The most dangerous words in a cyber insurance policy are not "not covered." They are "covered, up to a limit that is smaller than you think." A community bank in Minnesota learned this the hard way: it suffered a roughly $600,000 loss, and its insurer paid $100,000, applying a social-engineering sublimit while denying access to the larger computer-fraud limit. The loss was covered. The bank still absorbed five-sixths of it.

That gap between what a policy appears to cover and what it actually pays is the real hazard in bank cyber insurance, and it does not come from villainous insurers or careless banks. It comes from a structural mismatch: cyberattacks do not respect the neat categories that insurance policies are built around, and when a single loss could plausibly fall into more than one category, the policy language usually lets the insurer route it to the one that pays the least.

Why one loss has many possible labels

Insurance policies are organized into buckets. A bank typically carries several that touch a cyber incident: a cyber liability policy for data breaches, a fidelity bond for employee dishonesty and certain fraud, and a directors-and-officers policy for the lawsuits and regulatory investigations that follow. Each bucket has its own limit, its own exclusions, and, critically, its own sublimits, smaller caps on specific kinds of loss nested inside the larger policy.

A real cyberattack does not arrive pre-sorted into those buckets. Consider the common scenario at the center of these disputes: an attacker impersonates a bank executive in an email and tricks an employee into wiring money to a fraudulent account. What kind of loss is that? It is arguably "computer fraud," since a computer was used. It is arguably "social engineering" or "fraudulent instruction," since an employee was deceived into authorizing the transfer. It might touch "funds transfer fraud." The same event fits several definitions at once, and that ambiguity is the whole problem, because the categories carry very different limits.

Computer-fraud coverage often carries a high limit. Social-engineering coverage is frequently capped by a much smaller sublimit, sometimes a tenth or less of the main limit, precisely because insurers know deception-based fraud is common and expensive. So the single most consequential question after one of these losses is not whether it is covered. It is which label gets applied, because the label determines whether the bank recovers most of the loss or a fraction of it.

The characterization fight is the whole game

Here is the part that makes this treacherous rather than merely complicated. When a loss could fit multiple categories, the policy language generally gives the insurer significant power to characterize it, and the insurer has an obvious financial incentive to characterize it into the bucket with the smallest sublimit.

In the Minnesota case, the loss involved deception, so the insurer characterized it as social engineering and paid the social-engineering sublimit, declining to treat it as computer fraud, which would have paid far more. A federal court in Texas reached a similar result in a 2026 decision, enforcing a sublimit on a loss the insurer acknowledged was covered, turning the dispute not on whether the bank was covered but on how much. These are not coverage denials in the usual sense. The insurer agrees the loss is covered. The fight is over which covered category it belongs to, and that fight determines the payout.

This is why "am I covered for cyberattacks" is the wrong question for a bank to ask. The honest answer is almost always yes, and it is almost meaningless, because the coverage that matters is not the top-line limit printed on the policy but the specific sublimit that will actually apply to the specific kind of attack the bank suffers. A policy with a $5 million cyber limit and a $100,000 social-engineering sublimit offers $100,000 of real protection against the single most common way banks lose money to attackers, and the $5 million figure is close to a mirage for that scenario.

Why the buckets overlap in dangerous ways

The deeper reason this happens is that cyber risk was bolted onto an insurance structure designed for a pre-cyber world, and the seams show. Fidelity bonds were built to cover employee theft. Crime policies were built for robbery and forgery. Cyber policies were added later. Each was drafted at a different time with different assumptions, and a modern cyberattack cuts across all of them.

That produces two failure modes, and they pull in opposite directions. Sometimes coverage overlaps, and multiple policies could respond, which sounds good but triggers "other insurance" clauses in which each insurer points at the other and both delay while the bank waits. Sometimes coverage falls through the cracks, where a loss is the kind of thing each policy assumes another one handles, so none pays in full. Either way, the bank discovers the geometry of its coverage only after the loss, when it is too late to fix. The policies were not written to work together, because they were not written together, and the attacker does not care how they were drafted.

The new layer: AI exclusions

If the category problem were static, banks could at least learn the map. It is not static, because insurers are now adding a fresh source of characterization disputes on top: artificial intelligence exclusions. As AI becomes woven into both attacks and banks' own operations, insurers are narrowing policy language around it, with one survey finding 42% of companies now have AI-related exclusions in their cyber policies.

This matters because AI is becoming ambient rather than a discrete, identifiable component. If an attacker uses AI to craft a more convincing impersonation, or if a bank's own AI tool contributes to a loss, an insurer may argue an AI exclusion applies, adding a second characterization fight on top of the sublimit one. Now the question is not only "is this social engineering or computer fraud," but also "was AI involved in a way that voids coverage entirely." The sharper question for a bank renewing coverage in 2026 is no longer whether AI is covered, but which AI, in which policy, and under what conditions, because the exclusions are being written in language vague enough to fight over later. A new category of ambiguity is being layered onto an already ambiguous structure, at exactly the moment attacks are getting more sophisticated.

What actually protects a bank

The practical response, offered as information rather than instruction, is to stop treating the policy's headline limit as the measure of protection and start mapping the sublimits against the attacks the bank is actually likely to suffer.

The most useful exercise is to run the realistic scenarios through the policy in advance. Take the impersonation-wire-transfer attack, the ransomware demand, the vendor-compromise breach, and trace each one through the actual policy language to see which bucket it lands in and what sublimit caps it. Where the likely attacks map to small sublimits, that is where the real exposure sits, regardless of how large the top-line limit is. A bank that discovers its social-engineering sublimit is $100,000 can negotiate to raise it, buy a specific endorsement, or at least know the gap exists and reserve capital against it, rather than discovering it during a claim.

The broader point is that cyber insurance is not a product you buy and forget; it is a set of specific coverage boundaries that have to be matched to a specific threat profile, and the matching has to happen before an incident, because afterward the insurer's incentive is to characterize the loss into the cheapest available box and the policy language often lets it. Reviewing sublimits, clarifying overlapping policies, pinning down the AI language, and doing it with someone who reads these policies for a living is unglamorous work, and it is the difference between a policy that pays and a policy that pays a tenth.

How to read it

The uncomfortable truth underneath all of this is that a cyber insurance policy is not really a promise to cover cyberattacks. It is a collection of narrower promises to cover specific categories of loss up to specific limits, stitched together across policies that were never designed to interlock, with the insurer holding meaningful power to decide which promise applies when a loss could fit several. That is not a scandal and it is not fraud. It is the predictable result of insuring a fluid, cross-cutting risk with instruments built for discrete, well-defined ones.

For a bank, the takeaway is not that cyber insurance is worthless, it plainly is not, but that its value is entirely in the details that the headline coverage obscures. The banks that get paid what they expect are the ones that understood their sublimits, reconciled their overlapping policies, and nailed down the ambiguous language before an incident forced the question. The ones that get a surprise are the ones that read the big number on the front page and assumed it meant what it said. A $600,000 loss paid at $100,000 is not a coverage failure in the legal sense. The coverage did exactly what the policy said it would. The failure was in believing the policy said something more generous than it did, and that is a failure a careful reading, done early, can prevent.

Further reading