I Audited Five Community Banks and Credit Unions. They All Had Similar Gaps.

Over the past months, I audited the insurance policies at five community banks and credit unions. I read the policy forms, endorsements, and amendments across their cyber and D&O policies, and their fidelity bonds. Different carriers. Different program structures.

Each bank engaged Breezy Risk for a Risk Intelligence Report: a line-by-line review of its cyber liability policy, fidelity bond, and directors and officers policy, read together against the bank’s operations, vendor contracts, and regulatory requirements. Not a checklist. Every finding comes from reading the policy forms themselves. Institutions and carriers are anonymized.

The coverage gaps across the banks were strikingly similar. Five structural problems appeared in every program. That pattern changes the conversation. One bank with a gap is a broker discussion. Five banks with five different programs and the same gaps is an industry problem.

Scorecard

Finding Bank A Bank B Bank C Bank D Bank E
1. Wire fraud Severe Partial Severe Partial Severe
2. D&O cyber exclusion Severe Partial Partial Severe Severe
3. Vendor BI sublimit Severe Partial Adequate Partial Severe
4. Headline vs. recovery Partial Severe Severe Partial Severe
5. Interest income Severe Partial Adequate Severe Partial
Severe gap Partial gap or ambiguous Adequate or fixed

Five findings. Five for five on wire fraud conditions, D&O exclusions, and headline overstatement. Four of five on vendor coverage and interest income. Bank C had the strongest program. It still had three of the five gaps.


Wire Fraud: Zero Clean Paths to Full Recovery

On a $500,000 wire fraud loss, recovery ranged from $0 to $250,000.
All five banks had conditions that could void coverage entirely.

Wire fraud is the number one fraud threat to community banks ($3 billion in FBI-reported BEC losses, 2025). Every bank had social engineering coverage on its fidelity bond. Not the cyber policy. Carriers will not sell eCrime coverage to financial institutions. The bond carries the full load.

The problem is what the endorsement says. Four of five banks had sublimits between $250,000 and $500,000. All five had a verification warranty written as a condition precedent: if the employee skips the callback, coverage drops to zero. That warranty was designed for email-based BEC, not deepfake voice calls. One bank had a 50% co-payment clause the board did not know about. And in two banks, recovery swung by $4.5 to $4.75 million depending on how forensics classified the attack after the fact, a judgment the bank does not control.

What to check

  • Is the social engineering sublimit at least $500,000?
  • Is the verification warranty a condition precedent (coverage voided) or best-efforts (coverage reduced)?
  • Is there a co-payment clause? What percentage does the bank absorb?
  • What is the difference in recovery between a computer fraud and social engineering classification?

The Wire Nobody Covers · What Your Fidelity Bond Won’t Pay


D&O Cyber Exclusion: Every Director Was Personally Exposed

Every D&O policy had a cyber exclusion. Zero banks had full board protection after a breach.

After a breach, regulators investigate the board. Did they approve a cybersecurity strategy? Did they allocate adequate resources? The FFIEC, FDIC, and state regulators have all increased scrutiny of board cybersecurity oversight. These investigations are D&O claims.

Every D&O policy I reviewed had a cyber exclusion. The cyber carrier says board liability is a D&O claim. The D&O carrier says it arises from a cyber event. Directors are in the middle with neither policy responding. Only two banks had partial carve-backs. One credit union protected individual directors but excluded entity-level claims. One bank capped investigative costs at $100,000, but a multi-regulator defense can exceed $500,000 in the first six months. None had a Side A fallback.

What to check

  • Does your D&O policy have a cyber exclusion? Does it use “arising from” language (broad) or something narrower?
  • Is there a carve-back for regulatory investigations of individual directors?
  • Does your cyber policy include any board coverage provisions? (Most do not.)
  • Do you have a Side A difference-in-conditions layer?

The Board Nobody Insures


Vendor BI Sublimit: $0 to $5 Million. Most Banks on the Wrong End.

Vendor BI sublimits ranged from $0 to $5 million.
Only one bank had its core vendor named by endorsement.

Every bank runs on a single core platform. When the core vendor goes down, the bank goes down. The Marquis Software Solutions breach in August 2025, a ransomware attack that exposed data at 700+ banks and credit unions, made vendor risk an examiner priority.

One bank had no vendor coverage at all. One had $100,000; a three-day outage would exhaust it in two. One had coverage narrowed mid-term by a carrier amendment that excluded sub-vendor supply chain exposure after the policy was in force. Only one bank had its core vendor named by endorsement with a $5 million limit. And two of five only covered vendor outages caused by security breaches, not system failures. A software crash that shuts down the platform is not a security breach.

What to check

  • Is dependent BI present? If “Not Included” on the declarations, you have zero vendor coverage.
  • What is the sublimit? Model a 5-day outage at your core vendor.
  • Does it cover system failure, or only security breach?
  • Is your core vendor named, or covered only by a class definition?

The Vendor You Cannot Replace


Headline vs. Recovery: $12 Million in Limits, $500,000 in Recovery

Combined headline limits: $12 million to $27 million.
Realistic recovery on a multi-front incident: $500,000 to $3 million.

The declarations page shows what the board approved at renewal. Combined limits ranged from $12 million to $27 million. The realistic recovery on a multi-front incident, wire fraud, breach response, regulatory investigation, and board liability at the same time, ranged from $500,000 to $3 million.

The erosion comes from sublimits that share the aggregate, defense costs paid inside the limit, D&O cyber exclusions, verification warranties, and the gaps between the three policies where each carrier points at the others. A $5 million cyber policy with typical sublimits can pay $650,000 on a $4.2 million ransomware loss. Stack that against a bond sublimit and a D&O exclusion, and the bank’s total recovery is a fraction of the headline number. One bank: $12 million in combined limits, approximately $500,000 in realistic recovery.

What to check

  • List every sublimit. Note which are “part of and not in addition to” the aggregate.
  • Are defense costs inside or outside the limit?
  • Model a multi-front scenario. Map each cost to the policy that responds. Compare the total to the headline.
  • Does the board know the difference between the headline number and the realistic recovery?

The Fine Print Inside the Coverage


Interest Income: Most of a Bank's Revenue, Not Covered

70-85% of bank revenue is interest income. Most cyber BI definitions exclude it. One bank had an endorsement that fixes this.

Community banks earn 70-85% of revenue from net interest income. During a cyber outage, those loans continue to accrue interest contractually, but the BI definition in most cyber policies either excludes interest income or leaves it ambiguous. The definition was written for commercial businesses where interest income is incidental.

Two banks were on a carrier program that pays BI at a flat $500 per hour, a rate that covered only 20-25% of the bank’s hourly revenue. The math was set without interest income. Two other banks had ambiguous definitions, worded in a way that pays when the carrier wants it to, not when the bank needs it to. One bank had an endorsement that deletes the interest income exclusion entirely. It was the single most valuable endorsement in the sample.

I nearly missed this gap myself. It was not in my initial methodology. The odds that a generalist broker is checking are low.

What to check

  • Does the BI definition use a flat hourly rate? Compare it to your hourly interest income.
  • Look for the phrase “interest or investment income.” If excluded, your primary revenue stream is outside the BI definition.
  • Ask whether an Interest Income endorsement is available. The cost is a fraction of the premium.

The Revenue Your Policy Ignores


The Pattern

These findings compound. A single cyber incident touches all three policies, but none of them respond the way the board expects. The cyber carrier denies under a sublimit. The bond carrier denies under a verification condition. The D&O carrier denies under a cyber exclusion. The BI definition excludes the bank’s primary revenue. Each carrier points to the others.

Every bank in this sample was paying for insurance. None had a clear picture of what it would pay. The gaps are not broker errors. They are policy language designed for commercial businesses, applied to financial institutions without modification.

The fix is not more insurance. It is reading the insurance you already have.


About Breezy Risk

Joerg Proeve is an independent risk advisor. Corporate strategy and M&A integration at a global carrier, technology strategy and innovation at a national carrier, operations leadership at a cyber insurance MGA. He does not place policies. He audits them.

Ready to find out what your insurance will pay? Get in touch.
Joerg Proeve, Founder and Independent Risk Advisor
Joerg Proeve

Founder of Breezy Risk. Carrier and MGA background in insurance, earlier career in cybersecurity and engineering. Audits insurance for community banks and credit unions.

More about Joerg →