Cyber Insurance for Community Banks: What It Covers, What It Doesn't, and What Your Board Should Be Asking

Your bank has a cyber insurance policy. It’s on the books. The premium gets paid. The Board sees it listed in the risk management report.

But when was the last time anyone checked what your cyber policy covers?

I review cyber policies for clients, and the most common reaction I get from bank leadership is some version of:

“Wait, that’s not covered?”

The problem isn’t that community banks buy bad cyber policies. It’s that cyber insurance was designed for companies that store data and run a single network. Community banks hold financial data, process transactions, move money, depend on third-party vendors, and answer to regulators. Different risk profile. Your policy should reflect it.

Here’s how to tell if it does.

What Cyber Insurance Covers for a Community Bank

A cyber policy has two sides: first-party coverage (your own losses) and third-party coverage (when someone sues you).

First-Party Coverage
Your own losses
  • Breach response: Forensics, legal counsel, notification, credit monitoring. Even a few hundred records can run into six figures.
  • Business interruption: Lost income and extra expenses while systems are down, after a waiting period (usually 8 hours).
  • Cyber extortion/ransomware: Ransom payments, negotiation, forensic support.
  • Data restoration: Recovering or recreating data destroyed during an attack.
Third-Party Coverage
When someone sues you
  • Network security liability: Defense costs and settlements when a security failure causes harm to a third party.
  • Privacy liability: Claims from failure to protect personal information.
  • Regulatory proceedings: Defense costs when regulators investigate after a breach. For banks, this matters more than in most industries.

That’s the standard package. For a typical business, it works reasonably well. For a community bank, it has blind spots that deserve attention.

Blind Spots: Where Cyber Insurance Falls Short for Community Banks

Wire fraud coverage is probably not on your cyber policy at all

Wire fraud and business email compromise (BEC) are among the costliest cyber threats facing banks. BEC alone accounts for roughly $3 billion in reported losses annually. Banks are in the business of moving money, and attackers know it.

Outside banking, cyber policies commonly offer social engineering coverage as an endorsement with a $100K to $250K sublimit. Financial institutions are the exception. Cyber carriers generally do not write eCrime or social engineering coverage to FIs at all, so the line item on your declarations page may be one the underwriter never intended to sell you. This is a market appetite issue, not a broker miss.

That leaves the fidelity bond as the only policy that pays a wire fraud loss. Every bond I have read carries a social engineering endorsement, so the question is not whether you have it. It is the sublimit, which is often $250K against a computer fraud limit many times larger. If an employee is tricked into wiring $500K, the bond’s social engineering sublimit is the ceiling on recovery, not the bond’s headline limit.

And it is getting worse. AI-generated voice and video can now impersonate executives in real time, and most policy language was written for email-based scams. For a deeper look at how deepfakes are breaking callback verification procedures and widening this gap, see When AI Clones Your CFO’s Voice

What to look for: Find the social engineering sublimit on your bond, not your cyber policy, and compare it to a single day's wire volume. Check whether the bond defines "social engineering" broadly enough to include AI-generated voice and video. And if the bond requires a callback verification procedure, read whether it is a condition precedent, because a missed callback denies the claim rather than reducing it.

Your cyber and D&O policies, and your fidelity bond, may be pointing at each other

Banks carry fidelity bonds (covering employee dishonesty, forgery, computer fraud) alongside their cyber policies. These overlap in some areas and leave gaps in others.

Social engineering and fraudulent wire transfers are the most common gap. The fidelity bond may require “direct” fraud, someone physically stealing or forging. The cyber policy requires a “cyber event.” A BEC scam that tricks an employee into voluntarily initiating a legitimate wire transfer may not clearly fit either definition. The employee was not dishonest. There was no hack. Both carriers can argue it belongs to the other policy.

Directors and Officers (D&O) coverage adds another layer. If the Board is sued after a breach for inadequate oversight of cybersecurity, does the D&O policy respond? Most community bank D&O policies now carry a cyber exclusion, though the wording varies enough that two banks can get opposite answers. Where the exclusion is broad, it pushes everything to the cyber policy. The cyber policy does catch the directors, because they are named in its definition of Insured. What it does not do is behave like a D&O policy: there is no Side A tower, so the board shares one limit with forensics and notification, and those costs land first.

What to look for: Pull your cyber policy, D&O policy, and fidelity bond side by side. Check whether any of them have exclusions that push claims to one of the other policies. If you see phrases like "arising from a cyber event" in your D&O exclusions, or "computer fraud" carved out of your fidelity bond, those are the seams where coverage can fail.

Vendor outages may not be covered

Community banks depend on banking platforms, payment processors, and online banking providers. A breach or outage at any one of these vendors can bring operations to a halt.

Scenario: Your banking platform vendor suffers a ransomware attack. Your own systems are fine, but you cannot process transactions, access accounts, or serve customers for three days.

Many cyber policies either exclude third-party outages entirely, sublimit them, or require a “security failure” at the vendor. A configuration error, a failed update, or an operational failure at the vendor would not qualify. Your bank loses three days of operations, and your policy does not respond.

What to look for: Does your policy cover "dependent business interruption" or "contingent system failure"? Is there a sublimit? Does it require a "security event" at the vendor, or does it cover any "system outage"?

Ransomware coverage has 3 hidden traps

Financial institutions are among the most targeted industries for ransomware. Three things to check:

Trap 1: Sublimits.
Your declarations page says "$2M cyber." But ransomware/ extortion may be capped at $250K in the endorsements. Demand exceeds your sublimit? You pay the difference.
Trap 2: Security Warranties.
Cyber policies require MFA, patching, EDR, and backups as conditions of coverage. Miss one when a ransomware event hits, and the entire claim can be denied. MFA not enforced on remote access? Claim denied. Not because MFA would have stopped the attack. Because it was a contractual condition.
Trap 3: OFAC Sanctions Exclusion.
Most policies exclude ransom payments to OFAC-sanctioned groups. Banks deal with sanctions in daily compliance but many do not realize the same rules apply to their insurance. Pay a sanctioned group, and the carrier denies the claim. You may face OFAC penalties on top.

Regulatory coverage may be narrower than you think

Most cyber policies include regulatory proceedings coverage. But there are limits.

Fines and penalties are often excluded, or covered only where “insurable by law.” For banks, the 36-hour incident notification rule means regulators know quickly. The examination that follows can be extensive, and legal costs run into six figures.

The gap: your policy covers “regulatory proceedings” but may define it narrowly. An FDIC investigation framed as an examination rather than a formal enforcement action may not qualify.

Security Warranties: Where Cybersecurity Controls and Insurance Collide

Carriers require specific security controls as conditions of coverage: MFA on all remote access, EDR, patching within defined timelines, tested backups, email filtering, and employee security training. These are not recommendations. They are contractual requirements.

If any control is missing when a claim hits, coverage can be voided. A security gap is not just a vulnerability. It is an insurance gap. For a real-world example of how one missing MFA deployment voided an entire $5 million cyber policy, see What Happens When Your Security Warranty Fails.

If your bank works with an IT auditor or security firm, have them review your carrier’s warranty requirements alongside their assessment. For more on how examiner expectations and carrier requirements overlap, see Examiner Readiness.

5 Things to Check Before Your Next Board Meeting

Thirty minutes. If you get through all five, you will know more about your cyber coverage than most community banks ever will.

  1. Find your sublimits. Check the ransomware sublimit on the cyber policy against your aggregate, and the social engineering sublimit on the bond against a day’s wire volume. Below 25%? Flag it.

  2. Read your security warranties. List every control your policy requires. Verify your bank meets each one. One gap can void everything.

  3. Check your vendor coverage. Look for “dependent business interruption” language. If your policy only covers outages at your own bank, you have a gap.

  4. Look at your policies together. Pull cyber, D&O, and your fidelity bond. Look for exclusions that push claims to another policy. “Arising from a cyber event” in your D&O? That is a gap.

  5. Ask about deepfake coverage. Does the social engineering endorsement on your bond include AI-generated voice and video, or just written communications?

If any of these raises a question you cannot answer, bring it to your next broker conversation. For a detailed breakdown of how sublimits, retentions, and defense costs can reduce a $5 million policy to under $500,000 in actual recovery, see The Fine Print Inside the Coverage.

Or if you would rather have someone who reads these for a living walk through it with you, get in touch.

Joerg Proeve, Founder and Principal at Breezy Risk
Joerg Proeve

Founder & Principal of Breezy Risk. Carrier and MGA background in insurance, earlier career in cybersecurity and engineering. Audits insurance for community banks and credit unions.

More about Joerg →