Are production lines the weak link in a cyber policy or a gap in a property policy? Does a ransomware infection that stops valves and PLCs create purely a data loss or a physical-damage claim? For many UK manufacturers running ICS/SCADA, the right answer sits in the overlap: cyber and physical loss can be the same event, but insurers treat them differently.
Prepare to find a concise, decision-focused roadmap to understand when cyber cover will help, when property insurance is needed, and how SMEs can reduce costly mistakes when insuring industrial control systems. This analysis focuses on real loss scenarios, typical policy wordings, practical evidence required for a claim, and immediate steps that make a difference to recovery and insurer acceptance.
Quick essentials: manufacturers: cyber vs physical loss for ics/scada in one minute
- Cyber and physical losses often overlap. Insurers may split costs between cyber (IT, incident response, ransomware payment, data restoration) and property (repair/replacement of physical plant, machinery, contamination). The allocation matters for limits and excesses.
- Production downtime usually drives the biggest cost. Business interruption (BI) tied to physical damage to plant tends to be costlier per hour than pure IT system recovery in manufacturing contexts.
- Policy wording is decisive, not labels. The question is how an insurer defines "physical damage", "malicious cyber act", and "failure of electrical/mechanical parts" in the policy wording.
- For OT incidents, cyber cover alone often isn’t sufficient. Many cyber policies exclude physical damage or impose sub-limits; property policies may exclude cyber-originated losses. A combined approach or clear wording is essential.
- Practical actions reduce claim disputes. Immediate forensics, segregation of networks, IEC 62443 evidence, supplier records and incident logging materially improve the chance of a successful claim.
Should manufacturers prioritise cyber or physical cover for ics/scada?
Explanation
Manufacturers must treat this as a prioritisation of exposure rather than labels. If an SME’s primary exposure is halted production, contaminated product, or machinery damaged by unauthorised commands, the financial impact will often sit in property and BI portfolios. If the exposure is data theft, regulatory fines (GDPR), extortion or network recovery, cyber policies dominate.
Expert context
- Industrial control systems (ICS) and SCADA are OT environments where IT and physical processes are tightly coupled. Attacks such as manipulated set-points, forced valve positions or safety-instrumented system (SIS) interference create physical consequences.
- The National Cyber Security Centre (NCSC) documents how OT attacks can cause physical loss: see NCSC guidance for high-level scenarios.
Implications for cover
- Prioritise cover that matches the highest single-source financial exposure. For many manufacturers this will be property damage and BI because repair, replacement and lost production hours outweigh IT restoration costs.
- However, ignoring cyber cover risks uninsured costs like ransom demands, forensic response, regulatory fines and third-party liability for leaked client data.
Practical advice
- Map typical loss scenarios (node compromise, command injection, firmware corruption) to cost buckets: repair, replacement, decontamination, regulatory fines, BI and reputational remediation.
- Obtain policy wordings and run clause-by-clause checks with a broker who understands OT incidents. Look specifically for definitions of "physical damage", "malicious act", "computer system" and any sub-limits for cyber-related BI.
Common mistakes
- Assuming property insurance automatically pays for cyber-originated physical damage. Many property policies have cyber exclusions or require a proximate non-cyber cause.
- Buying a standalone cyber policy with narrow definitions that exclude physical damage caused by a malicious cyber act.
Cyber vs physical loss: which hits manufacturers' production hardest?
Explanation
Production hit is typically measured in lost output hours and restart time. Losses from physical damage (mechanical failures, fire, contamination) usually create longer restart times than simple IT downtime, but a deliberate OT attack can replicate or exceed physical-damage severity.
Context and data
- Indicative modelling (2025–26 market data): an unplanned stoppage caused by physical damage averages longer restart and higher per-hour losses than an IT-only outage. Example indicative figures: physical-damage BI cost £25k–£150k per hour for medium manufacturers; IT recovery may be £5k–£25k per hour, depending on automation level.
- Case studies (publicly reported): the NotPetya-style incidents that affected manufacturing have shown multi-week production loss vs. IT outages often resolved in days.
Implications
- Exposure depends on automation depth, manual workarounds availability and inventories. High-automation, low-spare-part operations suffer more from physical damage to PLCs or sensors.
- SCADA-targeted attacks that manipulate physical processes can cause equipment stress, leading to longer repair times and safety inspections.
Actionable steps
- Run a simple quantitative assessment: hourly revenue × recovery time = BI exposure. Calculate for (a) IT-only outage, (b) OT command manipulation without hardware damage, and (c) OT causing hardware failure.
- Use results to set priorities for limits and to decide whether to purchase additional BI cover, contingent supply-chain cover or increased property limits.
Is cyber insurance sufficient for ot incidents in manufacturing?
Clear answer
Not usually. Cyber insurance may cover incident response, extortion and certain BI elements, but many policies either exclude physical damage or have narrow triggers for property consequences. Therefore cyber insurance alone is typically insufficient for OT incidents that cause physical damage or contamination.
Why it matters
- Insurers often segment product lines: cyber policies are written for information systems; property policies cover physical plant. When an incident straddles both, disputes arise over which policy responds.
- The Financial Conduct Authority (FCA) and market circulars have highlighted the need for clarity in policy triggers; see FCA resources at FCA.
Practical considerations
- Look for cyber policies with explicit physical damage extensions or endorsements covering bodily injury, property damage and plant repair caused by a malicious cyber act. Confirm whether such extensions reduce the main cyber limit or are separate.
- Check property policies for cyber exclusions. Some property insurers now include express cyber-origin exclusions; others will cover physical damage if a proximate non-cyber cause exists.
Checklist for SMEs
- Ask insurers these questions in writing: "Does the policy cover physical damage caused directly by a malicious cyber act to PLCs, field devices and actuators?" and "How is BI triggered: by systems failure, physical damage, or both?"
- Maintain OT network diagrams, maintenance logs and segregated backups; these materially affect insurer decisions on cover and premium.
When does physical damage outweigh cyber losses for scada?
Explanation
Physical damage outweighs cyber losses where repair/replacement and safety-related downtime costs exceed the combined costs of forensic IT response, data restoration and ransom or regulatory exposure.
Key indicators
- Visible hardware destruction (burned motors, exploded sensors, contaminated product lines).
- Safety incidents requiring shutdown, inspection and recertification (SIS failing, HAZOP triggers).
- Long lead-time components where replacement takes weeks and causes extended production stoppage.
Real-world implications
- Example scenario: malicious command causes overheating and bearing failure in key press. Repair and rebalancing may take 4 weeks; BI loss >£1m. Cyber costs (forensics, network restore) might be £50k–£200k, physical dominates.
- Conversely, a ransomware infection that locks engineering workstations without affecting PLCs may result in shorter production impact but large ransom / data recovery costs where cyber side dominates.
How to decide
- Use contingency matrices combining time-to-fix, replacement lead-times, safety re-certification and per-hour revenue. If combined physical repair + BI > cyber recovery + ransom + regulatory, physical outweighs cyber.
Should smes insure supply chain cyber-physical risks in ics/scada?
Explanation
Supply-chain cyber-physical risks occur when a vendor, integrator or cloud service compromise causes OT commands or firmware tampering, leading to physical failure. SMEs increasingly depend on third-party ICS suppliers, so supply-chain cover is relevant.
Context
- Recent incidents show attacks can originate in supplier software updates or third-party remote access tools. The UK's Government and NCSC emphasise supply chain security in industrial contexts; see HM Government / NCSC.
Options and implications
- Contingent BI and supplier interruption cover can protect income lost when a vendor outage stops operations.
- Cyber policies may offer sub-limits for third-party vendor failures or supply-chain attacks; these are often capped and require careful negotiation.
Practical steps
- Include supplier risk clauses in contracts (incident notification, access logs, SLAs) and collect evidence to simplify claims.
- Consider contingent BI and cyber extensions for key suppliers, especially for remote maintenance vendors and cloud-based SCADA providers.
Costly mistakes manufacturers make choosing cyber versus physical cover
Explanation
Poor decisions typically stem from misunderstanding policy triggers, failing to map OT exposures, and not testing incident response with insurers or brokers.
Top mistakes and consequences
- Assuming one policy covers everything. Consequence: denied claims, protracted disputes, uncovered repair costs.
- Not reading definitions. Consequence: sub-limits or exclusions (e.g. "acts of war", "terrorism", or "electronic data only").
- Underestimating BI exposure. Consequence: insufficient limits that exhaust quickly during long repairs.
- Failing to collect OT evidence. Consequence: insurer rejects proximate cause; claim payment delayed or refused.
- Buying cheapest cyber policy. Consequence: narrow cover, minimal physical extensions, low incident support.
How to avoid these mistakes
- Obtain clause-by-clause reviews from a broker experienced in industrial/OT risk. Compare wordings rather than premiums alone.
- Keep incident playbooks, segregated backups, firmware inventories and maintenance logs to demonstrate due diligence.
- Consider layered cover: property (physical), cyber (IT/response/extortion) and contingent/supply-chain endorsements.
Comparative table: cyber vs physical cover for typical ics/scada incidents
| Scenario |
Typical response: cyber policy |
Typical response: property policy |
| Ransomware on engineering workstations |
Forensics, incident response, ransom negotiation, data restoration, limited BI |
Usually not covered unless proximate physical damage occurs |
| Malicious PLC commands cause motor burnout |
May cover some BI and investigation; often excludes physical repair or applies sub-limit |
Covers repair/replacement, plant decontamination and BI if triggers met |
| Third-party software update introduces unsafe firmware |
May offer vendor/technology liability and extortion cover; sub-limits common |
Property may cover resultant physical damage but supply-chain causes can complicate claims |
- Network and OT logs (time-stamped), PLC program snapshots and firmware versions.
- Maintenance and spares records, wiring diagrams and change control documentation.
- Forensic reports from certified incident responders; chain-of-custody for breached devices.
- Safety system logs (SIS/HMI alarms) and operator shift notes showing anomalous commands.
Ensure the incident response partner knows OT forensics. The NCSC and ICO provide useful baseline advice: ICO and NCSC.
Incident flow: from compromise to claim
🔎 **Detect** → 🧾 **Preserve evidence** → 📞 **Notify insurer & responder** → 🛠️ **Stop spread / isolate OT** → 🔧 **Repair & validate** → ✅ **Claim submission**
- 🔎 Detect: HMI/SCADA alerts, unusual set-points, unexpected reboots.
- 🧾 Preserve evidence: Snapshot PLC code, export logs, photograph hardware states.
- 📞 Notify: Inform insurer and approved OT forensic team immediately.
- 🛠️ Isolate: Segregate affected cells to reduce BI impact.
- 🔧 Repair: Replace damaged actuators, confirm KPIs, run safety tests.
- ✅ Claim: Compile evidence pack: timelines, costs, third-party invoices.
Balance strategic: what is gained and what is risked with different cover mixes
When combined cover is the best choice
✅ When production is heavily automated and a cyber-origin event can cause major physical harm, combined cover reduces the risk of coverage disputes and provides broader incident support.
✅ When vendors provide remote maintenance, vendor-supplied IoT/sensors are critical or software updates are frequent.
Red flags and what to watch for
⚠️ Small insurers offering cyber physical extensions without clear wording or with tiny sub-limits.
⚠️ Policies that treat any "computer attack" as excluded from property cover or that reduce property limits when a cyber trigger is used.
Doubts clarified: quick questions about manufacturers: cyber vs physical loss for ics/scada
Common questions people ask about manufacturers: cyber vs physical loss for ics/scada
How does an insurer decide which policy pays when both could respond?
Insurers decide based on proximate cause and specific definitions in policy wordings; the earliest covered event often dictates lead insurer. Context: documented timelines and forensics are used to establish proximate cause.
Why do some cyber policies exclude physical damage?
Insurers separate product lines to manage accumulation and catastrophe risk; physical damage can create much higher claims and is often reserved for property insurers. Context: ask for endorsements that explicitly include physical damage from malicious cyber acts.
What happens if a supplier’s compromise stops production?
Contingent BI or supplier interruption cover may respond; otherwise the insured must rely on contractual remedies. Context: include supply-chain endorsements and ensure supplier SLAs require incident notification.
Which evidence is most useful to prove an ot-originated physical claim?
PLC code snapshots, time-stamped logs, HMI screenshots, maintenance records and certified forensic reports. Context: early preservation and chain-of-custody are critical to avoid disputed causation.
How long before a claim is typically settled for an ot physical incident?
Claims can take months to over a year depending on complexity, investigations and repair timelines. Context: keep insurers updated and document interim mitigation and costs to support progress payments.
How to decide limits for BI that cover physical vs cyber triggers?
Calculate hourly revenue loss for plausible worst-case scenarios (physical repair time versus IT recovery time) and set limits accordingly. Context: include contingent supplier losses where relevant.
Conclusion: long-term value and empowerment
Manufacturers with ICS/SCADA face a dual risk: cyber incidents that cause IT loss and cyber incidents that cause physical harm. The most resilient approach is to map exposures, test evidence capture, and align policy wordings with real loss scenarios. Over time, layered cover that explicitly addresses cyber-origin physical damage, adequate BI limits, and supplier-contingent protection will reduce uninsured gaps and speed recovery.
- Review one policy clause today: locate and read the definitions of “physical damage”, “malicious act” and “business interruption”.
- Secure an incident evidence kit: basic tools to snapshot PLCs, export logs and photograph hardware states (store instructions in a folder accessible to duty manager).
- Contact one broker or insurer contact for a clause-by-clause review, noting specific concerns about ICS/SCADA triggers and supply-chain dependencies.