How much would an hour of halted production cost? For a UK SME with 1–50 staff the answer can be thousands in lost output. It can also mean emergency repairs and damaged customer trust.
Owners and directors without in-house cyber knowledge face prolonged business interruption. They also face the risk of GDPR fines and reputational harm that can outlast the outage. Quick, informed insurance decisions matter.
Manufacturing and OT systems need specific cyber insurance because standard policies often exclude industrial control outages and physical-damage claims.
UK SMEs should seek cover that names ICS and SCADA and that names ransomware. They must also check that business interruption cover applies to OT. Insurers should also pay incident response costs.
Map OT assets first. Document safety controls next. Ask brokers for OT-specific endorsements and premium estimates to cut downtime and contain claim costs.
Which policy will protect your plant?
An SME plant needs a policy that names OT and ICS incidents clearly. The policy must also state how business interruption for production lines is measured.
Many standard SME cyber policies exclude OT business interruption and physical damage unless an endorsement appears. Insurers expect an OT asset inventory, a segmentation diagram and evidence of safety-integrated incident response.
What an OT endorsement looks like
An OT endorsement adds first-party cover for controller damage and physical loss. It also adds OT-related business interruption cover.
The endorsement should name SCADA, PLCs and RTUs in the policy wording. Without that wording insurers may decline OT claims.
Questions to give your broker
Give a list of PLCs and HMIs, a segmentation diagram, backup test reports and vendor remote access logs. Ask for explicit sub-limits for physical damage and for BI days.
Request the retroactive date and any special warranties. These items shape whether a claim will pay.
How underwriters verify cover
Underwriters review documentation, not sales language. They may ask for recent OT test restores, screenshots of firewall rules and a vendor access register.
A weak submission will raise the premium or lead to declined cover.
Check these items before you sign renewal.
Standard SME cyber policies usually cover IT incidents like ransomware and extortion. They often pay forensic costs and notification expenses.
These policies typically exclude physical damage to plant and extended OT production loss unless an OT endorsement is purchased. Policy wordings vary, so check extortion and forensic limits. Check business interruption definitions and any OT endorsements carefully.
Typical first-party cover
Common first-party items include extortion payments, forensic investigations and IT or data restoration. Policies may also pay crisis PR and regulatory defence for data breaches.
Many insurers apply sub-limits to ransom and response costs. Check those limits closely.
Typical third-party cover
Third-party cover often includes liability for personal data breaches and legal defence costs. Regulatory fines under UK GDPR may be excluded or limited.
Insurers take ICO guidance into account when assessing ransomware incidents. ICO guidance
Typical OT exclusions and insurer expectations
Most standard policies exclude physical damage caused by manipulation of control systems and failures of safety systems. Losses where vendor remote access was undisclosed are frequently excluded.
Insurers expect evidence of safety backups, control-system patching, network segmentation and other OT controls when assessing cover or offering endorsements.
What to do now: practical steps for placement
Map your OT estate and compile the broker checklist and all evidence in a single folder. Ask your broker for an OT endorsement summary and get at least two insurer quotes.
Make sure each quote states whether physical damage and BI sub-limits apply. If unsure about exposure or controls, commission an OT risk scan focused on segmentation, backups and remote-access governance.
Give the insurer dated evidence such as segmentation diagrams, vendor access logs, backup test reports and a short incident-response plan. Many insurers may offer reduced loadings or better terms when key controls are verifiably in place.
Any premium reduction depends on the insurer, the market cycle and the quality of the evidence. Verifiable controls strengthen submissions but do not guarantee a premium cut.
What drives premiums in manufacturing
Underwriters price manufacturing risk by measurable factors such as days of BI exposure and revenue at risk per day. They also look at OT endpoint count, remote access exposure and past incidents.
Market practice shows premium loadings rise when these factors are poor. Loadings can vary widely, commonly by ten to fifty percent for identified weaknesses in submissions (market consensus 2024).
Underwriters request annual revenue, estimated production loss per day in pounds and the number of PLCs and RTUs. They also ask for days to restore from backups.
They want the number of vendor remote connections and the patching frequency. These inputs directly shape BI sub-limits and the premium.
How specific metrics change price
A plant with £100k revenue-at-risk a day will need larger BI limits than one with £10k a day. Historical ransomware incidents in the past three years typically increase rates and may limit cover.
Underwriters often reduce price when firms show test restores within twenty-four to seventy-two hours.
Visual decision process
Map OT assets → list PLCs, HMIs, SCADA servers
Show segmentation → produce VLAN/ACL diagram
Prove backups → encrypted offline tests
Disclose remote vendors → logs + MFA proof

Broker checklist for OT underwriting
A successful broker submission must include an OT asset inventory, a network segmentation diagram, remote-access logs, safety interlock documentation, backup test records and incident history. Failing to provide these items is the most common reason for declined OT cover.
Clear, dated evidence cuts underwriting time and reduces the premium.
Minimum documents to prepare
Prepare a list of PLC and SCADA hardware with vendor and model numbers. Include network diagrams showing firewalls and VLANs.
Provide backup test reports with dates. Add vendor remote access agreements and a register of IPs.
Common disclosure errors
The error most frequent at renewal is saying that remote access exists without session logs and MFA proof. Another common mistake is claiming a patch cadence that has no records.
Underwriters treat missing documents as material non-disclosure.
How to present evidence to underwriters
Use dated screenshots, test restore logs and a short cover letter that maps each document to underwriter questions. Highlight any ISO or Cyber Essentials Plus evidence.
This approach speeds assessment and limits requests for more information.
Check these items before you sign renewal.
OT incident playbook for SME plants
An OT incident playbook must prioritise safe plant operation and isolate affected controllers. It must also preserve forensic evidence.
Notify your insurer promptly. Many insurers expect early notification, often within twenty-four hours.
Notify regulators according to legal requirements when personal data is involved. The ICO normally expects notification within seventy-two hours of becoming aware of a breach.
Acting fast preserves cover and limits damage. The playbook must be simple, role-based and practised.
Within zero to six hours isolate the affected network segment and put impacted lines into safe manual mode if possible. Within six to twenty-four hours notify the plant manager, broker and insurer and engage an OT forensic investigator.
Record all actions and timestamps for the claim.
Evidence preservation steps
Do not reboot suspected PLCs without forensic advice. Make bit-stream backups of controller memory when safe.
Collect logs, take photographs of the plant floor and keep chain-of-custody records for hardware moved offsite. Failure to preserve evidence often leads to disputed claims.
Recovery and return to service
Perform test restores in an isolated lab before returning systems to live production. Document restore times and any configuration changes.
Run a controlled start sequence and watch safety interlocks closely for at least seventy-two hours after restart.
Operational technology and industrial control systems demand specific, technical mitigations that sit between IT best practice and factory engineering. Practical PLC security measures include restricting programming ports and removing or changing default accounts.
Apply firmware hardening where vendor guidance permits and keep an auditable record of patch windows that respect safety testing. When patching is impossible during production use compensating controls like network allow-listing and protocol gateways.
Read-only replicas of HMI data and strictly controlled vendor jump hosts with session recording substantially reduce exploit paths.
Air-gaps remain an option for the most critical controllers, and segmentation should be validated with measured rule-sets. Occasionally run red-team tests of vendor remote access.
These steps reduce the attack surface while preserving safe operations.
Realistic claim cost ranges for manufacturers
Reasonable UK SME claim ranges are: £20k–£200k for IT-only ransomware. £100k–£2m for OT incidents with production loss. In extreme cases costs can exceed £5m for complex equipment replacement and market losses (estimates 2023–2024 broker panels).
These ranges show why separate OT limits matter.
IT-only ransomware costs
IT-only events commonly cost between £20k and £200k for forensic work, data restoration and PR. The range depends on ransom demands and restoration time.
Regulatory costs may add further expense.
OT damage and extended BI costs
OT incidents that damage PLCs or HMIs, or that require long shutdowns, often cost £100k–£2m for repairs and lost production. Complex replacements or specialist engineering can push costs above £5m.
Confirm whether the policy applies separate sub-limits for physical damage and BI.
Example
An anonymised Midlands metalwork SME had a manipulated PLC that halted production for five days. The incident cost about £350,000 in lost output and repairs.
The insurer applied a physical damage sub-limit that left the firm with a six-figure uninsured shortfall. This case underlines why disclosure and OT endorsements matter.
Manufacturers often ask for clearer premium and limit expectations. As a practical benchmark for 2024 UK market practice, micro manufacturers with annual revenue under about £1m and limited production-at-risk may see IT-only BI premiums from about £500 to £3,000.
Adding OT endorsements and modest BI limits can lift renewal premiums into the £2,000–£10,000 band depending on evidence and revenue-at-risk. Small plants with visible production risk (£10k–£100k revenue-at-risk per day) typically face OT-enabled policies in the £5,000–£25,000 range with BI sub-limits sized to seven to thirty days.
Mid-sized manufacturers with higher daily exposure will see proportionally higher premiums and may require layered limits or parametric endorsements. These ranges vary by sector, historic incidents and verifiable controls, but give brokers and owners a starting point when budgeting for OT cover.
Clauses that void OT claims
Clauses that most commonly void OT claims include undisclosed vendor access, inaccurate warranties about patching, retroactive date gaps and failure to maintain offline backups. Brokers and insureds often miss these details and then face declined claims.
Read policy exclusions line by line.
Vendor access and non-disclosure
If vendor remote logins were not disclosed insurers can refuse OT claims citing non-disclosure. Keep a vendor access register and submit it at renewal.
This simple step prevents a common cause of denial.
Retroactive dates and continuous cover
Retroactive date gaps exclude losses that trace back before the insured period. Check the retroactive date and whether continuous cover is required for entitlement.
Many SME directors miss this when changing brokers.
Warranty wording traps
Warranties such as "all OT endpoints patched within thirty days" must be true and provable. If that statement is not true insurers can invoke warranty breaches to decline a claim.
Provide patch logs and remediation tickets.
Low-cost controls that lower premiums
Four measurable, low-cost controls underwriters accept are segmentation with deny-by-default rules, MFA for vendor access, daily encrypted offline backups with test restores and a documented OT incident plan tied to safety procedures. Evidence of these controls often reduces the premium and improves insurability.
Segmentation in practice
Implement VLANs with ACLs between IT and OT and document firewall rules. Provide a simple diagram and last review date to the broker.
Underwriters favour deny-by-default designs.
Backup and restore evidence
Keep daily encrypted offline image backups and run quarterly test restores with dated logs. Submit the test dates and restore times to underwriters.
Test restores that finish within twenty-four to seventy-two hours materially reduce perceived BI risk.
Access controls
Require MFA for all vendor remote access and retain session recordings for at least ninety days. Provide MFA logs and vendor IP lists at renewal.
This control directly addresses the most common entry vector.
Not relevant when the SME has no OT or industrial control assets (purely office IT or cloud-only operations) or when regulatory regimes require bespoke contractual insurance for essential services. In those cases seek sector-specific insurance advice rather than OT general guidance.
You can ask your broker for a short OT submission pack (one A4 per item listed above) and an insurer summary showing OT endorsements and sub-limits before you sign renewal.
Safety engineering and cybersecurity must be presented as a single assurance story for both operations teams and insurers. Functional safety frameworks like IEC 61508 and IEC 61511 govern safety instrumented systems and lifecycle activities.
IEC 62443 provides OT cybersecurity requirements. Align the safety lifecycle with cyber risk assessments by mapping safety-critical logic to threat models and by showing tested safety interlock behaviour after cyber events.
Demonstrate documented change control that includes safety sign-off and show that cyber incident response drills include safety teams. Insurers pay attention when a plant can show joint testing records where safety-critical controllers are exercised after security changes.
Showing integrated safety and OT cybersecurity practises reduces ambiguity about whether a controller failure is a safety incident, a cyber incident, or both. It clarifies coverage needs for physical damage and production downtime costs.
Frequently asked operational questions
What is the difference between IT and OT?
IT manages data, networks and business systems; OT controls physical processes like conveyors and PLCs. IT updates happen weekly or monthly; OT patching is slower and must consider safety. This difference drives separate insurance and incident response needs.
Does cyber insurance cover ransomware?
Many policies cover ransom payments and incident response but often with caps and conditions. Check for extortion sub-limits and whether ransom payments require forensic confirmation or law enforcement contact.
How much does cyber insurance cost for a small SME?
Typical UK SME premiums range from about £500 to £5,000 annually for IT-only cover; OT exposure raises premiums significantly depending on revenue-at-risk and controls. Exact prices depend on BI days, past incidents and evidence submitted (2024 market guidance).
Does cyber insurance cover operational technology?
It does so only when the policy explicitly endorses OT and ICS incidents or includes physical damage and OT BI sub-limits. Absent those endorsements OT damage and extended production loss are often excluded.
How can manufacturers reduce cyber insurance costs?
Give segmentation diagrams, MFA logs, backup test records and an OT audit or ISO/IEC 62443 evidence. Underwriters accept these items as proof and they usually reduce loading and improve insurability.
What is an IT/OT SOC and why do I need one?
An IT/OT SOC monitors IT and industrial alarms centrally and reduces detection time. Faster detection shrinks BI days and can lower insurer risk estimates. For SMEs, outsourced SOCs often balance cost and benefit.
What should be included in an OT incident plan?
Include isolation procedures, safe manual operation steps, evidence preservation, insurer and regulator notification timelines within twenty-four hours and contacts for OT forensic responders. Practise the plan annually.