A standard cyber policy usually does not fully cover OT/IoT risks in manufacturing. Ask for a specific endorsement or hybrid property/cyber wording if OT affects safety or production.
If time is tight, get a written carve-in and a conditional premium quote at least 30 days before renewal.
Which UK manufacturers qualify for standard cyber policies?
Most manufacturers that only use office IT and keep OT isolated can fit standard cyber policies. This works when OT does not affect safety or production.
Manufacturers with on-site PLCs, SCADA or safety systems usually need more than a standard cyber policy. Insurers treat OT as a physical risk that can cause property loss and safety incidents.
The Insurance Act 2015 creates a duty to present risks fairly when applying for cover. The applicant must disclose OT assets and known vulnerabilities or the insurer may refuse cover.
To be clear.
What defines "Limited OT" for insurers?
Insurers call OT "limited" when devices cannot control hazardous processes or safety systems. Simple sensors that only report temperature often qualify as limited OT.
If a device can change machine behaviour, insurers treat it as OT that raises the bar for cover. Underwriters will then ask for OT controls and may add exclusions or sublimits.
Which policy type usually fits small makers?
Small makers with minimal OT often fit a standard cyber policy with modest premiums and basic BI cover. This assumes OT is clearly segregated and cannot control machines.
If OT affects production or safety, brokers usually seek a hybrid policy or a bespoke endorsement. Tailored wording is common before renewal in those cases.
Briefly.
Real-world OT/IoT breach scenarios and typical insurer responses
A cyber attack that manipulates OT can cause physical damage and safety incidents, not only data loss. Insurers view those outcomes differently depending on policy wording and endorsements.
The error most frequent at this point is assuming that business interruption or data breach cover automatically pays for repairing damaged machines. That assumption often leads to denied claims.
Example: ransomware affecting a line
A manufacturer suffers ransomware that locks HMIs and interrupts PLC commands. The line halts and a mis-pulse damages weld fixtures.
In many claims, insurers paid forensic costs and crisis PR. They refused machinery repair unless the policy had an explicit physical damage by cyber endorsement.
How insurers normally respond to OT incidents
Insurers commonly pay forensic investigation, notification costs and extortion where ransom cover exists. They often exclude or limit payment for physical repair and product recall.
This works well in theory. In practice, insurers ask for OT surveys and proof of controls before agreeing to cover physical outcomes.
Real incidents show how policy wording and evidence affect recoveries. Norsk Hydro reported heavy BI losses after LockerGoga disrupted smelting and rolling operations for weeks.
Another example is NotPetya. That event caused multi-hundred-million-dollar losses at several manufacturers and showed IT-focused cyber cover may not protect manufacturers in the supply chain.
Earlier, Stuxnet and TRISIS proved PLCs and safety controllers can be manipulated to cause physical destruction. These cases make insurers probe whether OT controllers were compromised.
Insurers will ask for clear evidence about logs, segmentation and safety system integrity to support a claim for physical damage or extended BI.
In short.
Hidden exclusions and sublimits that affect OT claims
Exclusions and definitions decide OT cover. Small wording changes can switch a claim from payable to excluded.
Search for phrases like "industrial control systems", "physical damage", "product failure" and any wording on "silent cyber". These often decide the outcome.
Which exclusions cause the most problems?
Industrial control systems exclusions remove cover when an ICS causes damage or BI. Product failure exclusions can stop cover when a product malfunctions after a cyber event.
War, terrorism and pollution exclusions also matter. Malware that causes contamination may trigger pollution clauses and be excluded from cover.
How sublimits and waiting periods bite
Sublimits cap payout for risks such as extortion or PD by cyber. Waiting periods delay BI payments until a fixed time passes.
A policy with a low BI sublimit or a long waiting period can leave the business to cover most downtime costs despite having a cyber policy.
| Policy type |
Typical cover |
Common gap for OT |
When to choose |
| Standard |
Data breach, forensic, some BI, extortion |
Physical damage and OT failures often excluded |
Small firms with no control systems |
| Hybrid property/cyber |
Combines PD and cyber in one policy |
May have tighter underwriting and higher premium |
Manufacturers wanting PD by cyber without full bespoke wording |
| Bespoke endorsement |
Tailored cover for PD, OT BI and recall risks |
Requires evidence and may have sublimits |
Firms with high OT exposure and safety risks |
Many manufacturers assume a broker's verbal assurance or a general endorsement covers OT loss. The outcome depends on precise clause language in the policy.
Compare an "industrial control systems" exclusion that removes cover for loss arising from ICS failure with policies that define "physical damage" narrowly. The latter definition often excludes gradual contamination, latent product faults and firmware‑level corruption.
Underwriters also vary on war/terrorism wordings and silent cyber exposure. For OT insurance or hybrid property/cyber wording, insist on explicit definitions of "cyber event", "insured systems" and "physical damage from cyber".
To summarise.
Cost trade-offs: premiums, excesses and downtime losses
Premiums rise when OT exposure or past claims increase. Higher limits for PD and OT BI push premiums up further.
Sublimits and higher excesses reduce premium but shift cost risk back to the business. Insurers may offer lower premiums if security improvements occur.
Typical pricing drivers for underwriters
Underwriters price on revenue, OT asset criticality, claims history and documented controls. A recent OT risk survey usually reduces premium.
Prepare for a premium uplift if OT controls are immature. Brokers often show tiered pricing linked to mitigation milestones.
Benchmarks and what to expect
Benchmarks vary widely. Expect higher premiums than a pure IT firm, especially when cover includes physical damage and OT BI.
Ask brokers for multiple market options, including Lloyd's markets and specialist carriers. Compare sublimits and waiting periods, not just premium.
A brief pause here.
What happens if OT systems halt: claims and downtime
If OT stops, priorities are safety, containment and documentation for claims. Insurers require clear timelines and evidence to validate BI claims.
The most common mistake is poor evidence linking a cyber event to production loss; inadequate records reduce claim credibility.
How insurers assess OT BI claims
Insurers examine system logs, OT change records and maintenance history. They expect an audit trail showing cyber cause and production loss correlation.
Proof of tested recovery procedures and backup integrity makes claims more likely to succeed. Underwriters often request a post‑incident report.
Recovery time and BI tolerances
Negotiate BI wording to use measurable triggers like production units lost per hour. Measurable triggers prevent disputes over when BI started and ended.
Set realistic waiting periods tied to actual recovery steps. A shorter waiting period increases cost but reduces business cashflow risk.
Estimated cost: adding a specific "physical damage by cyber" endorsement commonly adds between 10% and 50% to a cyber premium for manufacturers with OT. Exact figures depend on revenue, controls and claims history.
Decision checklist: is a standard policy enough?
A standard policy is enough only when OT does not control safety or production and when devices are segregated. Otherwise bespoke cover is necessary.
Compile a checklist of asset criticality, control evidence and supplier contracts before renewal. Use this list when asking brokers for wording and quotes.
Action checklist to prepare for renewal
- Create an OT asset register with device role and firmware version.
- Provide a dated risk survey and a recent pentest or red team report.
- Show segmentation diagrams and backup test results.
Each item above materially affects underwriting decisions and the ability to secure physical damage or OT BI cover.
Who should be in the room when renewing?
Invite the Operations Manager, plant engineer and the broker. If possible, include an OT engineer or external assessor to explain mitigation.
Underwriters often ask technical questions on the spot. Having the right people reduces ambiguity and speeds agreement.
Underwriters typically expect a clear technical control baseline, not generic statements. At minimum, insurers usually require an up‑to‑date OT asset register and network segmentation diagrams.
They also expect documented secure remote access controls, an OT patching policy with pragmatic timelines, regular integrity checks and backups, and tested incident response plans that include OT response.
Demonstrable IoT device security measures and results from recent OT risk surveys or penetration tests materially improve the chance of securing industrial control systems insurance or wider SCADA cover.
In summary.
How to negotiate endorsements and sample wording
Negotiation succeeds when precise wording replaces vague promises. Present a draft endorsement and link it to specific evidence.
Ask the underwriter for an express carve‑in rather than relying on inferred coverage. That reduces disputes at claim time.
Sample endorsement language to propose
Physical Damage by Cyber Endorsement (concept):
"Notwithstanding any provision to the contrary, the insurer will indemnify the insured for physical loss of or physical damage to insured property directly caused by a cyber event to insured systems, provided that such insured systems were in active service at the time of the event. Cover is subject to the sublimit stated in the schedule and the insured's compliance with specified security conditions."
Use this as a starting point and ask legal counsel to check definitions like "cyber event" and "insured systems".
Steps to get an endorsement accepted
Step 1: Present OT evidence and a mitigation plan to the broker and underwriter. Step 2: Offer conditional timeframes to implement controls. Step 3: Accept realistic sublimits or excess in exchange for the carve‑in.
A concrete timeline for improvements often persuades underwriters to add endorsements within a renewal cycle.
Opinion: Secure a precise endorsement with a reasonable sublimit and a written plan to improve controls within 12 months. This approach keeps production protected now and reduces long‑term insurance cost once improvements are proven.
Mapping vendor and OEM responsibilities in contracts
Shifting risk to suppliers requires clear contracts that state patch timelines, vulnerability disclosure and indemnities for cyber‑caused damage. Many contracts lack these items today.
Ask for the right to audit vendor security or request evidence of secure development and pen test results. These clauses help both procurement and insurance negotiations.
Contract clauses that matter most
Require vendor warranties on patching timelines and CVE management. Ask for incident notification periods aligned with your insurer and regulator obligations.
Include indemnities for losses caused by vendor software or firmware failures. Limitations of liability for vendors often need negotiation to be useful.
How to present vendor risk to insurers
Bundle vendor evidence with your OT asset register and mitigation plan when submitting to underwriters. Insurers look for clarity on who performs updates and who has operational control.
If a vendor keeps control of a system, obtain their insurance details and ask whether their policy covers PD by cyber.
Before the FAQ, ask the broker to provide written sample wording and a conditional premium quote at least 30 days before renewal, so legal review and negotiation can proceed.
Frequently asked questions
Do cyber insurance policies cover OT/ICS?
Usually not. Only policies that expressly include OT/ICS or have a specific endorsement will cover OT systems. Ask for the exact clause and underwriter confirmation.
Are standard cyber policies sufficient for manufacturers with OT?
Rarely. IoT can bridge IT and OT and create physical risk. Combine improved controls, vendor clauses and bespoke endorsements for adequate protection.
What exclusions should manufacturers look for?
Look for industrial control systems, product failure, physical damage, war/terrorism, pollution and silent cyber exclusions. Flag these early and seek carve‑ins.
How much does cyber insurance cost for manufacturers with OT?
Costs vary by revenue, OT exposure, claims history and controls. Expect higher premiums than for an IT‑only firm. Obtain several market quotes and compare limits and sublimits.
Can cyber insurance cover business interruption from OT failures?
Yes, but only if BI wording covers OT or if an OT BI endorsement is added. Define BI triggers clearly, for example units per hour lost, when negotiating.
Will cyber insurance cover physical damage by cyber?
Often excluded. Physical damage by cyber is payable only with a tailored endorsement or a hybrid property/cyber policy. Review the policy schedule for any PD by cyber carve‑in.
The concrete plan
Compile an OT asset register, a recent OT risk survey and a mitigation roadmap. Present these documents to brokers and ask for explicit endorsement wording before renewal.
Secure written underwriter agreement on any conditional improvements and accept realistic sublimits or excess in exchange for cover. Track deadlines and get independent verification when possible.
NCSC guidance on secure remote access and segmentation
Exceptions: do not follow this advice if your operations have no OT/IoT devices affecting production or safety, or if a supplier contractually assumes OT risk and shows valid insurance and warranties.
Will cyber insurance cover physical damage by cyber?
Often excluded. Physical damage by cyber is payable only with a tailored endorsement or a hybrid property/cyber policy. Review the policy schedule for any PD by cyber carve‑in.