Risk Management
Cyber Insurance in Industry: Technical Requirements and How to Prepare for the Assessment
Insurers increasingly demand specific technical controls for OT environments. What they assess, how it affects the premium and how to prepare for the insurance assessment.

The insurance market after the major industrial incidents
The cyber insurance market changed profoundly after a series of high-impact incidents in manufacturing and infrastructure. NotPetya in 2017 caused billions in damages, with devastating effects on large industrial companies. Colonial Pipeline in 2021 showed what happens when a ransomware attack hits critical infrastructure. WannaCry shut down factories around the world.
Insurers responded in two ways: raising premiums and becoming far more selective about the risks they agree to cover. An industrial organization that cannot demonstrate a minimum level of cybersecurity maturity finds it increasingly hard to obtain coverage, or obtains it at much higher cost.
The consequence is that cyber insurance has become an indirect driver of security posture improvement: not by choice, but because obtaining reasonable coverage requires demonstrating adequate technical controls.
What insurers ask: the typical questionnaire
The process of underwriting a cyber policy typically begins with a detailed questionnaire. For industrial environments, the questions have evolved to include specific OT sections.
The main areas covered by these questionnaires:
Remote access: the question is almost always the same, "Does all remote access to OT/SCADA systems require MFA?" A negative answer is an immediate red flag for the underwriter.
Network segmentation: "Are OT systems separated from the IT network?", and often with technical follow-ups on how the separation is implemented and whether any dual-homed systems exist.
Patch management: "What is the process for applying security updates to OT systems?": the answer "not patchable for operational reasons" requires an explanation of the compensating controls.
Backup and recovery: "How often are control systems backed up? Are they tested? Are they kept offline?": ransomware attackers target backups, and insurers know it.
Incident response: "Is there an incident response plan? Does it include OT-specific scenarios? Is it tested with regular exercises?"
Asset inventory: "Do you have a complete inventory of the OT devices connected to the network?": the answer "not entirely" introduces uncertainty into the risk assessment.
The technical controls that move the premium
Not all controls carry the same weight in determining the premium. From experience with the most widely used underwriting questionnaires, a few controls stand out for their direct impact:
MFA on remote access: this is probably the single highest-impact control. An organization without MFA on remote access to OT systems is considered high risk almost automatically.
IT/OT segmentation: documented separation between the IT network and the OT network shows that a compromise of IT does not automatically propagate to OT and vice versa. It significantly reduces the risk of a high-impact incident.
EDR on SCADA/HMI workstations: extending endpoint detection tools to supervisory systems (where technically possible) is viewed positively as a detection capability.
Offline and tested backups: keeping backups of critical systems (PLC configurations, control logic, historian databases) offline and testing them regularly drastically reduces the impact of a ransomware attack.
A documented and tested IR plan: having a plan is not enough; it must be documented, specific to OT scenarios, and tested with tabletop exercises at least annually.
The OT paradox: legacy raises the risk, budgets do not follow
The structural problem for many industrial organizations is the OT paradox: the oldest systems, the ones with the most unfixable vulnerabilities, are often the most critical to production and therefore the hardest to replace.
A PLC from the early 2000s that does not support MFA, runs on firmware that cannot be updated and has no security logs is an objective point of risk. The insurer sees it, assesses it, and reflects it in the premium or in an exclusion from coverage.
The answer is not always immediate replacement, which can take years and millions. It is to demonstrate the compensating controls: physical or logical isolation of the legacy system, monitoring of network traffic to and from the system, controlled physical access procedures, compensation through the controls of adjacent systems.
Preparing for the assessment: concrete steps
An organization that wants to improve its insurance position has a fairly well-defined path:
-
Preliminary self-assessment: complete the standard questionnaire before the insurance assessment to identify the most obvious gaps. Many insurers make the questionnaires available in advance.
-
Identifiable quick wins: MFA on remote access, documenting backups and restore tests, drafting a basic IR plan: these are actions achievable in weeks, not years, and they have an immediate impact on the risk assessment.
-
Documenting legacy systems: do not hide the systems that cannot be patched; document why they cannot be updated and which compensating controls are in place.
-
Evidence, not just statements: the more sophisticated insurers ask for technical evidence (configuration screenshots, documented policies, assessment reports), not just yes/no answers to the questionnaire.
The goal is not to deceive the insurer: it is to present a realistic security posture with a credible improvement plan. An organization that is transparent about its vulnerabilities and has a documented remediation plan is in a better position than one that claims controls that do not actually exist.
The MON5 angle
Many of the insurance questionnaire questions are answered by MON5's outputs: the continuous inventory of the ANALYZE phase documents OT assets with their versions and known vulnerabilities, while the monitoring of the PROTECT phase shows that the industrial network is being watched. This is evidence that weighs both on the premium and on the validity of the payout in the event of a claim.
The compensating controls on legacy systems, which insurers require, also become demonstrable: the traffic to and from the device that cannot be patched is tracked and analyzed. Before your next policy renewal, it is worth reviewing the situation with an OT assessment.
Related articles
Regulations
IEC 62443 in practice: from gap assessment to your first remediation plan
IEC 62443 is the reference standard for industrial control system cybersecurity. How to use it concretely: structure, gap assessment and a first five-step remediation plan.
Compliance
ISO 27001 in OT Environments: Extending the ISMS Beyond the IT Perimeter
Many industrial organizations already hold ISO 27001 for IT. Extending it to OT environments demands a specific approach: different threat models, operational constraints and integration with IEC 62443.

Risk Management
The OT Cybersecurity Budget: How to Build the Business Case and Measure ROI
The OT cybersecurity budget is often an afterthought next to IT, even when operational risk is far higher. How to build a convincing business case and measure the ROI of industrial security investments.
Do you have visibility into your OT network?
MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.