OT Cyber Risk Articles & Guides — DeNexus Learn

What Underwriters Need to Know About OT vs. IT Cyber Risk Before Binding

Written by Donovan Tindill | Aug 6, 2026, 3:02:33 PM

What Underwriters Need to Know About OT vs. IT Cyber Risk Before Binding a Policy

You have a submission, a deadline, and a decision to make. The applicant runs industrial operations — a manufacturing plant, a utility, a pipeline, a data center — and somewhere in the file is an OT cyber exposure you're being asked to put capacity behind. The question in front of you isn't academic. It isn't "what is operational technology?" It's narrower and more urgent: what do you need to believe about this OT environment before you bind?

Most cyber underwriting guidance for OT answers a different question than that one. It explains OT to operators, or it walks through security architecture. This is about the pre-bind decision: what to assume, what to ask, and what to price differently when the risk on the desk is industrial (cyber-physical) rather than enterprise (data breach).

The one inversion that changes everything 

Enterprise IT security is built around confidentiality. The worst outcome is data exposed: records stolen, privacy breached, liability triggered. Cyber policies grew up around that model, which is why they center on breach response, notification, and third-party liability.

OT security inverts the priority. In an industrial environment, the worst outcome is a process that stops, a machine that breaks, or a person who gets hurt — cyber crossing into the physical. Availability and safety come first; confidentiality is often the least of the concerns. That inversion is the single most important thing to carry into an OT submission, because it changes the kind of loss you're underwriting.

An IT cyber loss is largely a cost event: response, restoration, liability, regulatory exposure. An OT cyber loss is a physical event with a cost attached: downtime priced by the hour, equipment repaired or replaced, product spoiled, contracts missed, and in the worst cases safety and environmental consequences. The loss mechanism is different, and because industrial downtime scales with time and physical damage compounds, the tail is fatter. You are not pricing a bigger version of enterprise cyber. You are pricing a different loss distribution.

Five places the IT-style questionnaire will mislead you. 

Most OT submissions arrive on questionnaires designed for enterprise cyber. They ask reasonable IT questions and produce answers that look complete while missing what an OT underwriter actually needs. Five areas matter most.

Segmentation and the IT/OT boundary. The IT-style question asks whether the network is segmented. What you need to know is whether the plant floor can keep running when the corporate network is compromised, how traffic crosses the boundary, and whether there's a demilitarized zone or a flat network wearing the word "segmented." Every OT environment has an official architecture and an unofficial one — vendor VPNs, dual-homed engineering workstations, cellular modems, and other conduits that never make it onto the network diagram — and the unofficial one is what actually determines exposure. Most OT-related incidents still originate in the IT environment and reach OT through that boundary [1], so the boundary's real architecture, not the yes/no, is the exposure.

Remote access into the OT environment. The questionnaire asks if remote access exists. What you need is how it's governed: MFA, an intermediary jump host, where the VPN terminates, and how many vendors hold standing access to controllers. Remote access is a primary intrusion pathway into industrial environments, and "yes" with no architecture behind it should read as an open question, not a closed one.

Recovery, and whether it's ever been tested. The IT question asks about backups. The OT question is whether the facility can fall back to manual control, whether isolation of the OT network has been validated under stress, and whether recovery has been rehearsed or merely documented. Restoring the data isn't the same as restoring trust in it — a recovery that skips integrity validation can put a compromised configuration back into production with a clean-looking timestamp. When Norsk Hydro was hit by LockerGoga ransomware in 2019, the company chose not to pay and restored from backups instead — a decision that still cost an estimated $71 million and left much of the business running manually for weeks [2]. A plant that has never tested running without its control system is carrying recovery risk it can't quantify, and neither can you.

Shared infrastructure and identity. The IT-style question asks whether backups exist and whether MFA is enforced somewhere in the environment. What you need to know is whether OT shares Active Directory, DNS, or privileged accounts with the corporate network — because if it does, an ordinary enterprise breach becomes an OT breach without anyone touching a controller. Domain controllers, jump hosts, and backup infrastructure carry more operational leverage than any single HMI, and they're usually ordinary Windows or Linux systems that can be hardened to a far higher standard than the plant floor. A questionnaire that never asks about shared identity is missing the fastest path from an IT incident to an OT one.

Asset visibility and end-of-life exposure. Enterprise environments are inventoried continuously. Brownfield OT environments frequently contain assets that haven't been catalogued since commissioning, and equipment years past vendor support. The questionnaire rarely surfaces this. The share of unsupported, end-of-life assets is a loss-magnitude multiplier that hides behind a clean-looking form. The count alone can mislead in the other direction too: a legacy asset that's genuinely isolated behind a validated boundary is a smaller loss driver than a newer system bridging IT and OT — age is a proxy for exposure, not a substitute for it.

In each case the pattern repeats: the IT-shaped question gets an answer, the answer looks fine, and the thing you needed to price is somewhere the form never asked. The pattern holds at the aggregate level too: "we have backups" or "we have logging" is a presence answer, not a coverage answer, and coverage of the asset population is what the loss curve actually prices. (For why the unanswered OT questions carry their own signal, see the companion piece on reading missing data.)

How OT changes pricing, not just risk grading 

It's tempting to treat OT as a modifier — take the cyber grade, adjust for the industrial wrinkle. That understates it. Availability-driven losses concentrate in ways enterprise cyber losses don't. A single event that halts a continuous process can breach the retention within a day and keep climbing while the plant is down. Physical damage doesn't reset when systems are restored; it has to be repaired or replaced on physical timelines. This is where the tail of the OT distribution lives, and it's the part a severity-blind grade misses most.

The 2021 Colonial Pipeline ransomware attack showed how fast that tail can arrive: a single compromised password led the company to proactively shut down the entire pipeline, triggering fuel shortages across the U.S. East Coast within days — a downstream, physical consequence far larger than the direct IT compromise that caused it [3]. And the 2017 TRITON malware, which targeted the safety instrumented systems at a petrochemical plant, is the clearest reminder that OT's worst-case tail isn't hypothetical: it was designed specifically to disable the systems that exist to prevent catastrophic physical failure [4].

The practical consequence is that OT cyber rewards thinking in exceedance terms rather than point scores. Not "this risk is a 7 out of 10," but "there's an X% chance annual loss exceeds the retention, and the plausible worst case looks like this." A grade tells you where a risk sits relative to peers. A loss curve tells you what you're actually exposed to when the bad year arrives — which is the number that decides whether the program is priced correctly. (The companion piece on reading a cyber loss report walks through how to interpret those curves.)

What "good" looks like in an OT submission 

The strongest OT submissions share a pattern, and it's worth knowing so you can ask for it when it's absent. They evidence rather than attest: a current network diagram instead of a segmentation checkbox, a remote-access architecture instead of a yes, a dated restoration test instead of a backup policy. They show that the controls most tied to loss severity — segmentation, governed remote access, tested recovery, shared infrastructure hardening — are not just present but demonstrable. And they let you separate what's strong from what's weak instead of averaging the two into a single reassuring number.

Where a submission can't show these things, the gap itself is priceable information rather than a reason to assume the middle of the distribution.

OT cyber is a different loss model, not cyber with a plant attached 

The underwriters who lose money on OT cyber are usually the ones who bound it on enterprise assumptions: confidentiality-first thinking applied to an availability-first risk, a point score standing in for a loss curve, a clean questionnaire mistaken for a well-understood exposure. The ones who price it well start from the inversion and never let go of it. The loss is physical. The tail is fat. The most important controls are the ones the standard questionnaire probes worst.

Binding an OT cyber risk on IT logic doesn't just misgrade it. It misprices the part of the distribution that actually costs money — the tail — which is the one part you can't afford to get wrong.

Related Reading

On the DeNexus Learn portal.

On the DeNexus blog.

References

[1] Dragos, Inc. — 2023 OT Cybersecurity Year in Review: confirms that approximately 70% of OT-related incidents originated from within the IT environment. https://www.dragos.com/resources/press-release/dragos-ot-cybersecurity-year-in-review-reports-rise-in-geopolitically-driven-attacks-ransomware-and-threat-groups

[2] Microsoft — "Hackers Hit Norsk Hydro with Ransomware. The Company Responded with Transparency": Norsk Hydro LockerGoga ransomware attack (March 2019), financial losses of approximately $71 million; the company did not pay the ransom and restored from backups instead, operating manually for weeks. https://news.microsoft.com/source/features/digital-transformation/hackers-hit-norsk-hydro-ransomware-company-responded-transparency/

[3] CNN — "Ransomware Attackers Used Compromised Password to Access Colonial Pipeline Network, Company Confirms": Colonial Pipeline ransomware attack (May 2021), a single compromised password led to the proactive shutdown of the entire pipeline, triggering fuel shortages across the U.S. East Coast. https://edition.cnn.com/2021/06/04/politics/colonial-pipeline-ransomware-attack-password/index.html

[4] FBI/IC3 — "TRITON Malware Remains Threat to Global Critical Infrastructure Industrial Control Systems (ICS)" (Private Industry Notification, 24 March 2022): TRITON/TRISIS malware (2017) targeted the safety instrumented systems (SIS) of a petrochemical plant, specifically designed to disable the systems that prevent catastrophic physical failures. https://www.ic3.gov/CSA/2022/220325.pdf