Specialist technology insurance
SCADA and Control Systems Insurance
Operational technology projects can affect industrial processes, safety controls and service continuity. Mercantile helps Australian technology businesses prepare clear underwriting information and review the interaction between products liability, technology professional indemnity, cyber and other relevant policies.
What makes this risk different?
Underwriters need to understand the product or service, who relies on it and what could happen if it fails. For this activity, describe industrial sectors, remote access, segregation, change control, fail-safe design, commissioning, monitoring, subcontracted coding and contractual performance commitments. Separate your own design and delivery responsibilities from those of component suppliers, installers, customers and subcontractors. Give the insurer a realistic account of maximum potential loss and any past claims or incidents.
Insurance questions to review
- Public and products liability: alleged third-party injury or property damage from operations, products and completed work, subject to exclusions and declared activities.
- Technology professional indemnity: defined professional services, software and advice exposures, often on a claims-made basis with notification and retroactive-date conditions.
- Cyber: incident response, privacy and covered network events, which may differ from a product defect or implementation error.
- Other cover: recall expense, property, stock, transit, management liability or crime where the actual operation warrants it.
Check limits, excesses, aggregate limits, exclusions, territorial and jurisdiction clauses and any contractually required insured parties. No item listed here is automatically included.
Illustrative exposure
Hypothetical example: A configuration change causes a control process to stop. The cause, resulting damage and economic loss need separate assessment. This example describes an exposure only; a claim outcome depends on the facts and policy.
SCADA and operational technology exposure
State what the control system monitors or actuates, the industries and physical processes involved, and whether the supplier only designs software or also installs and maintains hardware. Detail network segmentation, remote access, change approval, fail-safe behaviour, backup and manual override. Identify whether customers rely on the system for safety-critical or continuous operations.
A misconfiguration, software defect and malicious network intrusion can produce similar operational disruption but fall under different policy triggers. Examine technology PI, product liability and cyber definitions against the actual service contract, especially economic loss, physical damage, emergency response and contractual penalties.
What to send for a quote
Provide a concise business and product description, turnover split by activity and country, principal contracts, customer industries, manufacturing and supplier arrangements, testing and quality processes, existing schedules and claims history. Where relevant, include technical documentation through a suitable secure follow-up channel.
Frequently asked question
Is a cyber policy enough for an operational control failure?
Not necessarily; errors and omissions and physical damage terms also matter.
See also embedded systems, our technology insurance guide and existing quote areas.
Discuss your technology risk
We can review your operations and identify the information needed for an appropriate market approach.
