Risk Attribute

OT/IT Network Segmentation

Expert-reviewed Updated: 2026-09-03 Expert-reviewed: 2026-09-04 (Guido Hesse, Hesse Group Holding AG) Version 0.1.0

OT/IT network segmentation records whether operational technology such as production and process control systems is logically and physically separated from the corporate IT network, limiting the ability of a cyber incident to cross into physical operations.

Category
IT/Cyber
Data type
Yes/No
Risk drivers
Severity, Accumulation
Underwriting impact
Premium, Sublimit, Condition/Warranty

Typical proposal-form questions

  • Is the operational technology (OT) network, including production, SCADA and process control systems, logically and physically segmented from the corporate IT network?
  • What mechanism enforces the segmentation (e.g. firewall, data diode, demilitarised zone) and is any direct remote access into the OT network possible?
  • Has the segmentation been independently tested or audited, and when?

Evidence

  • Network architecture diagram showing IT/OT boundary
  • Firewall ruleset or segmentation policy
  • OT security assessment or penetration test report

Why it matters for underwriting

Where operational technology sits on the same flat network as corporate IT, a ransomware infection that begins in an office email inbox can propagate into programmable logic controllers, SCADA systems and production lines, converting what would otherwise be a data and business-email loss into physical machinery damage and a full production stoppage. This attribute therefore sits at the intersection of cyber and property/machinery underwriting, since inadequate segmentation increases the probable maximum loss for both cover types simultaneously and can trigger claims under machinery breakdown or business interruption covers from what began as a purely digital intrusion. Underwriters treat strong segmentation as a key differentiator between manufacturing or process-industry risks that can contain a cyber event to the office environment and those where a single successful phishing email could stop the entire plant.

Capturing the attribute and evidence

Proposal forms ask whether OT and IT networks are logically and physically segmented, what specific mechanism enforces that separation, such as a dedicated firewall, a demilitarised zone or, in higher-hazard settings, a unidirectional data diode, and whether any direct remote access path bridges the two environments. Underwriters request a network architecture diagram clearly showing the IT/OT boundary, the firewall ruleset or segmentation policy governing traffic between zones, and, for larger industrial accounts, an independent OT security assessment or penetration test confirming the segmentation holds in practice rather than only on paper. Vendor or maintenance remote-access connections into the OT environment are scrutinised specifically, since they are a frequently exploited bypass of otherwise sound segmentation.

Effect on coverage, premium and conditions

Verified, well-enforced segmentation supports standard terms across both cyber and machinery covers and higher sublimits for contingent business interruption following a cyber event. Weak or undocumented segmentation, or the presence of unmonitored remote-access bridges into OT, typically results in a condition requiring remediation within an agreed period, a reduced business interruption sublimit for cyber-triggered production losses, or a specific exclusion of physical damage arising from a cyber incident under the machinery cover. Flat networks with no meaningful separation between office and production systems are a frequent basis for declinature or for pricing the cyber and machinery risk as a single, highly correlated exposure.

Mitigation measures

A segmented architecture following recognised industrial control system security standards is recommended, typically implemented through firewalled zones, a demilitarised zone for any systems that must exchange data between IT and OT, and strict limitation or removal of direct remote access into the OT network. Any remaining remote access for vendors or maintenance should be routed through a monitored, time-limited jump host requiring multi-factor authentication rather than a permanent open connection. Periodic independent testing of the segmentation boundary is recommended to confirm that configuration drift or undocumented changes have not silently reopened a pathway between the two environments.