
Most freight companies have cyber insurance. Most of them have no idea what's actually in it.
The policy got bought because a customer required proof of coverage, or a broker bundled it into a renewal, or a board decided after reading a news story that it was time to "have something in place." The certificate went into the file. Nobody read the policy.
That's the problem I want to walk through this week. Because when the incident hits — the ransomware, the wire fraud, the data breach — that policy is the only thing standing between your operation and a financial event you might not survive. And the gaps in what most freight operations actually bought are wider than they realize.
The Social Engineering Exclusion
Here's the one that gets freight companies first.
A bad actor impersonates a vendor, sends an email with updated wire instructions, and your team sends the payment. Six figures gone. You file the claim under your cyber policy.
The claim gets denied.
Why? Because most standard cyber policies cover unauthorized access to your systems — not voluntary transfers made by your team based on fraudulent communications. That's social engineering, and it's either excluded outright or buried under a separate coverage rider with a much smaller sub-limit. Some policies offer it. Many don't. Most freight operators don't know which one they have.
Given that wire fraud and BEC are the most common cyber events hitting brokers right now, this is the gap that matters most.
The Ransomware Sub-Limit
Most policies advertise a headline coverage number — "up to $1 million in cyber coverage" or similar. What they don't make obvious is that ransomware payouts are usually capped at a much lower number inside that coverage.
A million-dollar policy might have a $250,000 sub-limit on ransomware. Or $100,000. Or less. If the attacker demands $400,000 and your policy caps at $100,000, you're paying the other $300,000 out of pocket — or accepting the operational losses of not paying. Either way, the headline number on the policy isn't what you actually have.
This is a renewal-call conversation. The number on the certificate is not always the number you'll get.
The "Reasonable Security Measures" Clause
This is the one that voids policies entirely.
Most cyber policies require the insured to maintain "reasonable security measures" as a condition of coverage. The definition varies, but most policies expect at minimum: multi-factor authentication on email and remote access, regular software patching, employee security training, and basic incident response procedures.
If you have a breach and the insurer determines you weren't meeting those requirements — say, MFA wasn't enabled on the inbox that got compromised — the claim can be denied entirely. Not reduced. Denied. The policy you've been paying premiums on for two years pays out nothing.
Most freight operators don't realize their policy has this clause until the claims adjuster cites it.
Coverage Most Policies Don't Include
A few things that aren't typically covered in a standard cyber policy unless you bought specific add-ons:
- Loss of revenue from operational disruption during a ransomware event
- Customer notification costs and credit monitoring after a data breach
- Regulatory fines from state-level data privacy laws
- Reputational harm and PR response
- Third-party liability if your breach exposes a customer or carrier
- Cargo or freight losses tied to a cyber incident — including hijacked loads enabled by a compromised email
That last one is freight-specific and worth flagging. If a fake dispatcher uses your compromised inbox to reroute a load and the freight is lost, the cyber policy may not cover the cargo value. Your cargo policy may not cover it either if the loss involves cyber compromise. The two policies can leave a gap in the middle that nobody insured.
What to Do This Quarter
Three practical moves worth making before your next renewal:
- Pull your policy and read the exclusions section. Not the cover page. The exclusions.
- Confirm with your broker whether social engineering and BEC are covered, and at what sub-limit.
- Ask what specific security controls the policy requires you to maintain — and confirm you actually have them in place. Get it in writing.
If the answers are vague, that's the answer. The policy you're paying for isn't the protection you think it is.
The Real Issue
Cyber insurance is one of the most misunderstood line items on a freight operation's budget. Most policies are written to limit the insurer's exposure, not to maximize the insured's protection. That's not malicious — that's how insurance works. But it means the burden is on you to know what you actually bought.
The freight operations are getting this right by reading their policies. The ones that don't are paying premiums for protection that won't be there when the loss hits.
Find Out Where You Actually Stand
Run the Freight Cyber Risk Scorecard to see whether your operation meets the basic security requirements most cyber policies are quietly assuming you have. Five minutes, free, and it'll tell you whether you'd survive an insurer's review after a claim — or whether you'd be paying out of pocket.
The certificate in your file doesn't pay claims. The policy behind it does. Now's the time to know which one you actually have.
The Cyber Freight Room — Where freight meets cybersecurity. 🚛🔐

