Are manufacturers frustrated by insurance policies that ignore the realities of connected factories? Does uncertainty about PLCs, SCADA and GDPR fines make renewal meetings stressful? This guide explains, in plain English, how cyber insurance interacts with IoT/OT risks for UK manufacturing SMEs and what matters when comparing policies.
Key points for cyber insurance for manufacturing SMEs with IoT/OT exposure in one minute
- Who needs specific IoT/OT cover: any SME using PLCs, SCADA, industrial sensors, robotics, or third‑party-managed OT that affects safety, production or customer data. Not every factory is the same; exposure depends on connectivity and process criticality.
- What policies typically cover and often exclude: standard cyber policies cover data breaches and incident response; many exclude physical damage, business interruption to OT (CBI) and unpatched legacy OT unless specifically endorsed. Watch for silent cyber wording and physical damage sublimits.
- Real costs are larger than IT-only incidents: ransomware or manipulation of OT can cause prolonged production stoppages, regulatory fines (ICO/NIS2) and repair costs running into tens or hundreds of thousands for SMEs. Examples below quantify typical ranges.
- Premium drivers and hidden costs: number of internet‑connected devices, legacy ICS/PLC systems, remote access, third‑party maintenance, lack of segmentation and absence of reactive plans increase premium and sublimits. Insurers request evidence.
- How to choose a policy quickly: use the checklist at the end, prepare an asset list, evidence of controls (network segmentation, backups, access control), incident plan and basic OT hardening to improve chances and reduce price.
Who in UK manufacturing needs IoT/OT cyber cover and why it differs from office IT
Manufacturing SMEs that should expect specific IoT/OT underwriting questions include those operating any of the following:
- PLCs, RTUs or DCS controlling production lines.
- SCADA dashboards with remote supervisory control or remote telemetry.
- Robotic cells, CNCs, additive manufacturing with networked controllers.
- IoT sensors tied to quality control, inventory or environmental systems (temperature, humidity) where failure causes spoilage or safety hazards.
- Third‑party hosted OT/edge platforms or managed services that integrate with production.
Why underwriting differs from IT:
- OT often affects physical processes: a cyber event can cause plant damage or safety incidents rather than only data loss. This raises potential claims for physical damage, product spoilage and third‑party liability.
- Many industrial controllers run legacy firmware that cannot be patched frequently, so insurers treat them as higher risk.
- Remote access for engineers and third‑party maintenance is common in manufacturing and increases attack surface, insurers will ask about VPNs, multi‑factor authentication (MFA) and vendor access controls.
- Loss metrics differ: business interruption is measured in lost production hours and potential contract penalties rather than pure revenue lost from a website outage.
Implications for SMEs:
- Policies written for office IT may not respond to OT impacts. Typical consequences include declined claims for physical damage or reduced settlement due to sublimits.
- NIS2 and other supply‑chain expectations increasingly push insurers to treat manufacturers as part of critical infrastructure; disclosure of OT connectivity at quotation stage matters.
Case study summaries are illustrative and indicative at time of writing.
Example 1: ransomware encrypts production SCADA (small food manufacturer)
Sequence: attacker gains access via an engineer's compromised remote access tool → ransomware spreads to HMIs and SCADA historian → line controllers stop responding → production halted for 5 days.
Costs (indicative):
- Incident response and forensic: £18,000–£35,000
- Emergency engineering and PLC reprogramming: £20,000–£60,000
- Business interruption (lost output + spoilage): £75,000–£200,000
- Regulatory and customer mitigation (notifications, testing): £10,000–£30,000
- Total claimed/real cost range: £120,000–£325,000
Key points: insurers often contest whether the root cause sits within insured cyber perils (malicious code) or a physical fault; clear forensic trail and rapid containment evidence matter.
Example 2: attacker manipulates sensor setpoints causing product spoilage (pharmaceutical contract manufacturer)
Sequence: insecure IoT sensor gateway exposed to the internet; attacker adjusts temperature thresholds unnoticed for 36 hours; batch quality fails; recall and contract penalties follow.
Costs (indicative):
- Product recall and disposal: £60,000–£150,000
- Third‑party liability (client compensation): £30,000–£120,000
- Business interruption and contract penalties: £40,000–£200,000
- Compliance and regulatory review (possible MHRA/ICO involvement depending on data): £20,000–£50,000
- Total: £150,000–£520,000
Sequence: supplier's remote monitoring platform compromised; malicious firmware update pushed to connected welders, causing stoppage across multiple subcontracted sites; insurer receives complex multi‑insured claims.
Costs and implications (indicative):
- Multi‑site business interruption: £50,000–£350,000
- Complexity increases forensic and subrogation costs: £30,000–£100,000
- Potential legal costs for contractual disputes: £25,000–£120,000
Why these examples matter:
- Even SMEs can face six‑figure losses from OT compromise.
- Insurers will probe connectivity, patching practices and contract terms with vendors; gaps here drive denials or sublimits.

What typical policies cover: OT exclusions, physical damage, contingent BI and GDPR fines
A standard SME cyber policy usually includes:
- Data breach response costs (forensics, notification, credit monitoring where required).
- Business interruption tied to insured cyber event (IT-related loss) with a monetary hourly/daily limit.
- Ransom payments (often subject to approval and legal constraints).
- Cyber extortion and reputational PR support.
- Legal defence costs and regulatory fine response costs (subject to sublimits and local law).
Commonly seen exclusions and limitations for OT exposure:
- Physical damage exclusion: many policies exclude physical damage to plant, machinery and equipment caused by cyber events unless a specific endorsement is purchased. Without that endorsement, insurers may decline claims where malware caused actual hardware failure.
- Silent cyber wording: some property policies exclude cyber‑caused losses and insurers may expect cyber policies to fill that gap. Clarify interaction between property, PL and cyber policies.
- Contingent business interruption (CBI): interruption due to supplier or customer cyber events may be sublimited or excluded. Manufacturing SMEs that depend on a cloud OT platform should check for CBI cover and sublimits.
- Legacy/unsupported systems: insurers typically require declaration and sometimes additional conditions or higher excess for legacy OT.
- War/terror and nation‑state exclusions: advanced persistent threats may be treated differently; many policies carve out or limit state‑sponsored acts.
GDPR and regulatory fines:
- Under GDPR, the ICO can impose fines for personal data breaches; cyber policies sometimes respond to the cost of regulatory defence and in some cases fines/penalties, but this varies. In the UK, FCA and ICO guidance have changed wording over time; confirm current insurer stance.
- Many insurers will cover regulatory response costs (legal defence, investigation) but exclude or cap statutory fines unless specifically stated. For manufacturing SMEs handling employee/contractor or customer data, this nuance is critical.
Practical implications:
- Do not assume a standard cyber policy will pay for plant repair or physical replacement. If controlling OT risks is core to the business, seek endorsements for physical damage and product recall coverage.
- Expect insurers to require evidence of controls (network segmentation, air gaps where used, restricted vendor access, up‑to‑date backups, incident plans).
Premium drivers and hidden costs for IoT-enabled SMEs (what increases price beyond payroll/revenue)
Primary premium drivers specific to IoT/OT exposure:
- Number and type of connected OT devices: hundreds of thin‑client IoT sensors vs a handful of isolated PLCs have very different risk profiles.
- Remote vendor/third‑party access: frequent third‑party maintenance or cloud‑connected OT platforms raise premiums and conditions.
- Use of legacy or unsupported control systems: evidence of mitigation for unpatchable devices reduces premium impact.
- Lack of segmentation between IT and OT networks: insurers favour micro‑segmentation, air gaps or industrial DMZs.
- History of incidents and frequency of near misses.
Hidden or less obvious costs:
- Excesses and deductibles tied to OT claims: insurers may specify separate excess for physical damage or CBI.
- Sublimits for specific cover types (GDPR fines, forensic costs, product recall) that reduce paid amounts even when policy limits appear large.
- Premium loading after an incident and potential mid‑term underwriting adjustments.
- Requirement to purchase additional endorsements (firms often discover they need to add physical damage, CBI, or supplier failure endorsements).
- Increased claims handling complexity and legal fees when OT and IT overlap, raising the insurer's internal cost allocation which may affect renewals.
How to reduce premium impact:
- Document OT architecture: clear asset inventory and evidence of controls often lead to better terms.
- Implement basic OT hygiene: restrict remote access, enforce MFA for vendor logins, maintain offline backups of critical control logic.
- Use recognised standards: IEC 62443 compliance efforts, or evidence of following NCSC and NIS2 guidance, can be persuasive during underwriting.
Comparing cyber policies: stand-alone cyber vs packaged manufacturing cover (detailed comparison)
| Feature |
Stand‑alone cyber policy |
Packaged manufacturing policy with cyber add‑on |
| Typical focus |
Data breach, IT systems, incident response |
Property, physical damage, product liability; cyber often sublimited |
| Physical damage response |
Usually excluded unless endorsed |
May include physical damage but often excludes cyber‑caused damage unless explicit |
| Contingent business interruption |
Available as specific extension |
Often not included or limited; requires explicit wording |
| Regulatory fines / defence |
Commonly included subject to wording |
Variable; property packages rarely cover regulatory cyber costs |
| Suitability for OT risk |
Better base but needs OT endorsements (physical damage, CBI) |
Good for integrated property/cyber if cyber wording is strong |
| Underwriting depth for OT |
Specialist cyber underwriters ask detailed OT questions |
May be handled by generalist underwriter; less OT expertise |
| Cost for SME |
Can be higher if many endorsements required |
May appear cheaper but can leave gaps and hidden sublimits |
Practical comparison and recommendation (neutral):
- Stand‑alone cyber policies are usually underwritten by cyber specialists who will probe IoT/OT exposures and can offer targeted endorsements (physical damage, CBI, product recall). They are appropriate when OT presents material cyber‑caused risks.
- Packaged manufacturing policies can be suitable when property and machinery risks dominate and the cyber exposure is minimal or already well mitigated. However, many package policies have weak cyber wording and may rely on cyber add‑ons with sublimits.
- For SMEs with connected production assets, the safest neutral approach is to obtain a stand‑alone cyber quotation that includes specific OT endorsements and then compare how a packaged policy would respond to the same scenario (ask hypothetical claim scenario questions during renewal).
What insurers will ask: typical underwriting questions for OT exposures
- Inventory of connected OT/IoT devices and details of PLC/SCADA vendors.
- Details of remote access methods and vendor access protocols (VPN, MFA, jump servers).
- Evidence of network segmentation and industrial DMZ implementation.
- Patch and change management processes for OT, including frequency and compensating controls for non‑patchable devices.
- Incident response plan specific to OT and contact details for access to on‑call engineers.
- Details of backups (are PLC logic backups kept offsite and air‑gapped?) and recovery testing records.
- Third‑party contracts for OT maintenance and liability allocation.
Providing clear documentation ahead of quotation reduces follow‑up requests and can materially improve quotations.
Practical checklist: choosing the right policy for OT risk
Things to prepare before talking to insurers
- Asset list: inventory of all IoT/OT devices, hostname/IP, vendor, model, firmware age.
- Network diagram: show segmentation between IT, OT and vendor access points.
- Incident playbook: named responders, contact details for OT engineers, backups and recovery steps.
- Evidence of controls: MFA for remote access, documented patching exceptions for legacy devices, air‑gapped backups of PLC logic.
- Contracts and SLAs with suppliers: who controls firmware updates and who bears what liability.
Policy comparison checklist (questions to ask each insurer)
- Does the policy exclude physical damage caused by cyber incidents? If yes, what endorsement covers it and at what cost?
- Is contingent business interruption due to supplier/customer cyber event included? What sublimit applies?
- Are regulatory fines and defence costs for GDPR included or sublimited/excluded?
- Are there specific sublimits for product recall, supplier failure, or forensic costs? What are those limits?
- How is war/nation‑state activity treated? Is there a clarification for APTs?
- What excess applies to OT‑related claims (physical damage, CBI)?
- Does the insurer require specific controls as conditions precedent to cover or as warranties (e.g. network segmentation verified)?
OT risk assessment flow
OT risk assessment flow
🔍 **Step 1** → ⚙️ **Step 2** → 🛡️ **Step 3** → ✅ **Outcome**
- 🔍 Map devices: list PLCs, HMIs, sensors and remote connections.
- ⚙️ Score exposure: internet-connected? vendor access? safety-critical?
- 🛡️ Mitigate quick wins: restrict remote access, enable MFA, isolate OT VLANs.
- ✅ Insure smartly: present evidence to underwriters and seek OT endorsements.
Balance strategic: the trade-offs of insuring OT risk vs self‑retaining risk
When insurance is the best option ✅ (high‑impact scenarios)
- When OT failure causes safety risk, large product loss, or contract penalties that exceed the business’s ability to absorb losses.
- Where customers or regulators demand demonstrable transfer of cyber risk (supply‑chain requirements, NIS2 obligations).
- When remote vendor access and cloud OT platforms create exposure to supplier cyber incidents.
What to watch for, red flags ⚠️ (where insurance may not help)
- Policies that look cheap but have tight sublimits for physical damage or CBI may leave the SME exposed to major uncovered costs.
- Non-disclosure or poor documentation of OT architecture can lead to mid‑term cancellations or claim disputes.
- Reliance on a packaged policy without a clear cyber wording that addresses OT incidents.
Dismissed myths and common errors (quick corrections)
- Myth: "Property insurance will pay for any cyber‑caused machinery damage." Reality: many property policies have specific cyber exclusions; confirmation needed.
- Error: failing to declare remote vendor access or cloud OT services at quote time; this often leads to repudiation or downgraded cover at claim time.
- Myth: "Small size means low risk." Reality: a single halting incident can cost an SME more than its annual profit.
Cyber insurance for manufacturing SMEs with IoT/OT exposure
How does cyber insurance treat PLCs and SCADA?
Cyber policies treat PLCs and SCADA as high‑risk OT assets that may cause physical damage or prolonged BI; insurers will require details and may exclude physical damage unless endorsed. Providing segmentation and backups reduces friction.
Why do insurers ask for network diagrams?
Insurers ask to assess segmentation, vendor access, and integration points; diagrams show whether OT is properly isolated from IT and internet‑facing services.
What happens if a supplier’s IoT service causes downtime?
Coverage depends on contingent business interruption wording; many policies limit or exclude supplier‑caused losses unless CBI is explicitly purchased. Check sublimits carefully.
Can cyber insurance cover ICO fines for data breaches?
Some policies cover regulatory defence costs; cover for statutory fines varies and is often limited or excluded. Confirm the policy wording and applicable law.
How much does OT endorsement typically add to premium?
There is no single figure; endorsements depend on exposure and controls. Indicative uplift can range from a small percentage for well‑controlled setups to large increases for risky, internet‑exposed OT. Prepare documentation to reduce uplift.
What evidence speeds up underwriting for OT risks?
An asset inventory, network diagram, vendor access policy, backup proof and simple penetration or vulnerability test results are the most persuasive documents.
Which standards help when negotiating cover?
Demonstrable alignment with IEC 62443, NCSC guidance and NIS2 readiness helps; show certification or progress on remediation where possible.
Conclusion: long‑term benefits of aligning insurance with OT risk
Manufacturing SMEs with IoT/OT exposure that treat cyber insurance as part of a broader operational resilience plan gain tangible advantages: clearer risk transfer, stronger supplier credibility and faster recovery after incidents. Aligning technical controls, vendor management and insurance wording reduces surprises at claim time and helps protect continuity of production.
First steps to take today
- Create a one‑page asset map of connected OT devices and remote access points (10 minutes).
- Confirm offline backups of PLC/HMI logic and store a copy offsite or air‑gapped (under 10 minutes to verify existence).
- Email a simple network diagram and the vendor access policy to the chosen broker or underwriter to start a targeted quotation.