Here's a fact pattern I see more than any other in real estate cyber claims, and it's the one most cyber policies handle worst.
Your firm is holding money that isn't yours. An earnest deposit. A tenant's security deposit. A month of rent rolls. Closing funds waiting on a settlement date. A fraudster sends wire instructions that look right — the client's name, the property address, the timing all check out — and someone on your team sends the client's money to a bad actor's account. Twenty minutes later it's been forwarded through three more banks and it's gone.
Now ask the question that decides everything: who files the claim, and which coverage answers it?
Most people — including a lot of people who sell insurance — get this wrong, because the claim doesn't route the way it looks like it should. Understanding why is the difference between a firm that gets made whole and a firm that learns what “no coverage” means with a client's money on the line.
It looks like a third-party claim. It resolves like a first-party one.
When the stolen money belonged to your client, the demand comes at you. The client wants their funds back, and they're entitled to want that — you were holding their money and it went out your door. In form, that's a third-party situation: someone outside your firm has a grievance against your firm.
But on a properly built cyber policy, that claim doesn't get handled by liability coverage at all. It gets handled by the Cyber Crime coverage — which is first-party coverage.
On the Arch NetSafe® 2.0 program we place for real estate firms, the Cyber Crime endorsement defines a covered loss as direct financial loss sustained by the insured entity, “or by a customer of the Insured whose funds are under the care, custody and control of any Insured, including funds held in any Insured Account.” That last part — care, custody and control — is the mechanism. It means the policy treats your client's money in your account the same way it treats your money in your account. When it's stolen, the policy reimburses the loss directly. You make the client whole, the client's demand is satisfied, and the whole event resolves without a lawsuit ever maturing.
A first-party answer to a third-party problem. That's the elegance of the provision — and it's why the claim carries no duty to defend. Not because something went wrong, but because there's nothing to defend. Crime coverage is fund reimbursement, not litigation coverage. Nobody hires defense counsel to reimburse a bank balance.
This is also why the coverage matters so much in real estate specifically. Most cyber policies sold in the general market stop at “direct financial loss sustained by the insured” — your money, full stop. A brokerage or title firm that holds client funds can buy one of those policies, see “Social Engineering: Covered” on the declarations page, and still have nothing that responds when the stolen money was a client's. The words care, custody and control are the whole ballgame, and they're missing from most of the policies we review.
The condition attached to that coverage — and why it exists
The Arch Cyber Crime endorsement carries one condition every insured needs to know cold: the callback requirement. Coverage does not apply to fraudulent instructions that were not authenticated through a method other than the original means of the request before the money moved.
In plain English: if the wire instructions came by email, someone at your firm has to verify them through a different channel — a phone call to a number you already had on file, an in-person confirmation, a separate secure portal — before sending. Reply to the email asking “is this really you?” and the fraudster who controls the mailbox will happily say yes. That doesn't count, and it shouldn't.
This isn't the carrier being difficult. It's the same control the FBI has recommended for years, because it defeats nearly every business email compromise scheme at the cost of a two-minute phone call. The condition exists because the control works.
Now run the fact pattern with the callback skipped
Here's where the routing we walked through above stops being academic.
The natural home for the client-funds claim is the Cyber Crime endorsement. That is precisely the coverage the callback condition lives in. Skip the verification, and the fund reimbursement — the clean, no-litigation, first-party resolution — is denied. And because crime coverage never carried a duty to defend in the first place, there's no defense obligation sitting behind the denial. The coverage that would have answered simply doesn't, and nothing about it obligates the carrier to do anything else.
Your client is still out their money. They're still looking at you. The policy's front door just closed.
Whether any other door opens depends entirely on how the fraudulent instruction arose — and this is the distinction that decides real claims.
If your systems were actually breached — the fraudster was inside your email, read the transaction file, and built the fraudulent instructions from your client's private information — then the client's ensuing claim against your firm has a second path: the Network Security & Privacy Liability coverage part. A breach of your systems exposed the client's information, that exposure caused her loss, and her claim against you arises from a network security failure. That coverage part is true liability insurance: it carries a duty to defend, and the callback condition does not appear in it. On the Arch program, a separate endorsement also removes the standard exclusion for theft of money from the definition of covered loss — which matters, because the damages in this lawsuit are stolen money. Defense owed, and potentially the judgment too.
If your systems were never touched — pure pretexting, a look-alike domain, spoofed instructions built from publicly available deal information, no compromise of your network anywhere in the chain — then there is no network security event, no privacy violation, and no trigger for the liability coverage. In that fact pattern, the Cyber Crime endorsement wasn't the best coverage for the loss. It was the only coverage. Skip the callback there and the cyber policy produces a total denial with no defense obligation anywhere in it.
At that point the claim migrates to your E&O policy — where fund-handling, escrow, and trust account exclusions are common. Some E&O policies respond to a negligent-supervision theory. Many don't. That's a conversation to have with your E&O advisor before the wire goes out, not after.
What the callback is actually protecting
So the hierarchy for a stolen-client-funds claim looks like this. The Cyber Crime endorsement's care-custody-and-control coverage is the front door: first-party mechanics, no lawsuit required, conditioned on the callback. The Network Security & Privacy Liability part is the fallback: liability mechanics, defense owed, not callback-conditioned — but only available when a genuine breach of your systems sits in the causal chain. And if neither fits, you're negotiating with an E&O carrier about exclusions, or writing the check yourself.
Seen that way, the callback isn't a compliance checkbox protecting a sublimit. In the no-breach fact pattern, it's protecting the only insurance response that exists.
Which leads to the operational advice we give every firm we insure, regardless of what their policy requires: put callback verification in your wire procedure for every transfer, every time, using a phone number from your existing file — never one supplied in the instructions themselves. Train everyone who can touch a wire. Document the verification. It's the rare control that simultaneously prevents the loss, preserves the coverage, and costs nothing.
The question to ask about your own policy
If your firm holds client money in any form, pull your cyber policy and look for two things. First, does your Social Engineering or Cyber Crime coverage extend to a customer's funds in your care, custody and control — in those words or their equivalent — or does it stop at your own? Second, does your policy have a dedicated Network Security & Privacy Liability coverage part that would defend you if a client sued after a breach? In our policy reviews of cyber forms sold to real estate firms, it's common to find one of the two missing. It's not rare to find both missing — sometimes with an exclusion in their place that names “customer account balances” specifically.
If you're not sure what your policy says, send it to us — declarations, full form, and every endorsement, because the answer is usually in the endorsements. We'll walk you through it, no pressure, no obligation.
Eric Mauriello is a Partner at PBI Group and leads the firm's cyber insurance coverage practice for residential real estate professionals. Reach him at 973-349-2194.
This article is educational and summarizes policy mechanics in general terms. It is not legal advice, and it does not modify any policy. Coverage outcomes depend on the specific policy language, endorsements, and facts of each claim — make all final coverage determinations from your actual policy documents, and involve your legal counsel in claim decisions.