These case study examples show how CPR’s new coverage can respond in practice, helping organisations navigate the financial, operational and personal impacts of cyber events.
Executive protection
Cyber incidents can have a direct personal impact on the people responsible for leading a business. Included as part of CPR, executive cyber protection helps senior leaders manage the financial, practical and personal consequences of a cyber event.
-
A phishing email compromises a CEO’s digital identity
The incident: The CEO of a construction company clicks on a malicious link sent to their personal email address. Malware is downloaded onto their personal laptop, exposing sensitive information and allowing cyber criminals to misuse their digital identity.
The impact: What begins as a phishing attack quickly becomes a personal cyber incident, leaving the CEO facing financial and practical consequences.
How the policy responds: The policy provides access to incident response and forensic support to remove the malware and secure the CEO’s personal computer. It can also cover document replacement services, dark web monitoring and credit monitoring, helping the CEO identify and respond to any misuse of their personal information.
-
A ransomware attack locks a restaurant owner out of their personal computer
The incident: A restaurant owner visits a malicious website from their personal computer. Malware is downloaded onto the device, encrypting files and applications before presenting a ransom demand. Without a viable backup, the owner cannot access important data stored on the device.
The impact: The owner risks permanently losing access to valuable data and personal applications, with limited options available for recovery.
How the policy responds: The policy can cover the ransom payment and provides access to specialist support to remove any remaining malicious software. This enables the owner to regain access to their data and restore the device to a secure state.
-
A contractor invoice scam targets a CFO at home
The incident: A CFO receives an invoice for building work completed at home, followed by an email with updated bank details. They pay from their personal account, unaware that the contractor’s email has been compromised and the funds are being diverted to a cyber criminal.
The impact: The original payment is lost, but the legitimate contractor still needs to be paid, leaving the CFO facing the prospect of settling the invoice twice.
How the policy responds: The policy can respond to the covered personal financial loss and reimburses the misdirected funds. This allows the CFO to pay the legitimate contractor without bearing the additional cost personally.
-
Cyber attack stress takes its toll on a company founder
The incident: An engineering firm suffers a major ransomware attack involving system encryption and threats to publish sensitive commercial information. As the incident escalates, the founder and CEO faces increasing pressure over the potential financial and reputational consequences.
The impact: The strain of managing the incident begins to affect the CEO’s wellbeing during an already challenging period for the business.
How the policy responds: The policy can provide access to psychological support from a licensed mental health professional following the cyber incident. This helps the CEO manage the psychological impact of the cyber event while continuing to lead the business through its recovery.
-
A cyber threat forces a school principal to relocate
The incident: Following a cyber attack, a school experiences the theft of staff and student data. During the incident, the principal’s home address is exposed and cyber criminals issue a credible threat of physical violence against the principal and their family.
The impact: Due to concerns for their safety, the principal and their family must leave their home while the threat is investigated and addressed.
How the policy responds: The policy can cover the cost of temporary relocation, including accommodation and transport expenses. This enables the principal and their family to relocate safely while the incident is resolved, reducing its immediate personal impact.
Affirmative AI
CPR explicitly addresses a range of cyber events involving artificial intelligence, giving SMEs clearer protection as AI becomes part of everyday business operations.
-
Deepfake CEO impersonation leads to payment fraud
The incident: A finance employee at a professional services firm receives an email from the CEO requesting an urgent video call. During the call, the employee is instructed to make a same-day payment to a contractor. The CEO’s appearance and voice seem genuine, but both have been replicated using deepfake technology created from publicly available material.
The impact: The employee follows the instructions and sends the payment to a cyber criminal. By the time the fraud is discovered, the funds cannot be recovered.
How the policy responds: CPR explicitly affirms cover for social engineering attacks involving AI, including deepfakes and voice cloning. The cyber crime cover can respond to the misdirected payment, helping reduce the financial impact on the insured. -
AI-generated fake website targets a retailer’s customers
The incident: Cyber criminals create a fraudulent version of a cosmetics retailer’s website using AI-generated content and branding. The fake site closely resembles the genuine website, and customers place orders and make payments believing they are buying from the retailer.
The impact: The retailer faces customer complaints, reputational damage and the costs associated with removing the fraudulent site and reimbursing affected customers.
How the policy responds: CPR can cover the cost of removing AI-generated impersonations under its corporate identity theft cover. Where the policy terms are met, customer payment fraud cover can also respond to affected customers’ losses, helping the retailer manage the incident and protect its brand. -
AI agent removes critical business system
The incident: An accountancy firm uses an AI agent to manage parts of its IT environment. The AI hallucinates that a critical file server has been decommissioned and is no longer required. Relying on this incorrect conclusion, the AI removes the server from the environment, which results in unexpected downtime to the firm’s computer systems and which leaves employees unable to access client files, emails and business applications.
The impact: Business operations stop, client work is delayed and the firm loses income while the system is restored.
How the policy responds: CPR treats this type of AI error as a system failure. The policy can respond to covered restoration costs and business interruption losses, helping the insured restore the system and recover lost income.
-
Stolen credentials are used to run up AI platform charges
The incident: After an employee falls victim to a phishing attack and unknowingly provides their login credentials, a cyber criminal uses those credentials to gain access to a professional services firm’s AI platform. The cyber criminal then consumes the platform’s processing capacity and AI resources to generate outputs and support further malicious activity, a practice known as LLMjacking.
The impact: The unauthorised activity generates substantial usage charges that are billed to the firm before the compromise is identified.
How the policy responds: CPR includes affirmative cover for losses arising from LLMjacking through its unauthorised use of computer resources cover. This enables the insured to recover covered AI usage charges and reduce the financial impact of the attack.
-
Malware disrupts an AI-powered stock management system
The incident: A food retailer uses an AI-powered system to monitor inventory and automate replenishment. A malware attack compromises the retailer’s systems and corrupts the data used by the AI platform.
The impact: Stock management and ordering are disrupted. The retailer must remove the malware, restore its data and reconfigure the AI tool before normal operations can resume.
How the policy responds: CPR expressly includes AI systems within the definition of computer systems. The policy can therefore respond to covered costs incurred to remove the malware and restore the affected AI technology to its previous functionality.
-
AI prompt error deletes production database
The incident: The manufacturer’s computer systems suffer unexpected downtime, which prevents production instructions from being set to the factory floor. Operations are disrupted and the manufacturer loses revenue while the database is restored.
The impact: Production instructions can no longer be sent to the factory floor. Operations are disrupted and the manufacturer loses revenue while the database is restored.
How the policy responds: CPR extends the operator error trigger within system business interruption cover to unintended human errors involving AI systems. The policy can respond to covered restoration costs and lost income resulting from the outage.
-
An AI-driven data disclosure leads to legal action
The incident: A healthcare provider uploads patient information to an AI programme used to support diagnosis and analysis. An unrelated third party later queries the same system and is inadvertently shown information derived from the healthcare provider’s data.
The impact: Sensitive patient information is exposed. The healthcare provider must notify affected individuals and faces legal action following the privacy breach.
How the policy responds: CPR includes accidental disclosures arising from the use of AI systems within the definition of privacy breach. The policy can respond to covered breach notification costs and defence costs or damages arising from the resulting claim.
18-month indemnity period
Even after systems are restored, revenue can take time to recover as customers and contracts return. That’s why we’ve extended our indemnity period from 12 months to 18 months, providing longer lasting support during this period.
-
A prolonged outage costs a manufacturer its customers
The incident: A manufacturer suffers a major system failure that stops production for an extended period. Unable to supply component parts, the business cannot meet its contractual commitments to long-standing customers.
The impact: Customers move to alternative suppliers and cancel their contracts. Even after production resumes, revenue remains below expected levels because customers do not immediately return.
How the policy responds: CPR’s 18-month indemnity period recognises that the financial consequences of a cyber event can continue after systems are restored. The policy can continue to respond to covered income loss while the manufacturer rebuilds customer relationships and revenue.
-
Compromised social media account disrupts online sales
The incident: A retailer relies on social media to market products and generate online sales. After an employee is tricked into sharing login credentials, cyber criminals take control of a key company account.
The impact: The retailer loses access to an important sales and marketing channel, and revenue declines until access is restored.
How the policy responds: CPR includes business social media accounts within the definition of computer systems. The policy can cover 18 month business interruption losses while the account remains unavailable.
Legal disclaimer: These examples are intended for illustrative purposes only and not intended to address the circumstances of any particular insured. Each claim submitted to CFC by an insured is based on the terms and conditions of the coverage provided to that particular insured and the facts and circumstances relating to a particular claim.
For any questions on our new cyber cover, please contact cyber@cfc.com or to get a quote, visit Connect, our broker trading portal.