The Problem
Cyber insurance used to mean filling out a short questionnaire and paying a premium. Wisconsin manufacturers renewing or applying for coverage today are increasingly finding carriers asking for proof of specific security controls before offering coverage at all, and manufacturers who cannot answer clearly are seeing higher premiums, ransomware sub-limits, or outright declined applications.
Why it Matters Operationally
Insurers now treat manufacturing as a higher-risk category given how frequently the sector is targeted by ransomware. Wisconsin's 2021 Act 73 established a formal insurance data security law requiring carriers themselves to run risk assessments and report breaches to the state within three business days. That law regulates insurers, not manufacturers directly, but its practical effect reaches policyholders anyway: carriers accountable for their own data security tend to underwrite more rigorously across the board. Overstating security maturity on an application can also mean a denied claim later, if an insurer discovers after an incident that a listed control was not actually in place.
The Simple Explanation
Underwriters are now asking a fairly consistent set of questions: is multi-factor authentication fully deployed, particularly on remote access and privileged accounts; is endpoint detection and response software in place rather than legacy antivirus; are backups stored offline or immutable and actually tested; is there a written, tested incident response plan; is employee security training conducted regularly; and, increasingly for manufacturers specifically, is the IT network segmented from OT. Coverage terms and pricing are now directly tied to how many of these are true.
Practical Checklist
- Is multi-factor authentication deployed across remote access, email, and privileged accounts
- Is EDR software installed on servers and workstations, not just legacy antivirus
- Are backups stored offline or immutable, and has a restore actually been tested
- Is there a written incident response plan, tested through a tabletop exercise
- Is security awareness training conducted regularly for employees
- Is there a patch management process for internet-facing systems
- Is the IT network segmented from OT
What You Can Do Now
Before your next application or renewal, go through the checklist above honestly and close the highest-impact gaps, MFA and tested backups especially, ahead of time. Be transparent on the application about anything still in progress rather than rounding up.
When Outside Help Makes Sense
Translating your actual security posture into the specific language an underwriter is looking for is not always straightforward, and a security partner who understands both the technical controls and how insurers evaluate them can materially improve your terms. This is especially valuable ahead of a renewal deadline rather than scrambling once the questionnaire arrives.