Document customer records, call recordings, credentials, deposits and who can change supplier or remittance details. FTC guidance recommends assessing vendor risk and reviewing cyber-policy questions such as response and third-party claims; it does not prove payment fraud is covered.[3][4]
Separate unauthorized data access from a fraudulent payment instruction. Ask the insurer which forms address each scenario and what verification steps, exclusions and sublimits apply; do not assume commercial auto, general liability or cyber automatically responds.[2][3]