Comparison
Cyber Liability vs. Crime and Fidelity: Which Covers a Loss?
Cyber liability responds to data breaches and network attacks, while crime and fidelity coverage responds to theft of money or property, including employee dishonesty and social engineering fraud.
Cyber liability generally responds when a network is attacked or data is exposed, while crime and fidelity coverage generally responds when money or property is stolen, whether by an employee or an outside fraudster. Many losses, especially social engineering and funds-transfer fraud, touch both policies, so businesses often carry both and coordinate the limits.
A ransomware attack that shuts down a company's systems, a breached customer database, and an employee who quietly diverts vendor payments to a personal account can all feel like the same kind of problem: something went wrong with the business's money or data because of a bad actor. But from an insurance standpoint, these are typically two different coverage lines, and knowing which one applies can matter a great deal when a claim is filed.
Cyber liability insurance is built around the technology and data side of a loss. It typically covers costs like breach notification, forensic investigation, credit monitoring, business interruption from a network outage, and liability to third parties whose information was exposed. Crime and fidelity coverage, by contrast, is built around the theft of money, securities, or other property, whether the thief is an employee, a vendor, or an outside criminal who tricks someone into sending funds.
The overlap shows up most clearly in social engineering fraud and fraudulent funds transfer, where an email or phone scam convinces an employee to wire money to a fraudulent account. Some cyber policies offer limited social engineering coverage, and some crime policies do too, but sublimits and requirements differ enough that businesses often end up needing both policies working together rather than relying on just one.
Cyber Liability
Coverage for data breaches, network attacks, and related liability
Strengths
- Responds to data breach notification, forensic investigation, and credit monitoring costs after an incident
- Covers business interruption and extra expense from a network outage or ransomware attack
- Provides third-party liability coverage for claims by customers or partners whose data was exposed
- Often includes access to breach response vendors, legal counsel, and public relations support
- Can cover ransom payments and negotiation costs in a ransomware event, subject to policy terms
Where it falls short
- Generally does not cover the direct theft of money by an employee acting alone without a network intrusion
- Social engineering and funds-transfer fraud coverage is often limited or requires a separate endorsement
- Coverage often depends on the business meeting minimum security controls, such as multi-factor authentication
Best for
Businesses that store customer data, rely on networked systems, or accept electronic payments and want protection against breaches and network attacks.
Crime and Fidelity
Coverage for theft of money and property, including employee dishonesty
Strengths
- Covers employee theft and embezzlement, including fidelity bond-style protection against dishonest acts by staff
- Covers theft of money, securities, and property by third parties as well as employees
- Can include coverage for computer fraud and funds-transfer fraud, depending on the endorsements purchased
- Often required by lenders, franchisors, or contracts that call for fidelity bond protection
- Covers forgery and certain check fraud losses that fall outside typical cyber policy language
Where it falls short
- Does not typically cover breach notification costs, credit monitoring, or third-party data liability
- Does not respond to business interruption caused by a network outage or ransomware attack
- Social engineering coverage is frequently offered as a narrow sublimit rather than full policy limits
Best for
Businesses concerned about employee dishonesty, funds-transfer fraud, or theft of money and property, alongside their cyber exposure.
Side by side
| Cyber Liability | Crime and Fidelity | |
|---|---|---|
| Core coverage | Data breach, network attacks, and related liability | Theft of money, securities, and property |
| Employee theft | Generally not covered | Core coverage, often called fidelity or employee dishonesty |
| Ransomware | Typically covered, including some ransom negotiation costs | Not covered |
| Breach notification costs | Typically covered | Not covered |
| Social engineering fraud | Sometimes covered, often as a sublimit or add-on | Sometimes covered, often as a sublimit or add-on |
| Business interruption from a network outage | Typically covered | Not covered |
| Third-party data liability | Core coverage | Not covered |
| Typical buyer | Businesses handling customer data or online payments | Businesses with employees who handle money or payables |
Where the two policies diverge
Cyber liability is fundamentally about the confidentiality, integrity, and availability of data and systems. If a hacker locks up a company's files and demands payment, or a database of customer records is exposed, cyber liability is generally the policy that responds, with coverage extending to forensic investigation, notification letters, and liability defense.
Crime and fidelity coverage is fundamentally about theft, regardless of whether a computer was involved. If a longtime bookkeeper diverts company funds into a personal account over several years, that is a fidelity claim, not a cyber claim, even though it may eventually involve reviewing electronic financial records.
The gray area: social engineering and funds-transfer fraud
The scenario that most often causes confusion is a business email compromise, where a fraudster impersonates a vendor or executive and convinces an employee to wire funds to a fraudulent account. This blends a cyber-enabled deception with an actual theft of money, and different carriers draw the coverage line differently depending on whether the policy is cyber or crime.
Because of this overlap, it is worth asking an agent to review both policies together to confirm that social engineering coverage exists somewhere in the program, rather than assuming either policy automatically fills the gap.
Why many businesses carry both
Businesses that handle both sensitive data and significant cash flow, such as those processing customer payments or managing payroll, often carry cyber liability and crime and fidelity coverage side by side. The two policies are usually priced and underwritten separately, so adding one does not typically increase the cost of the other significantly, and together they close a much wider range of exposure than either alone.
How to decide
Do you store customer or employee data electronically?
If a breach could expose sensitive information, cyber liability is generally the coverage designed to respond.
Do employees have access to company funds or payables?
Crime and fidelity coverage addresses the risk of internal theft that cyber liability typically does not.
Could a fraudulent wire transfer slip past your controls?
Ask specifically about social engineering coverage in both policies, since it is often limited and easy to overlook.
Would a network outage stop your operations?
Business interruption from a cyberattack is a cyber liability feature, not something crime coverage addresses.
Do contracts or lenders require a fidelity bond?
Some agreements specifically call for fidelity coverage, which cyber liability does not satisfy on its own.
The bottom line
Cyber liability and crime and fidelity coverage address different root causes of loss, data compromise versus theft of money or property, and the overlap between them is narrower than many business owners assume. Businesses with meaningful exposure to both data breaches and internal or external theft often find it worthwhile to carry both policies and confirm how funds-transfer fraud is treated in each.
Frequently asked questions
Coverage covered here
Industries this affects
Keep comparing
Cyber vs technology E&O
Cyber liability covers the costs of a data breach or network security incident, while technology errors and omissions covers claims that a tech company's product or service failed to perform as promised.
Read itD&O vs EPL
Directors and Officers (D&O) insurance protects leadership decisions from claims tied to mismanagement, while Employment Practices Liability (EPL) covers claims from employees alleging discrimination, harassment, or wrongful termination.
Read itReady to see your options?
One application. Up to 10 competing quotes. Answer a few questions and we will shop your business to our A-rated carrier network, then a licensed agent walks you through the options.
