, APAC
736 views
/Envato

How cyber insurance gaps can leave factory damage uncovered

Production shutdowns can outweigh data theft for industrial operators.

A ransomware attack that reaches a factory floor can do more than lock files. It can stop machinery, halt production, and disrupt supply chains. But when the damage turns physical, manufacturers may find that neither their cyber nor property policy fully covers the loss.

Tokio Marine Kiln Group Ltd. (TMK) Asia warned that this protection gap could become more significant as automation, industrial connectivity, and artificial intelligence increase the likelihood of attacks affecting physical processes.

In a 25 June 2026 release, TMK said Asia-Pacific accounts for more than half of global manufacturing output and was responsible for around a third of global cyber incidents in 2024, more than any other region and up 13% year on year. Manufacturing was the most targeted industry, whilst system intrusion attacks rose from 38% to around 80% of breaches in the region. TMK cited the 2025 IBM X-Force Threat Intelligence Index and Verizon’s 2025 Data Breach Investigations Report for the cyber data.

“Asia's manufacturing sector is experiencing an unprecedented rise in cyber risk as factories rapidly adopt Industry 4.0 technologies, including automation, artificial intelligence, IT, and cloud-based operations,” Lakshitha Fernando, general manager of Solarelle Insurance Pvt. Ltd. in the Maldives, told Insurance Asia in a written response.

Whilst those technologies can improve productivity and competitiveness, they also give attackers more ways to disrupt production, compromise intellectual property and interrupt supply chains, he added.

The risk becomes more complex when attackers reach operational technology connected to production machinery and plant processes.

Large industrial losses remain uncommon enough that buyers do not always prioritise the exposure, Georgie Furness-Smith, cyber underwriter at TMK, said.

“One of the reasons this risk remains underinsured is that it has not yet translated into a large number of visible losses,” Furness-Smith said in the report.

TMK said attacks are increasingly targeting systems controlling machinery, facilities and production processes, whilst the assessment and insurance of these risks remain largely based on traditional IT exposures.

Coverage falls between policies
The insurance problem emerges when a digital attack produces physical damage.

TMK said cyber policies typically exclude physical damage, whilst property policies can exclude cyber-related perils. This can leave repair costs, damaged machinery and resulting business interruption outside the protection manufacturers expect their insurance programmes to provide.

The mismatch can persist even amongst large companies. TMK’s underwriting data shows that some regional corporates buy multimillion-dollar property programmes to protect multibillion-dollar industrial assets but leave those assets uninsured against losses arising from a cyberattack.

According to Chris Hewison, insurance audit partner at PricewaterhouseCoopers (PwC) China, the concern from a Hong Kong insurance-market perspective is that existing cover may not align with the underlying exposure.

“Many cyber policies exclude physical damage, whilst property policies often exclude cyber-related perils,” Hewison said. “Consequently, insureds may discover after a significant incident that repair costs, machinery damage and related business interruption losses are not fully covered.”

He said these exposures require more than conventional cyber underwriting. Insurers may need to assess them through a combination of cyber, property, engineering and business-interruption expertise because the risks depend on industrial processes, safety systems, machinery behaviour and operational technology environments.

Jeremie Deschamps, regional head of cyber advisory for Asia at Lockton Companies LLC, similarly pointed to production shutdowns rather than data breaches as a potentially bigger loss for manufacturers. He said plant-level cyber maturity remains uneven even as companies digitise their operations.

Deschamps said manufacturers increasingly need to frame technical findings in terms insurers can underwrite, including potential downtime, cyber-triggered property damage and measurable resilience. These factors can help determine the scope of cover a company can secure.

Making coverage explicit
Closing the gap also requires manufacturers to understand how their systems and insurance programmes interact.

“Organisations should implement proper cybersecurity governance, continuous risk assessments, employee awareness programs, and comprehensive incident response capabilities,” Fernando said.

He also sees cyber insurance developing beyond financial compensation by giving policyholders access to incident-response specialists, forensic expertise, legal assistance and business-interruption protection.

Hewison said manufacturers should identify dependencies between critical IT and operational technology systems and assess whether their property, cyber and business-interruption programmes would respond to a cyber-triggered event. He cited Hong Kong’s Insurance Authority GL20 framework as a useful reference for identifying critical systems and dependencies, conducting business-impact analysis, continuously monitoring risk and planning incident response.

For insurers, Hewison said affirmative cover for cyber-triggered physical damage and business interruption could help address the protection gap, although the complexity of these exposures requires specialist underwriting. Clear policy wording, accumulation modelling, incident-response support and better policyholder education would also be important, whilst ambiguous cyber exposures within traditional property programmes could create further uncertainty.

He also said insurers and brokers could position cyber insurance more broadly as an operational-resilience product rather than chiefly as protection against data breaches. Depending on the cover purchased, policies can encompass incident response, forensic services, cybercrime, liability, business interruption and cyber-triggered physical damage.

Specialist products are already available, though TMK said only a limited number of insurers provide affirmative protection specifically designed for cyber-triggered physical damage and resulting business interruption. TMK said it has provided insurance for these losses for more than 10 years.

The exposure also extends beyond manufacturing. TMK identified logistics, healthcare, utilities and power generation as sectors particularly reliant on interconnected systems and operational technology. Highly integrated production networks can also allow disruption at one location to produce wider regional or global consequences.

As production becomes more automated and connected, TMK expects incidents affecting physical processes to become a bigger concern.
 

Join Insurance Asia community

Follow the link s for more news on

Join Insurance Asia community
Since you're here...

...there are many ways you can work with us to advertise your company and connect to your customers. Our team can help you design and create an advertising campaign, in print and digital, on this website and in print magazine.

We can also organize a real life or digital event for you and find thought leader speakers as well as industry leaders, who could be your potential partners, to join the event. We also run some awards programmes which give you an opportunity to be recognized for your achievements during the year and you can join this as a participant or a sponsor.

Let us help you drive your business forward with a good partnership!