Most of the cyber insurance conversations I have start with ransomware. The claims data says that's the wrong thing to lose sleep over.
Coalition's 2026 cyber claims report looked at last year's claims and found that business email compromise and funds transfer fraud made up 58% of incidents. Ransomware was the costliest at an average of $269,000 a claim — but the thing most likely to actually happen to a 15-person law firm is a convincing fake wire instruction that somebody in the office follows.
Here's the part that catches people off guard.
Your policy has a headline limit. Say $1M. Funds transfer fraud usually doesn't get that limit — it gets a sublimit, often a small fraction of it. Sometimes it isn't in the base policy at all and sits in a separate endorsement you either bought or didn't. Coalition's own coverage guidance says it plainly: social engineering coverage may only be available through an additional endorsement, and the scope can be narrow.
So a firm carrying a $1M policy can wire out $141,000 — last year's average funds transfer fraud loss — and find out the real coverage for that specific event is a sliver of the number on the cover page.
Two questions worth asking before your next renewal: what is my funds transfer fraud sublimit, and does it sit inside or outside my main limit? If your broker has to go look it up, that's already useful information.
Want the next one in your inbox?
One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.
Subscribe via email