Skip to content

Resource

Cyber insurance for manufacturers: what carriers are actually asking now.

A general cyber insurance application asks if you have backups. A manufacturer's application asks whether your OT network is segmented, whether your vendor portal access is locked down, and whether what you attested to on the application actually matches what's running on your floor. The gap between those two things is where claims get denied.

Dawn SizerDawn Sizer · CEO and Co-Founder, 3rd Element Consulting ·

Why manufacturers get evaluated differently.

Most industries buy cyber insurance primarily for third-party liability. What happens if customer data gets exposed and someone sues. For manufacturers, that's usually not the biggest exposure. The biggest exposure is the production line stopping.

When ransomware hits a manufacturing environment, every hour of downtime is direct revenue loss, missed delivery commitments, and contractual exposure to customers waiting on shipments. Median ransomware downtime in manufacturing has run around 48 hours, with severe incidents extending to one or two weeks. For a mid-size operation, even two days of full production halt can mean hundreds of thousands of dollars in lost revenue before counting the cost of remediation or any ransom. That's why business interruption coverage matters more in a manufacturer's policy than it does almost anywhere else, and why carriers underwrite manufacturers with that exposure specifically in mind.

Cyber insurance requirements for manufacturers

The OT problem nobody else has to think about.

A manufacturer's network isn't just office computers. It includes programmable logic controllers, SCADA systems, robotics, IoT sensors, and connected equipment. Much of it running older operating systems that can't be patched the way a laptop can.

Carriers now ask specifically whether the office network and the operational technology network are segmented. An attacker who compromises an office workstation through a phishing email shouldn't have a path to the equipment running the floor. Most manufacturers built their networks before that boundary was a deliberate design decision, which means the segmentation either doesn't exist or was never verified. Our guide to OT/IT network segmentation covers what a project involves.

This connects directly to a real claim pattern carriers have seen: ransomware deployed through compromised vendor portal credentials, encrypting the production network on a weekend when nobody was watching. The entry point wasn't the plant floor. It was a vendor relationship that had standing access nobody had reviewed.

The patching problem, addressed honestly.

Carriers expect documented patch schedules and remediation timelines. For a manufacturer running specialized equipment that can't tolerate frequent updates, or legacy systems that have been running unmodified for years because replacing them isn't simple, that expectation runs into a real operational constraint.

Carriers know this. The answer isn't pretending the equipment can be patched on a normal schedule. It's compensating controls. Network segmentation that isolates what can't be patched, restricted access to those systems, and closer monitoring around them. A manufacturer who can explain why a piece of equipment isn't patched and what's been done instead is in a fundamentally different position than one who has no answer at all.

Security awareness training: the requirement most manufacturers underestimate.

Human error is involved in the overwhelming majority of cyber incidents, which is why carriers ask about training and phishing simulations. Most manufacturers have some version of this. A video new hires watch once, a poster in the break room.

Here's where this becomes a real problem, not just a compliance gap. Most applications ask you to attest that security awareness training is in place and conducted regularly. If you check that box without an actual program, without records of who completed it, when, and what the phishing simulation results showed, you haven't just left a gap in your security posture. You've made a representation to the carrier that isn't true. If a breach happens and the claim gets investigated, that gap between what you attested and what actually existed becomes the carrier's basis for denial. The absence of training is a security problem. A false attestation about training is an insurance problem, and a worse one.

Sublimits: why your coverage isn't what the headline number says.

A $1 million cyber policy doesn't mean $1 million of coverage for everything. Most policies include sublimits. Smaller caps buried inside the overall limit for specific categories of loss. Ransomware extortion payments often have their own sublimit. So does business interruption. So does forensics and incident response.

A manufacturer who assumes a $1 million policy means $1 million of ransomware protection may discover at the worst possible moment that the ransomware sublimit is a fraction of that number. Given that business interruption is the primary exposure for a manufacturer, reading the sublimit language for business interruption and extortion coverage specifically, not just the headline policy limit, is one of the most important things to do before signing, not after a claim.

Your attestation has to match your actual environment.

This is the point that matters more than any individual control. The application isn't a marketing questionnaire. It's a representation the carrier prices the policy against and relies on if a claim comes in.

You can't attest to controls you don't actually have and expect the policy to perform the way you think it will. If the application says MFA is enforced across all remote access and ERP portals, and the reality is it's enforced on email but not on the ERP system vendors use to connect, that gap is exactly what an underwriter looks for during a claims investigation. Carriers increasingly ask for screenshots, configuration exports, and documented evidence instead of accepting a checked box. Because self-attestation that doesn't match reality has become a primary reason claims get denied, independent of whether the breach itself was preventable.

The honest version of this: figure out what's actually in place before you fill out the application, not after. If the answer to a question is partially true, the application should reflect that, and the gap should get closed before renewal. Not papered over with a yes.

What carriers are specifically asking manufacturers right now.

MFA enforced across email, remote access, and ERP or EDI portals specifically. Not just the office network. Most carriers won't quote a manufacturer without it, and MFA implementation alone often qualifies for a meaningful credit on premium.

OT and IT network segmentation, with evidence the boundary actually exists and has been tested, not just described.

Endpoint detection and response across both office and production-adjacent systems, with documented alert monitoring. Not legacy antivirus relabeled as EDR.

Immutable, tested backups that ransomware can't reach by compromising the production network, since backups are now a primary target in the majority of ransomware incidents.

Vendor access reviewed and controlled, particularly for any third party with standing access to ERP, EDI, or production systems.

A documented, tested incident response plan. Not a document that exists but has never been exercised.

Documented security awareness training with records, not an assumption that it happened.

What changes when this is handled correctly.

The application gets answered from documentation, not memory. Every control attested to actually exists and can be evidenced if a claim is ever reviewed. The OT and IT networks are segmented with a tested boundary. Vendor access is reviewed instead of assumed safe. Training has records behind it. Sublimits are understood before a renewal, not discovered during a claim.

A business managed to CIS Controls, the framework we align to, produces most of this as a byproduct of how the environment runs, not as a scramble before an application is due. The renewal becomes a documentation exercise instead of a gap-closing project, and the attestation reflects what's actually true.

If you're not confident your current attestation matches your actual environment, or you've never reviewed what your sublimits actually cover, that's exactly what an IT Environment Review is for.

Schedule an IT Environment Review

Common questions

Questions leadership usually asks first.

Why does cyber insurance underwriting look different for manufacturers than other industries?
Because the dominant exposure is different. Most industries buy cyber insurance primarily for third-party liability. For manufacturers, business interruption is usually the bigger concern. When ransomware stops production, every hour of downtime is direct revenue loss and contractual exposure to customers waiting on shipments. Carriers also ask manufacturers specifically about OT and IT network segmentation and vendor access, because manufacturing networks include equipment and systems that don't exist in a typical office environment.
What happens if we attest to security controls we don't actually have?
It creates a worse problem than the missing control itself. The application is a representation the carrier relies on to price your policy. If a claim is investigated and the actual environment doesn't match what was attested, that mismatch becomes the carrier's basis for denying the claim. Separate from whether the underlying incident was preventable. The honest approach is figuring out what's actually in place before completing the application, not checking a box that sounds right.
What is a sublimit, and why does it matter for a manufacturer specifically?
A sublimit is a smaller cap on a specific category of loss inside your overall policy limit. A $1 million policy might have a much smaller sublimit for ransomware extortion payments or business interruption. Since business interruption is usually the primary exposure for a manufacturer, the sublimit for that category matters more than the headline policy number. Reading those sublimit terms before signing, rather than discovering them during a claim, is essential.
Can we get coverage if our manufacturing equipment can't be patched on a normal schedule?
Yes, but the application needs to address it honestly rather than ignore it. Carriers understand that specialized manufacturing equipment and legacy systems sometimes can't tolerate frequent patching. The answer is compensating controls, network segmentation isolating that equipment, restricted access, and closer monitoring, documented and explained, rather than an application that pretends a normal patch schedule applies everywhere.
What is an IT Environment Review?
The IT Environment Review is free and takes about 30 minutes by video or phone. We ask a set list of questions about your environment, answer yours, and send you a written summary afterward.

Next step

Schedule an IT Environment Review.

Get a clear picture of whether your cyber insurance attestation matches your actual environment and what carriers are asking manufacturers right now.