OT Cyberattacks Cost About $1 Million. Fewer Than One In Four Listed An Insurance Claim.

Estimated reading time: 5 minutes

Most organizations running cyber-physical systems experienced a cyberattack on operations in the past year, Claroty’s survey found. Nearly all of them lost money. Fewer than one in four listed an insurance claim among the results.

Operational technology (OT) cyberattacks cost organizations about $1 million on average. Fewer than one in four led to an insurance claim.

Claroty surveyed 2,000 business and technology leaders at organizations that run cyber-physical systems (CPS). Fifty-eight percent said a cyberattack had hit their operations in the past 12 months. Of those, 94% reported a financial impact. The average loss was $1.04 million.

Respondents named what their most significant operational incident led to. Operational downtime topped the list, at 43%. Safety incidents or hazards followed at 40%. An insurance claim came last of eight impacts, at 23%. The report does not say why so few incidents led to a claim. It also does not say whether all respondents answered that question or only those hit by an incident.

Sapio Research ran the survey for Claroty across 16 industries and more than 40 countries.

Bar chart of what the most significant OT cyber incident led to, from operational downtime at 43 percent to an insurance claim last at 23 percent, from Claroty's 2026 survey, created by cyber insurance news
Impacts of respondents’ most significant operations-related cyber incident. Respondents selected all that apply. Source: Claroty, The Global State of Operational Security 2026.

OT Security Spending And Cyber Insurance

Insurance also sits at the bottom of the spending list. Respondents chose up to three drivers of cybersecurity investment in their CPS environments. “Insurance requirements or financial pressure” ranked last of 10, at 15%.

Cyber threats and operational risk led at 37%. Technology modernization followed at 36%. Risk of business disruption or revenue loss came third, at 29%.

Claroty says regulators and cyber insurers are extending their reach into operational protection. It says they increasingly demand demonstrable controls that reduce risk to the production environment.

See also  Third-Party Cyber Risks Endanger Insurance Industry: 59% of Breaches Linked to Vendors

A different survey published this week drew a sharper insurance link. Kaseya asked managed service providers (MSPs) what drives their clients’ security spending. Twenty percent named compliance or cyber insurance requirements.

OT Downtime Runs Days, Not Hours

Downtime from OT cyberattacks averaged three days. Sixty percent of those hit reported more than 12 hours of downtime. Nine percent reported 8 to 30 days or more. Seven percent of electric utilities reported 15 to 21 days.

Recovery planning trails the problem. Only 21% are very confident their business continuity and disaster recovery plans cover operational environments. Another 11% are not very or not at all confident.

Recovery time drives the size of a business interruption loss. CFC extended its business interruption indemnity period to 18 months this week. PwC found only 39% of security, risk and operations leaders have fully formalized cyber continuity plans.

Third-Party Access To Cyber-Physical Systems

Vendor connections add exposure. Fifty-three percent of respondents named third-party access as a risk. Of those, three in four reported at least one operational incident that stemmed from it. Respondents reported an average of three such incidents.

Forty-nine percent have partial or no monitoring of third-party connections to operational assets.

Claroty says securing vendor access satisfies critical cyber insurance underwriting requirements. It says underwriters use a checklist of controls and processes to decide coverage, with operational resilience a guiding principle.

OT Security At Smaller Operators

Losses from OT cyberattacks rise with company size. Organizations with 10,000 or more employees lost $2.24 million on average. Those with fewer than 100 employees lost $321,000.

See also  Cyber Insurance Claims Data Shows Criminals Shift To Data Theft And Long-Tail Damage

Smaller firms watch their vendors least. Fifty-five percent of organizations with fewer than 100 employees have partial or no monitoring of third-party connections. Only 48% are confident in their recovery planning.

GuidePoint warned this week that AI is bringing more attacks to organizations once too small to draw an attacker’s attention.

AI And Fragmented Governance

Seventy percent of respondents use AI in operational environments, at least in limited form. Thirty-five percent named AI-powered cyberattacks among the top threats to operational integrity. IT-related disruptions affecting operations ranked first, at 37%. Ransomware drew 27%.

Ownership of the problem is split. Only 16% say IT and operational security governance is fully integrated. CIOs are most often accountable for operational security, cited by 39%. CIOs and CISOs each control the budget at 28% of organizations.

Claroty says organizations should treat operational resilience as a core business capability. Its advice for 2027 budgets includes strict vendor access controls, session recording, and continuous monitoring.

YouTube video

FAQ – OT Cyberattacks

How common are cyberattacks on operational technology?

58 percent of organizations running cyber-physical systems said a cyberattack hit their operations in the past 12 months, according to Claroty’s survey of 2,000 leaders.

How much do OT cyberattacks cost?

The average loss was 1.04 million dollars. Organizations with 10,000 or more employees averaged 2.24 million dollars. Those with fewer than 100 employees averaged 321,000 dollars.

How often did an OT incident lead to an insurance claim?

23 percent listed an insurance claim among the impacts of their most significant operational incident. It ranked last of eight impacts. The report does not say why.

See also  Invision Cyber Partners with Trend Micro to Launch US Cyber Insurance

How long does OT downtime last?

Three days on average. 60 percent of those hit reported more than 12 hours, and 9 percent reported 8 to 30 days or more.

Do insurance requirements drive OT security spending?

Less than other factors, by this survey. Insurance requirements or financial pressure ranked last of 10 investment drivers, at 15 percent.

How well do organizations monitor vendor access?

49 percent have partial or no monitoring of third-party connections to operational assets. Among firms with fewer than 100 employees, 55 percent do.

Leave a Comment

×