Skip to main content
Cyber & Data

Cyber Insurance for Nonprofits: Ransomware & Wire Fraud

Written by , Founder & Principal ProducerPublished · Last updated 11 min read

AINSAssociate in General Insurance, The Institutes · Former commercial insurance underwriter

Nonprofits and small organizations hold data that is genuinely worth stealing: donor names tied to giving history and payment details, client and patient records, employee files with Social Security numbers and direct deposit information, and the email account of whoever approves payments. Attackers are not choosing targets by prestige. They are choosing by opportunity, and a lean organization with a shared password, an unpatched server and no dedicated IT staff is an easier target than a bank.

Cyber insurance is the coverage that responds when that goes wrong. It is also the coverage where the application itself has become part of the product, because carriers now underwrite the security controls you have in place before they will offer terms. This article covers what the coverage does, how the two halves of it differ, the fraud scenario that catches the most organizations, and what underwriters expect to see. It fits into the broader program outlined on our nonprofit insurance hub.

The Exposures That Actually Show Up

Four patterns account for most of what small organizations experience:

  • Ransomware and system encryption. Files and systems are locked, often after the attacker has quietly explored the network for days. Backups are frequently targeted first, specifically so paying looks like the only option. CISA's StopRansomware guidance is the practical baseline for prevention and response.
  • Business email compromise. Someone gets into an email account, usually through a phishing page, and reads quietly. They learn how invoices are approved and who signs off, then insert themselves into the conversation. The FBI's Internet Crime Complaint Center is where these get reported, and speed matters — a wire caught within hours can sometimes be recalled.
  • Data theft and exposure. Donor, client or employee records leave the organization, whether through an intrusion, a misconfigured cloud folder, a lost laptop or a vendor's breach.
  • Vendor and platform compromise. The donor CRM, payroll provider or IT vendor is breached, and your data is in it. The obligation to notify affected people usually still lands on your organization.

Organizations delivering services under confidentiality obligations, including those in mental health and human services, carry an additional layer, because the same event can trigger regulatory obligations on top of the ordinary breach response.

Breach Response Versus Third-Party Liability

Cyber policies do two different jobs, and conflating them is why organizations are surprised by what is and is not paid.

First-party coverage pays your costs. Subject to policy terms, this typically includes:

  • Incident response, forensics and legal counsel who specialize in breach matters
  • Determining who was affected and what notification law requires
  • Notifying affected individuals, plus credit or identity monitoring where offered
  • Restoring corrupted data and rebuilding systems
  • Lost income and extra expense while operations are disrupted
  • Cyber extortion costs, including ransom negotiation — subject to sanctions law, because paying a group on the OFAC list can itself be a violation regardless of the circumstances
  • Crisis communications and public relations support

Third-party coverage pays for claims made against you. Typically this includes privacy liability, network security liability, regulatory defense costs and fines where they are insurable by law, media liability for content-related claims, and assessments arising from payment card obligations if you take card donations.

The first-party side is the part organizations use most. Notification obligations are set by state law and by sector-specific rules where they apply, they attach even when nobody has yet been harmed, and the forensic work needed to determine scope is not something a small organization can perform on its own. Being handed an experienced breach coach in the first hour is frequently the most valuable thing the policy delivers.

Funds Transfer Fraud: the Claim That Falls Between Policies

The most common loss small organizations report is not encryption. It is money sent to a criminal on purpose, because the request looked legitimate. A finance staffer receives an email that appears to come from the executive director approving an urgent wire. A vendor emails updated banking details before a scheduled payment. A payroll direct deposit is quietly redirected.

This is where coverage gets technical, and where reading the policy matters:

  • Social engineering fraud covers losses where an employee was deceived into transferring funds voluntarily. It is very often a sub-limit, well below the policy's main limit, and it may be conditioned on having a verification procedure such as a call-back to a known number.
  • Funds transfer fraud and computer fraud typically address unauthorized transfers made without an employee's involvement.
  • Employee theft is normally a commercial crime matter rather than a cyber one, and organizations that handle cash donations or manage client funds should carry both.

Two organizations can have "cyber insurance" and get very different answers to the same wire fraud loss. Confirm which of these your program includes, at what limit, and what conditions apply. It is one of the specific items worth checking during a yearly insurance audit.

What Underwriters Now Expect

Cyber underwriting changed substantially. Applications used to be short. Now carriers ask detailed control questions, and the answers affect whether coverage is offered at all. Expect to be asked about:

  • Multi-factor authentication, especially on email, remote access, VPN, and administrative accounts. This is the single most commonly required control, and a "no" here can end the conversation.
  • Backups that are tested, versioned, and kept offline, immutable or otherwise segregated from the main network, along with whether you have ever practiced a restore.
  • Endpoint detection and response or a managed detection service, rather than consumer antivirus alone.
  • Patching and end-of-life software, including unsupported operating systems and servers still running because a program depends on them.
  • Email filtering and controls that flag external senders or lookalike domains.
  • Privileged access management, meaning administrator rights are limited and daily work does not happen in an admin account.
  • Security awareness training and simulated phishing for staff and, where relevant, volunteers with system access.
  • A written incident response plan that names who to call, in what order.
  • Remote desktop exposure, which underwriters expect to be closed or protected.
  • Vendor management, including which third parties hold your data.

Answer these truthfully. Applications are increasingly treated as warranties, and describing a control you do not actually have is a fast way to turn a covered claim into a coverage dispute. If you cannot answer yes to multi-factor authentication and tested offline backups, fixing those two items is usually the highest-value work available, insured or not.

Practical Steps Before the Renewal Conversation

You do not need an IT department to make meaningful progress:

  • Turn on multi-factor authentication for email and any system holding donor, client or employee data.
  • Write down a verification rule for payment changes: any request to change bank details or send an urgent wire gets confirmed by phone at a number already on file, never a number in the email.
  • Confirm you have a backup that an attacker with your administrator password could not delete, and test restoring from it.
  • Inventory where sensitive data lives, including spreadsheets on individual laptops and shared drives nobody has cleaned out in years.
  • Limit who can move money and who has administrative access, then review that list.
  • Record who you would call in the first hour of an incident.

Programs that take payments and manage rosters online, from youth development to food and nutrition organizations, tend to accumulate more of this data than leadership expects, precisely because collecting it is routine.

What notification law actually requires here

Breach notification is a state-law obligation, it attaches to the data rather than to your budget, and it is triggered by where the affected person lives — so a Kansas City organization with donors on both sides of the line is routinely working under two statutes at once.

Missouri (RSMo 407.1500) requires notice to any affected Missouri resident. "Personal information" means a name combined with an unencrypted, unredacted data element — Social Security number, government ID, a financial account or card number together with its security code, medical or health-insurance information, or a unique electronic identifier with its access credentials. Two details organizations miss:

  • Notify more than 1,000 consumers at once and you must also notify the Attorney General and all consumer reporting agencies.
  • If you conclude a breach poses no reasonable likelihood of harm and therefore do not notify, you must document that determination and keep it for five years. A decision not to notify is itself a record you have to be able to produce.

Kansas (K.S.A. 50-7a02) is triggered once an investigation determines that misuse of the information has occurred or is reasonably likely to occur, and requires notice as soon as possible and without unreasonable delay. The same 1,000-consumer threshold applies for notifying the nationwide consumer reporting agencies.

Sector rules sit on top of both — organizations that are HIPAA-covered entities or business associates work under the federal breach notification rule as well. The FTC's Data Breach Response guide is a plain-English walkthrough of the sequence.

The practical point: the forensic question "whose data, in which states?" is what determines your legal obligations, and answering it is expensive. That determination is a first-party cyber cost, which is why the coverage matters even to organizations that consider themselves too small to be targets.

Frequently asked questions

We are a small nonprofit with no IT staff. Are we really a target? Targeting is automated and opportunistic rather than selective. Attackers scan for exposed remote access, unpatched systems and accounts without multi-factor authentication, then act on whatever answers. A lean organization holding donor records, payroll files and a shared password is an easier target than a bank, not a less interesting one.

Does our general liability policy cover a data breach? Generally no. Modern general liability forms carry exclusions for electronic data and for access-or-disclosure of confidential information. Assume the answer is no unless a cyber endorsement says otherwise.

A staff member wired money to a fake vendor. Is that covered? That depends on wording rather than on the label on the policy. Voluntary transfers induced by deception fall under social engineering fraud, which is frequently a sub-limit well below the policy limit and may require a call-back verification procedure to have been in place. Unauthorized transfers with no employee involvement fall under funds transfer or computer fraud. Check which your program has, and at what limit.

Do we have to notify if the breach was at our vendor rather than at us? Usually yes. Notification duties generally follow the organization that owns the data relationship, not the one whose systems failed. Your donor CRM or payroll provider being breached is still your notification obligation, which is why vendor contracts and the vendor's own insurance are worth reviewing.

Can a claim be denied over what we put on the application? Yes, and it is the fastest-growing dispute in cyber. Applications now ask detailed control questions and are increasingly treated as warranties. Saying multi-factor authentication is enabled everywhere when it covers only some accounts can void coverage for the exact claim it was meant to pay.

What two changes are worth making first? Multi-factor authentication on email and on anything holding donor, client or employee data; and a backup that an attacker holding your administrator password could not delete, which you have actually tested restoring from. Those two answer most of the underwriting questions and prevent most of the losses.

Is a ransom payment covered? Often, subject to the extortion sub-limit and to sanctions law. Payments to sanctioned entities are prohibited regardless of coverage, which is one reason the policy's breach counsel and negotiation panel matter more than the dollar limit.

Getting the Coverage Right

Cyber is not a standalone purchase. It coordinates with crime coverage for theft of funds, with professional liability where a service failure is alleged, and with D&O where the board's oversight of data security is questioned. Getting the boundaries right is exactly the sort of gap the nonprofit insurance checklist is designed to surface.

If you want a straight read on your current cyber liability coverage, including sub-limits, funds transfer wording and what your application actually warranted, request a review or contact our team.

Ready to Protect Your Organization?

Get a personalized insurance quote based on your specific risks and needs.