The UK Payment Systems Regulator had a reasonable idea. If banks were on the hook for authorized push payment fraud -- the kind where a victim is deceived into wiring money willingly -- banks would have a financial incentive to prevent it. Mandatory reimbursement went into effect in October 2024.
Authorized push payment losses in the UK fell 2% in 2024. In the first half of 2025, they rose 12%.
This isn't a criticism of the policy. It's a demonstration of a principle: moving who pays after fraud happens does not move when fraud happens, or where it enters. The attack surface didn't change because the liability assignment did.
I bring this up because the equivalent bet in the SMB world is cyber insurance.
When I ask business owners -- law firms, medical practices, mid-market operators -- how they've handled their fraud exposure, "we have coverage" is the most common answer. It's not a wrong answer. Coverage has real value. But it's the same structure as the UK's APP reimbursement mandate: a financial backstop that activates after the loss, not a mechanism that prevents the loss.
The AFP's 2026 Payments Fraud and Control Survey found that 74% of organizations experienced business email compromise in 2025 -- a sharp increase from 63% the year before. That number didn't move when cyber insurance became a standard line item in operations budgets. The fraud kept finding the entry points that coverage doesn't close.
The math is simple. Insurance is priced off loss frequency and severity data. When losses rise -- as they did in the UK despite mandatory reimbursement -- premiums rise, coverage terms tighten, exclusions expand. The businesses most exposed to fraud end up paying more for backstop coverage that covers less. The AFP's 2026 data already shows this trajectory in the U.S. commercial market.
Here's the more direct problem. Cyber insurance policies have conditions. They require reasonable security controls to be in place. Demonstrably inadequate email security -- no DMARC enforcement, no BEC-detection tooling, no privileged account protections -- is grounds for claim denial. The backstop has a floor, and the floor is the same controls you should have had anyway.
So the question isn't whether to carry coverage. The question is what coverage actually covers -- and what it doesn't.
Here's what it doesn't cover:
- The reputational cost of a breach at a law firm that handles client funds.
- HIPAA penalty exposure at a medical practice whose patient records were accessed during a credential-theft attack.
- Three weeks of operational disruption while you rebuild.
- The financial loss itself, increasingly, if the investigation determines your controls were deficient as losses rise and insurers tighten terms.
The UK's APP reimbursement experiment is useful because it ran at scale and produced clean data. The result: you cannot insure or reimburse your way out of an attack surface problem. The attack surface has to close.
For an SMB, that means addressing the actual entry point -- which, as the first post in this series established, is your endpoint: your email environment, your credentials, your staff's ability to catch a spoofed invoice or a social engineering attempt before the wire goes out.
Coverage belongs in the stack. It just isn't the stack.
John (Chris) Rondthaler is the founder of IT CloudLink, an IT and cybersecurity consultancy serving healthcare practices, law firms, and compliance-driven SMBs in the Los Angeles area. He has worked two real financial fraud incidents firsthand. His byline "The Fraud Liability Debate Is Asking the Wrong Question" was published in Fintech Bloom in May 2026.