SPECIALTY LINES · 5 MIN READ
Cyber Liability, Crime, and Social Engineering
The third-party side of cyber splits into two principal grants. Network security liability covers claims from failures of the insured's network security - transmitting malware, enabling denial-of-service attacks, or unauthorized access that harms others. Media liability (multimedia or online content liability) covers content torts: defamation, libel, slander, false light, copyright and trademark infringement, plagiarism, and misappropriation of name or likeness in the insured's electronic and printed content. A defamation claim over an online article is a media claim, not a network security claim. Regulatory defense and fines coverage responds to government proceedings - a state attorney general or FTC investigation after a breach - paying defense costs and civil penalties where insurable by law; many jurisdictions permit insuring civil penalties but not criminal fines. PCI DSS assessment coverage addresses contractual fines and assessments from the card brands after payment-card breaches. The most litigated boundary in cyber crime is computer fraud versus social engineering fraud. Computer fraud insuring agreements require loss resulting directly from an intruder's unauthorized manipulation of the insured's computer system. Social engineering fraud (fraudulently induced transfer) responds when an authorized employee, deceived by a spoofed email or impersonation call, voluntarily initiates the transfer. Business email compromise - the spoofed-CEO wire - is the paradigm social engineering loss, and after years of coverage litigation modern forms expressly carve BEC out of computer fraud and route it to a social engineering agreement with a much lower sublimit, commonly in the $100,000 to $500,000 range. When both a commercial crime policy and a cyber policy carry funds-transfer-fraud coverage, the conventional allocation runs the cyber sublimit first with the crime policy excess, though the final order depends on each policy's other-insurance wording. Large programs stack limits in towers: a primary policy plus excess layers, each attaching at the exhaustion of all underlying limits. Excess layers are typically following form - incorporating the primary's terms except where expressly modified - and attach vertically: the first excess pays only after the primary is exhausted by payment of covered loss, then erodes its own limit before the next layer attaches. Aggregation clauses (common-cause endorsements) determine whether related events share one limit or several.
Key rules
Defamation and infringement claims belong to media liability, not network security.
Media liability covers content-based torts in the insured's online and printed material; network security liability covers harms flowing from security failures like malware transmission or unauthorized access.
Why the exam cares: Grant-matching questions give a content tort and test whether you route it to the media agreement.
Computer fraud needs an intruder; social engineering needs a deceived employee.
Courts read computer fraud to require unauthorized system manipulation by an outsider, while social engineering responds to voluntary transfers induced by fraudulent instructions - the two are effectively mutually exclusive.
Why the exam cares: The spoofed-CEO wire is the classic exam scenario, and the tested answer is social engineering at its sublimit.
BEC losses are carved out of computer fraud and sublimited under social engineering.
After insureds litigated for full computer-fraud limits on email-induced wires, modern forms expressly route business email compromise to the lower social engineering sublimit with a voluntary-transfer predicate.
Why the exam cares: The exam tests both the carve-out and the consequence - recovery capped at the sublimit, not the full crime limit.
Regulatory coverage pays defense plus civil penalties only where insurable by law.
Government investigations after a breach fall under regulatory defense and fines; insurability of the penalty depends on jurisdiction, and criminal fines are generally uninsurable.
Why the exam cares: Questions distinguish private lawsuits (third-party liability) from government proceedings (regulatory grant).
Excess cyber layers follow form and attach vertically on exhaustion of underlying limits.
Each excess policy incorporates the primary's terms unless expressly modified and pays only after all underlying limits are exhausted by covered loss, eroding its own limit before the next layer attaches.
Why the exam cares: Tower-mechanics questions test vertical exhaustion against pro-rata distractors.
Numbers to memorize
- $100,000-$500,000 — typical social engineering / fraudulently-induced-transfer sublimit range, far below full crime limits
Common traps
- Claiming a spoofed-email wire under computer fraud — remember an authorized employee's voluntary transfer is social engineering, subject to its lower sublimit.
- Routing a defamation suit to network security liability — remember content torts are the core of the media liability grant.
- Assuming all fines are insurable under the regulatory grant — remember insurability is jurisdiction-dependent, and criminal fines are generally uninsurable.
- Splitting a tower loss pro rata across layers — remember standard excess cyber attaches vertically, each layer paying only after the one below is exhausted.
For any fraudulent transfer, ask one question - did an intruder move the money, or did a deceived employee - and the insuring agreement and limit follow automatically.
Test it before the exam does
Our P&C bank drills Specialty Lines with AI-explained answers. 20 questions free, no signup.
Taking the P&C exam in your state?
Studying for the Property & Casualty insurance exam? Track every lesson free — progress syncs with the app.
Start free