Skip to main content
CharterSelect — Charter School Insurance
Governance & Legal Shield

Crime vs. Cyber Coverage for Charter Schools

The $80,000 Email That Neither Your Cyber Policy Nor Your Crime Policy Will Pay For. Why the most common way money walks out of a school falls into the exact gap between your two financial-crime policies, and the one endorsement that closes it.

A vendor you’ve paid for years sends an email. New banking details, please update the file. Your business manager updates it and sends the next payment, same as always.

The vendor never sent that email. The money is gone the same afternoon.

You file a claim on your cyber policy. Denied. You file on your crime policy. Denied. Both, in writing, within a week of each other.

Two policies. One loss. Zero coverage. Here’s how that happens, and how it doesn’t have to.

These two policies do completely different jobs

People say “we have cyber and crime, we’re covered” the way they say “we have insurance.” It’s a category, not an answer. Crime and cyber protect against different things, and the most common loss a school actually suffers lives in the space between them.

A crime policy protects your assets from theft. Employee dishonesty, an embezzling bookkeeper, stolen money or securities, forgery, robbery, certain computer fraud where a thief breaks in and moves your funds. The core idea is that someone took something from you.

A cyber policy protects against the consequences of a network or data event. Ransomware, a breach of student or staff records, the cost to notify families, regulatory exposure, the business interruption when your systems are down. The core idea is that your data or your network got hit.

Read those two descriptions again and look for the wire fraud from the opening. It isn’t in either one.

The seam where the money disappears

The technical name for the opening scenario is social engineering fraud. Sometimes it shows up as “deception fraud” or “fraudulent instruction.” A human being at your school was tricked into voluntarily sending money to a criminal.

Now watch both carriers walk away from it.

The cyber carrier looks at it and says: nobody breached your network. No system was hacked. Your own employee read an email and chose to send a payment. That’s not a cyber event, that’s a payment your staff authorized.

The crime carrier looks at the same loss and says: nobody broke in and took your money. Your employee had full authority to send wires and used it. You voluntarily parted with the funds. That isn’t theft under this policy.

Both denials are, frustratingly, defensible under standard policy language. The loss is real, the money is gone, and each policy points at the other one. This is not a rare edge case. Tricking an employee into a wire is now one of the most common and most expensive financial losses any organization suffers, schools included.

Why schools are easy targets for this

Criminals running these schemes do homework, and a charter school hands them most of it for free.

Your budget is public. Your board meeting minutes are public. Your vendors, your leadership names, your fiscal calendar, often all findable in an afternoon. The attacker knows who your CFO is, knows you pay a facilities vendor, and knows roughly when. They send a clean, well-timed email from a lookalike address.

On the other side of that email is a back office run lean. Accounts payable is one or two people, both of them stretched, both of them trained to be responsive and helpful. A request to update vendor banking details doesn’t look like an attack. It looks like a Tuesday.

That combination, public information plus a small trusting back office, is exactly the profile these schemes hunt for.

The fix is one endorsement and one habit

This gap is well known in the industry, which is the uncomfortable part. It gets closed with a specific add-on, and a generalist broker who never raised it with you simply didn’t do the work.

Add the social engineering fraud endorsement. It goes by a few names, fraudulent instruction or deception fraud coverage among them, and it’s usually added onto the crime policy. It is the piece that actually responds when an employee is tricked into sending money. Without it, you are exposed no matter how much cyber and crime coverage you carry.

Check the sublimit, because it’s almost always smaller than you think. Social engineering coverage is frequently capped well below your main crime limit, sometimes at a small fraction of it. A policy that technically includes it but caps it at $25,000 against an $80,000 loss is a partial answer dressed up as a full one. The limit needs to match the size of a payment your school could realistically send.

Put a verification habit in place. Any change to vendor banking details gets confirmed by a phone call to a known number, never the number in the email. Some carriers require this kind of control before they’ll pay. It also stops most of these losses before they start.

That’s the whole fix. An endorsement, an adequate sublimit, and a callback rule.

What a real review would have caught

A broker doing the job hands you more than a cyber quote and a crime quote stapled together. They map the seam between them out loud. They tell you that the single most likely financial crime against your school is the one neither base policy covers, they confirm the social engineering endorsement is on the crime policy, and they pressure-test the sublimit against the actual size of your wires.

A generalist who treats your school as a small account quotes the two policies, says “you’re covered for crime and cyber,” and moves on. Technically true. Practically, they left the most common door wide open.

Before your next payment goes out

You don’t need an audit to find out where you stand on this. You need to know one thing.

So here’s the question worth asking:

If someone emailed your business office tomorrow posing as a known vendor and asked to update banking details, and that payment went out before anyone caught it, which policy pays, and what’s the limit on it? If the answer is “I assume one of them does,” that assumption is exactly what these schemes are built to exploit.

← Back to Governance & Legal Shield

Related reading

Not sure how your coverage compares?

A complimentary benchmark review shows how your charter school's coverage and pricing stack up against similar schools — no obligation.

Get a Free Review