The money leaves. Nothing was hacked.
Crime coverage responds to theft of money and securities — by employees, by outsiders, and by people who simply asked convincingly.
What Crime actually does
Commercial crime covers direct financial loss from theft. Employee dishonesty is the classic exposure, but for technology companies the dominant loss is funds transfer fraud and social engineering: a convincing email, an urgent request, a changed set of wire instructions, and money that is functionally unrecoverable within hours.
There is real overlap with cyber policies, which typically offer a social engineering sublimit. The difference is size and structure. A cyber sublimit might be $100k or $250k; a crime policy can carry a full limit. Companies that hold client funds, run payroll for others, or move meaningful money should carry both and know which responds first.
If you handle customer funds — payments, payroll, escrow, treasury — customers and partners increasingly require crime coverage by contract. It is also standard in most financial-institution and fintech vendor requirements.
Buy it when
- A customer or bank partner requires crime coverage
- You started holding client funds
- You hired your first finance or AP staff
- You had a near-miss on a fraudulent payment request
What it covers
Grants vary by carrier and form. These are the components we look for when we place it.
Employee theft
Theft of money, securities, or property by employees, including collusion.
Funds transfer fraud
Fraudulent instructions to your bank to transfer funds from your account.
Social engineering fraud
Loss from transfers you made voluntarily because you were deceived — the most common technology company crime loss.
Forgery and alteration
Loss from forged checks, drafts, and written instruments.
Client coverage
Theft from your customers by your employees — often contractually required for companies handling client money.
What it doesn't cover
We put this in front of you at binding — the only moment you can still do something about it.
- Indirect and consequential loss, including lost interest and reputational harm
- Loss discovered after the policy period without an extended discovery period
- Theft by owners and partners, in most forms
- Trade secret and intellectual property theft
- Loss of cryptocurrency, unless specifically endorsed
Three ways this policy earns its premium
Composite scenarios drawn from how these losses typically develop. Illustrative, not case files.
A spoofed CEO request moves $220,000
An attacker studies your team on LinkedIn, times the request to a travel week, and gets a wire approved. Crime pays where the cyber sublimit would have run out.
A controller diverts vendor payments over 14 months
Fictitious vendors, small amounts, real invoices. Discovered at audit. Employee theft coverage responds.
What limit is normal
Ranges we commonly see for technology companies. Your contracts and exposure decide the answer — this is where the conversation starts, not where it ends.
| Stage | Typical | |
|---|---|---|
| Early stage | $250k – $500k | Often satisfied by the social engineering sublimit on cyber instead. |
| Holding client funds | $1M – $5M | Frequently specified by contract with bank or enterprise partners. |
| Payments / fintech | $5M+ | Structured alongside a fidelity bond where a partner requires one. |
Companies that need this
- Companies that hold, move, or disburse customer funds
- Fintech, payments, payroll, and treasury platforms
- Companies with a finance team that can initiate wires
- Companies with contractual crime insurance requirements
What we need to quote
- Payment authorization controls and approval thresholds
- Dual authorization and callback verification procedures
- Whether you hold or disburse client funds, and average balances
- Bank account structure and reconciliation frequency
- Prior crime and fraud losses
Most of this is collected once in the Atlas submission and reused across the markets we approach.
Start a submissionSituations that put this policy on your desk
Crime, answered
Usually as a sublimit well below the policy limit. If a single fraudulent wire could exceed it, a crime policy is the fix.
Yes, and more importantly they are frequently a condition of coverage. Callback verification on any change to payment instructions is the single highest-value control here.
Find out what crime costs for your company.
Tell us about the business once. A broker reviews it the same business day and comes back with a plan and a timeline.