Operational technology is not information technology, and the distinction decides the claim
A connected plant creates at least four different exposures that are routinely treated as one. They are not one.
- Information technology — email, ERP, customer data, payment flows. What most cyber policies were written for.
- Operational technology — the systems that run the plant. A loss here stops production and can damage equipment, which is a materially different claim from a data breach.
- Industrial control systems — PLCs, SCADA, HMIs and safety instrumented systems, frequently running software that cannot be patched on an IT schedule because doing so stops the line.
- Embedded and connected products — software inside the thing you ship. This is a product exposure that happens to be digital, and it may sit closer to product liability than to cyber.
Then there are the parties: vendors with remote access into your control systems, integrators, and the technology supply chain behind your components.
“Cyber insurance covers ransomware” is not a useful statement. Whether a policy responds to a plant shutdown depends on the trigger, whether the form contemplates operational technology at all, waiting periods, sublimits, whether physical damage to equipment is excluded, and whether the response obligations were met. Cyber coverage does not automatically insure equipment damage, and property coverage does not automatically insure a production delay caused by a network event.
The standards that define this ground
NIST Special Publication 800-82 Revision 3, Guide to Operational Technology (OT) Security (September 2023) is the controlling federal reference. It provides an overview of OT and typical system topologies, identifies common threats and vulnerabilities, and recommends security countermeasures — explicitly accounting for the performance, reliability and safety constraints that make OT different from IT. It covers industrial control systems, building automation, physical access control and environmental monitoring.
NIST IR 8183 Revision 2, Cybersecurity Framework 2.0 Manufacturing Profile gives manufacturers a voluntary, risk-based approach mapped to CSF 2.0, including the Govern Function and expanded treatment of supply chain risk management and platform security. It is an Initial Public Draft, not a final standard, and should be treated accordingly.
CISA’s Critical Manufacturing Sector Cybersecurity Framework Implementation Guidance sets out a seven-step implementation process, maps existing tools to Framework components, and provides risk assessment methodology and case studies for manufacturers.
None of these is an insurance document. They describe what a defensible security posture looks like — which is the same evidence an underwriter asks for, and the same record that matters if a claim is disputed.
Elsewhere in this ecosystem: Manufacturing · Resource Center · Operations · Coverage · Risk management · Glossary
The distinctions that change the answer
The patch cycle is the exposure
Your vendor’s access is your exposure
Where insurance and the standards meet
NIST SP 800-82 Rev. 3 treats availability and safety as primary in operational technology, where most information-security guidance treats confidentiality as primary. That inversion is exactly why a cyber policy written around data may not respond well to a plant that has stopped. Whether any policy responds depends on its trigger, whether the form contemplates operational technology at all, waiting periods, sublimits, physical-damage exclusions and whether response obligations were met. These are form-level questions, and they require reading the policy.
Related material that is live now
Cyber liability
Coverage cluster
Manufacturing glossary
Map the plant network before the renewal
Which systems are connected, who has remote access, and what stops if they go down. Those three answers change the cyber conversation from generic to specific.
.png?width=500&height=136&name=4J%20commercial%20insurance%20broker%5B1%5D%20(1).png)