OT Cyber Risk Articles & Guides — DeNexus Learn

Why Missing Data Is a Risk Signal, Not a Blank Field: Underwriting OT Cyber Submissions

Written by Donovan Tindill | Aug 6, 2026, 3:02:04 PM

Why Missing Data Is a Risk Signal, Not a Blank Field: Underwriting OT Cyber Submissions 

A submission lands on your desk. The IT section is complete: MFA everywhere, EDR deployed, backups documented, a tidy incident-response plan attached. Then you reach the OT section, and it thins out. Segmentation: blank. Remote access into the plant: blank. Recovery testing: blank. Roughly seven in ten OT questions are unanswered.

The easy read is that the applicant simply didn't get to those questions, and that the blanks are neutral: unknown, not bad. Price the IT posture, note the OT gaps as follow-ups, move on.

That read is the mistake, and it's an expensive one. In OT cyber, a submission that can't evidence its controls is telling you something. The blank is not the absence of a signal. It is the signal.

Why a blank OT answer is not neutral  

Cyber underwriting has quietly shifted from evaluating controls to evaluating evidence of controls. An attested control — a checkbox ticked, a policy named — carries less weight than a control the applicant can actually show: a current network diagram, a jump-host configuration, a restoration test with a date on it. That distinction matters more in OT than anywhere else, for a structural reason: in cybersecurity compliance regimes such as a NERC CIP audit, it's the performance of the task and corroborating evidence that proves the work is completed [1].

The controls that most reduce OT loss are the ones a non-specialist submission is least equipped to describe: network segmentation between IT and the plant floor, governed remote access with MFA and an intermediary host, OT-native monitoring that would catch a rogue command to a controller, and tested fallback to manual operation. These aren't the controls a generic cyber questionnaire probes well, so when the applicant's security team is IT-led, the OT answers are the ones that go blank. The silence correlates with exactly the exposure you most need to price.

Put plainly: the areas an OT submission leaves empty are rarely random. They cluster around the controls that separate a contained incident from a plant-wide shutdown. Treating that cluster as "unknown, therefore neutral" quietly prices it as average, when the base rate says it's usually worse than average. These unknowns function as risk factors that can act as loss-magnitude multipliers in a real cyber incident.

The three things silence usually hides 

Across OT submissions, unanswered questions tend to fall into three groups, each mapping to controls that drive loss severity.

Segmentation claimed, not shown. The application says the OT network is segmented from IT, but there's no network diagram, no description of the demilitarized zone, no account of how traffic crosses the boundary. IT and OT might be physically separated with a firewall, but logically the rules might be wide open ("ip any any"). Segmentation is the single control most associated with keeping an IT-origin compromise out of the plant — and according to Dragos's 2023 OT Cybersecurity Year in Review, approximately 70% of OT-related incidents originated from within the IT environment. A segmentation claim with no supporting evidence is the highest-value blank on the form. Dragos

Remote access answered "yes," then dropped. The applicant confirms remote access into the OT environment exists, then goes quiet on how it's governed: no mention of MFA, no intermediary jump host, no VPN termination point, no account of who holds standing access. Remote access is a primary intrusion pathway into industrial environments; "yes, and we'll say no more" is not reassurance.

Backups asserted, recovery untested. Backups are checked off, but there's nothing on restoration testing, DCS/SCADA/HMI/PLC tags-graphics-logic coverage, whether the plant can run in manual mode, or on whether isolation of the OT network has ever been validated under stress. A backup that has never been restored is a plan, not a capability.

Each of these maps cleanly onto the structure of the OT security standards underwriters increasingly lean on, from the layered controls in NIST SP 800-82r3 to the foundational requirements in IEC 62443-3-3. The frameworks tell you which questions matter. The blanks tell you which of those the applicant can't answer.

Structural reading beats checklist scoring 

A checklist scores what's present and moves on. A structural read asks a harder question: given what this applicant could show and didn't, what's the most likely state of the controls they left blank?

That reframing changes how a gap is treated. It also argues for scoring IT and OT confidence separately rather than blending them into one number. In DeNexus's experience across IT and OT cybersecurity assessments, the OT environment rarely matches IT's control maturity — it consistently lags behind. A submission can warrant high confidence on its IT posture and low confidence on its OT posture at the same time, and a single averaged score hides precisely the imbalance that matters. The applicant in the opening example — strong IT, 70% of OT blank — would score respectably on a blended scale. Split the confidence in two, and the OT column lights up red where it should.

This is the reasoning behind what DeNexus calls the Sound of Silence: in the DeRISK UWA Agentic assessment, unanswered OT questions are treated as an adverse signal to be surfaced rather than a gap to be smoothed over, and IT and OT confidence are reported independently so the imbalance stays visible. The mechanism matters less than the underlying principle, which any underwriter can apply by hand: read the blanks as data.

What to do with a silent submission 

Reading silence as signal doesn't mean declining every incomplete file. It means the blank triggers a defined action instead of a default pass. In practice, three responses cover most cases:

  • Request the specific missing evidence, naming it precisely — the network diagram, the remote-access architecture, the date of the last restoration test. A serious applicant can produce these; the request itself is diagnostic, because an applicant who can't produce them has told you something further.

  • Price the residual uncertainty when the evidence can't come in time, rather than assuming the middle of the distribution. Silence should cost something, or applicants learn that leaving the hard questions blank is free.

  • Refer or decline when the silence covers the controls that most drive severity and can't be resolved before binding. A confident decision to walk away from an unpriceable tail is a better outcome than a cheap policy on a risk you never actually assessed.

None of these is "note it and move on." The blank earns a response.

The finding is in what's missing  

The quality of an OT cyber decision is set as much by what the submission can't show as by what it can. Generic cyber underwriting was built around information that was present and mostly reliable, so it learned to score the answers on the page. OT submissions break that habit, because the most important answers are the ones most likely to be absent — and their absence is not noise. It's the most honest data on the form.

The underwriters who price OT well are the ones who stopped reading blanks as zero and started reading them as evidence. The question a silent submission answers is the one it never fills in: what can this applicant not show, and why?

Related Reading

On the DeNexus Learn portal 

On the DeNexus blog.