Resource
Cyber insurance for manufacturers: what carriers are actually asking now.
A general cyber insurance application asks if you have backups. A manufacturer's application asks whether your OT network is segmented, whether your vendor portal access is locked down, and whether what you attested to on the application actually matches what's running on your floor. The gap between those two things is where claims get denied.
Why manufacturers get evaluated differently.
Most industries buy cyber insurance primarily for third-party liability. What happens if customer data gets exposed and someone sues. For manufacturers, that's usually not the biggest exposure. The biggest exposure is the production line stopping.
When ransomware hits a manufacturing environment, every hour of downtime is direct revenue loss, missed delivery commitments, and contractual exposure to customers waiting on shipments. Median ransomware downtime in manufacturing has run around 48 hours, with severe incidents extending to one or two weeks. For a mid-size operation, even two days of full production halt can mean hundreds of thousands of dollars in lost revenue before counting the cost of remediation or any ransom. That's why business interruption coverage matters more in a manufacturer's policy than it does almost anywhere else, and why carriers underwrite manufacturers with that exposure specifically in mind.

The OT problem nobody else has to think about.
A manufacturer's network isn't just office computers. It includes programmable logic controllers, SCADA systems, robotics, IoT sensors, and connected equipment. Much of it running older operating systems that can't be patched the way a laptop can.
Carriers now ask specifically whether the office network and the operational technology network are segmented. An attacker who compromises an office workstation through a phishing email shouldn't have a path to the equipment running the floor. Most manufacturers built their networks before that boundary was a deliberate design decision, which means the segmentation either doesn't exist or was never verified.
This connects directly to a real claim pattern carriers have seen: ransomware deployed through compromised vendor portal credentials, encrypting the production network on a weekend when nobody was watching. The entry point wasn't the plant floor. It was a vendor relationship that had standing access nobody had reviewed.
The patching problem, addressed honestly.
Carriers expect documented patch schedules and remediation timelines. For a manufacturer running specialized equipment that can't tolerate frequent updates, or legacy systems that have been running unmodified for years because replacing them isn't simple, that expectation runs into a real operational constraint.
Carriers know this. The answer isn't pretending the equipment can be patched on a normal schedule. It's compensating controls. Network segmentation that isolates what can't be patched, restricted access to those systems, and closer monitoring around them. A manufacturer who can explain why a piece of equipment isn't patched and what's been done instead is in a fundamentally different position than one who has no answer at all.
Security awareness training: the requirement most manufacturers underestimate.
Human error is involved in the overwhelming majority of cyber incidents, which is why carriers ask about training and phishing simulations. Most manufacturers have some version of this. A video new hires watch once, a poster in the break room.
Here's where this becomes a real problem, not just a compliance gap. Most applications ask you to attest that security awareness training is in place and conducted regularly. If you check that box without an actual program, without records of who completed it, when, and what the phishing simulation results showed, you haven't just left a gap in your security posture. You've made a representation to the carrier that isn't true. If a breach happens and the claim gets investigated, that gap between what you attested and what actually existed becomes the carrier's basis for denial. The absence of training is a security problem. A false attestation about training is an insurance problem, and a worse one.
Sublimits: why your coverage isn't what the headline number says.
A $1 million cyber policy doesn't mean $1 million of coverage for everything. Most policies include sublimits. Smaller caps buried inside the overall limit for specific categories of loss. Ransomware extortion payments often have their own sublimit. So does business interruption. So does forensics and incident response.
A manufacturer who assumes a $1 million policy means $1 million of ransomware protection may discover at the worst possible moment that the ransomware sublimit is a fraction of that number. Given that business interruption is the primary exposure for a manufacturer, reading the sublimit language for business interruption and extortion coverage specifically, not just the headline policy limit, is one of the most important things to do before signing, not after a claim.
Your attestation has to match your actual environment.
This is the point that matters more than any individual control. The application isn't a marketing questionnaire. It's a representation the carrier prices the policy against and relies on if a claim comes in.
You can't attest to controls you don't actually have and expect the policy to perform the way you think it will. If the application says MFA is enforced across all remote access and ERP portals, and the reality is it's enforced on email but not on the ERP system vendors use to connect, that gap is exactly what an underwriter looks for during a claims investigation. Carriers increasingly ask for screenshots, configuration exports, and documented evidence instead of accepting a checked box. Because self-attestation that doesn't match reality has become a primary reason claims get denied, independent of whether the breach itself was preventable.
The honest version of this: figure out what's actually in place before you fill out the application, not after. If the answer to a question is partially true, the application should reflect that, and the gap should get closed before renewal. Not papered over with a yes.
What carriers are specifically asking manufacturers right now.
MFA enforced across email, remote access, and ERP or EDI portals specifically. Not just the office network. Most carriers won't quote a manufacturer without it, and MFA implementation alone often qualifies for a meaningful credit on premium.
OT and IT network segmentation, with evidence the boundary actually exists and has been tested, not just described.
Endpoint detection and response across both office and production-adjacent systems, with documented alert monitoring. Not legacy antivirus relabeled as EDR.
Immutable, tested backups that ransomware can't reach by compromising the production network, since backups are now a primary target in the majority of ransomware incidents.
Vendor access reviewed and controlled, particularly for any third party with standing access to ERP, EDI, or production systems.
A documented, tested incident response plan. Not a document that exists but has never been exercised.
Documented security awareness training with records, not an assumption that it happened.
What changes when this is handled correctly.
The application gets answered from documentation, not memory. Every control attested to actually exists and can be evidenced if a claim is ever reviewed. The OT and IT networks are segmented with a tested boundary. Vendor access is reviewed instead of assumed safe. Training has records behind it. Sublimits are understood before a renewal, not discovered during a claim.
A business managed to CIS Controls, the framework we align to, produces most of this as a byproduct of how the environment runs, not as a scramble before an application is due. The renewal becomes a documentation exercise instead of a gap-closing project, and the attestation reflects what's actually true.
If you're not confident your current attestation matches your actual environment, or you've never reviewed what your sublimits actually cover, that's exactly what an IT Environment Review is for.
Common questions
Questions leadership usually asks first.
Continue reading
Related work and reading.
IT for Manufacturers
How we manage OT-adjacent IT, network segmentation, and vendor access for environments where downtime is expensive.
Read more: IT for ManufacturersCyber Insurance Readiness
Close the gap between what the application says and what's actually running before renewal. Not during a claim.
Read more: Cyber Insurance ReadinessCyber Insurance IT Requirements
The baseline controls every carrier now expects, before the manufacturing-specific questions layer on top.
Read more: Cyber Insurance IT RequirementsNext step
Schedule an IT Environment Review.
Get a clear picture of whether your cyber insurance attestation matches your actual environment and what carriers are asking manufacturers right now.
