A cracked enclosure or wrong ingress rating can turn a claim into a rejection. Gather proof of IP/IK ratings, correct mounting and dated maintenance before you buy cover.
Check evidence before you buy or renew cover.
Industrial IoT and smart device insurance: cover
A policy must name the perils it covers and the proof insurers want. Underwriters often ask for technical certificates and dated maintenance records.
How it protects SMEs
Cover typically pays for incident response, forensic costs and business interruption. Policies often pay for emergency OT response and forensic investigation when wording allows. Some policies pay for physical repair after a cyber event only when they name that risk.
Common exclusions and practical steps
Exclusions that hit IIoT claims include failure to maintain, firmware negligence and slow deterioration. If a device fails after missed patching or poor mounting, insurers often deny the claim.
The most frequent error at this point is missing dated patch logs and test photos. Prepare dated patch logs, test certificates and maintenance photos to contest a denial.
The Insurance Act 2015 and the NIS Regulations 2018 affect duties for essential services. Check these laws if OT links to public services.
How insurers judge risk
Underwriters use enclosure ratings, test reports and maintenance logs as proxy signals of care. Clear, dated evidence speeds underwriting and cuts dispute risk.
Supply chain, third‑party limits and sublimits
Claims tied to supplier kit or cloud providers often sit under contingent business interruption. Policies may include dependent‑property clauses but these take negotiation.
Sublimits for OT or physical damage often sit below the main cyber limit and may apply per device. Ask for worked examples showing how sublimits would apply in a real loss.
Check evidence before you buy or renew cover.
Assessing industrial IoT risk before buying cover
A short risk check saves money at quote time. Gather device specs, mounting details and the firmware update plan before you speak to a broker.
Device inventory and exposure
List every device, its role and its site location. Include serial numbers and connectivity so underwriters can map exposure.
This list shows which kit is critical and needs higher cover. It also helps decide indemnity periods and sublimits.
Tests and evidence insurers want
Insurers expect IP/IK certificates, EMC test reports and environmental tests. Also send manufacturer's firmware policies and proof of applied patches.
The NCSC IoT security guidance is often cited by underwriters. See the NCSC guidance for device design and update expectations.
Check evidence before you buy or renew cover.
Risk quantification for buyers
Estimate one day of outage cost for each site function before picking limits. Use daily revenue or the cost to reroute production as a simple metric.
This figure helps when choosing indemnity periods and when discussing sublimits with a broker. Use a company figure when you speak to underwriters.
Estimated cost to an SME for one day of production loss often ranges from £10,000 to £120,000 depending on sector and automation level; use a company figure when discussing limits with underwriters.
Industrial IoT insurance: required policy clauses and endorsements
Ask for clear cyber‑physical wording and an endorsement naming "physical damage caused by a cyber event." Add a contingent business interruption clause.
Wording examples to request
- Use short clauses when you engage brokers: "Loss of or damage to insured property directly caused by unauthorised access to, or malicious code affecting, the insured's OT systems." This wording links a cyber attack to physical loss.
Limits, sublimits and waiting periods
Check BI waiting periods, which commonly run from 24 to 72 hours. Property damage sublimits after a cyber event can be a small fraction of the main cyber limit.
Always ask brokers or insurers for examples of past claims handling to see how limits worked in practice.
What to do now (evidence and placement steps)
Gather device lists, IP/IK certificates and firmware schedules before you approach a broker. Deliver these with quote requests so underwriters can assess exposure without extra surveys.
Ask suppliers to fill a short spec for critical devices and keep a simple maintenance log from day one. That evidence is the single most effective way to avoid a denial for failure to maintain.
When negotiating, insist the policy names physical damage from cyber events and includes contingent BI. Attach the evidence requirements to the policy so adjusters know what to request.
Check evidence before you buy or renew cover.
Reducing premiums through IoT security measures and evidence
Small steps on enclosures and firmware can cut incident frequency and impact. Insurers reward clear controls with better terms when evidence is ready at quote time.
Enclosure choices: IP, IK and materials
Choose an enclosure rating that fits the site and keep the test certificate. For outdoor pumps, stainless steel with IP66 and IK08 is common.
For indoor sensors, polycarbonate with IP54 often suffices. Match the material to UV and salt exposure if needed.
| Environment |
Recommended IP |
Recommended IK |
Material |
Typical cost (GBP) |
| Indoor, low dust |
IP54 |
IK06 |
Polycarbonate |
£10 - £50 |
| Outdoor exposed |
IP66 |
IK08 |
Stainless steel |
£40 - £150 |
| Wash‑down, food site |
IP67 |
IK10 |
316 stainless |
£80 - £300 |
Firmware, patching and logs
A clear firmware update plan and immutable patch logs cut dispute risk. Insurers want dates, versions and verification checks after each update.
If logs are missing, a denial for failure to maintain is common. Keep signed PDFs or immutable audit records for every patch.
If devices are purely consumer and not integrated into operational processes, this guidance may not apply; conversely, large corporates with global risk programmes will need bespoke underwriting that sits outside SME product offerings.
Check evidence before you buy or renew cover.
Choosing the right enclosure goes beyond mechanical protection. Underwriters want documentation linking IP and IK ratings, material and mounting to site exposure.
What most guides omit is the role of material in salt corrosion and UV damage. For example, a low‑cost polycarbonate box used outdoors risks UV cracking and corrosion claims.
Provide the test certificate, photo of the installation and a mounting spec to remove the need for a site survey in many cases. This can avoid a restrictive sublimit for physical damage.
Framing enclosure choices in the policy pack as part of IoT maintenance and OT security helps underwriters. Reference EMC testing and firmware patching where relevant to improve placement chances.
Concrete, numbered examples help brokers and finance teams compare mitigation costs to likely failure costs. Use clear figures when you speak to underwriters.
-
Consider an anonymised food‑packaging SME where a single failed sensor led to five days of stoppage. Daily lost revenue stood at £40,000 and repair plus clean‑down cost £60,000.
-
Replacing exposed sensors with IP67 316 stainless enclosures and a managed patch service cost £12,000. This cut mean time to failure by 70% and paid back within the first year when BI was counted.
-
A remote water pump with an IP54 enclosure suffered ingress that required a £12,500 motor replacement. Upgrading to IP66 + IK08 at £85 per unit reduced repeat failures.
These before/after figures are the numbers underwriters and CFOs need to justify spend.
Check evidence before you buy or renew cover.
Specification-to-policy checklist
Match each technical document to a clear policy clause before procurement. Underwriters accept evidence more readily when it follows a consistent template.
Ready-to-send spec template
Use a short spec per device so suppliers give the right evidence. Copy and paste this into supplier requests.
Device specification template
- Device name: [name]
- Manufacturer: [name]
- Model/part no: [part]
- Serial no: [serial]
- Function: [monitor/control]
- Location: [site, zone]
- IP rating: [e.g. IP66]
- IK rating: [e.g. IK08]
- Material: [e.g. 316 stainless]
- Mounting type: [wall, pole, recessed]
- Power: [mains/PoE/battery]
- Connectivity: [cellular/Ethernet/Wi‑Fi]
- Firmware update policy: [schedule, OTA method]
- EMC test ref: [report id]
- Environmental tests: [temp, humidity, vibration]
- Warranty terms: [length, cover]
- Supplier contact for incidents: [name, phone, email]
Maintenance log example
A one‑line log entry often works for claims. Keep a simple CSV or signed PDF with entries like:
- Date, Actor, Device serial, Patch version, Verification result, Photo link
Keep logs for seven years to match many warranty and regulatory checks. This retention helps in long‑tail disputes.
Check evidence before you buy or renew cover.
Claims process for industrial IoT incidents in England
Know the steps to file a claim and the evidence you will face. Claims handlers need hardware proof and forensic reports to link a cyber act to physical damage.
Initial response and containment
Notify the insurer and preserve devices for forensic work as soon as compromise is suspected. Do not wipe devices; document chain of custody.
Early notification often improves the chance of cover for forensic costs. Keep communications short and dated.
Evidence insurers request during a claim
Expect requests for installation photos, test certificates, maintenance logs and firmware history. Adjusters often want third‑party forensic reports to confirm causation.
Failure to give dated evidence is a common reason for denial. Have the evidence pack ready before an incident.
Typical timeline for a claim
Insurers usually acknowledge a claim within 5 working days and ask for evidence within 10 to 20 working days. Forensic work can take 2 to 8 weeks depending on complexity.
The legal and regulatory context includes the Data Protection Act 2018 and the Network and Information Systems Regulations 2018. These laws can affect reporting duties and fines after an IIoT incident.
Contact a specialist cyber insurance broker with an IIoT checklist and evidence pack when you seek renewal or a new quote. The broker can place endorsements and negotiate sublimits.
Check evidence before you buy or renew cover.
Frequently asked questions
What exactly does industrial IoT mean for my business?
Industrial IoT covers sensors, controllers and devices that monitor or control industrial processes. These devices connect to networks and can cause physical effects if compromised.
For SMEs, common examples include energy meters, conveyor sensors and remote pumps.
What enclosure rating do insurers prefer for my devices?
Insurers often expect at least IP66 and IK08 for outdoor exposed kit. The exact rating depends on exposure and site risk.
Provide the test certificate and an installation photo with your evidence pack.
How long should I keep firmware and maintenance records?
Keep logs for a minimum of seven years for warranty and claim review. Dated, uneditable logs like signed PDFs carry more weight with adjusters.
Logs should show dates, versions and verification steps.
Can a manufacturer's warranty replace insurance?
Warranties and insurance do different jobs; warranties cover defects, not business interruption from a cyber attack. Insurers may still decline if a warranty limits recovery.
Combine warranty and insurance when possible.
Will a standard cyber policy cover physical damage?
Only when the policy explicitly covers physical damage resulting from a cyber incident. Many standard cyber policies focus on data loss and response costs.
Insist on an endorsement naming physical damage and keep repair invoices and test reports for claims.
Who in the business should own this work?
Assign a named responsible person, such as the operations manager or DPO for data devices. The insurer will want a named contact in the evidence pack and for incident response.
This named contact cuts delays during a claim.
If a supplier offers device insurance, is that enough?
Supplier policies can help but may not cover your business interruption or third‑party liabilities. Check for contingent BI cover and exclusions for cyber‑caused physical damage.
If wording is unclear, ask for the policy text and compare it with your own quote.
Final recommendation and next step
Gather device specs, IP/IK certificates and dated maintenance logs now. Share them with your broker when you request a quote.
This step reduces survey requests, speeds placement and limits surprises at claim time.