Manufacturers often assume standard cyber policies focus on data breach and extortion. For factories and workshops running PLCs, SCADA and connected IoT sensors the more pressing issue is operational disruption, safety implications and physical damage driven by OT-specific vectors. This content explains how OT and IoT exposure changes insurability, what typical policy wordings may or may not cover, how interruption costs can be quantified, and which technical controls insurers typically expect. The explanation is UK-focused with links to official guidance and practical checklists for small and medium manufacturers to evaluate or discuss options with regulated advisers.
Key takeaways
- OT/IoT exposure often changes the loss profile: insurers view operational downtime, process failure and safety risk differently to IT-only incidents.
- Limits and sub-limits matter: business interruption and contingent supply chain loss for OT incidents frequently require higher or separate limits than standard cyber policies.
- Common exclusions appear for physical damage and safety events: many policies exclude deliberate manipulation of industrial processes unless specific wording is purchased.
- Practical controls improve insurability: segmentation, industrial firewalls, asset inventories and patch/maintenance evidence reduce premiums and refusals.
- SME vs microbusiness differences: smaller manufacturers may access tailored cover or endorsement add-ons; documentation is critical for any size.
How OT and IoT exposure changes cyber cover for manufacturers
Manufacturing environments introduce controllers, sensors and actuators that directly affect production and safety. Insurers assess these environments for both cyber and physical exposure: a malware infection on a corporate laptop is different from unauthorised writes to a PLC that stop a conveyor or compromise product quality. Underwriters will therefore seek details on the OT estate, maintenance windows, fail-safe measures and whether safety systems (SIS) are isolated. The presence of legacy protocols (for example Modbus, OPC UA, Ethernet/IP) and unsupported devices typically raises scrutiny, and insurers may ask for evidence of compensating controls or require specific endorsements to extend cover to process manipulation or physical damage.
Typical underwriting questions for OT/IoT
Underwriters often request an OT inventory, network architecture diagram, uptime metrics, evidence of segmentation between IT and OT, patching/maintenance regimes and supplier/third-party access controls. For SMEs this may be a short questionnaire but must include whether remote access to control systems is permitted, whether multi-factor authentication is enforced, and whether industrial firewalls or EDR-for-OT solutions are in place. Evidence of periodic third-party OT assessments or certifications (for example alignment with IEC 62443) can materially affect acceptability and price. Lack of such evidence often leads to narrower cover, higher excesses or refusal to insure OT-driven losses.
How insurers classify OT losses
Insurers commonly separate loss causes into: (a) data breach / privacy loss; (b) extortion and ransomware affecting IT systems; (c) operational disruption originating in OT/IoT; and (d) physical damage or safety events linked to malicious commands or faulty IoT devices. Policies frequently treat (a) and (b) as standard cyber events, while (c) and (d) may be excluded, limited, or require specific endorsements. For manufacturing SMEs, that classification affects whether business interruption cover will respond and whether physical damage or product recall costs are covered after an OT incident.
Choosing insurance limits for OT and IoT risks
Selecting limits requires assessing potential downtime costs and the likely duration of plant outage after an OT-related incident. For a small manufacturing unit, costs include lost production margin, labour standby, spoilage or scrappage, expedited recovery actions, third-party liabilities and potential regulatory fines where personal data or compliance failures are implicated. Estimates usually combine: (a) hourly or daily gross margin loss rates for each production line, (b) mean-time-to-recover (MTTR) projections for OT incidents, and (c) contingent supplier or customer penalties. SMEs often underestimate MTTR for OT because specialist ICS/OT recovery teams and spare parts lead times extend restoration.
Indicative approach to calculate BI limits (only for planning purposes)
A pragmatic, indicative method for SMEs is: list critical lines and their typical hourly gross margin loss; estimate a conservative MTTR (for OT incidents often 3–10 days depending on spare part and specialist availability); sum the product of hourly loss × MTTR across affected lines and add a contingency (20–50%) for recovery costs, remediation and third-party expenses. This result gives a starting point for the business interruption limit. Policies often have waiting periods and sub-limits for OT-related BI; these are important negotiation points during placement.
Sample comparative table of policy features for OT exposure
| Feature |
Standard SME cyber policy |
OT/IoT endorsed policy |
| Data breach cover |
Typically included |
Included |
| Ransomware affecting IT |
Typically included |
Included, with BI extensions |
| Operational loss from PLC/SCADA manipulation |
Often excluded |
Covered if endorsed; may need proof of controls |
| Physical damage to plant |
Usually excluded (property/machinery policy may apply) |
Possible inclusion with combined wording or parametric triggers |
| Supply chain/candidate liability |
Limited |
Extended but may have aggregate limits |

Common policy exclusions for OT/IoT in manufacturing
Many cyber policies were written with data-centred losses in mind and therefore include exclusions that can catch OT incidents. Typical exclusion categories include: physical damage or bodily injury resulting from cyber events; product recall or contamination claims unless specifically added; failure of firmware or firmware updates; wear-and-tear and gradual degradation; intentionally malicious acts by insured employees without proper controls; and cyber incidents affecting industrial control protocols. Some policies exclude losses arising from failure to maintain safety-critical software or from unauthorised remote access if multi-factor authentication was not enforced.
How to read and challenge exclusions
When assessing a policy, focus on the definitions: what constitutes a cyber event, what counts as physical damage, and how business interruption triggers are worded (is it ‘system unavailability’ or ‘production stoppage’?). Insurers may allow endorsements that narrow or remove exclusions for an additional premium if the insured can demonstrate robust OT controls and documented maintenance regimes. For SMEs lacking in-house documentation, commissioning an OT inventory and a short third-party attestation can materially affect the outcome.
Real-world OT/IoT claims and business interruption lessons
Several well-documented incidents worldwide show how OT intrusion cascades into extended downtime. For example, manipulated control system commands can cause immediate production stoppage, require forensic OT teams for safe restoration, and create extended validation periods for product quality. For small manufacturers, the primary financial impacts are lost sales, penalty clauses with buyers, costs of rushed product re-testing, and reputational loss that affects future contracts. Claims analysis commonly highlights two recurring weaknesses: inadequate segmentation between business IT and OT, and insufficient logging or monitoring in OT that prevents rapid incident detection.
Short case scenarios (anonymised, illustrative)
1) A small food manufacturer experienced a malware outbreak that crossed into a packaging line due to a shared VPN credential used for remote vendor maintenance. Production halted for five days; spoilage and expedited recovery doubled the initial estimated loss. The insurer covered data-related costs but refused full BI because the policy’s OT endorsement was not purchased. 2) A components supplier had a PLC firmware overwritten via an exposed engineering workstation. Restoration required a specialist vendor with a two-week lead time for a replacement board; losses exceeded standard cyber limits and required negotiation with underwriters who then applied a high excess.
Risk controls insurers expect for manufacturers
Insurers commonly look for evidence of the following controls: a maintained OT asset inventory, segmentation between IT and OT networks (with industrial DMZ), restricted remote access enforced by MFA and monitored VPN gateways, industrial-grade firewalls, application whitelisting for engineering workstations, scheduled and documented patch/maintenance procedures, incident response plans that include OT-safe recovery steps, and regular OT vulnerability assessments. For SMEs, insurers often accept pragmatic implementations when documented, for example, proof of segmented VLANs, a log of maintenance windows and records from a managed service provider showing patching and backups.
Mapping controls to insurability and premium impact
- Asset inventory and segmentation: often reduces refusal risk and can lower premiums. - Documented third-party access controls and MFA: reduces likelihood of exclusions for remote access incidents. - Regular OT testing or IEC 62443 alignment: may allow wider coverage or reduced sub-limits. - Incident response plans with OT-safe recovery steps and evidence of tabletop exercises: improves claim outcomes and may reduce waiting periods. Evidence of these controls is usually more influential than purchasing expensive technology alone.
GDPR, regulation and insurer expectations for manufacturers
Manufacturers handling personal data (staff records, customer details, CCTV footage) remain subject to the UK GDPR and ICO obligations. Insurers expect data protection basics, data minimisation, retention policies, breach notification processes and staff training, and may ask for evidence of incident reporting processes in the event of personal data loss. Separately, supply chain and critical infrastructure rules are shifting: NIS Regulations and EU-derived NIS2 in cross-border contexts affect larger suppliers, but SMEs in manufacturing should monitor requirements and sector guidance. Official guidance from the UK National Cyber Security Centre is often cited during underwriting and can be referenced: NCSC. For data-specific duties, refer to the Information Commissioner's Office: ICO.
Certifications and standards that matter
Standards such as IEC 62443 and ISO/IEC 27001 (with OT adaptations) are persuasive to underwriters. Evidence of adherence or third-party audits shows a mature control posture. For regulatory changes and government guidance, the UK Government publications and sector-specific guidance for critical suppliers can be relevant: GOV.UK. While certification does not guarantee cover, it frequently reduces negotiation friction and can broaden policy wording options.
How cover differs for microbusinesses and SMEs with OT
Microbusinesses (1–10 employees) often run simpler OT estates but have limited documentation and budget for controls. Insurers may offer standard cyber products with optional OT endorsements or require a higher excess. SMEs with 11–50 employees may have more complex OT systems and therefore face more thorough underwriting; however, they also tend to be able to invest in compensating controls and independent attestations, which helps placement. For both groups, clarity and evidence are decisive: a short, clear OT asset register and a simple network diagram frequently unlock better terms than expensive but undocumented security tooling.
Practical differences in placement and cost drivers
Placement for microbusinesses often relies on standardised SME cyber products with minimal bespoke wording; expect narrower OT cover and lower limits unless specific endorsements are purchased. For mid-sized SMEs, bespoke placement and broking expertise are more common, and premiums reflect detailed risk features: remote access policies, third-party vendor controls, and historical maintenance records. Cost drivers include estimated MTTR, number of remote access points, history of IT/OT incidents, supply chain dependencies, and evidence of business continuity provisions.
OT/IoT exposure quick visual
Severity →
Low
(Isolated sensors)
Medium
(Remote access, shared networks)
High
(Legacy PLCs, vendor remote control)
Priority actions
- Segment IT/OT and secure remote access
- Document assets and maintenance regimes
- Obtain OT-ready endorsement if exposure > medium
Strategic analysis: pros and cons of adding OT endorsements
Pros: adding an OT endorsement expands coverage to realistic manufacturing risks, reduces reliance on property or product liability policies for cyber-rooted physical loss, and shortens disputes at claim time when wordings are clear. Cons: premiums rise, insurers may apply more restrictive warranties or higher excesses, and claims may be subject to detailed post-incident forensic review. The decision to add endorsements depends on the financial exposure (estimated BI and potential safety impact), the ability to evidence controls, and the cost-benefit analysis comparing investment in controls against increased premium or uninsured risk.
Checklist for manufacturers preparing for underwriting (download and adapt)
- Maintain an OT asset register (device type, vendor, firmware, location). - Provide a simple network diagram showing IT/OT segmentation and remote access points. - Document patch and maintenance schedules and third-party vendor access logs. - Show incident response plan with OT recovery steps and contact list for OT specialists. - Supply records of tabletop exercises, certifications, or assessments (IEC 62443 or independent OT reviews). - Estimate hourly loss rates per critical production line and a conservative MTTR for OT incidents.
Short templates and next steps
Documenting the above points typically takes less than a few days for most SMEs and significantly improves underwriting outcomes. Evidence-based documentation often leads insurers to offer higher limits or remove narrow exclusions. Where in-house capability is lacking, consider a short engagement with an OT-focused assessor for a one-page attestation to present during placement.
Infographic
Manufacturing OT/IoT incident flow → impact & cover
Initiation
Unauthorised command, firmware corruption or compromised vendor access
Operational impact
Production stops, quality defects, safety system trips
Financial consequences
BI loss, spoilage, recall, contractual penalties
Key insurance check: is the incident defined as a cyber event or as physical damage? Read policy triggers carefully.
FAQ
What specific OT devices should be included in the asset register?
Include PLCs, RTUs, SCADA servers, HMIs, engineering workstations, OT gateways, industrial sensors, actuators and any IoT devices tied to production. Firmware versions and vendor support status are important.
Can a standard cyber policy cover physical damage caused by a hacked PLC?
Some policies include physical damage if an appropriate endorsement is purchased, but many standard cyber policies exclude such losses; property or machinery insurance may also be relevant depending on wording.
How much does OT endorsement typically add to premium?
Costs vary widely depending on exposure and controls; endorsements can increase premium materially for high-exposure environments. Exact figures depend on underwriter assessment and evidence provided.
Are voluntary standards like IEC 62443 recognised by insurers?
Yes. Evidence of alignment with IEC 62443 or third-party OT assessments is persuasive and often improves access to broader cover or better terms.
How should an SME estimate MTTR for OT incidents?
Estimate conservatively by considering specialist vendor lead times, firmware replacement windows, validation/testing and regulatory checks. SMEs often use 3–10 days as an initial planning range depending on spare parts and specialist access.
Will insurers accept a single-page OT network diagram?
Yes. A clear, accurate single-page diagram that shows segmentation, remote access points and critical lines is often sufficient as initial evidence for underwriting.
What role do third-party vendors play in underwriting?
Third-party remote access, maintenance contracts and vendor security posture are material. Insurers often require details of vendor access controls and may apply conditions or endorsements if vendor risk is significant.
Is notification to the ICO required for OT incidents?
If the incident involves personal data loss or a personal data breach that risks individuals’ rights, notification to the ICO may be required. For guidance, see the ICO: ICO guidance.
How often should OT controls be reviewed for insurance purposes?
Annual reviews are common, with focused updates after any significant change (new vendor, remote access addition, or equipment upgrade). Evidence of ongoing review is useful for underwriting.
Conclusion
Action plan, three practical steps (<10 minutes each)
1) Create a one‑page OT asset list: device type, firmware, vendor and location. This can be built from plant floor labels and vendor invoices.
2) Draw a simple network diagram: mark the IT/OT boundary, remote access points and the location of critical lines. Use a tablet or paper sketch and photograph it.
3) Email or save evidence of recent maintenance or vendor access logs (last 6–12 months) to show active upkeep. These three items improve underwriting outcomes and typically take under 30 minutes total to assemble.
Manufacturing SMEs with OT/IoT exposure benefit from evidence and pragmatic controls: documentation, segmentation and clear recovery plans often unlock better cover without excessive cost. For decisions about cover levels, wording interpretation or regulatory compliance, consult a regulated insurance or legal professional.