August 4, 2026 | Insight
Insurers Should Require a Cyber Safety Standard of Care for the Built Environment
August 4, 2026 | Insight
Insurers Should Require a Cyber Safety Standard of Care for the Built Environment
The American built environment has become more digitally connected, and the insurance market is increasingly exposed to cyber-physical losses that traditional underwriting categories do not fully capture. Buildings, water systems, hospitals, transit systems, industrial facilities, and other critical infrastructure increasingly rely on operational technology (OT), automation, remote access, sensors, software updates, and networked controls. Such controls include the Rockwell Automation MicroLogix 1100 and 1400 programmable logic controllers — technology used in U.S. water and wastewater sector utility companies for monitoring and system control — that hackers have been targeting since July 27. These technologies provide performance and efficiency gains, but they also increase the risk that a cyber incident could produce physical consequences by disrupting operations, damaging property, or threatening human life.
Insurers should therefore require evidence of reasonable care in cyber-engineering practices as part of the underwriting process. Over time, that evidence should be verified by a qualified cyber safety engineer of record or an equivalent professional responsible for ensuring that connected systems are designed, documented, commissioned, and maintained with cyber safety in mind.
Defining the Cyber Safety Engineer of Record
Responsibility for cyber safety remains mostly unassigned in the engineering profession. A structural engineer is accountable for the safety of a building’s physical structure. Electrical engineers are accountable for electrical safety. Fire protection engineers are accountable for life-safety systems. But there is often no recognized cyber safety engineer of record responsible for ensuring that connected systems are designed, documented, commissioned, and maintained with cyber safety in mind.
For insurers, that creates an underwriting problem. There is no consistent professional role, no common documentation package, and no reliable evidence trail showing whether reasonable cyber care was exercised.
Cyber safety engineers should be specialists who, much like fire safety engineers, do not replace other engineers but add an additional layer of safety to the built environment. Their tasks should include compiling a registry of all technologies embedded in a project’s systems, specifying cyber protections for those technologies, overseeing their correct installation, supporting cyber commissioning, and handing off instructions for ongoing maintenance to the facility owner.
That record of design intent, verification, deficiency correction, and owner acceptance is exactly the kind of evidence insurers need to price risk, evaluate claims, and distinguish reasonable care from avoidable negligence.
Cyber safety engineers cannot promise that an environment will never be hacked or otherwise compromised. Their goal is to help ensure that physical systems fail safely if software, hardware, networks, or vendor access are compromised. They must also ensure that the response to a cyber incident does not depend on the compromised physical system functioning correctly.
In insurance terms, the objective is not risk elimination. It is risk engineering: reducing the likelihood of loss, limiting severity, documenting residual risk, and improving claim defensibility.
Why a Cyber Safety Standard of Care Is Needed
Cybersecurity has long been considered an information technology function, where data, networks, access control, patching, monitoring, and compliance are central. These are crucial, but they do not fully account for OT, which is used to control physical processes. Cyberattacks in OT environments can affect pumps, valves, elevators, HVAC systems, medical equipment, access control systems, building automation systems, power systems, and industrial equipment.
Cyberattacks in these environments don’t just risk data theft or a ransomware demand — they can also create property losses, business interruption, bodily injury exposure, environmental damage, and professional liability disputes.
Recent cyber campaigns, such as those attributed to the Chinese-affiliated Volt Typhoon group, demonstrate the need to secure networks that support American critical infrastructure. Incidents such as the Colonial Pipeline ransomware attack further show that cyber-physical disruption is not hypothetical. They expose a design assumption failure: OT systems are often engineered to be physically safe and durable but are digitally insecure.
In IT environments, confidentiality of data is often the highest priority. In OT environments, safety and availability are paramount. That difference matters to insurers because a cyber incident in the built environment may not present as a traditional privacy breach. It may present as a property claim, a casualty claim, a professional liability claim, a technology errors-and-omissions claim, a business interruption claim, or some combination of all of them.
To answer this challenge, what is needed is not another compliance checklist but rather an engineering cyber safety standard of care.
A standard of care does not demand perfection. It requires that engineers show the care and skill ordinarily demonstrated by engineering professionals under similar circumstances. Standards of care have historically developed when society recognized that risks in the built environment could no longer be left to voluntary mitigation by designers. Fires, collapses, explosions, and other accidents have shaped engineering codes, licensing, inspection regimes, and insurance and liability norms.
Cyber-physical systems now present the same conditions that historically drove action: foreseeable hazards, repeatable failure modes, and the potential for catastrophic consequences.
What Insurers Should Require as Evidence of Reasonable Care
A cyber safety standard of care should produce evidence that insurers can use. Without evidence, cyber safety remains an aspiration rather than an underwriting factor.
At minimum, insurers should expect a covered project or facility to be able to produce the following:
- A cyber-physical consequence assessment identifying how compromise of connected systems could affect life safety, property, operations, public services, or mission continuity.
- A technology registry listing all connected OT, building automation, access control, safety-adjacent, vendor-managed, cloud-connected, and remotely accessible systems.
- Design documentation showing that cyber safety requirements were included in project specifications, procurement language, and system architecture.
- Evidence that remote access, vendor access, administrative accounts, authentication, logging, backups, and recovery procedures were designed and verified.
- Cyber commissioning records showing that installed systems were tested against cyber safety requirements before acceptance.
- A deficiency log showing unresolved cyber safety gaps, corrective actions, and owner acceptance of residual risk.
- Owner handoff documentation explaining how the facility should maintain cyber safety over time.
- Periodic maintenance and recertification records showing that cyber safety did not end at project delivery.
These records would allow insurers to distinguish between an organization that exercised reasonable care and one that allowed foreseeable cyber-physical risk to remain unmanaged.
The Role of the Insurance Industry
What concrete next steps should insurers take for a cyber safety standard of care? Answering this question was one of the tasks of the 2026 Cyber Safety Summit in Washington, DC, organized by Lucian Niemeyer of Building Cyber Security. The event brought together engineering leaders, academics, infrastructure owners, insurers, technology providers, and safety advocates around a shared objective: establishing a cyber safety standard of care for the built environment. The summit did not provide all the answers, but it established a roadmap to a safer cyber-physical world.
Crucially, a dedicated insurance working group should develop underwriting questions, premium-credit criteria, professional liability expectations, policy language considerations, and claims documentation standards for cyber-physical risk. These should be tied to concrete evidence of reasonable care, including technology registries, cyber commissioning records, remote-access controls, vendor-access documentation, deficiency correction records, owner handoff materials, and periodic maintenance evidence.
It should not take a catastrophic cyber-physical failure such as the Colonial Pipeline incident to generate action. Connected systems that are vulnerable to cyber incidents and accidents are already ubiquitous in American workplaces, homes, medical facilities, transportation infrastructure, and power plants. Engineers have an obligation to protect public safety as technology rapidly changes. Insurers have an equally important role in making reasonable care visible, measurable, and economically meaningful. A cyber safety standard of care is essential to move cyber-physical risk from an unmanaged exposure to an insurable, evidence-based, professionally governed risk.
Dr. Georgianna Shea is chief technologist at the Center on Cyber and Technology Innovation (CCTI) and the Transformative Cyber Innovation Lab at the Foundation for Defense of Democracies (FDD), where Stephen Thursby is an intern. For more analysis from the authors and FDD, please subscribe HERE. Follow FDD on X @FDD and @FDD_CCTI. FDD is a Washington, DC-based, nonpartisan research institute focusing on national security and foreign policy.