How exposed are Asia's factories to cyberattacks?
Many industrial losses fall outside traditional insurance policies.
Asia-Pacific (APAC) manufacturers are becoming more vulnerable to cyberattacks that can damage factories and disrupt production, but many may not have insurance covering the resulting physical losses.
“As operational technology becomes more integrated with IT (information technology) systems, cyber-attacks are increasingly targeting systems that control industrial activity, raising the potential for disruption to physical operations impacting machinery, facilities and production processes,” Georgie Furness-Smith, a cyber underwriter at Tokio Marine Kiln Group Ltd. (TMK) Asia, said in a June statement.
She said cyber risks remain underinsured partly because big industrial losses have been relatively uncommon, even as attacks on operational technology continue to increase.
APAC region accounts for more than half of global manufacturing output and posted about one-third of worldwide cyber incidents in 2024, the highest share of any region, TMK said in a report.
Manufacturing was the most targeted industry, whilst system intrusion attacks accounted for about 80% of breaches, up from 38% a year earlier.
TMK said many standard cyber insurance policies exclude physical damage, whilst property insurance might exclude losses caused by cyber incidents. As a result, companies could face uninsured repair costs and business interruption after an attack.
It added that manufacturers, logistics operators, healthcare providers, utilities, and power generators face growing exposure as they adopt more connected equipment, automation, and artificial intelligence.
Munich Reinsurance Company also identified a protection gap amongst consumers.
Its Global Cyber Risk and Insurance Survey 2026 found that 58% of respondents had experienced or been affected by a cyberattack, including online shopping fraud, malware, fraudulent bank transfers, data theft, and identity theft.
Despite that, 41% said they neither had nor intended to buy personal cyber insurance. Amongst those without cover, 32% were unaware such products existed, 31% considered them too expensive, and 19% did not understand what they covered.
Munich Re estimated global fraud losses at as much as $500b annually, including both digital and nondigital fraud.
Questions to ponder:
- How can manufacturers close cyber insurance gaps as factories become more connected and automated?
- Should cyber insurance evolve to cover physical damage caused by attacks on industrial systems?
- What can insurers do to improve awareness and adoption of cyber insurance amongst businesses and consumers?
EXPERT OPINION
There is likely to be a significant risk, which is growing. In additional to traditional cyber exposures manufacturing and operational technology companies also face major emerging challenges including very high rates of shadow AI, and growing connectivity exposures across asset management software and automation systems.
A second issue is that manufactures typically have cyber incident response ownership issues as key risk owners will vary across site specific engineers, external vendors and centralised information security teams. This means incidents are more challenging to resolve and respond to, and business interruption loss profiles tend to be worse than traditional organisations.
In respect of the insurance policy piece, where events result in physical damage they are difficult to insure under cyber liability policies as they often include property damage and personal injury exclusions. Similar property wordings traditionally include cyber exclusion, and particularly consequential losses from cyber events.
There are some solutions in the marking including cyber write backs on property programs, affirmative property damage cover on cyber liability insurance and various insurance program endorsements. Often however organisations haven't don't the pre risk assessment work to understand what realistic physical and consequential losses a manufacturing business could face, so they don't do the underlying work to identify what gaps could arise in the program and how best they can be remediated.
These issues will be come more prominent given the focus on AI model integration with robotics, and the focus on agentic orchestration for operational technology assets.
Asia's manufacturing sector is experiencing an unprecedented rise in cyber risk as factories rapidly adopt Industry 4.0 technologies, including automation, artificial intelligence, IT, and cloud-based operations. While these innovations enhance productivity and competitiveness, they also expand the cyber threat landscape. A single ransomware attack or network intrusion can disrupt production, compromise intellectual property, interrupt global supply chains, and result in substantial financial and reputational losses.
Cyber resilience must therefore become a boardroom priority rather than an operational afterthought. Organizations should implement Proper cybersecurity governance, continuous risk assessments, employee awareness programs, and comprehensive incident response capabilities. From an insurance perspective, cyber insurance has evolved beyond financial indemnification to become a strategic risk management solution, providing organizations with access to specialist incident response, forensic expertise, legal support, and business interruption protection. As cyber threats continue to evolve, proactive risk management will be the defining factor that separates resilient manufacturers from vulnerable ones.
APAC manufacturers are rapidly digitizing plants in the world's most-attacked sector. Their biggest cyber loss isn't a data breach, it's a ransomware-driven production shutdown. Modernization programs are making APAC a high-growth OT security market with distinctly uneven plant-level maturity. Insurance wise, translating findings into financial and insurance language, downtime scenarios, cyber-driven property damage, underwriting-ready resilience metrics are becoming increasingly relevant to scope and secure the best cover.
In my view, the article highlights a significant and growing protection gap for Asia-Pacific manufacturers. Cyber risk is no longer limited to data breaches, ransomware or non-physical business interruption. As factories become increasingly reliant on Operational Technology (OT), automation, AI-enabled production and connected supply chains, cyber incidents can result in physical damage, production shutdowns and wider supply-chain disruption.
From a Hong Kong insurance market perspective, the key concern is that insurance coverage may not align with the underlying exposure. APAC accounted for approximately one-third of global cyber incidents in 2024, with manufacturing being the most targeted sector. At the same time, many cyber policies exclude physical damage, whilst property policies often exclude cyber-related perils. Consequently, insureds may discover after a significant incident that repair costs, machinery damage and related business interruption losses are not fully covered.
Cyber insurance should evolve to provide affirmative cover for cyber-triggered physical damage and business interruption, but this requires specialist underwriting. Unlike traditional cyber risks, cyber-physical exposures require an understanding of industrial processes, safety systems, machinery behaviour and OT environments. These risks should therefore be assessed through a combined cyber, property, engineering and business interruption lens rather than as a simple extension to conventional cyber policies.
Manufacturers can reduce this protection gap by identifying their critical IT and OT dependencies and assessing whether existing property, cyber and business interruption programmes respond appropriately to cyber-triggered events. Hong Kong’s Insurance Authority GL20 framework provides a useful reference, emphasising the identification of critical systems and dependencies, business impact analysis, continuous monitoring, and incident response planning. For insurers, the opportunity is substantial, with the global cyber insurance market expected to continue growing. However, sustainable growth will depend on clear policy wordings, robust accumulation modelling, effective incident response support and better policyholder education. The industry should avoid creating further uncertainty through silent or ambiguous cyber exposures within traditional property programmes.
The article also highlights a continuing awareness gap. Cyber insurance is often viewed solely as a data breach product, whereas insurers and brokers should position it more broadly as an operational resilience solution encompassing incident response, forensic services, cyber crime, liability, business interruption and, where purchased, cyber-triggered physical damage cover.
Overall, I agree with the article’s conclusion that Asia’s factories face a growing cyber-physical risk exposure and that the insurance protection gap is real. Manufacturers should undertake structured cyber-physical exposure assessments, insurers should develop clear affirmative coverage where they possess the required expertise, and brokers should help clients align operational resilience risks with policy coverage. In Hong Kong and across APAC, those insurers best able to combine cyber expertise, engineering knowledge and disciplined underwriting are likely to be the most successful.