Cyber Insurance for Title Agencies: What Your Policy Won't Cover
August 25, 2026 · Alex Weeks · Fraud & Security, Title Industry
Every independent shop I talk to has a cyber policy now. Underwriters ask for it, lenders ask about it, and the premium is small enough against the fear that nobody argues. Almost none of those owners have read the endorsements. That’s not a gotcha. The base policy is legible enough — you know what ransomware response and breach notification mean. The part that decides whether you survive a bad Friday sits three documents deeper, in language that only gets interesting after you have a claim. Read it now, because title agency cyber coverage has a specific shape, and it doesn’t match how title agencies actually lose money.
The Policy Was Written for a Break-In
Cyber insurance grew up around unauthorized access. The paradigm event: someone gets into a system they had no right to be in. Ransomware encrypts your files. An attacker walks off with a database of borrower SSNs. The whole coverage architecture assumes that story — response costs for the intrusion, liability for the data that got out, business interruption for the days you were down. Read the insuring agreements with that lens and every one makes sense: each answers the same question — what happens when someone gets in? That’s a real risk and it deserves coverage. It just isn’t the thing most likely to take a seven-figure bite out of an independent shop.
Nobody Broke In. Your Closer Sent It.
Picture the loss that actually happens. A closer gets updated payoff instructions two days out, on a thread that’s been running three weeks, in a message that reads exactly like the eight before it. She checks it against what she knows. It’s consistent. She sends the wire. Nothing of yours was hacked. If a credential was stolen at all, it was stolen on the other side of the transaction — at the lender, the agent’s office, the borrower’s inbox. An employee with genuine authority to move money looked at the instructions, believed them, and moved it. That is a categorically different event from a break-in, and insurers have long treated it as one. The funds left through the front door, carrying a valid badge.
That’s where the contested language lives. Whether the loss involved actual unauthorized access to a computer system. Whether it’s computer fraud or funds transfer fraud — separate insuring agreements, separate triggers. And the concept that does the most damage: voluntary parting. Your employee handed it over. Nobody took it. I’m not claiming carriers act in bad faith. I’m claiming the product was engineered around a different event, and the fault lines are structural rather than accidental.
The Number on the Front Page Isn’t the Number
Coverage for this exists. It usually goes by social engineering fraud, sometimes fraudulent instruction, and it’s commonly not base coverage at all — it’s an endorsement you either bought or didn’t. It also commonly carries its own sublimit, well below the policy’s headline aggregate. An agency can hold an aggregate limit that comfortably covers any file it handles, and a far smaller effective limit on the single loss it is most likely to have. The number on the declarations page and the number that would respond to a wire loss are frequently not the same. Most owners have never checked which is which; they know the big number, because that’s the one on the certificate.
Policy language varies enormously here — that’s not a hedge, it’s the condition you’re operating in. Two agencies four blocks apart can hold policies that behave completely differently on the same loss. Which is why none of this substitutes for pulling your own binder and reading the endorsement schedule.
The Conditions Precedent Are the Real Trap
These endorsements come with conditions. Not suggestions — conditions. Callback verification to a number established before the transaction, not one supplied inside the instruction. Dual authorization above a dollar threshold. Written procedures the insured represents it follows. Sometimes a requirement that the verification be documented, not merely performed. Now notice the trap: the loss occurs because someone skipped the step. Nobody loses a wire on the file where the closer called a known-good number and got a human being. The loss falls on the one occasion the control didn’t run — the same occasion the carrier will examine whether the condition was met. The coverage is real, and contingent on the exact behavior whose absence caused the claim. That’s not a loophole — it’s the deal you signed, and it means the endorsement is worth about what your worst day’s discipline is worth.
The Policy Is Not a Substitute for the Control
Agencies buy insurance believing it converts a catastrophic risk into a premium. Clean trade: write the check, sleep better. That isn’t the deal. What you bought converts a catastrophic risk into a premium plus a standing obligation — to run the verification procedure every single time, including the Friday afternoon when the seller is annoyed, the closer is four files behind, and the instruction came from someone she’s emailed nine times this month. If the procedure only runs when somebody remembers, your coverage is thinner than your certificate suggests.
Four Questions to Take to Your Broker
Ask these at renewal, and make somebody answer in writing. What is the sublimit on social engineering or fraudulent instruction, as distinct from the aggregate? What verification conditions are precedent to that coverage — specific enough that I could hand them to a closer tomorrow as a written procedure? Does the policy respond when the fraud targets the payoff side, the lender’s instructions, rather than the buyer’s funds? And is there coverage when an employee is deceived, as opposed to when systems are penetrated? If nobody can answer that last one crisply, you don’t yet know what you own.
Where the Software Earns Its Keep
The gap the policy leaves is a discipline gap, and discipline erodes under volume. So don’t ask people to remember. That’s the work Sentinel Plus does on the payoff side, which is where the carrier questions get hardest. It reads every payoff letter before the money moves — with AI vision, including the fax-of-a-photocopy pages that defeat ordinary OCR — extracts the wire instructions, checks the routing number against the Federal Reserve directory, compares the document against a nationwide library of verified lender fingerprints, and returns PASS, REVIEW or FAIL in seconds with an itemized list of what looked wrong. It doesn’t make the call. It makes sure the call gets made on every file rather than the ones somebody remembered, and every verdict is recorded with the exact ruleset that produced it. That record matters twice: once because the control actually ran, and once if you have to show a carrier that it did. Insurance is the backstop. The verification is the defense. Get the second running every time, and the first is far more likely to be there when you need it.
