The Double Denial: How an OT Attack Falls Between Two Towers
The Allianz Risk Barometer 2026 places cyber incidents at the top of the global business risk ranking for the fifth consecutive year, at 42% of responses and roughly 10 points ahead of artificial intelligence in second place. Cyber is a top-three risk for Indian respondents specifically. What that headline hides is a settlement problem that most Indian risk managers only discover after a loss: when a cyber event physically damages plant, two insurers can each point at the other and neither pays.
The mechanism is concrete. A threat actor reaches an Indian manufacturer's operational technology (OT) layer, manipulates a programmable logic controller, and forces a boiler, compressor or turbine outside its safe operating envelope. Bearings seize, a heat exchanger ruptures, a batch reactor overpressures. The damage is unmistakably physical. When the corporate files under its Standard Fire and Special Perils cover or its Industrial All Risks (IAR) policy, the property insurer reads the cyber exclusion now embedded in that wording, typically an LMA5401-style Property Cyber and Data Exclusion, and declines.
The corporate then turns to its standalone cyber policy. That insurer reads its own physical damage and bodily injury exclusion, notes that the cyber tower responds to data, privacy liability, extortion and business interruption rather than to burnt-out machinery, and declines as well. The insured is left holding the entire loss in the space the market calls silent cyber, or non-affirmative cyber: exposure that neither tower affirmatively priced or intended to carry.
This post is not another underwriting-boundary explainer. It is a recovery playbook for the corporate already sitting on a double denial, covering how you prove the physical-damage trigger, read the exclusion before the next loss, sequence notification to both towers without waiving rights, protect privilege, and negotiate an affirmative cyber-physical-damage extension so the gap is closed before it is tested again.
Proving the Physical-Damage Trigger After an OT or ICS Attack
Recovery starts with evidence, and the evidentiary burden here is unusual because the property insurer will argue the loss is really data corruption dressed up as physical damage. Under the proximate cause doctrine that governs Indian first-party property settlements, you must show that a covered physical peril, most often fire, explosion or sudden and accidental mechanical breakdown, was the effective cause of the damage, and that the cyber act was the initiating chain rather than the loss itself.
That means two forensic tracks running in parallel from day one. A digital forensics team preserves the industrial control system (ICS) record: PLC logic changes, historian and SCADA time-series data, engineering workstation logs, and the human-machine interface event trail that shows setpoints being driven beyond safe limits. A separate chartered engineer or metallurgist documents the physical failure mode: metallurgical analysis of a failed component, thermal signatures, overpressure evidence, and a root-cause narrative that links the manipulated command to the mechanical outcome.
Sequence and dating matter. Distinguish clearly between the portion of the loss that is genuinely physical (the seized machine, the burnt switchgear) and the portion that is data or software (corrupted recipes, wiped controllers), because the property tower will only entertain the former. Quantify the physical-damage head of claim on a reinstatement-value basis with supporting engineering estimates. Keep the business interruption flowing from physical damage documented separately, since even where a write-back covers the property damage it may not extend to the consequential loss. The stronger and earlier this record is, the less room the property insurer has to recharacterise a physical loss as an excluded cyber-data loss.
Reading the Cyber Exclusion in Your Property and Marine Wordings Before Loss
You cannot argue a coverage position you have not read. Since the Lloyd's market moved to write silent cyber out of property and marine wordings, Indian placements led or reinsured through London carry standardised cyber clauses, and the exact clause number decides whether a physical loss is recoverable at all.
Two forms dominate property placements. An LMA5401-style clause is the absolute Property Cyber and Data Exclusion: it bars loss connected to any cyber act or cyber incident with no carve-back, so a fire started by a manipulated controller is excluded outright. An LMA5400-style clause is the more insured-friendly endorsement: it excludes cyber generally but writes back physical loss or damage caused by fire or explosion resulting from a cyber incident. If your property wording carries the write-back, an OT attack that ends in a fire may in fact be covered, and the denial can be challenged on the clause itself. If it carries the absolute form, the property tower is closed and your recovery must come from the cyber side or a bespoke extension.
Marine and transit covers have their own version. The market-standard CL380 Institute Cyber Attack Exclusion Clause removes cyber-caused loss from cargo and hull wordings, which matters for Indian exporters whose OT-linked losses touch goods in transit or port handling equipment.
Build a one-page exclusion map for every property, engineering and marine policy in the programme: clause number, whether a fire or explosion write-back exists, any resulting-damage carve-back, and the matching position in the cyber policy. The map turns a vague fear of silent cyber into a specific, sub-limit-level gap you can price and close at renewal.
Read the two towers together, not in isolation. The failure mode that produces a double denial is a property wording with an absolute exclusion sitting next to a cyber wording with a hard physical-damage exclusion, so that a covered peril exists in neither.
Sequencing Notification to Both Towers Without Waiving Your Rights
Once an OT loss is suspected, notification is a timing and drafting problem, not a formality. Under the IRDAI (Protection of Policyholders' Interests) Regulations, 2024, notice and the appointment of a surveyor for large property losses run on defined timelines, and late or defective notice gives an insurer a procedural ground to resist. You notify both the property tower and the cyber tower promptly, but you draft each notice so that neither concedes the point the other insurer needs.
Run the regulatory clock in parallel with the insurance clock. CERT-In directions require reporting of specified cyber incidents within 6 hours of detection, and sector rules such as the RBI and SEBI cyber resilience frameworks impose their own timelines. Missing a statutory reporting deadline while you deliberate over which insurer to notify is an avoidable own goal that can surface later as a warranty or condition breach.
The drafting discipline is to notify factually and neutrally. To the property insurer, describe the physical damage and the covered peril, and reserve your position on causation rather than volunteering that a cyber act was involved before you have to. To the cyber insurer, report the security incident as its policy requires. Do not send the property insurer a letter that characterises the whole event as a cyber loss, and do not send the cyber insurer a letter that concedes the damage was purely physical and outside its scope. Each admission can be quoted back to you by the other carrier.
Preserving Privilege and Building the Forensic Record
The forensic report that proves your physical-damage trigger is the same document that can sink you if it is discoverable and unhelpful. Managing privilege from the first hour is therefore part of the recovery strategy, not a legal afterthought.
Engage external counsel at the outset and commission the incident forensics, both digital and engineering, under that counsel's instruction so the work is capable of attracting legal advice or litigation privilege rather than being a routine operational report available to every party. A forensic finding that the attacker manipulated a controller supports your property claim, but a loosely worded interim report that speculates about employee negligence or an unpatched known vulnerability can be used by the property insurer to allege a breach of a reasonable-precautions condition, and by the cyber insurer to allege non-disclosure at inception.
Separate the streams deliberately. Keep the privileged legal-strategy analysis apart from the factual, non-privileged material that you will need to share with surveyors and insurers to advance the claim, because you cannot simultaneously withhold a report and rely on it to prove your loss. Decide early which findings are claim evidence to be disclosed and which are strategy to be protected.
Coordinate the loss adjuster and the surveyor into the record rather than around it. The surveyor appointed under the property claim will form a view on cause and quantum that carries weight in any later dispute before the Insurance Ombudsman or a consumer forum, so your engineering evidence should be put to that surveyor early and in structured form. Under the utmost good faith duty that governs the contract, disclose what the policy conditions require, but do so through a controlled process. A disciplined, privilege-aware evidence file is frequently the difference between a negotiated recovery and a denial that hardens into litigation.
Negotiating an Affirmative Cyber-Physical-Damage Extension at Renewal
The durable fix for a double denial is to stop relying on ambiguity and buy affirmative cover for the exact peril. After a near-miss or a contested claim, the renewal is the moment to convert silent cyber into a written, priced coverage grant across both towers.
There are three practical routes, and the right answer is usually a combination. First, secure a write-back on the property side: negotiate the LMA5400-style fire and explosion write-back, or a broader resulting-physical-damage extension, in place of an absolute exclusion, so that OT-triggered fire and explosion losses fall back inside the property policy. Second, buy affirmative cyber-physical-damage (CPD) cover on the cyber side as a specific insuring agreement with its own sub-limit, extending the cyber tower to property damage and, where available, resulting business interruption from a cyber cause. Third, where neither tower will move far enough, place a difference-in-conditions layer or a specialist cyber-physical wrap that sits over both and responds where the primary policies leave a gap.
Watch the mechanics that quietly reintroduce the gap. Check that the property write-back and the cyber CPD grant use compatible definitions of cyber act and cyber incident, so a loss is not defined out of one while being priced into the other. Confirm the sub-limits are adequate against a realistic maximum loss for your most critical process line, not a token figure. Scrutinise waiting periods and time deductibles on any business interruption element, and align the two towers' notification conditions so a single event does not breach one policy while satisfying the other.
Underwriters will ask what changed. Bring the OT security controls, network segmentation between IT and OT, tested incident response, and the exclusion map to the renewal meeting. A credible risk-improvement story is what turns a theoretical extension into an affordable, affirmative grant rather than a declined request.
Closing the Silent-Cyber Gap Before the Next Incident
Silent cyber is, at bottom, a wordings problem. Whether an OT attack that wrecks a turbine is recoverable depends on a clause number in your property policy, a physical-damage exclusion in your cyber policy, and whether anyone read the two together before the loss. The corporates that recover are the ones that mapped the exclusions in advance, preserved the physical-damage evidence, sequenced their notifications with care, and bought affirmative cover for the peril rather than hoping the ambiguity would break their way.
Doing that well requires seeing how each insurer actually drafts its cyber exclusion, its write-back, and its physical-damage carve-out, because the same risk can be covered by one carrier's LMA5400 write-back and excluded outright by another's absolute clause. Sarvada gives brokers and risk managers searchable access to insurer policy wordings so these clauses can be compared side by side across the market, and the silent-cyber gap identified before a loss rather than during a denial. To evaluate the platform for OT and cyber-physical placements, Request Access.
The FY2026-27 threat environment will keep pushing cyber into physical plant, and insurers will keep tightening exclusions to price the exposure they intend to carry. The organisations that treat the property and cyber wordings as a single, readable coverage problem, rather than two separate purchases, will be the ones still standing when a controller is manipulated and the boiler fails. The gap does not close itself. It closes at renewal, on paper, with clauses you have actually read.