Does professional liability cover a client's wire-fraud loss, or just crime and cyber?
The same client-fund wire-fraud event can produce a crime claim, a cyber claim and an E&O claim at once. Two real rulings show why the E&O answer isn't automatic.
Breach, ransomware, wire fraud and regulatory defence — bound to the exact language customers and regulators require. Already appointed? Send us the account. New here? Apply for appointment below.
Cyber liability covers the first-party costs of recovering from a cyber event — incident response, forensics, ransomware, lost income — and the third-party liability when a customer's or employee's data is exposed. It's the line that now lives at the intersection of customer contracts, board expectations and regulator demands.
Customer contracts and investor diligence can ask for cyber limits or specific wording. We compare the request with the policy's limit, retention, definition and conditions before binding a programme.
Sensitive client data creates breach-response, notification and third-party liability questions. The right review starts with the data types, systems, record volume and client commitments, not only employee count.
Funds-transfer fraud and vendor impersonation can create material first-party loss. Cyber and crime forms can address them differently, so the social-engineering language and limits should be reviewed against the dollars moving through the firm.
AI-assisted output, connected products and operational technology can create liability questions that a generic policy may not address as intended. Review the services definition, exclusions and customer promises against the actual product.
Incident response, forensics, legal counsel, customer and regulator notification, credit monitoring and PR — the first-call costs that hit before any litigation does.
Extortion payments where insurable, system restoration and lost income while the business is offline — including operational technology (OT) shutdown on connected production systems.
Wire fraud, fake-vendor invoices and email compromise — sized to the dollars actually moving through the firm and bound with explicit social-engineering language (not a sub-limit).
Third-party claims from clients, customers and employees whose data was exposed — plus defence and fines (where insurable) for HHS, SEC, FINRA, state AGs and international regulators.
If a hack causes physical injury — including via connected products — that sits with GL or product liability, not cyber. We place the two so they line up.
Many cyber forms exclude state-sponsored attacks. The wording matters: a Russian ransomware crew can read either way. We push for affirmative non-state coverage on every renewal.
If a vendor patch sat unapplied for a year and the loss traces to that exact CVE, expect a fight. We flag what hygiene the carrier actually requires to keep cover in force.
Cyber and AI liability sized to clear enterprise procurement and grow with every round.
See the pageFirst-party + third-party cyber, contingent BI and crime — bound to client MSA requirements.
See the pageDedicated cyber for law firms, accounting firms and agencies holding sensitive matter data.
See the pageHIPAA breach response, ransomware on the EHR and OCR regulatory defence — sized to patient volume.
See the pageFunds-transfer fraud at closing, rent and vendor payments — the largest cyber loss in real estate.
See the pageOT/ICS ransomware and contingent BI — when a hack stops the line, not just the office network.
See the pageRegulated PII, funds-transfer fraud and FINRA/SEC regulatory defence — sized to AUM.
See the pageDonor PII, finance email compromise and ransomware on the donor database.
See the pageWire fraud on draws and vendor payments — the fastest-growing loss for construction firms.
See the pageEvery submission gets matched internally against the carrier relationships most likely to write it — not shopped blind into a dozen inboxes.
A slow market costs you the account. Matched submissions move straight to underwriting, and you're kept posted, even when the answer is no.
No 40-page form, no repeated questions. Send what you've got and we take it from there.
The same client-fund wire-fraud event can produce a crime claim, a cyber claim and an E&O claim at once. Two real rulings show why the E&O answer isn't automatic.
California AI startup insurance for enterprise deals: separate product and privacy obligations from customer MSA limits, Tech E&O, cyber and D&O.
Cyber insurance does not automatically cover client-fund theft. Professional firms should map cyber, crime, social engineering and E&O wording together.
Before you commit to a quote, get the numbers. A custom Cyber Risk Report — loss estimates scaled to your revenue, the six hygiene controls underwriters score and live market pricing for your industry. Delivered in 24 hours, free.
Get the free reportApply to become an appointed Nomos Wholesale partner — same-day appetite matching, direct access to E&S and specialty markets.
Get appointedSend us the submission — we'll see what fits. We can worry about the paperwork later.