Personal cyber insurance: cover for scams, identity theft and online fraud
Banks and telcos share some responsibility for phishing losses, but the gap that leaves is exactly where personal cyber insurance sits. Here is what it does and does not fix.
Scam losses in Singapore are large enough that MAS and the Infocomm Media Development Authority built a formal framework around them β the Shared Responsibility Framework (SRF) β to set out when banks and telcos owe a consumer compensation for a phishing scam loss. That framework is a meaningful backstop, but it applies to a specific, defined category of scam, and its existence doesn't mean every online fraud loss is automatically recovered. That's the space personal cyber insurance is designed to sit in.
Where the official framework's protection actually applies
The Shared Responsibility Framework assigns duties to financial institutions and telcos β banks as custodians of your money and the primary gatekeeper against fraudulent outflows, telcos as the infrastructure carrying SMS authorisation codes β and sets expectations for payouts when either party breaches those duties in a phishing scam covered by the framework. If you're a victim, the process runs through your financial institution first: you report the scam, the institution investigates (sometimes looping in the telco), and you're told the outcome, with dispute resolution avenues, including FIDReC, still available if you disagree.
Crucially, the framework is scoped to a defined category of phishing scams and to institutions within its list of participants. A FIDReC case study shows how liability can still end up split even in a scam both consumer and bank agree happened: a young professional tricked into entering a one-time password on a phishing site had his card used for an unauthorised overseas charge, and after a failed chargeback, an adjudicator split the loss 50/50 β the bank for a less-than-clear OTP message, and the consumer for providing an OTP without confirming what it was for. Even where the system works as designed, you can still bear a real share of the loss.
What personal cyber insurance actually covers
Personal cyber cover, whether sold as a standalone policy or bundled into a home insurance plan, is built to respond to losses that fall outside banking dispute frameworks altogether β situations where there's no chargeback to request and no financial institution duty that was clearly breached. Depending on the specific policy, this can include:
- Financial loss from online fraud or unauthorised transactions that aren't otherwise recovered through a bank dispute or chargeback process.
- Costs associated with identity theft, such as expenses incurred restoring your identity or accounts after they've been compromised.
- Cyber extortion or ransomware-style losses, on some plans, where a scammer demands payment to restore access to your data or accounts.
- Cyberbullying or online harassment-related costs, on plans that extend that far, which is a less common but growing addition to household cyber benefits.
As an example, some home insurance plans in Singapore now bundle a personal cyber protection benefit β covering online theft or fraud up to a stated limit β directly into the policy, alongside more traditional benefits like contents cover and worldwide personal liability. This reflects insurers treating digital fraud as a routine household risk, on par with a burst pipe, rather than a specialist add-on.
What it typically does not cover
Personal cyber insurance is not a substitute for the bank-level protections and dispute processes that already exist, and most policies exclude losses that a bank or card scheme is separately obligated to reimburse β the insurance responds to what's left over. It also generally does not cover losses from your own fraudulent or grossly negligent conduct, mirroring the standard banks apply when deciding whether to limit liability for unauthorised transactions. A cyber benefit with a modest cap, such as one bundled into a home policy, may cover only a fraction of a serious fraud loss β worth checking against your realistic exposure rather than assuming it's comprehensive because it's included.
Reducing your exposure regardless of insurance
Insurance is a backstop, not a first line of defence, and the practical habits that reduce scam risk are the same ones FIDReC's own case studies point to: never provide a one-time password for a transaction you haven't specifically confirmed, treat urgent "verify your account" messages with suspicion however official they look, and enable transaction alerts so you notice unauthorised activity immediately rather than days later. Reporting a suspected scam to your financial institution and the police promptly also matters for both the SRF process and any insurance claim, since delay can affect the outcome under either.
What to check before buying
- Is cyber protection already bundled into a home or other policy you hold, and if so, what's the actual limit?
- What specific categories of loss does the policy cover β fraud, identity theft, extortion β and which does it exclude?
- Does the policy require you to have first pursued recovery through your bank or the SRF process before it responds?
- Is the payout limit realistic against the kind of loss you're actually worried about?
You can check your overall coverage, including any cyber benefit bundled into an existing policy, at /gap-check.
Talk to an advisor
Whether you need standalone cyber cover, or whether a benefit already bundled into your home policy is enough, depends on your own digital habits and financial exposure. A licensed advisor can help you see where the official frameworks leave off and where insurance might sensibly pick up. Use the portal's advisor matching to find one who can review your cyber exposure, or ask our assistant to explain a specific cyber benefit you've come across.
Sources
This content is educational information from a licensed advisor, not financial advice. Product details vary by insurer β verify specifics with an advisor.