Business Email Compromise Canada

Business Email Compromise Canada: Is Your Company Covered?

Business email compromise (BEC) can create significant financial losses for Canadian businesses. But does cyber insurance cover it? The honest answer is: possibly, but not automatically.

A BEC loss may involve cyber insurance, commercial crime insurance, a social engineering endorsement, funds transfer fraud coverage, or multiple policy sections. Whether coverage responds depends on how the fraud occurred and the specific wording, limits, conditions, exclusions, and endorsements in your policies.

Key Takeaways

  • Owning a cyber insurance policy does not automatically mean every fraudulent payment is covered.
  • Social engineering coverage may exist within a cyber policy, crime policy, or standalone endorsement.
  • A policy’s overall limit may not be the amount available for BEC losses.
  • Payments voluntarily authorized by employees may be treated differently than transfers initiated directly by criminals.
  • Payment verification controls can reduce risk and may affect underwriting or coverage eligibility.
  • Immediate reporting to your bank, insurance broker, IT team, law enforcement, and regulators is critical.
  • A policy-by-policy review is the safest way to determine whether your organization is adequately protected.

If your company sends wire transfers, pays invoices electronically, updates vendor banking information, or administers payroll electronically, request a confidential, no-obligation insurance review from ALIGNED.

What Is Business Email Compromise?

Business email compromise is a targeted fraud in which a criminal impersonates or gains control of a trusted email account to persuade a business or individual to transfer money or disclose sensitive information.

Common BEC scams include:

  • Executive impersonation
  • Vendor payment redirection
  • Payroll diversion
  • Gift card fraud
  • Requests for employee or customer information

BEC attacks often begin with:

  • A compromised employee or vendor mailbox
  • A look-alike domain name or email address
  • A fake executive payment request
  • Revised banking instructions on an otherwise legitimate invoice
  • A payroll direct deposit change request
  • Requests for tax, customer, employee, or banking information
  • Pressure to act quickly, secretly, or outside normal procedures

Unlike traditional cyberattacks, many BEC incidents involve no malware and no suspicious attachment. Messages may arrive within legitimate email conversations, making BEC both a cybersecurity risk and a financial controls risk.

Does Cyber Insurance Cover Business Email Compromise?

Cyber insurance may respond to some aspects of a BEC event, but coverage structures vary significantly.

Depending on policy wording, covered costs may include:

  • Incident response and forensic investigations
  • Legal and privacy counsel
  • Notification and crisis management expenses
  • Data restoration and account remediation
  • Business interruption following a covered cyber event
  • Social engineering, cybercrime, or fraudulent transfer losses
  • Third-party claims arising from compromised information or systems

The real question is not: “Do we have cyber insurance?”

The real question is: “Which specific policy provision addresses this exact loss, and what conditions apply?”

ALIGNED’s cyber insurance specialists can compare realistic loss scenarios against the actual policy wording being proposed or renewed.

Could Crime Insurance Respond Instead?

Commercial crime insurance is designed to address risks such as:

  • Employee dishonesty
  • Theft of money or securities
  • Computer fraud
  • Funds transfer fraud
  • Other financial-crime exposures

However, social engineering fraud creates a unique challenge because an employee may voluntarily authorize a payment after being deceived.

This distinction often determines whether coverage applies and which policy section responds.

When reviewing business email compromise coverage, evaluate:

  • Whether social engineering fraud is expressly covered
  • Who may be impersonated
  • Whether vendors, customers, executives, and employees are included
  • Whether email, phone calls, text messages, or other communications qualify
  • Whether payment verification procedures are mandatory
  • Whether the loss must be considered “direct”
  • Whether voluntary-parting exclusions apply
  • Whether client funds, inventory, or third-party losses are covered
  • Available limits, sublimits, deductibles, retentions, and aggregates

Cyber Insurance vs. Crime Insurance vs. Social Engineering Coverage

Cyber Insurance

Typical Scenario: Mailbox compromise, privacy breach, or system intrusion

Potential Gap: Fraudulent transfer losses may have separate limits or exclusions.

Question to Ask: Is cybercrime or social engineering expressly included?

Crime Insurance

Typical Scenario: Theft, employee dishonesty, computer fraud

Potential Gap: Employee-authorized payments may be treated differently.

Question to Ask: Does the policy address deception of an authorized employee?

Social Engineering Endorsement

Typical Scenario: Executive, vendor, customer, or employee impersonation

Potential Gap: Narrow definitions, verification requirements, or low sublimits.

Question to Ask: Who can be impersonated and what property is covered?

Funds Transfer Fraud Coverage

Typical Scenario: Unauthorized instructions sent directly to a financial institution

Potential Gap: May not apply when an employee authorizes the payment.

Question to Ask: Who actually initiated the transfer instructions?

Third-Party Liability Coverage

Typical Scenario: Customer or vendor alleges damages following a compromise

Potential Gap: Third-party liability and first-party financial loss may be handled separately.

Question to Ask: Does the policy respond to both internal losses and third-party claims?

A Five-Step Business Email Compromise Coverage Review

ALIGNED applies its Audit. Optimize. Execute. methodology rather than assuming policy titles equal protection.

1. Audit the Exposure

Document:

  • Payment processes
  • Wire transfers
  • Vendor changes
  • Payroll updates
  • Client funds
  • Payment authority levels
  • Transaction sizes
  • Sensitive information exposure

2. Reconstruct Realistic Scenarios

Test scenarios such as:

  • Executive impersonation
  • Supplier payment changes
  • Payroll diversion
  • Stolen credentials
  • Fraudulent invoices
  • Customer payment redirection

3. Match Each Scenario to Policy Wording

Review:

  • Cyber insurance
  • Crime insurance
  • Social engineering provisions
  • Computer fraud coverage
  • Funds transfer fraud coverage
  • Property and liability policies

4. Optimize Limits and Controls

Compare:

  • Maximum plausible loss
  • Applicable sublimits
  • Deductibles
  • Verification requirements
  • Approval workflows

5. Execute and Document

Implement:

  • Coverage improvements
  • Staff training
  • Payment controls
  • Incident response planning
  • Annual reviews

Controls That Can Reduce BEC Risk

Strong technology controls are important, but financial controls are equally critical.

Best practices include:

  • Independently verify banking-detail changes.
  • Use trusted phone numbers already on file.
  • Require dual approval for designated transaction thresholds.
  • Separate vendor-data management from payment approval.
  • Eliminate executive “emergency” exceptions.
  • Monitor mailbox forwarding rules and unusual sign-ins.
  • Require MFA for email, finance, HR, and administrative accounts.
  • Train finance, payroll, HR, procurement, and leadership teams.
  • Reward employees for questioning suspicious requests.
  • Conduct regular tabletop exercises.

What Should Canadian Businesses Do After a BEC Incident?

Immediately:

  1. Contact your financial institution.
  2. Request payment recall or recovery assistance.
  3. Notify your insurance broker.
  4. Alert your IT or cybersecurity response team.
  5. Preserve evidence and secure affected accounts.
  6. Report the incident to law enforcement.
  7. Report to the Canadian Anti-Fraud Centre where appropriate.

If personal information is involved, additional privacy obligations under PIPEDA or provincial legislation may apply.

Frequently Asked Questions

Does cyber insurance automatically cover business email compromise?

No. Coverage depends on policy wording, definitions, exclusions, endorsements, limits, conditions, and the facts of the loss.

Is social engineering fraud the same as funds transfer fraud?

Not necessarily. Social engineering usually involves a deceived employee authorizing a payment, while funds transfer fraud often focuses on unauthorized instructions sent directly to a financial institution.

What is a social engineering sublimit?

A social engineering sublimit is the maximum amount available for covered social engineering losses and is often much lower than the overall policy limit.

Can vendor impersonation losses be covered?

Potentially. Coverage depends on the policy wording and whether the circumstances satisfy all applicable conditions and definitions.

Can MFA prevent all BEC losses?

No. MFA helps reduce account takeover risk but does not replace payment verification procedures, dual approval controls, monitoring, training, or incident response planning.

Why use a broker when evaluating BEC coverage?

An experienced broker can compare realistic loss scenarios across multiple policies, identify coverage gaps, review sublimits and conditions, and negotiate appropriate coverage enhancements.

Protect the Business, Leadership Team, and Employees

BEC can create substantial financial losses, disrupt supplier relationships, expose sensitive information, and divert management resources.

Insurance planning should extend beyond a standalone cyber policy.

ALIGNED provides integrated advice across:

A coordinated review helps ensure that cyber, crime, leadership continuity, succession planning, and employee protection strategies work together.

Review Your Business Email Compromise Exposure Before Money Moves

A fraudulent email becomes a financial loss when trust replaces verification.

The solution is not fear. It is a disciplined review of:

  • Payment workflows
  • Internal controls
  • Cybersecurity measures
  • Insurance wording
  • Incident response procedures

Start your cyber and crime insurance review with ALIGNED.

There is no obligation to purchase coverage. Share your current policies and basic risk information, and a licensed ALIGNED broker can help identify practical next steps.

What Happens Next?

  1. ALIGNED reviews your operations, payment exposure, existing coverage, and renewal timing.
  2. You receive recommendations based on your actual risk profile.
  3. Coverage options, limitations, and trade-offs are clearly explained.
  4. Information is handled through ALIGNED’s advisory and quoting process.
  5. The review is practical, commercially focused, and low pressure.

Disclaimer: This article is for general information purposes only and does not constitute legal, privacy, financial, underwriting, or claims advice. Coverage varies by insurer, policy wording, endorsements, limits, exclusions, jurisdiction, risk profile, and the facts of each claim. Speak with a licensed ALIGNED broker regarding your specific circumstances.

Buy Insurance Online Now!

We offer online insurance products for multiple industries, just fill out a simple application form and get a quote today!