cover a cyber incident under a policy that does not explicitly mention cyber (NY DFS, Insurance Circular Letter No. 2 (2021)).

DFS has directed insurers to state in each policy whether cyber losses are covered or excluded (NY DFS, Insurance Circular Letter No. 2 (2021), item 2). Homeowners, directors and officers, and general liability forms therefore increasingly carry express cyber exclusions.

Cyber policy

First-party: forensics, notification counsel, data recovery, business interruption, extortion. Third-party: defense, settlements, regulatory inquiries, judgments.

Crime policy

Computer fraud, funds transfer fraud, and social engineering fraud insuring agreements. Each has its own definitions and often its own sublimit.

Silent cyber in other policies

Homeowners, D&O, general liability, and errors and omissions forms that never mention cyber. Regulators have asked insurers to add express grants or exclusions.

Sources: FTC, Cyber Insurance, https://www.ftc.gov/business-guidance/small-businesses/cybersecurity/cyber-insurance; NY DFS, Insurance Circular Letter No. 2 (2021), https://www.dfs.ny.gov/industry_guidance/circular_letters/cl2021_02; Ernst & Haas v. Hiscox (9th Cir. 2022), https://cdn.ca9.uscourts.gov/datastore/opinions/2022/01/26/20-56212.pdf

Coverage halfTypical items listed by the FTCFamily office question
First-party
  • Legal counsel on notification and regulatory obligations
  • Recovery and replacement of lost or stolen data
  • Lost income from business interruption
  • Crisis management and public relations
  • Cyber extortion and fraud
  • Forensic services

Does “fraud” here reach a wire the office authorized, or only funds taken without consent?
Third-party
  • Payments to consumers affected by a breach
  • Claims and settlement expenses
  • Litigation and regulatory response costs
  • Settlements, damages, and judgments

Does the policy include “duty to defend” wording, and who selects counsel?

Source: FTC, Cyber Insurance (small business cybersecurity guidance), https://www.ftc.gov/business-guidance/small-businesses/cybersecurity/cyber-insurance. Third column: Dilendorf Law Firm drafting questions.

Where the gaps appear for wealthy families

The largest gap is the payment the victim authorized. Insurers have argued that computer fraud coverage requires hacking and that a wire initiated by the insured’s own employee is not a direct loss (American Tooling Ctr., Inc. v. Travelers Cas. & Sur. Co. of Am., No. 17-2014 (6th Cir. July 13, 2018)).

Three federal appellate courts rejected those arguments under the policies before them. The Sixth Circuit held that a manufacturer “immediately lost its money when it transferred the approximately $834,000 to the impersonator” (American Tooling v. Travelers, slip op. at 7).

The Eleventh Circuit read “resulting directly from” to require proximate causation rather than an immediate link (Principle Solutions Grp., LLC v. Ironshore Indem., Inc., No. 17-11703 (11th Cir. Dec. 9, 2019), slip op. at 9). The Ninth Circuit held that a fraudulent email received by an employee could still be an instruction directing a bank to transfer funds (Ernst & Haas v. Hiscox, slip op. at 17).

Those insureds prevailed only after years of litigation. Others did not; in 2025 a federal court in Pennsylvania held that forgery coverage required a forged financial instrument, so forged signatures on a term sheet and letters did not qualify (KMS Dev. Partners LP v. Fed. Ins. Co., No. 24-1613 (E.D. Pa. Feb. 3, 2025), slip op. at 12).

American Tooling v. Travelers

$834,108

Vendor impersonation by email. Insurer argued no direct loss and no Computer Fraud.

6th Cir. 2018: coverage; summary judgment for insured

Principle Solutions v. Ironshore

$1.717M

Executive impersonation; bank hold released after employee callback. Insurer argued causation was broken.

11th Cir. 2019: coverage affirmed

Ernst & Haas v. Hiscox

$200,000

Fake invoices from a “founder.” Insurer argued employee initiation defeated funds transfer fraud coverage.

9th Cir. 2022: dismissal reversed

KMS Development v. Federal Ins.

$800,000

Forged signatures on a term sheet and letters induced escrow and fee payments.

E.D. Pa. 2025: no coverage; not a financial instrument

Sources: opinions at https://www.opn.ca6.uscourts.gov/opinions.pdf/18a0138p-06.pdf; https://media.ca11.uscourts.gov/opinions/pub/files/201711703.pdf; https://cdn.ca9.uscourts.gov/datastore/opinions/2022/01/26/20-56212.pdf; https://www.govinfo.gov/content/pkg/USCOURTS-paed-2_24-cv-01613/pdf/USCOURTS-paed-2_24-cv-01613-0.pdf. Amounts as stated in the opinions.

A second gap is definitions. The Government Accountability Office found that cyber policies lack common definitions and that terms such as “cyberterrorism” can leave coverage unclear (GAO-21-477).

Insurers are also excluding cyber warfare and infrastructure outage losses, and an attack attributed to a state actor may fall within that exclusion (GAO-22-104256).

A third gap is the limit, which GAO reports insurers reduced for some sectors (GAO-21-477). Social engineering endorsements are commonly sold at a sublimit that may be lower than a single routine wire.

The fourth gap is structural. A commercial form insures the entity and its employees, while the family’s exposure runs through the principal, spouse, trusts, special purpose vehicles, and household staff who release payments but may not be employees.

The Financial Crimes Enforcement Network has observed increased reporting of deepfake media used to defeat identity verification, which widens the impersonation risk for each of those persons (FinCEN, Alert FIN-2024-Alert004 (Nov. 13, 2024)).

1

The authorized payment

Insurers contest direct loss, use of a computer, and fraudulent instruction when the insured’s own staff releases the wire. Outcomes turn on exact definitions.

2

Undefined and excluded events

No common definition of “cyberterrorism.” Cyber warfare and infrastructure outage exclusions are spreading. Attribution to a state actor may defeat the claim.

3

Sublimits

Social engineering and funds transfer fraud are often endorsed at a fraction of the policy limit. Limits in some sectors have been reduced.

4

Who is insured

Principal, spouse, trusts, SPVs, household staff, and personal devices may fall outside the defined terms Insured and Computer System. Deepfakes widen the impersonation surface.

Sources: court opinions cited above; GAO-21-477, https://www.gao.gov/products/gao-21-477; GAO-22-104256, https://www.gao.gov/products/gao-22-104256; NY DFS Circular Letter No. 2 (2021); FinCEN Alert (Nov. 13, 2024), https://www.fincen.gov/news/news-releases/fincen-issues-alert-fraud-schemes-involving-deepfake-media-targeting-financial

$20.9 billionLosses reported to the FBI IC3 in 2025 across 1,008,597 complaints

$3.05 billionBusiness email compromise losses reported in 2025

58%Share of attempted theft frozen through the FBI Financial Fraud Kill Chain in 2025 ($679 million of $1.16 billion)

26% to 47%Cyber insurance take-up among one large broker’s clients, 2016 to 2020

Sources: FBI IC3, 2025 Internet Crime Report, pp. 6, 8, 17, https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf; GAO-21-477 highlights (May 2021), https://www.gao.gov/assets/gao-21-477-highlights.pdf

Clauses to negotiate before binding

Policy forms are not public documents, so the following are Dilendorf Law Firm drafting objectives rather than quotations from any form.

  1. Social engineering at full limitFunds transfer fraud, computer fraud, and social engineering fraud should share the policy aggregate. Any unavoidable sublimit should be scaled to the largest routine wire.
  2. Causation languageReplace “resulting directly from” with loss directly or indirectly resulting from a covered event, or define the term as proximate cause.
  3. Fraudulent instructionInclude instructions received by any insured person by email, telephone, video, or messaging, whether or not the fraudster touched the insured’s systems, whoever the sender claims to be.
  4. Synthetic mediaState that impersonation by cloned voice, video, or generated documents is a covered means of deception.
  5. Insured persons and entitiesSchedule the principal, family members, trusts, foundations, and special purpose vehicles as insureds, and extend “computer system” to personal devices and accounts used for family business.
  6. Verification conditionDelete the callback condition or replace it with the office’s written procedure, and add that a good faith failure to follow it does not void coverage.
  7. NoticeRun the notice period from discovery by a named officer, and add a law enforcement notice clause consistent with the DFS framework that is not a condition precedent.
  8. Digital assetsAdd cryptocurrency and tokens to the definitions of “money” and “securities,” and fix a valuation date.
  9. War and state actor exclusionRequire a carve-back for attacks that are not part of an armed conflict and place the burden of attribution on the insurer.
  10. Choice of counsel and forensicsReserve the right to select counsel and forensic firms at preapproved rates, with costs advanced by the insurer.

Source: Dilendorf Law Firm drafting objectives, informed by the court opinions, GAO reports, and DFS guidance cited in this article.

How Dilendorf Law Firm helps

Dilendorf Law Firm represents victims of business email compromise, account takeovers, and SIM swaps, and has arbitrated more than 100 cybercrime matters.

Before renewal, we review the cyber form, the crime form, and the household’s other policies side by side, identify sublimits and conditions, and draft the endorsements above for the broker.

After an incident, we manage notice to the insurer and coordinate the bank recall and the IC3 report. Retired law enforcement agents conduct the network compromise investigation under privilege, and we preserve the evidence the insurer will demand.

If the insurer denies the claim, we test the denial against the policy wording and the published decisions and, depending on the facts, pursue it in court or arbitration.

Contact Us

Before your next renewal, or within hours of a suspicious wire, contact Max Dilendorf at +1 212 457 9797 or info@dilendorf.com, or use our contact page.

This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.

Frequently asked questions

What does a cyber insurance policy cover?

Most policies combine first-party and third-party coverage. First-party coverage pays the insured’s own costs, such as forensic services, legal counsel on notification duties, data recovery, business interruption, and cyber extortion (FTC, Cyber Insurance).

Third-party coverage responds when someone else brings a claim, including settlement expenses, regulatory inquiries, and judgments (FTC, Cyber Insurance). Theft of funds by impersonation is often placed in a separate crime policy rather than the cyber form.

A family office should read both policies together.

Why is social engineering fraud a gap?

Because the principal or an employee authorizes the payment. Insurers have argued that computer fraud coverage requires hacking and that a loss caused by an employee’s own wire instruction is not “direct” (Ernst & Haas v. Hiscox (9th Cir. 2022)).

Federal appellate courts have rejected those arguments on specific policy wording, but each ruling turned on the exact definitions in the form (American Tooling v. Travelers (6th Cir. 2018)). Many insurers now offer social engineering coverage only as a separate endorsement with its own limit.

That limit may be a fraction of the main policy limit.

What is silent cyber and why does it matter?

The New York Department of Financial Services describes silent cyber as the risk that an insurer must pay for a cyber incident under a policy that never mentions cyber (NY DFS Circular Letter No. 2 (2021)). DFS has told insurers to state clearly whether each policy covers or excludes cyber losses (NY DFS Circular Letter No. 2 (2021)).

For a family, that means homeowners, directors and officers, and general liability policies may now carry express cyber exclusions. Coverage that was once assumed may need to be purchased on purpose.

Do cyber policies exclude attacks by foreign governments?

Often, at least in part. The Government Accountability Office reports that insurers are excluding coverage for losses from cyber warfare and infrastructure outages (GAO-22-104256).

GAO also notes that terms such as “cyberterrorism” lack standard definitions across policies (GAO-21-477). A family office should ask how the policy treats an attack attributed to a state actor that targets a private victim.

The wording of the war exclusion, and any carve-back for cyber operations, may decide the claim.

How much does a family office typically lose in a wire fraud?

There is no reliable public figure for family offices alone. The FBI Internet Crime Complaint Center reported $20.877 billion in total losses across 1,008,597 complaints in 2025 (FBI IC3, 2025 Annual Report, p. 6).

Business email compromise accounted for about $3.05 billion of that amount (FBI IC3, 2025 Annual Report, p. 8). Individual disputes in the published opinions involved losses from $200,000 to more than $1.7 million.

Reported losses may understate the exposure of a single high-value household.

Should the policy require a callback before a wire is released?

Many insurers condition social engineering coverage on a verification step, such as a callback to a known number. A family office should either build that step into its payment procedure or negotiate the condition out of the policy.

Insurers have argued that an employee’s verification of a fraudulent instruction breaks the chain of causation (Principle Solutions v. Ironshore (11th Cir. 2019)). The Eleventh Circuit rejected that argument under the policy before it, but the dispute took years (Principle Solutions v. Ironshore (11th Cir. 2019)).

A clear written procedure reduces the risk of a denial.

Does the policy cover the principal’s personal accounts and household staff?

Usually not unless the definition of “Insured” says so. Commercial forms typically name the entity and its employees.

A family’s exposure extends to the principal, spouse, children, trusts, special purpose vehicles, and household staff who handle payments. Each of those persons and entities should be listed or captured by a defined term.

Personal devices and personal email accounts used for family business should also be within the definition of the insured’s computer system.

Must a family office notify law enforcement after an incident?

Many policies now require it. DFS has stated that cyber insurance policies should include a requirement that victims notify law enforcement (NY DFS Circular Letter No. 2 (2021), item 7).

Prompt notice can also help recover funds. In 2025, the FBI’s Financial Fraud Kill Chain froze $679 million of $1.16 billion in attempted thefts, a 58 percent success rate (FBI IC3, 2025 Annual Report, p. 17).

A missed notice deadline may give the insurer a coverage defense. The policy’s notice period should be measured from discovery by a named officer, not from the event itself.

When should a family office involve counsel in the insurance process?

Before renewal and again within hours of an incident. Before renewal, counsel can compare the cyber form and the crime form, identify sublimits, and draft the endorsements described in this article.

After an incident, counsel manages notice, coordinates the bank recall and law enforcement reports, and preserves the evidence the insurer will demand. Coverage disputes in the published opinions were decided on documents created in the first days of the loss.

Depending on the facts, early involvement may preserve a claim that would otherwise be denied.

Sources

[1] Federal Trade Commission, Cyber Insurance (Cybersecurity for Small Business). https://www.ftc.gov/business-guidance/small-businesses/cybersecurity/cyber-insurance

[2] U.S. Government Accountability Office, GAO-21-477, Cyber Insurance: Insurers and Policyholders Face Challenges in an Evolving Market (May 20, 2021). https://www.gao.gov/products/gao-21-477

[3] U.S. Government Accountability Office, GAO-21-477 Highlights (May 2021). https://www.gao.gov/assets/gao-21-477-highlights.pdf

[4] U.S. Government Accountability Office, WatchBlog, Rising Cyberthreats Increase Cyber Insurance Premiums While Reducing Availability. https://www.gao.gov/blog/rising-cyberthreats-increase-cyber-insurance-premiums-while-reducing-availability

[5] U.S. Government Accountability Office, GAO-22-104256, Cyber Insurance: Action Needed to Assess Potential Federal Response to Catastrophic Attacks (June 21, 2022). https://www.gao.gov/products/gao-22-104256

[6] New York State Department of Financial Services, Insurance Circular Letter No. 2 (2021), Cyber Insurance Risk Framework (Feb. 4, 2021). https://www.dfs.ny.gov/industry_guidance/circular_letters/cl2021_02

[7] Federal Bureau of Investigation, Internet Crime Complaint Center, 2025 Internet Crime Report. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf

[8] American Tooling Center, Inc. v. Travelers Casualty and Surety Co. of America, No. 17-2014 (6th Cir. July 13, 2018). https://www.opn.ca6.uscourts.gov/opinions.pdf/18a0138p-06.pdf

[9] Principle Solutions Group, LLC v. Ironshore Indemnity, Inc., No. 17-11703 (11th Cir. Dec. 9, 2019). https://media.ca11.uscourts.gov/opinions/pub/files/201711703.pdf

[10] Ernst and Haas Management Company, Inc. v. Hiscox, Inc., No. 20-56212 (9th Cir. Jan. 26, 2022). https://cdn.ca9.uscourts.gov/datastore/opinions/2022/01/26/20-56212.pdf

[11] KMS Development Partners LP v. Federal Insurance Co., No. 24-1613 (E.D. Pa. Feb. 3, 2025) (GovInfo). https://www.govinfo.gov/content/pkg/USCOURTS-paed-2_24-cv-01613/pdf/USCOURTS-paed-2_24-cv-01613-0.pdf

[12] Financial Crimes Enforcement Network, FinCEN Issues Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions, FIN-2024-Alert004 (Nov. 13, 2024). https://www.fincen.gov/news/news-releases/fincen-issues-alert-fraud-schemes-involving-deepfake-media-targeting-financial

Discuss Your Matter

Confidential consultations by appointment.

Call us now Request consultation