Cyber Risk · Practical Client Case
From fragmented controls to a claims-ready cyber programme
An anonymised composite case showing how an industrial group can translate technical controls, supplier dependencies and outage scenarios into a defensible insurance structure.
The challenge
A multi-site industrial group relied on a central ERP platform, operational technology, outsourced cloud services and more than 200 technology suppliers. The existing cyber policy had been renewed on revenue and headcount information, but there was no shared view of the financial consequences of a prolonged outage.
Coverage uncertainty
Material sub-limits applied to dependent business interruption, social engineering and incident-response services. Several critical vendors were not mapped.
Evidence uncertainty
IT could describe recovery tasks, but finance had not defined how lost production, expediting costs and customer penalties would be documented.
The Kompetenz approach
Dependency map
Critical systems, sites, data flows and external providers were mapped to revenue processes.
Loss scenarios
Ransomware, cloud outage, supplier compromise and payment fraud were modelled.
Wording design
Limits, waiting periods, vendor triggers and key exclusions were aligned to the scenarios.
Claims rehearsal
IT, legal, finance and communications rehearsed notification and evidence collection.
Scenario used for programme design
A privileged-account compromise causes encryption of the ERP environment and disrupts production scheduling across three sites. Restoration takes 12 days; manual workarounds preserve part of output, while expedited logistics and specialist response costs rise sharply.
Programme changes illustrated by the case
Limit selection moved from benchmarks to scenarios
The working limit was compared against a severe ERP outage, dependent-provider failure and privacy event, including restoration and extra expense.
Dependent business interruption became explicit
Named and unnamed supplier language, waiting periods and proof requirements were reviewed against the dependency map.
Incident response became claims-ready
Panel vendors, approval thresholds, notification responsibilities and cost-capture templates were incorporated into the response plan.
Retention reflected real liquidity
The deductible and waiting period were tested against the organisation’s ability to finance response and lost margin during the first days of disruption.
Lessons for risk managers
- A policy cannot compensate for an unknown dependency.
- Business interruption requires finance-owned evidence, not only technical logs.
- Cyber wording should be tested against an event timeline before renewal.
- Supplier failure and direct attack should be modelled separately.
- The first claims rehearsal should happen before the first claim.