Skip to main content
(443) 502-5645 sales@pbigroupsolutions.com 1405 S Fern St #96426, Arlington, VA 22202
Policy Coverage Review · Cyber Liability

What if the last page of your cyber policy deleted the coverage you bought it for?

A plain-English, coverage-by-coverage review of an actual CFC Cyber Proactive Response v4.0 policy (underwritten at Lloyd's) sold to a real estate brokerage, compared against the PBI Group Arch NetSafe® 2.0 program — so you can read your own declarations page, and your own endorsements, with a sharper eye.

An independent, educational comparison — not affiliated with or endorsed by CFC Underwriting Limited or Lloyd's.

Cyber insurance is hard to compare because the differences that decide a claim don't live on the price quote. They live in endorsements, sublimits, and definitions — often on the last pages of the policy. This review is the clearest example we've published: the reviewed CFC policy is genuinely strong on breach response and business interruption, and then a one-page endorsement at the back — the Absolute Theft of Funds Exclusion Clause — removes coverage for “theft of money or financial assets in any format, including but not limited to cash, bank notes, electronic currency, customer account balances, and stock or bond certificates.”

There is an important structural reason this happens. CFC's Cyber Proactive Response is a modular, highly customizable policy — its coverage sections are switched on or off at placement based on the insured's industry class. Some classes are offered the full form; for others, specific insuring clauses are removed before the policy is ever issued. In our experience, for the Title Agent and Real Estate Agent & Broker classes, the Cyber Crime coverages — the very sections that respond to wire fraud and theft of funds — are frequently excluded. That is what happened here: the Cyber Crime insuring clause wasn't sublimited or merely conditioned, it was removed for the class before issuance. Which coverage you actually have on this paper depends heavily on how your class was underwritten — one more reason to read your own Declarations closely.

For real estate brokerages, escrow and title companies, and property managers, two differences matter above all the rest. First: whose money is covered. Real estate firms hold other people's money — earnest deposits, security deposits, rent rolls, closing funds. On the reviewed policy, the entire Cyber Crime insuring clause was removed at placement (marked NO COVER GIVEN on the Declarations), and the absolute exclusion was added behind it — naming customer account balances specifically.

Second: who defends you when a client loses her own money. When a bad actor breaches your network or email, reads a client's closing details, and uses that private information to deceive her into wiring her own funds to a fraudulent account, she has a claim against you — because a breach of your systems exposed the information that harmed her. We call this 3rd Party Wire Fraud coverage. The reviewed CFC policy does include a Network Security & Privacy Liability part — but her claim is a claim about stolen funds, and the absolute theft-of-funds exclusion applies to the whole policy.

An honest review cuts both ways, so we say this plainly: in seven of the thirty-four areas we checked, the reviewed CFC policy is stronger than Arch NetSafe® 2.0 — including a $1,000,000 hardware/bricking limit, a shorter business-interruption waiting period, and a longer recovery period. Those rows are marked green in CFC's column below. They are real advantages. They also don't touch the #1 cyber loss in real estate: wire fraud and the theft of funds — where the reviewed policy provides no coverage at all.

The Arch program is shown at a $1,000,000 aggregate limit with a $1,000 deductible. The reviewed CFC policy carries $1,000,000 limits with a $5,000 single aggregate deductible (paid once, then no further deductible that policy year) — a different deductible structure, which we note rather than score. Because these two policies were not issued to the same firm, we compare what actually decides claims — coverage structure, sublimits, conditions, and exclusions — not premium. A green cell marks the stronger coverage; where both cells are green, the policies are comparable. Select any row for the details and why they matter.

What we found

Headline findings from our page-by-page review of the CFC Cyber Proactive Response v4.0 policy — every endorsement read, every sublimit checked.

16
PBI Group / Arch Advantages
Coverage areas where Arch NetSafe® 2.0 is stronger — broader coverage, higher sublimits, better conditions, or no exclusion.
11
Comparable
Coverage areas where the reviewed CFC Cyber Proactive Response v4.0 policy matches Arch NetSafe® 2.0 — shown with both cells green in the grid below. 7 additional areas favor CFC, marked green in its column.
34
Features Compared
Every coverage part, endorsement, sublimit, condition, and exclusion checked — page by page, through the last endorsement of both policies.

Side by side, coverage by coverage

Organized the way Arch NetSafe® 2.0 is built — coverage parts plus the Cyber Crime endorsement. Select any coverage to expand the details.

Third Party · Coverage Parts A & BThird Party Liability — when a client or regulator comes after you
Network Security & Privacy Liability (3rd Party Wire Fraud)
CFC Cyber Proactive Response v4.0
$1,000,000*
Subject to absolute theft-of-funds exclusion
PBI Group | Arch NetSafe® 2.0
$1,000,000
Dedicated Coverage Part A

CFC Cyber Proactive Response v4.0

The reviewed policy does include a Network Security & Privacy Liability insuring clause (Insuring Clause 5) at $1,000,000 — covering malware transmission, denial-of-service, failure to prevent unauthorized access, and privacy claims. But the Absolute Theft of Funds Exclusion added by endorsement applies to the entire policy: no payment for “theft of money or financial assets in any format, including … customer account balances.” A client's claim over her stolen closing funds runs straight into it.

PBI Group | Arch NetSafe® 2.0

A dedicated third-party Coverage Part covering claims from unauthorized access, malicious code transmission, denial-of-service attacks, and Privacy Violations — defense and damages up to the full aggregate. This is the coverage that responds to 3rd Party Wire Fraud: when a breach of your systems exposes a client's information and she is deceived into wiring her own funds to a bad actor, her claim against you is covered here.

Why it matters: This is the defining real estate cyber claim. A hacker reads your email, learns about a closing, and tricks your client into wiring her own funds to a fraudulent account. She has a claim against you — and on the reviewed policy, the insurer can point to a one-page exclusion that names stolen funds “in any format.” The liability coverage part exists; the scenario it's needed for most is carved away.
Regulatory Proceedings & Fines
CFC Cyber Proactive Response v4.0
$1,000,000
Full limits · investigations included
PBI Group | Arch NetSafe® 2.0
$1,000,000
Full policy limits

CFC Cyber Proactive Response v4.0

Insuring Clause 5-D pays fines and penalties resulting from a “regulatory investigation” — defined broadly to include formal hearings, official investigations, examinations, and inquiries — at full policy limits, plus defense costs.

PBI Group | Arch NetSafe® 2.0

Defense costs and civil fines/penalties from regulatory actions alleging Privacy Violations — including investigations commenced by civil investigative demand — to full limits. GDPR and CCPA are added to the Privacy Law definition by endorsement.

Why it matters: Both policies fund regulatory defense and fines at full limits — genuine parity, and better than the sublimited regulatory coverage we frequently find on commodity forms.
Privacy Law Breadth (GDPR / CCPA)
CFC Cyber Proactive Response v4.0
Generic
No statutes named in the form
PBI Group | Arch NetSafe® 2.0
Named
HIPAA · GLBA · GDPR · CCPA by endorsement

CFC Cyber Proactive Response v4.0

The v4.0 wording defines privacy breach and regulatory investigation broadly but does not enumerate specific privacy statutes. Broad language often responds — but you are relying on interpretation rather than a named grant.

PBI Group | Arch NetSafe® 2.0

The Privacy Law definition explicitly includes HIPAA, GLBA, the FTC Act, state breach notification laws, and — by endorsement — GDPR and CCPA, all at full limits.

Why it matters: When a regulator cites a specific statute, a policy that names that statute leaves nothing to argue about. Certainty is the product you're buying.
PCI-DSS Assessments
CFC Cyber Proactive Response v4.0
$1,000,000
In base insuring agreement
PBI Group | Arch NetSafe® 2.0
$1,000,000
Full policy limits

CFC Cyber Proactive Response v4.0

PCI fines, penalties, and card brand assessments — including fraud recoveries, operational reimbursements, and case management fees — at full policy limits (Insuring Clause 5-E).

PBI Group | Arch NetSafe® 2.0

Monetary assessments from Payment Card Associations or Acquiring Banks for PCI non-compliance, covered to full policy limits.

Why it matters: Both policies handle this well — a genuine point of parity.
Media Liability
CFC Cyber Proactive Response v4.0
$1,000,000
Purchased · shared aggregate
PBI Group | Arch NetSafe® 2.0
$1,000,000
Dedicated Coverage Part B

CFC Cyber Proactive Response v4.0

Media Liability (Insuring Clause 7) was purchased on the reviewed policy: defamation and intellectual property infringement arising out of media content — including AI-assisted content — at $1,000,000, within an aggregate shared with the liability clauses.

PBI Group | Arch NetSafe® 2.0

A full Media Liability Coverage Part covering copyright infringement, defamation, plagiarism, trade libel, and invasion of privacy in media activities — included in every Arch placement.

Why it matters: Both policies cover the listings, marketing, virtual tours, and social content real estate firms publish daily. Credit where due: on the reviewed policy, this coverage was actually bought — something we can't say for every policy we review.
Management Liability (Cyber D&O)
CFC Cyber Proactive Response v4.0
$1,000,000
Board & C-suite claims from a cyber event
PBI Group | Arch NetSafe® 2.0
Not Included
Addressed by a separate D&O policy

CFC Cyber Proactive Response v4.0

Insuring Clause 5-C pays sums that board members, C-level executives, in-house lawyers, and risk managers become legally obliged to pay from claims arising directly out of a cyber event — a coverage most cyber forms don't carry.

PBI Group | Arch NetSafe® 2.0

The Arch cyber program does not include a management liability insuring agreement; claims against directors and officers following a breach are typically addressed under a separate management liability / D&O policy.

Why it matters: A fair point for CFC. If shareholders or partners pursue leadership personally after a breach, this clause responds. It's a genuine differentiator — just not one that touches the wire-fraud exposure at the center of real estate cyber risk.
Theft of Funds (Loss Definition)
CFC Cyber Proactive Response v4.0
Absolutely Excluded
By endorsement · names customer account balances
PBI Group | Arch NetSafe® 2.0
Covered
Standard exclusion removed by endorsement

CFC Cyber Proactive Response v4.0

The Absolute Theft of Funds Exclusion Clause — the last endorsement on the reviewed policy — deletes the base form's narrower escrow exclusion (which had a carve-back) and replaces it with an absolute exclusion for theft of money or financial assets in any format, expressly including electronic currency and customer account balances. No carve-back survives.

PBI Group | Arch NetSafe® 2.0

The Arch endorsement removes the standard exclusion for theft of money or securities from an Insured — a significant enhancement most cyber policies don't offer.

Why it matters: When money itself is stolen — not just data — this is the language that decides the claim. One policy removes the exclusion; the other installs an absolute one and names your clients' account balances in it.
First Party · Coverage Part CData Incident Response — the cost of cleaning up a breach
Data Incident Response Expense
CFC Cyber Proactive Response v4.0
$1,000,000
Full response stack · 72-hr panel condition
PBI Group | Arch NetSafe® 2.0
$1,000,000
All response services · full limits

CFC Cyber Proactive Response v4.0

Insuring Clause 1 funds legal and regulatory costs, IT forensics, crisis communications, privacy breach management (notification, credit monitoring, call center), and even third-party breach management — each at $1,000,000 per claim. One condition to know: costs incurred in the first 72 hours without insurer consent must be with approved claims panel providers. A separate Post Breach Remediation section adds up to $50,000 for security improvements after a covered event.

PBI Group | Arch NetSafe® 2.0

Legal counsel, forensic IT, notifications, credit monitoring, identity theft services, PR/crisis management, and data restoration — each to full policy limits, with insurer-selected counsel and forensics for quality control.

Why it matters: Both policies fund a full breach response at full limits — genuine parity on the coverage real estate firms are most likely to actually use. CFC's post-breach remediation add-on is a nice extra.
Property Damage / Bricking
CFC Cyber Proactive Response v4.0
$1,000,000
Hardware replacement · incl. temporary equipment
PBI Group | Arch NetSafe® 2.0
$250,000
Includes hardware replacement

CFC Cyber Proactive Response v4.0

Hardware Replacement Costs (Insuring Clause 4-B) pays to replace computer hardware rendered unusable by a cyber event at $1,000,000 per claim — including temporary interim equipment during recovery — where replacement is more cost-effective than re-flashing.

PBI Group | Arch NetSafe® 2.0

Covers the cost to replace hardware rendered non-functional when its firmware or software is maliciously reprogrammed (“bricking”), plus data restoration — $250,000 sublimit.

Why it matters: A genuine CFC advantage: four times the Arch sublimit. Modern ransomware can permanently disable every device in an office, and $1,000,000 replaces all of it. We mark it green on their side because it's true.
Reputational Harm
CFC Cyber Proactive Response v4.0
$1,000,000
12-month period · plus Lost Bids coverage
PBI Group | Arch NetSafe® 2.0
$250,000
14-day wait · 6-month recovery

CFC Cyber Proactive Response v4.0

Consequential Reputational Harm (Insuring Clause 4-G) pays income lost to customer flight after a cyber event at $1,000,000 over a 12-month reputational harm period — and a companion section covers income lost from bids or RFPs you fail to make or win because of the event, also at $1,000,000.

PBI Group | Arch NetSafe® 2.0

Lost net income from adverse publicity following a data breach — $250,000 sublimit, 14-day waiting period, 6-month Period of Recovery.

Why it matters: Another real CFC advantage — higher limit, longer period, plus lost-bids coverage Arch doesn't offer. Reputational harm coverage is rare at all; this is a strong version of it.
Cryptojacking / Unauthorized Use of Resources
CFC Cyber Proactive Response v4.0
Not Covered
Lived in the deleted Cyber Crime clause
PBI Group | Arch NetSafe® 2.0
$250,000
90-day calculation period

CFC Cyber Proactive Response v4.0

The v4.0 form covers cryptojacking and botnetting losses — but that coverage sits inside Insuring Clause 2 (Cyber Crime), which was removed in its entirety on the reviewed policy: NO COVER GIVEN.

PBI Group | Arch NetSafe® 2.0

Additional utility costs (electricity, internet) from unauthorized cryptocurrency mining on your network — $250,000 sublimit.

Why it matters: A quiet casualty of striking the whole Cyber Crime clause: coverages that have nothing to do with wire fraud — like cryptojacking and telephone hacking — disappeared with it.
Breach Response Hotline & Proactive Services
CFC Cyber Proactive Response v4.0
24 / 7
Response app · threat monitoring
PBI Group | Arch NetSafe® 2.0
24 / 7
Dedicated breach counsel hotline

CFC Cyber Proactive Response v4.0

A 24/7 cyber incident response line, the CFC Response mobile app, and genuinely useful proactive services: real-time threat alerts, dark web monitoring, phishing simulations, and remote remediation support — with no impact on policy limits.

PBI Group | Arch NetSafe® 2.0

Immediate access to a pre-arranged breach response legal team at 844-202-1600 the moment something looks wrong.

Why it matters: Both carriers connect you to experienced responders fast. CFC's proactive prevention stack is among the best in the market — credit where it's due.
First Party · Coverage Part DBusiness Interruption — income you lose while systems are down
Business Interruption — Security Breach
CFC Cyber Proactive Response v4.0
$1,000,000
8-hr wait · 12-month recovery · no sublimit
PBI Group | Arch NetSafe® 2.0
$1,000,000
12-hr wait · recovery up to 180 days

CFC Cyber Proactive Response v4.0

Income Loss and Extra Expense at $1,000,000 per claim with an 8-hour time franchise and a 12-month indemnity period — and once downtime exceeds the franchise, loss incurred during those first 8 hours is paid too. We read every endorsement looking for the hidden BI sublimit pattern; there isn't one on this policy.

PBI Group | Arch NetSafe® 2.0

Lost income and extra expense when a breach makes your systems inoperable — up to the full aggregate, 12-hour waiting period, Period of Recovery extended to 180 days by endorsement. No sublimit endorsement reduces it.

Why it matters: Both policies provide full-limit BI — and CFC's terms are better: a 4-hour-shorter wait and roughly double the recovery window. When a competitor earns a green cell, it gets one.
Business Interruption — System Failure & Operator Error
CFC Cyber Proactive Response v4.0
$1,000,000
System failure and human error triggers
PBI Group | Arch NetSafe® 2.0
$1,000,000
Non-malicious outages covered

CFC Cyber Proactive Response v4.0

BI on the reviewed policy is triggered by a cyber event, a system failure (application bug, internal network or hardware failure), or operator error — unintentional human mistakes in entering data or configuring systems. Three triggers, all at full limits.

PBI Group | Arch NetSafe® 2.0

Extends BI to systems down from administrative, programming, or other unintentional errors — not just hacking — up to the full aggregate.

Why it matters: Both cover the botched update that takes your office down for a week. CFC's express operator-error trigger is slightly broader on paper — marked accordingly.
Business Interruption — Dependent Business
CFC Cyber Proactive Response v4.0
Cloud vendors only
“Supply chain partner” = hosted computing · report required
PBI Group | Arch NetSafe® 2.0
$1,000,000
Any contracted vendor · $250K for system failure

CFC Cyber Proactive Response v4.0

Dependent BI (Insuring Clause 4-F) pays $1,000,000 — but “supply chain partner” is defined as a third party providing hosted computing services (infrastructure, platform, file storage, application services) unless another vendor is scheduled by endorsement. A non-technology vendor outage isn't covered. And a condition precedent requires a written root-cause report from the partner before the claim is payable.

PBI Group | Arch NetSafe® 2.0

Covers your income loss when a Dependent Business — any service provider under written contract — suffers a breach ($1,000,000) or system failure ($250,000 sublimit) that interrupts your operations.

Why it matters: If your title vendor, transaction coordinator, or showing service goes down and your closings stall, the Arch policy responds; the reviewed policy responds only if the failed vendor is a cloud provider — and only after that vendor documents its own outage in writing for your insurer.
Business Interruption — Technology Contractor
CFC Cyber Proactive Response v4.0
$1,000,000
Cloud / SaaS / hosting outages
PBI Group | Arch NetSafe® 2.0
$250,000
Breach or system failure

CFC Cyber Proactive Response v4.0

For the vendors CFC's definition does cover — cloud hosts, SaaS platforms, data centers — the limit is $1,000,000 per claim, whether the outage comes from an attack, a system failure, or operator error at the vendor.

PBI Group | Arch NetSafe® 2.0

Covers income loss when a Technology Contractor — cloud host, SaaS provider, data center — suffers a breach or system failure, $250,000 per trigger.

Why it matters: The mirror image of the row above: for pure cloud outages, CFC's limit is four times higher. Real estate runs on SaaS, so this is worth real money — both facts belong on the page.
Voluntary Shutdown
CFC Cyber Proactive Response v4.0
Covered
Includes regulator-ordered shutdown
PBI Group | Arch NetSafe® 2.0
Covered
With insurer consent

CFC Cyber Proactive Response v4.0

Income loss is covered when you reasonably and deliberately take systems offline to manage a cyber event and mitigate a wider loss — and also when a regulator orders you offline. No prior-consent requirement in the insuring clause.

PBI Group | Arch NetSafe® 2.0

Covers income loss when you intentionally shut systems down after discovering a breach, with insurer consent — rewarding fast defensive action.

Why it matters: Both policies avoid punishing you for pulling the plug fast. CFC also covers the shutdown you don't choose — the one a regulator orders.
First Party · Coverage Part ECyber Extortion — ransomware demands
Cyber Extortion / Ransomware
CFC Cyber Proactive Response v4.0
$1,000,000
Full limits · no ransomware sublimit
PBI Group | Arch NetSafe® 2.0
$1,000,000
Full limits · no ransomware sublimit

CFC Cyber Proactive Response v4.0

Insuring Clause 3 pays the ransom itself plus negotiation costs and the cost of procuring cryptocurrency, for threats spanning malware, lockouts, data disclosure, and brand attacks — $1,000,000 per claim. We checked every endorsement for a buried ransomware-event sublimit; there isn't one. Conditions: insurer's prior written agreement before payment, and the incident must be reported to law enforcement.

PBI Group | Arch NetSafe® 2.0

Expenses to investigate, negotiate, and (with insurer consent) pay a ransomware demand — the full $1,000,000 applies, with both Security Threats and Privacy Threats covered and no separate ransomware cap.

Why it matters: Full parity, and worth naming: many competitor policies show $1,000,000 on the Declarations and cap ransomware at $25,000–$50,000 in a late endorsement. Neither policy here plays that game.
Cyber Crime EndorsementCyber Crime — wire fraud, the #1 threat in real estate
Social Engineering (Wire Fraud)
CFC Cyber Proactive Response v4.0
Not Covered
Insuring Clause 2 removed · NO COVER GIVEN
PBI Group | Arch NetSafe® 2.0
$250,000
Includes client funds in your care & custody

CFC Cyber Proactive Response v4.0

The v4.0 base form contains social engineering coverage — phishing and vishing attacks that trick an employee into transferring company funds. On the reviewed policy the entire Cyber Crime insuring clause was removed: the Declarations page reads NO COVER GIVEN.

PBI Group | Arch NetSafe® 2.0

Covers loss from fraudulent instructions purporting to come from a customer, vendor, bank, title company, escrow agent, closing attorney, real estate broker, or mortgage broker — and critically, extends to your clients' funds held in your care, custody, and control, including funds in any insured account. One condition to know: instructions must be verified through a second channel (e.g., a callback) before transferring — a best practice the FBI recommends regardless.

Why it matters: Wire fraud is the #1 cyber loss in real estate, and on the reviewed policy the answer to it is a blank line. This wasn't a sublimit or a condition — the coverage simply wasn't placed. In our experience, this carrier frequently declines Cyber Crime coverage for real estate and title classes, so if you hold a policy on this paper, check your own Declarations for the same three words.
Electronic / Funds Transfer Fraud
CFC Cyber Proactive Response v4.0
Not Covered
Insuring Clause 2 removed
PBI Group | Arch NetSafe® 2.0
$250,000
Includes client funds in your care & custody

CFC Cyber Proactive Response v4.0

The base form's Funds Transfer Fraud section — unauthorized electronic transfers and theft of company funds from a bank by electronic means — was removed with the rest of Insuring Clause 2.

PBI Group | Arch NetSafe® 2.0

Covers fraudulent instructions directing your financial institution to transfer funds from your account — including client funds held in any insured account.

Why it matters: This is the coverage for the account takeover: no employee is deceived, the attacker simply moves the money. On the reviewed policy, that loss is uninsured.
Invoice Manipulation
CFC Cyber Proactive Response v4.0
Not Covered
Insuring Clause 2 removed
PBI Group | Arch NetSafe® 2.0
$250,000

CFC Cyber Proactive Response v4.0

The base form covers theft of client money intended for you, diverted by fraudulent communications impersonating your firm — including doctored invoices and changed banking details. Removed with Insuring Clause 2.

PBI Group | Arch NetSafe® 2.0

Covers loss when a hacker inside your systems distributes doctored invoices to your clients, leaving you unable to collect payment.

Why it matters: When a fraudster impersonates your firm and redirects a commission payment or rent roll, the reviewed policy pays nothing — the money was never “yours” to lose, and the coverage that answers that argument was removed.
Telephone Fraud
CFC Cyber Proactive Response v4.0
Not Covered
Insuring Clause 2 removed
PBI Group | Arch NetSafe® 2.0
$250,000

CFC Cyber Proactive Response v4.0

Telephone hacking coverage — fraudulent calls and bandwidth theft through a compromised phone system — exists in the base form and was removed with Insuring Clause 2.

PBI Group | Arch NetSafe® 2.0

Covers long-distance toll charges when your PBX or voicemail system is hijacked to place fraudulent calls.

Why it matters: A compromised VOIP system can rack up tens of thousands in toll charges over a single weekend.
Client Funds in Your Care, Custody & Control
CFC Cyber Proactive Response v4.0
Absolutely Excluded
Exclusion names “customer account balances”
PBI Group | Arch NetSafe® 2.0
Covered
Express extension in the Cyber Crime endorsement

CFC Cyber Proactive Response v4.0

Two documents work together here. The base form actually contemplates client-funds coverage — it has sections for theft of funds held in escrow and theft of client funds. On the reviewed policy, those sections were removed with Insuring Clause 2, and the Absolute Theft of Funds Exclusion then forecloses the subject entirely — expressly naming customer account balances.

PBI Group | Arch NetSafe® 2.0

The Arch Cyber Crime endorsement defines covered loss as direct financial loss sustained by the insured “or by a customer of the Insured whose funds are under the care, custody and control of any Insured, including funds held in any Insured Account.”

Why it matters: Real estate firms hold other people's money — earnest deposits, security deposits, rent rolls, closing funds. Whose money is covered is the single most important question you can ask of a cyber policy, and these two policies give opposite answers in writing.
Cyber Crime Aggregate (all coverages)
CFC Cyber Proactive Response v4.0
$0
NO COVER GIVEN
PBI Group | Arch NetSafe® 2.0
$250,000

CFC Cyber Proactive Response v4.0

With Insuring Clause 2 removed in full, the effective cyber crime aggregate on the reviewed policy is zero.

PBI Group | Arch NetSafe® 2.0

All four Cyber Crime insuring agreements share a $250,000 aggregate.

Why it matters: The aggregate is the number that pays the claim. The average wire fraud loss in real estate exceeds $50,000 on its own; the reviewed policy's number is zero.
Exclusions & Operational TermsThe exclusions and conditions that decide real estate claims
Escrow & Trust Account Funds
CFC Cyber Proactive Response v4.0
Excluded
Base-form carve-back deleted by endorsement
PBI Group | Arch NetSafe® 2.0
Covered
No escrow, trust, or closing exclusion

CFC Cyber Proactive Response v4.0

The base form's “Theft of funds held in escrow” exclusion contained a carve-back preserving escrow theft coverage. The endorsement on the reviewed policy deletes that exclusion and its carve-back, replacing both with the absolute exclusion — so escrow and trust account losses are excluded with no path back in.

PBI Group | Arch NetSafe® 2.0

The Arch policy contains no exclusion targeting escrow, trust account, title, or closing activities — and the Cyber Crime endorsement affirmatively covers client funds in insured accounts.

Why it matters: For a firm that touches escrow — and in real estate, that's nearly everyone — this is where the money actually moves. It's the first thing we look for in any policy sold to a real estate firm.
Retroactive Date
CFC Cyber Proactive Response v4.0
Unlimited
Stated on the Declarations
PBI Group | Arch NetSafe® 2.0
Full Prior Acts
All Coverage Parts

CFC Cyber Proactive Response v4.0

The reviewed Declarations state an unlimited retroactive date — breaches that began before the policy and are discovered during it are covered.

PBI Group | Arch NetSafe® 2.0

No retroactive date restriction on any Coverage Part — breaches that began before the policy and are only discovered now are still covered.

Why it matters: Attackers commonly sit inside systems for months or years before discovery. Both policies get this right — full prior acts on each side.
Limit Structure & Reinstatement
CFC Cyber Proactive Response v4.0
Each & every claim
First-party limits reinstate for unrelated claims
PBI Group | Arch NetSafe® 2.0
$1,000,000 aggregate
Shared across all Coverage Parts

CFC Cyber Proactive Response v4.0

First-party insuring clauses (incident response, crime, extortion, BI) carry each-and-every-claim limits with no annual aggregate: if one event consumes $800,000, a second unrelated event still has the full $1,000,000 available. Liability clauses share a $1,000,000 aggregate.

PBI Group | Arch NetSafe® 2.0

A single $1,000,000 aggregate applies across all Coverage Parts for the policy year — the standard structure for cyber programs.

Why it matters: A structural CFC advantage worth naming plainly: in a year with two unrelated incidents, the reviewed policy's first-party limits refill. It doesn't offset a $0 crime aggregate — but it's real, and it's green on their side.
Biometric Data
CFC Cyber Proactive Response v4.0
No Exclusion
PBI Group | Arch NetSafe® 2.0
No Exclusion

CFC Cyber Proactive Response v4.0

We checked every endorsement for the biometric data exclusion appearing on newer competitor forms; the reviewed policy does not carry one.

PBI Group | Arch NetSafe® 2.0

No biometric data exclusion in the Arch policy.

Why it matters: Fingerprint time clocks, smart-lock logs, camera analytics — biometric privacy suits are one of the fastest-growing claim types. Neither policy excludes them.
Unsupported / Legacy Systems
CFC Cyber Proactive Response v4.0
No Exclusion
PBI Group | Arch NetSafe® 2.0
No Exclusion

CFC Cyber Proactive Response v4.0

No end-of-life or end-of-support systems exclusion appears on the reviewed policy.

PBI Group | Arch NetSafe® 2.0

No exclusion for end-of-life or end-of-support systems.

Why it matters: An emerging exclusion on newer forms that can zero out a claim when the attacker enters through an old machine. Neither policy carries it.
Cyberterrorism / Cyberwarfare
CFC Cyber Proactive Response v4.0
Partial
Cyberterrorism covered · narrow cyber war carve-back
PBI Group | Arch NetSafe® 2.0
Covered
Cyberterrorism carved back in

CFC Cyber Proactive Response v4.0

Fair reading: cyber terrorism is expressly inside the “cyber event” definition, and the terrorism exclusion carves cyber events back in. But a separate cyber war exclusion for state-attributed attacks carves back only the incident-response section and systems physically outside an “impacted state” — a narrower safety net than a full cyberterrorism carve-back.

PBI Group | Arch NetSafe® 2.0

The war exclusion explicitly does not apply to cyberterrorism — attacks by non-state actors remain covered.

Why it matters: Major ransomware strains are routinely attributed to state-linked groups by forensic firms and the press. The breadth of the carve-back decides whether that attribution becomes the insurer's exit.
Claim Reporting Deadline
CFC Cyber Proactive Response v4.0
60 days
Automatic extended reporting period
PBI Group | Arch NetSafe® 2.0
90 days
After the policy period

CFC Cyber Proactive Response v4.0

An automatic 60-day extended reporting period follows the policy period — and it does not apply if any other insurance would respond.

PBI Group | Arch NetSafe® 2.0

Endorsement extends the reporting window to 90 days after the policy period ends.

Why it matters: Thirty extra days matters when a breach is discovered right at renewal — late notice is one of the most common reasons cyber claims are denied.
Consent to Settle (“Hammer Clause”)
CFC Cyber Proactive Response v4.0
Capped at offer
80/20 cost sharing after refusal
PBI Group | Arch NetSafe® 2.0
50% above offer
Insurer still pays half of excess loss

CFC Cyber Proactive Response v4.0

If you refuse a settlement the insurer recommends, its liability for the claim is capped at the amount it could have been settled for — nothing above it — and further defense costs are shared 80/20.

PBI Group | Arch NetSafe® 2.0

If you refuse a recommended settlement, Arch still pays 50% of covered loss above the proposed settlement amount.

Why it matters: If you believe a claim against your firm is wrong and want to fight it, the Arch clause keeps the insurer half-in above the offer; the reviewed policy leaves everything above the offer to you.
Court Attendance Expenses
CFC Cyber Proactive Response v4.0
$100,000
Nil deductible
PBI Group | Arch NetSafe® 2.0
$100,000

CFC Cyber Proactive Response v4.0

Reimburses sums incurred, with insurer agreement, to attend court, tribunals, arbitrations, and mediations — $100,000 aggregate with no deductible.

PBI Group | Arch NetSafe® 2.0

Reimburses your expenses to attend hearings, trials, depositions, and ADR proceedings — $100,000 aggregate.

Why it matters: Litigation means your people in conference rooms instead of at closings. Equal, meaningful limits on both sides.
Extended Reporting Period Options
CFC Cyber Proactive Response v4.0
1 year
100% of annual premium
PBI Group | Arch NetSafe® 2.0
1 / 3 / 6 years
Tail options

CFC Cyber Proactive Response v4.0

A single optional extended reporting period of 12 months at 100% of annualized premium.

PBI Group | Arch NetSafe® 2.0

Tail options of 1, 3, or 6 years are available when the policy is cancelled or non-renewed.

Why it matters: If you ever sell the firm or wind it down, a 6-year tail option covers the long discovery window cyber claims can have. The reviewed policy tops out at one year.

CFC figures reflect an actual CFC Cyber Proactive Response v4.0 policy underwritten at Lloyd's and issued to a real estate brokerage for the 2025–26 policy year, reviewed page by page — the wording, the Declarations, and every attached endorsement. The insured's identity is withheld. The Arch program is shown at a $1,000,000 / $1,000 configuration; the reviewed CFC policy carries $1,000,000 limits with a $5,000 single aggregate deductible — a different deductible structure, noted rather than scored. The two policies were not issued to the same firm, so premium is not compared. CFC coverage options, endorsements, and limits vary by placement — where a coverage exists in the base form but was removed or excluded on the reviewed policy, we say so; in our experience this carrier frequently declines Cyber Crime coverage for real estate and title classes. Your policy's terms may differ, which is exactly why we recommend a review of your specific documents. CFC® and Cyber Proactive Response are trademarks of their respective owners; use here is for factual comparison only and implies no affiliation or endorsement.

Want this review done on your policy?

Send us your current cyber policy — declarations pages, the full form, and every endorsement — and we'll walk you through what's covered, what isn't, and what we'd do differently. No pressure, no obligation.

Request Your Cyber Policy Review
Eric Mauriello
Eric Mauriello
Cyber Insurance Coverage Lead
973-349-2194

WE RECOMMEND THAT YOU REVIEW ANY PROPOSAL WITH YOUR LEGAL COUNSEL AS PART OF YOUR DECISION MAKING PROCESS. THIS PAGE IS ONLY A HIGHLIGHT OF TERMS AND DOES NOT REPRESENT ALL TERMS IN THE POLICY LANGUAGE. YOU SHOULD MAKE ALL FINAL DETERMINATIONS ABOUT COVERAGE BASED ON THE ACTUAL POLICY LANGUAGE.

You'll be surprised how affordable the best can be.

Let PBI Group get you a quote — no fluff, no pressure, just a fair price for strong coverage.