Cyber Risk Can Be Physical…? 

Anita Molitor

4 Min Read

Cyber property damage refers to physical damage caused by a cyber incident, including damage to machinery, infrastructure or stock. 

At first glance, cyber insurance and physical damage may not seem like natural bed fellows. One belongs to the world of data, networks and systems; the other to machines, buildings, stock and infrastructure. Yet this is precisely where the risk is changing. When digital systems control physical processes, a cyber incident can very quickly move out of the server room and onto the factory floor, into the warehouse, onto the vessel or inside the building itself. 

That is what makes this topic so relevant for businesses today. Companies need to look beyond familiar categories and question whether their risk landscape still fits the way their insurance programmes are structured. We’re all aware we need to protect our data, but we need to open our eyes to how deeply our digital environments are connected to our physical ones. 

What do we mean by cyber property damage? 

Cyber property damage refers to physical damage caused by a cyber incident, including damage to machinery, infrastructure or stock. 

Sectors using Operational Technology, including Industrial Control Systems (ICS), SCADA (Supervisory Control and Data Acquisition) systems or the Internet of Things, are among the most affected. Everything is interconnected, which means that, in the event of a cyberattack, operations can quickly come to a standstill. This involves a huge number of companies, because if we look at the IoT alone, the number of connected IoT devices is set to grow by 14 per cent by 2025 and reach 39 billion by 2030; >50 billion by 2035, according to IoT Analytics. 

Why the line between digital and physical is disappearing 

In many companies, the systems that once simply monitored operations now actively control them. Production lines, cooling systems, pumps, sensors, cranes, access controls and building management systems are often connected, automated and remotely accessible. This brings enormous advantages, but it also means that a weakness in a digital system can have very practical consequences in the real world. 

A cyberattack does not have to destroy data to cause damage. It may be enough to alter a setting, interrupt a shutdown process, disable a safety mechanism or manipulate a control signal. The result can be fire, overheating, spoiled stock, damaged machinery or business interruption with a very physical root cause. 

When cyber risk leaves a physical mark 

So where is the property damage in all this? The best-known example dates from 2014: cybercriminals used spear-phishing to gain access to the network of a German steelworks, manipulated the shutdown process of a blast furnace and thereby caused considerable property damage and production losses. 

Another example is where a group of hackers gained access to a facility via a backdoor in third-party software; the hackers injected malware to gain access to the IoT system. This enabled them to manipulate the manufacturing process, causing a fire to break out. 

In shipping, for example, hackers could manipulate a ship’s engine systems and put them out of action. This could lead to collisions with other vessels, causing damage to the ship and its cargo. 

High-rise buildings provide another example. Many are ‘smart’ these days, meaning that critical systems such as heating, water pumps and ventilation systems are digitised. If hackers were to take control of these systems, this could lead to widespread power cuts and property damage. 

These examples show why the insurance discussion cannot stop at the cause of the incident. It also has to consider the consequences. If the trigger is cyber, but the loss is physical, the question of which policy responds can quickly become complicated. 

Overcoming the coverage gap 

Cyber insurance focuses on data leaks, data breaches and network security – not on property damage. Property insurance generally covers material risks such as fire or flooding but increasingly excludes cyber-related incidents. So we have a coverage gap. The first step must be taken by companies themselves: they need to carry out a risk assessment to determine whether a cyberattack could result in property damage. It is important to understand that continuous adaptation to the rapidly changing threat landscape is essential. 

This cannot be left solely to the IT department. In cybersecurity, IT and operational technology (OT) should be firmly united and make decisions on changes to OT systems together. Instead of time-based maintenance, the focus should be on risk-based maintenance that takes potential cyber risks into account. Systems should be monitored not only for their condition, but also for their cybersecurity. 

OT must also be included in the tested incident response plan to ensure an appropriate response in the event of a cyberattack. A purely mechanical inventory of plant assets will no longer suffice; asset management should cover both mechanical and digital assets. 

Improving security measures is important because it can help mitigate the risk, but it only addresses part of the problem. Existing property and cyber insurance policies should therefore be reviewed for any gaps in cover. Cyber cover must be examined very carefully, as some policies cover property damage only to IT hardware, which is of little help in the event of genuine property damage. 

Where does the gap sit? 

The gap often sits between the wording of a cyber policy and the exclusions or limitations in a property policy. One may not go far enough into physical damage; the other may step back when the cause is cyber-related. That is why it is so important not to look at policies in isolation, but to test how they would respond together in a real scenario. 

It is important to know what insurance cover is in place, not least because property damage resulting from a cyber-attack is highly complex. The forensic team must determine whether the property damage was caused by a cyber incident or by other factors. A single incident can trigger multiple insurance policies, requiring insurers to cooperate effectively. 

The solution starts before the incident 

For companies, this means the discussion should begin long before a claim occurs. Cyber, property, engineering, risk management and operations all need to be part of the same conversation. Only then can the company understand where the exposure lies, where cover already exists and where a tailored solution may be needed. 

The good news is that cover for property damage resulting from a cyberattack is available on the market, but it needs to be assessed carefully. The key is to understand how existing cyber and property policies interact, where exclusions may apply and whether additional cover is needed. 

Anita Molitor

Cyber Specialist

T +43 664 962 40 08

Related Industries & Solutions

Share this article

Related Insights

GrECo and DIGNITA Join Forces to Strengthen Their Position in Bosnia and Herzegovina
MGAs operate within authority granted by insurers, with responsibility for underwriting, policy issuance, portfolio management and, depending on the model, claims support or coordination.
MGAs operate within authority granted by insurers, with responsibility for underwriting, policy issuance, portfolio management and, depending on the model, claims support or coordination.