Spreading And Sharing The Risk

Michael Gaudet

S4x24 - ICS Security Conference · Day 3 · Main Stage

Overview

In his S4 conference talk, "Spreading And Sharing The Risk," Michael Gaudet, a seasoned cyber broker specializing in energy and power organizations, delves into the intricate world of cyber insurance and its critical intersection with Operational Technology (OT) security. Gaudet, with three decades in the insurance business and 12 years focused on cyber risk for critical infrastructure, aims to demystify the complexities of risk transfer for OT professionals. The core premise of his presentation is to foster a crucial collaboration between OT security experts and the cyber insurance marketplace, arguing that a deeper mutual understanding is essential for enhancing the resilience of vital energy and power systems.

Watch on YouTube

Visual summary for Spreading And Sharing The Risk by Michael Gaudet
Visual summary for Spreading And Sharing The Risk by Michael Gaudet

Key moments

  1. 0:00 Introduction: Cyber insurance for energy and power
  2. 2:10 Overview of talk's three core ideas
  3. 2:50 Addressing skepticism about cyber insurance claims
  4. 3:20 NotPetya case: Property vs. dedicated cyber insurance
  5. 4:00 Underwriter biases against energy/power sector
  6. 4:40 The small, profitable energy cyber insurance market

Spreading And Sharing The Risk

Speakers: Michael Gaudet

Conference: S4

YouTube: https://www.youtube.com/watch?v=tnWthqJOKY8

Overview

In his S4 conference talk, "Spreading And Sharing The Risk," Michael Gaudet, a seasoned cyber broker specializing in energy and power organizations, delves into the intricate world of cyber insurance and its critical intersection with Operational Technology (OT) security. Gaudet, with three decades in the insurance business and 12 years focused on cyber risk for critical infrastructure, aims to demystify the complexities of risk transfer for OT professionals. The core premise of his presentation is to foster a crucial collaboration between OT security experts and the cyber insurance marketplace, arguing that a deeper mutual understanding is essential for enhancing the resilience of vital energy and power systems.

The talk highlights the unique characteristics and challenges of the cyber insurance market for the energy and power sector, which Gaudet describes as a highly specialized "microcosm" within the broader cyber insurance landscape. While the general public often hears negative headlines about cyber insurance, Gaudet emphasizes that the dedicated cyber policies for critical infrastructure often perform differently. His insights are particularly relevant for OT security professionals who, despite their vital role in protecting these systems, often have limited involvement or understanding of their organization's cyber insurance strategies. This presentation serves as a call to action, urging OT teams to engage more strategically with risk management and insurance processes to better protect their assets and ensure effective risk transfer.

Background

▶ Watch: Introduction: Cyber insurance for energy and power (0:00)

The concept of cyber insurance has been present for over two decades, yet its application within the energy and power sector presents a distinct set of challenges and nuances. Gaudet's experience reveals that this segment is a highly specialized "sub-segment" of the broader cyber market, with dynamics that often diverge from general cyber insurance trends. A key finding from his observations is that an overwhelming majority — 24 out of the 25 largest power and utility organizations in the United States — actively purchase cyber insurance. However, the insurers they utilize are typically niche providers, unknown to the general public, underscoring the specialized nature of this market.

A significant barrier to effective collaboration, Gaudet notes, is the pervasive skepticism among OT security professionals regarding cyber insurance. This skepticism is often fueled by negative headlines that question whether cyber claims are genuinely paid and if insurers are trustworthy. Gaudet acknowledges these concerns, particularly referencing high-profile cases like the NotPetya attack. Following NotPetya, many insurers found themselves in court, attempting to decline coverage for substantial cyber business interruption claims. Companies such as Merck and Mondelez notably won judgments against their insurers in these disputes. However, Gaudet makes a critical distinction: these high-profile cases often involved property insurance policies that were not specifically designed to cover cyber risks, rather than dedicated cyber insurance policies. This subtle but crucial differentiation is often lost in public discourse, contributing to the general distrust.

In contrast to the headline-driven narrative, Gaudet, as a broker representing the buyer, asserts that his direct experience with dedicated cyber insurance in the energy and power space shows that claims are generally covered and paid most often. This suggests a more reliable, albeit less publicized, track record for specialized cyber policies. Nevertheless, the market faces internal challenges from underwriters who harbor biases against the energy and power sector. A segment of these underwriters perceives critical infrastructure as an "excluded class," unwilling to assume the perceived "upper end" of risk due to concerns about systemic risk. This refers to the potential for a single cyber incident to trigger widespread, cascading failures across interconnected systems, making the financial exposure unpalatable for some insurers. Despite this apprehension, Gaudet points out that a smaller, specialized segment of the market, comprising about five to seven primary insurance companies, has successfully focused on this space, demonstrating profitability and growth over the last decade. This specialized market, while smaller, is ripe for increased maturity, which Gaudet believes OT security insights can significantly help inform and advance.

Key Findings

▶ Watch: Addressing skepticism about cyber insurance claims (2:50)

Gaudet's presentation distills the complex interplay between OT security and cyber insurance into three overarching ideas, each providing a distinct lens through which to view risk management in critical infrastructure. These concepts collectively underscore the need for a more integrated and strategic approach to cyber risk.

First, Gaudet emphasizes that insurance risk management isn't always insurance. This foundational concept suggests that while insurance is a vital tool for risk transfer, it is but one component of a broader risk management strategy. Organizations must consider a spectrum of approaches, including risk avoidance, risk mitigation (through robust security controls), and risk acceptance, before resorting to insurance as a final line of defense for residual risks. This perspective encourages OT professionals to view their security efforts not just as technical implementations but as integral parts of the organization's overall financial and operational resilience strategy.

Second, the talk highlights that the current level of maturity in cyber insurance for the energy and power sector requires a significant amount of strategy to be effective. Given the specialized and often skeptical environment, simply purchasing a policy is insufficient. Organizations, particularly those in critical infrastructure, must adopt a proactive and informed strategy when engaging with the cyber insurance market. This involves understanding the nuances of policy language, accurately quantifying their unique OT risks, and effectively communicating their security posture to underwriters. Gaudet asserts that a more strategic engagement will inevitably lead to better outcomes, including more favorable premiums and comprehensive coverage tailored to the specific threats faced by OT environments.

Finally, Gaudet posits that OT security professionals can derive substantial benefits, both personally and for their organizations, by investing time to understand the insurance landscape. By bridging the knowledge gap between technical security and financial risk transfer, OT professionals can become more effective advocates for security investments, better articulate the value of their work in financial terms, and contribute to more robust organizational resilience. This understanding can empower them to influence policy decisions, collaborate more effectively with risk management teams, and ultimately help "move the ball forward" in securing critical infrastructure.

In addition to these three core ideas, Gaudet's observations reveal the profitability of the specialized cyber insurance market for energy and power over the past decade. Despite initial underwriter skepticism and concerns about systemic risk, the approximately five to seven insurance companies that actively focus on this sector have been "very profitable" and "rewarded for that." This demonstrates that while perceived as high-risk, the energy and power sector can be a viable and lucrative market for insurers willing to understand and appropriately price the unique risks involved, especially with better informed input from OT security professionals.

Technical Deep Dive

▶ Watch: NotPetya case: Property vs. dedicated cyber insurance (3:20)

While Gaudet's talk is not technical in the traditional sense of code or protocol analysis, it delves into the "technical" mechanics of risk transfer and the specialized considerations for OT environments within the cyber insurance framework. The core mechanism discussed is risk transfer, where the financial burden of potential cyber incidents is shifted from the insured entity to the insurer in exchange for a premium. For this transfer to be effective, particularly in the complex OT domain, several technical and procedural elements must be meticulously managed.

A key "technical" aspect Gaudet highlights is the distinction between property insurance policies and dedicated cyber insurance policies. This is a critical nuance often misunderstood, as exemplified by the NotPetya cases. Property insurance is designed to cover physical damage to assets, and while some policies might have clauses that could be interpreted to include certain types of cyber-induced property damage or business interruption, they are fundamentally not crafted to address the full spectrum of cyber risks. Dedicated cyber insurance, by contrast, is specifically engineered to cover financial losses arising from cyber incidents, including data breaches, ransomware attacks, business interruption due to IT/OT system outages, regulatory fines, and incident response costs. The "technical" details within these policies, such as definitions of "cyber incident," "system failure," and "business interruption," are paramount and dictate what is actually covered. OT professionals need to understand these definitions to ensure their unique risks, such as process control system failures or safety system compromises, are adequately addressed.

The role of underwriters also presents a "technical" challenge. Underwriters assess risk and determine policy terms and premiums. Gaudet notes a significant bias among some underwriters who view energy and power as an "excluded class" due to concerns about systemic risk. In an OT context, systemic risk refers to the potential for a localized cyber attack to propagate across interconnected industrial control systems (ICS) or critical infrastructure networks, leading to widespread outages, environmental damage, or safety incidents. This interconnectedness and the potential for cascading failures make quantifying and pricing risk exceptionally difficult for traditional underwriters. The "technical" challenge here is to translate complex OT architectures, threat models, and security controls into a language that underwriters can understand and factor into their risk assessment models. This requires OT professionals to articulate their security posture, incident response capabilities, and resilience measures in a structured, data-driven manner.

Furthermore, Gaudet implicitly touches upon the "technical" process of risk quantification. For insurers to assume risk, they must be able to quantify it. This involves assessing the likelihood of various cyber threats materializing in an OT environment and the potential financial impact (e.g., downtime costs, recovery expenses, regulatory penalties). OT security professionals, with their deep understanding of asset criticality, vulnerabilities, and threat vectors (e.g., ICS-specific malware, supply chain attacks targeting industrial components), are uniquely positioned to provide the granular data necessary for accurate risk quantification. Without this technical input, underwriters rely on broader, often less specific, risk models, which can lead to higher premiums or inadequate coverage.

Finally, the function of a cyber broker, like Gaudet himself, serves as a "technical" intermediary. Brokers represent the buyer, navigating the specialized market of 5-7 primary insurers. Their "technical" expertise lies in understanding the subtle differences between policies from various providers, negotiating terms, and ensuring that the coverage aligns with the specific risk profile of an OT organization. This involves a deep understanding of the market's capacity, appetite for risk, and the specific requirements for underwriting critical infrastructure. The broker acts as a translator between the highly technical world of OT security and the financial language of insurance, ensuring that the risk transfer mechanism functions effectively for the client.

Demo / Proof of Concept

▶ Watch: Underwriter biases against energy/power sector (4:00)

This technical article is based on a conceptual talk about the interaction between cyber insurance and OT security. As such, the presentation did not include a live demonstration or a proof of concept of any technical exploit, tool, or system. The speaker's focus was on the strategic and collaborative aspects of risk management and insurance.

Defensive Implications

▶ Watch: The small, profitable energy cyber insurance market (4:40)

Gaudet's talk provides several crucial defensive implications for OT security professionals, urging them to move beyond purely technical defenses and integrate financial risk management into their overall security strategy.

Firstly, OT security professionals must actively engage in quantifying and communicating risk. Instead of just identifying vulnerabilities or implementing controls, they need to translate these into measurable financial impacts that resonate with insurers and corporate leadership. This involves understanding potential business interruption costs, recovery expenses, and regulatory fines stemming from OT cyber incidents. By providing detailed, data-driven insights into their specific threat landscape, asset criticality, and the effectiveness of their controls, OT teams can help underwriters accurately assess and price their risk, potentially leading to more favorable policy terms and premiums. This bridges the communication gap between highly technical security teams and the financial risk management functions.

Secondly, a strategic approach to cyber insurance is paramount. OT organizations should not view cyber insurance as a mere compliance checkbox but as an integral part of their resilience strategy. This means OT security professionals should be involved in the insurance procurement process, reviewing policy language to ensure that unique OT risks (e.g., process disruption, safety system compromise, physical damage from cyber attack) are adequately covered under dedicated cyber insurance policies, not just general property or liability policies. Understanding policy exclusions and limitations is critical to avoid uncovered losses during an incident. This also implies aligning security investments with insurance requirements, potentially using insurance assessments as a driver for security maturity improvements.

Thirdly, collaboration between OT security, risk management, and insurance brokers is essential. Gaudet emphasizes the need for OT professionals to interact with insurance professionals. This collaboration can involve educating brokers and underwriters about the intricacies of OT environments, the specific threats they face, and the robust security measures in place. Conversely, OT professionals can learn from insurers about emerging threats, incident trends, and best practices that influence underwriting decisions. This mutual education can foster a more informed and effective risk transfer ecosystem. By actively participating, OT teams can ensure that the insurance policies truly reflect their operational realities and provide meaningful protection.

Fourthly, leveraging insurance requirements as a benchmark for security maturity. Insurers often require certain security controls and practices as a prerequisite for coverage or to offer better rates. OT security teams can use these requirements as an external validation and a business case for implementing or enhancing specific security measures, such as network segmentation, incident response planning, or robust access controls. Meeting these standards not only improves the organization's security posture but also demonstrates a commitment to risk management, which can be advantageous in the insurance market.

Finally, OT professionals should understand the broader context of risk management beyond just insurance. Insurance is a tool for transferring residual risk. The primary defense remains robust security controls and incident response capabilities. By improving their security posture, OT organizations can reduce their overall risk exposure, potentially lowering their insurance premiums and making them more attractive to a wider range of insurers. This holistic view positions OT security as a value-add that contributes to both operational continuity and financial stability.

Key Takeaways

  • Cyber insurance for energy and power is a highly specialized market segment, distinct from general cyber insurance, primarily served by a small number of niche insurers.
  • Skepticism from OT professionals about cyber insurance is common, often stemming from misinterpretations of headlines (e.g., NotPetya cases involving property insurance, not dedicated cyber policies).
  • Dedicated cyber insurance claims are generally covered and paid, according to the speaker's experience as a broker representing buyers in the energy and power sector.
  • Strategic engagement with the cyber insurance market is crucial for OT organizations to achieve effective risk transfer, secure favorable terms, and ensure comprehensive coverage for unique OT risks.
  • OT security insights are vital for maturing the cyber insurance space, helping underwriters accurately quantify and price systemic risks in critical infrastructure.
  • Understanding cyber insurance benefits OT professionals by enabling them to better articulate security's value, drive strategic investments, and enhance organizational resilience.

About the Speaker(s)

Michael Gaudet is an experienced cyber broker with a long-standing career in the insurance business. For the past 30 years, he has worked in the insurance industry, with the last 12 years specifically dedicated to serving energy and power organizations as a cyber broker. In this role, Gaudet acts as a representative for the buyer, focusing on helping clients understand, quantify, and transfer cyber risks effectively. His expertise lies in navigating the specialized segment of the cyber insurance market that caters to critical infrastructure.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

Dr. Gaudet's talk on cyber insurance for OT is a crucial intervention, cutting through the typical FUD and misinformation surrounding risk transfer in critical infrastructure. As a seasoned cyber broker for energy and power, Gaudet provides rare, invaluable insider signal on a highly specialized market often misunderstood by OT professionals. He clearly articulates why dedicated cyber policies are different from general property insurance, dismantling common skepticism with concrete data and direct experience. This session is a call to action for OT teams to strategically engage with insurance, offering clear, actionable guidance that will significantly enhance their organization's…

Heather Calloway (CISO) — STRONG ACCEPT

Michael Gaudet's session effectively bridges the critical gap between technical OT security and the financial realities of cyber insurance for critical infrastructure. He delivers a clear, unsentimental call to action for OT security leaders to engage strategically with risk transfer mechanisms, moving beyond technical controls to understand and influence their organization's financial resilience. This presentation offers essential guidance for CISOs and board members grappling with the systemic risks inherent in protecting vital energy and power systems.

→ Top-rated talks at S4x24 - ICS Security Conference

All talks from S4x24 - ICS Security Conference