Cyber Insurance for Manufacturers: OT, IoT, and Downtime

Cyber insurance for a manufacturer has to be built around the production floor, not the front office: coverage that reaches the operational technology running the line, business interruption terms that match what a stopped plant actually costs by the hour, and a deliberate answer for the seam where a cyber event causes physical damage that neither a standard cyber policy nor a standard property policy clearly owns.

Manufacturers buy cyber insurance believing their exposure looks like everyone else’s — stolen data, phished email, a locked file server. It doesn’t. A manufacturer’s worst cyber day is a production outage: controllers locked, lines stopped, batches scrapped, shipments missed, and equipment sometimes physically damaged on the way down. This article walks through why the “air gap” between the plant floor and the internet rarely survives scrutiny, how cyber business interruption coverage really behaves when a line stops, and where the overlap between a cyber policy and a property policy quietly turns into a gap.

A modern CNC machining line at night, powered but completely still — enclosed machines with doors closed, unfinished parts motionless on the conveyor, and a single steady amber stack light overhead — a visual metaphor for a manufacturer's real cyber loss: a plant that is intact and powered, yet not producing.
A manufacturer’s cyber loss is measured on the production floor — in stopped lines, scrapped batches, and restart time — which is why the policy has to be built around downtime, not just data.

Why does a manufacturer’s cyber exposure live on the plant floor?

Most cyber policies were designed for businesses whose crown jewels are records. A manufacturer’s crown jewels are throughput.

Operational technology (OT) is the hardware and software that directly monitors and controls physical equipment and processes — the PLCs, industrial control systems, SCADA systems, HMIs, and sensors that actually run a production line — as distinct from the IT systems that run email, ERP, and the office. When an attacker reaches IT, a business loses data and time. When an attacker reaches OT — or when the company shuts OT down defensively because it can’t tell how far an IT intrusion spread — a business stops making the thing it sells.

That distinction is why manufacturing cyber coverage can’t be bought the way the market has been trained to buy commercial insurance — receive a quote, buy the cheapest thing, move on. A fast quote prices a limit against a generic breach. It never asks what the cyber liability policy actually does the day the floor goes quiet. Manufacturing is one of the largest pieces of Iowa’s economy — food processing, machinery, and ag equipment plants across the state — and many of those operations run on control systems installed decades before anyone underwrote a cyber policy against them.

Is the air gap protecting your OT — or is it a myth?

The most common sentence in a manufacturing cyber conversation is some version of “our production systems aren’t connected to the internet.” It is almost never fully true anymore.

The air gap erodes one reasonable decision at a time: the equipment vendor gets remote access for support and diagnostics. The ERP system starts pulling live production data off the floor. IoT sensors get added for predictive maintenance and quality monitoring. A cellular modem goes into a panel so an integrator can troubleshoot without a site visit. An engineer bridges the networks with a laptop because walking a USB stick across the plant got old. Each connection was justified. Together they mean the plant floor is reachable — and most ransomware that stops production doesn’t attack the PLCs directly anyway. It takes down the IT systems the plant can’t run without — order processing, scheduling, shipping, quality records — or forces an OT shutdown as a precaution.

The insurance consequence is direct: an insured who represents their OT as air-gapped on an application, when it is connected in any of the ways above, is handing the carrier a question to raise at claim time. This is the difference between understanding the risk you are keeping and the risk you are transferring — and the honest answer starts with an accurate map of what actually touches what.

What does a cyber event cost when the line stops?

The oldest cautionary tale in manufacturing insurance is the facility fire with no business income coverage — twelve to eighteen months of revenue gone, because nobody knew the coverage existed until the building was already down. The cyber version of that story is now far more common than the fire, and it doesn’t require a single flame: idle labor on a scheduled shift, in-process batches scrapped, changeover and restart time, expedited freight to protect delivery commitments, contract penalties for missed ship dates, and customers who quietly dual-source afterward.

A stopped line is a business interruption loss with a cyber cause — which means the cyber policy’s BI terms deserve the same scrutiny a property BI program gets, and rarely receive it.

Does cyber business interruption match how a plant actually restarts?

Four terms decide whether it does.

The waiting period is the cyber policy’s time deductible — the number of hours systems must be down before business interruption coverage begins to pay. Waiting periods commonly run from a handful of hours to a full day or more, and for a plant running continuous processes or tight shipping windows, the difference between an 8-hour and a 24-hour waiting period can be most of the loss. Second, the period of restoration: when coverage stops. Systems being restored is not the line being restored — requalifying equipment, rebuilding schedules, clearing backlogs, and winning back throughput can run well past the day IT declares victory, and policies differ on how much of that tail they cover. Third, how the loss is measured: a manufacturer needs the calculation to reflect lost production and the extra expense of protecting customers, not just a generic revenue formula. Fourth, the gaps already examined in ransomware coverage gaps — sublimits and coinsurance on the extortion coverage itself — all still apply here, on top of the BI terms.

Every one of those is invisible on a premium comparison. All of them are visible in the policy — if someone reads it before it’s needed.

Where do a cyber policy and a property policy leave a manufacturer exposed?

This is the seam the title calls the property-cyber overlap, and for manufacturers it’s the sharpest edge of the whole program.

Cyber policies broadly exclude physical damage to tangible property. Commercial property policies were built for fire, wind, and water — and many exclude, sublimit, or never contemplated damage with an electronic cause of loss. A cyber event that overwrites firmware, drives equipment outside its operating limits, or ruins in-process product sits exactly where those two exclusions meet — the same quiet mechanics of sublimits, exclusions, and conditions that decide most coverage disputes.

Bricking coverage is the cyber insuring agreement that pays to replace hardware rendered permanently unusable by a covered cyber event — equipment that is physically intact but functionally dead. Not every cyber policy includes it; where it exists, it is often sublimited and may cover replacement but not the production time lost while replacements are sourced. Whether the seam between the cyber and property policies is closed — by endorsement, by carrier selection, by deliberate program design — is a placement question. Left unasked, it becomes a claim-time question, and coverage that looked fine on paper fails exactly when it matters.

How should a manufacturer structure cyber coverage before renewal?

Start with the floor, not the quote. Map what actually connects to the production environment — vendor remote access, IoT sensors, ERP integrations, that cellular modem in the panel. Price an hour of true downtime, including scrap, restart, and expediting, and set the waiting period and limits against that number instead of a guess. Then read the cyber policy and the property policy side by side at the physical-damage seam, and make someone name which policy owns each scenario.

The timing favors doing this now: as of mid-2026 the cyber market has softened substantially, and manufacturers who can document their controls — network segmentation between IT and OT, MFA on remote access, tested backups — are seeing meaningfully better coverage available for the same or better cost than their expiring terms. A soft market rewards exactly the diligence a hard market demands.

This mapping is a core module of the Business Risk Diagnostic™, Avanti Group’s pre-quote due diligence: laying your production dependencies and downtime economics against how your cyber liability coverage would actually respond — waiting period, restoration period, bricking, the property seam — before recommending anything. Most of the market quotes manufacturing cyber fast and hopes the plant never stops; the Diagnostic assumes the stop and reads your commercial program against it first.

Frequently Asked Questions

Does cyber insurance cover attacks on OT and industrial control systems?

Only if the policy is written to reach them. Coverage depends on how the policy defines a computer system and a covered event — some definitions comfortably include PLCs, SCADA, and other operational technology, while others were drafted with office IT in mind. A manufacturer should have the definitions read against its actual production environment before binding, not after an incident.

What does cyber business interruption cover for a manufacturer?

Lost income and extra expense from a covered cyber event, after a waiting period (a time deductible measured in hours) and within a period of restoration. The details decide the outcome: how long the waiting period runs, whether restoration extends to the plant actually producing again rather than systems merely being restored, and how lost production is measured.

What is bricking coverage?

Bricking coverage pays to replace hardware rendered permanently unusable by a covered cyber event — equipment that is physically intact but functionally dead, such as controllers with corrupted firmware. It is not standard in every cyber policy, is often sublimited, and may pay for replacement hardware without covering the production time lost while replacements arrive.

Will our property policy cover equipment damaged by a cyber attack?

Often unclear — which is the problem. Property policies were built for fire, wind, and water, and many exclude or sublimit damage with an electronic cause of loss, while cyber policies broadly exclude physical damage to tangible property. A cyber-caused equipment loss can fall into the seam between the two unless the program is deliberately structured to close it.

Our production systems are air-gapped — do we still need cyber insurance?

Yes, and the air gap deserves a hard look. Vendor remote access, IoT sensors, ERP integrations, and maintenance connections erode most air gaps over time — and even a genuinely isolated line usually depends on IT systems (orders, scheduling, shipping) that can force a production stop when they go down. Misdescribing OT as air-gapped on an application can also create problems at claim time.

Want to compare your options?

Click the button below to head to our quotes page where you can enter some basic information to have our team help with your insurance!

Ready to get started?

Start Your Quotes Today

Enter some basic information below to get the process started.

Service Options