Payout Watch

Insurers urged to tackle insider fraud together

By Charlott Smith September 10, 2026
Insurers urged to tackle insider fraud together - insider fraud prevention
Cifas Workplace Fraud Trends report highlights 13% of UK employees admitted selling company login details in 2024.

Insider fraud in UK businesses is more common—and more accepted—than previously understood. New data from the Cifas Workplace Fraud Trends report reveals that 13% of employees reported either selling company login details to a former colleague or knowing someone who had done so within the past year. The same share of workers also believed such behavior could be justified, a figure that rises sharply among leadership.

Almost a third of senior managers (32%) and 36% of directors surveyed considered selling access to company systems acceptable. The findings suggest a troubling normalization of fraudulent behavior, particularly at higher levels where oversight should be strongest.

Nick Burgess, head of professional and management risks at Markel UK, frames the issue as a systemic risk requiring a coordinated insurance response. Brokers, he notes, are often the first line of defense for businesses seeking to mitigate fraud exposure, but current coverage gaps leave clients vulnerable.

Most insurers treat insider fraud as a standalone risk, Burgess says, rather than part of a broader cyber or management liability framework. This siloed approach fails to account for how insider threats often intersect with other vulnerabilities, such as weak access controls or poor employee monitoring. The result is fragmented coverage that doesn’t reflect real-world attack paths.

For example, an employee selling credentials may also expose the company to data breaches or regulatory fines, yet these risks are rarely bundled under a single policy. Brokers struggle to explain to clients why a cyber policy won’t cover credential theft, even when it directly enables a ransomware attack. The disconnect between policy wording and actual fraud scenarios creates blind spots in risk management.

Insurers push for proactive fraud prevention

Burgess argues that insurers must move beyond reactive fraud coverage to proactive resilience programs. This could include mandatory cyber hygiene assessments tied to underwriting, or incentives for businesses to implement multi-factor authentication and privileged access management. The goal isn’t just to transfer risk but to reduce it through better prevention.

In practice, this shift would force brokers to take a harder look at their clients’ internal controls. A company with lax password policies or no audit trails for system access isn’t just a fraud target, it’s a policy risk. Brokers who ignore these red flags may find themselves advising clients on coverage that won’t hold up when claims are filed.

The Cifas data also highlights a generational divide. Younger employees, who may have grown up with digital access as a given, appear more likely to justify fraudulent behavior than older workers. This suggests that fraud prevention efforts need to address cultural attitudes alongside technical safeguards. Training programs that frame insider fraud as a collective threat, rather than an individual moral failing, might have more impact than traditional compliance lectures.

Broker expertise gap worsens fragmented coverage

Markel’s focus on organisational resilience reflects a broader industry reckoning. Insurers are increasingly recognizing that fraud isn’t just a legal or financial issue; it’s an operational one. A single compromised account can cascade into a broader breach, yet many policies still treat fraud as an isolated event. The lack of joined-up thinking extends to brokers, who often lack the expertise to guide clients through the overlapping risks of cyber, crime, and management liability coverage.

Burgess points to a simple but critical question brokers should ask clients: How would you detect an insider threat before it became a claim? If the answer is vague, or worse, dismissive, the client’s fraud exposure is likely underestimated. The insurance industry’s response must evolve from writing checks after the fact to helping businesses build defenses that make fraud harder to execute in the first place.

For now, the Cifas report shows a harsh reality: insider fraud isn’t a niche problem confined to a few rogue employees. It’s a mainstream risk, tolerated at alarming rates even among those responsible for oversight. Without a coordinated approach from insurers and brokers, the financial and reputational fallout will only grow.

Leave a Reply

Your email address will not be published. Required fields are marked *