What Cyber Insurers Now Require Before They Will Write OT Coverage
Cyber insurance renewal has become one of the more reliable forcing functions in industrial security. Not because underwriters have become security experts, but because they have paid enough industrial ransomware claims to start asking for evidence rather than attestation.
The practical effect is that a renewal questionnaire now functions as an informal security audit, with premium and coverage terms attached to the answers. Operators who can evidence their controls negotiate from a stronger position. Operators who cannot are increasingly finding OT-related losses sub-limited, excluded, or priced in a way that makes the coverage marginal.
Why Underwriters Started Asking
Industrial ransomware claims are expensive in a way that enterprise claims are not. A locked corporate file server is a recovery problem. A production line halted for three weeks is a business interruption claim, and business interruption is where the large numbers sit.
The 2026 Frost and Sullivan survey of OT security decision-makers found that 60 percent of industrial organizations experienced an OT security incident during 2025, and that 96 percent of those originated from an IT-level compromise. That pattern is visible in claims data too, and it explains why questionnaires now focus heavily on the boundary between IT and OT rather than on OT alone. Our guide to why most OT incidents start in IT covers what that means architecturally.
What Questionnaires Commonly Ask For
Requirements vary by insurer, by market and by the size of the risk, so treat the following as the pattern rather than a definitive list. Confirm specifics with your broker.
|
Area |
What Is Typically Asked |
What Evidence Looks Like |
|
Asset inventory |
Whether you know what is on the OT network |
A validated inventory with firmware versions, not a spreadsheet from 2019 |
|
IT/OT segmentation |
Whether OT is separated from the corporate network |
Architecture diagram plus firewall rule review, ideally third-party reviewed |
|
Remote access control |
How vendors and staff reach OT systems |
MFA enforcement, session logging, documented revocation process |
|
Backup and recovery |
Whether OT configurations can be restored |
Offline backups of controller logic, with a tested restoration record |
|
Incident response |
Whether a plan exists and has been exercised |
An OT-specific plan plus dated records of a tabletop exercise |
|
Monitoring |
Whether OT network activity is monitored |
Passive monitoring deployment with alerting and defined escalation |
|
The distinction that changes the outcome Underwriters increasingly distinguish between controls you describe and controls you can evidence. A questionnaire answer stating that OT is segmented carries less weight than an architecture review document. A statement that backups exist carries less weight than a dated restoration test record. The gap between those two positions is frequently the gap between standard terms and a sub-limit. |
Where Industrial Operators Most Often Fall Short
Backups that were never restored
Almost every operator has backups. Far fewer have ever restored a controller configuration from one. OT backup and recovery differs fundamentally from IT backup because restoring PLC logic requires the right engineering software version, the licence, and a documented runbook. An untested backup is an assumption, and underwriters have learned to ask.
Incident response plans written for IT
A plan that says isolate the affected host does not survive contact with a running process. OT incident response requires decisions about whether to continue operating or shut down, and about who holds the authority to make that call. Insurers increasingly ask whether the plan has been exercised, which is what a tabletop exercise produces evidence of.
Segmentation that exists on the diagram only
The documented architecture and the live configuration diverge over time as connections are added operationally. A segmentation review that maps actual crossings rather than intended ones is what produces defensible evidence.
Asset inventories that are out of date
An inventory assembled during a project three years ago does not reflect the current estate. Continuous or periodically refreshed asset inventory is both an insurance answer and the foundation of every other control on the list.
Preparing for Renewal
Start roughly three months before renewal, because several of these items cannot be produced quickly. A tabletop exercise takes weeks to schedule with the right people. A restoration test needs a maintenance window. An architecture review takes time to conduct properly.
Work through the questionnaire early rather than at submission, identify which answers you can evidence and which you can only assert, and close the most consequential gaps first. Where a gap cannot be closed before renewal, documenting a funded remediation plan is generally received better than an unqualified assurance that turns out to be untrue at claim time.
Why Choose Arista Cyber
Arista Cyber produces the evidence underwriters ask for, because it is the same evidence a regulator or an auditor asks for. An OT risk assessment generates the asset inventory and architecture review. Segmentation and DMZ work produces the boundary documentation. An incident response program with a facilitated tabletop produces the exercise record.
The point worth making internally is that none of this is insurance work. It is security work that happens to satisfy an insurance requirement, which means the spend is justified whether or not the premium moves.
Next Steps
If renewal is within six months, the questionnaire is worth reading now rather than at submission. Explore our OT cybersecurity services, read about the IT/OT boundary, or contact the Arista Cyber team.
Common Questions
Does cyber insurance cover physical damage caused by a cyberattack?
It depends entirely on the policy, and this is one of the most important things to check rather than assume. Cyber policies and property policies handle cyber-initiated physical damage differently, and the interaction between them is where coverage gaps appear. Industrial operators should review both policies together with their broker rather than reading the cyber policy in isolation.
Will improving OT security actually reduce our premium?
Sometimes, but the more consistent effect is on coverage terms rather than premium. Demonstrable controls influence whether OT-related losses are covered at full limits, sub-limited, or excluded, and that difference typically matters more than the premium line. Treat the security work as protecting the coverage rather than as buying a discount.
What single piece of evidence carries the most weight?
A third-party architecture and risk assessment, because it addresses several questionnaire areas at once and carries more weight than self-attestation. It produces the asset inventory, the segmentation review, and a documented view of remote access, which covers a substantial portion of a typical questionnaire. Our guide to what an OT risk assessment involves covers what that produces.
|
Renewal coming up? Arista Cyber produces the asset inventory, architecture review and tested incident response evidence that underwriters now expect. |