Funds-transfer / wire fraud
In one sentence
Being tricked into sending a payment to an attacker's account, usually via a convincing fake email.
Funds-transfer fraud is the theft that follows a successful BEC: a bookkeeper pays a fraudulent 'updated' invoice or a fake urgent request. The money moves instantly and is rarely recovered, which is why a verification step matters so much.
Why it's on your cyber insurance application
Some carriers require a documented payment-verification procedure for full funds-transfer-fraud coverage.
How the Readiness Check scores it
The free Check asks the same question a carrier will. Here it is, why it's asked, and the fix if today's honest answer is no. The full application question list has the rest.
Funds-transfer controls
Before changing bank details or sending an unusual payment, do you verify by phone using a known number?
Why carriers ask: Funds-transfer fraud is the single most common small-business loss type. A documented call-back verification procedure is cheap and prevents it, and some carriers require it for full FTF coverage.
If the answer is no: Institute the call-back rule today and tell every person who can move money. It's free and it prevents the most frequent claim type outright.
The written evidence carriers accept
A “yes” on the application needs a document behind it. In the Readiness Pack, those documents are:
Guides that cover this
Cyber insurance for construction contractors: what carriers require in 2026
Contractors face the same seven cyber insurance requirements as everyone else, plus sharper questions about wire fraud, because construction's payment flows make it a top target for funds-transfer fraud. Here's the contractor-specific readiness list.
The 7 controls every cyber insurance application asks about in 2026
Cyber insurance applications in 2026 require MFA, EDR, tested backups, patching, email security, security awareness training, and a written incident response plan. Here's each requirement, why carriers ask, and what evidence you need before you sign the attestation.
Why cyber insurance claims get denied, and how attestations really work
Cyber claims get denied for inaccurate application answers, failure to maintain attested controls, late notice, and exclusions. Here's how the attestation works, what claim investigations actually check, and how to make sure the policy you're paying for pays out.
Related terms
Would you pass this question today?
The free Readiness Check scores you across the ten control domains carriers probe, in five minutes, no email required for the score.