Cyber Insurance for Oil & Gas, Mining & Contractor Risks

close up view of system hacking

Ransomware, wire fraud, and data breaches now target the operational businesses that never touch a credit card. This guide explains what cyber insurance covers, what it doesn’t (your GL, crime, and property policies leave gaps), and why oil & gas, storage tank, cell tower, mining, and contractor operations need it. Cyber insurance for specialty risks is critical to any operation.


Crescenta Valley Insurance · Specialty Risk Advisory

Cyber Insurance for Oil & Gas, Storage Tank, Cell Tower, Mining & Contractor Risks

“We’re not a tech company” is the most expensive sentence in your risk file. Here’s what cyber coverage actually is, what it is not, and why the operational businesses that never touch a credit card are now the ones getting hit.

If you drill wells, run a tank field, climb towers, move ore, or pull permits, you probably don’t think of yourself as a cyber target. That instinct is exactly why your sector is one. The threat landscape has shifted from stealing data to stopping operations — and a shutdown on a rig, a smelter, a pump station, or a jobsite is worth far more to an extortionist than a spreadsheet of email addresses ever was.

This guide is written for owners and risk managers in hard-to-place, physical-risk industries. We’ll keep the jargon light: what cyber insurance covers, what it does not cover (this is where most businesses get burned), the handful of threats you actually need to understand, and how the exposure looks different for oil & gas, underground storage tanks, cell tower contractors, mining operators, and specialty contractors of every kind.

Key takeaways

  • Your GL policy does not cover cyber. Commercial general liability has explicit data and cyber exclusions. A breach or ransomware event is not a “GL claim.”
  • The money is in downtime, not data. Roughly 80% of recent mining-sector attacks were financially-motivated ransomware aimed at halting operations. Oil & gas ransomware surged an estimated 935% in a single year.
  • The costliest everyday threat is a fake wire request. Business email compromise drives billions in reported losses — and it often falls into a coverage gap between your crime and cyber policies.
  • Cyber belongs on a real commercial program. We position it as a package layer alongside your GL, property, and environmental coverage — not as a standalone product you buy in a panic.

What cyber insurance actually is

Cyber insurance is really two coverages living under one name. First-party coverage pays for your own losses. Third-party coverage pays for the claims other people bring against you. A good policy does both. The pieces that matter most to an operational business:

  • Business interruption & extra expense — lost income and the cost to keep running when systems (or the industrial controls tied to them) go down. This is the line item that dwarfs everything else for a rig, smelter, or pump station.
  • Ransomware & extortion — negotiation, the ransom itself where permitted, and the specialists who get you back online.
  • Data restoration — rebuilding corrupted or encrypted systems and data.
  • Breach response — forensics, legal counsel, notification, and credit monitoring when personal or employee data is exposed.
  • Funds transfer / social engineering fraud — reimbursement when someone is tricked into wiring money (usually a sublimited add-on — see the warning below).
  • Regulatory defense — the cost of responding to state privacy regulators, and increasingly to federal critical-infrastructure reporting rules.
  • Dependent / contingent business interruption — your losses when a vendor you rely on gets hit and takes you down with them.

What cyber insurance is NOT

This is the part worth reading twice, because the gaps between policies are where uninsured losses live. Cyber insurance is a specific, purpose-built line. It is not, and does not overlap cleanly with, any of these:

It is not your General Liability policy

Modern commercial general liability forms carry an access-or-disclosure / electronic-data exclusion. Damage to, loss of, or exposure of electronic data is carved out. If a hacker steals your project files or an employee’s information, your GL carrier is not the one paying — and a third-party lawsuit over that leaked data lands in the same excluded bucket.

It is not your Crime / Fidelity policy

Crime coverage responds to employee theft and, in some forms, computer fraud — a hacker directly manipulating your systems to move money. But when your own employee is deceived into authorizing a wire to a fraudster, many crime forms treat that as “voluntary parting” and decline it. That single distinction — computer fraud vs. social engineering fraud — is the most common six-figure gap we see. It usually has to be bought back by endorsement, and it’s often sublimited well below the rest of the policy.

Broker’s flag: If your only “cyber” protection is a social-engineering endorsement on a crime policy, check the sublimit. A $2M crime policy can carry a $100K–$250K social-engineering cap and verification conditions (a required callback to a known number) that void the claim if your staff skipped the step. Read the trigger, not the limit.

It is not your Property policy

Most property forms now contain a cyber exclusion (the market standard descends from the old CL 380 language). A cyberattack that shuts your operation down, or that physically damages equipment through the control system, can fall between your property policy (which excludes the cyber cause) and a bare cyber policy (which may exclude the physical damage). Bridging that “cyber-physical” gap for OT-heavy operations takes deliberate structuring.

It is not Professional Liability (E&O) on its own

Tech E&O covers your performance — the low-voltage or IT work you did for a client that failed. It is not the same as first-party cyber. Contractors with both a service-delivery exposure and a network exposure need both addressed; one does not backfill the other.

The threats in plain English

You don’t need to be a security engineer. You need to recognize five things:

  • Hacking / intrusion. An attacker gets into your network, usually through a stolen password, an unpatched device, or a remote-access portal. In industrial environments, exposed VPNs and vendor tunnels are the most common front door.
  • Ransomware. Your files — or the systems that run your equipment — get encrypted, and you’re extorted to unlock them. The average cost to recover from a ransomware event (not counting the ransom) runs into the millions; the ransom demand on attacker-disclosed incidents has averaged around $5 million.
  • Data breach. Someone steals personal, financial, or employee information. This triggers notification laws, credit monitoring, and often litigation. The U.S. average total cost of a breach set a record at roughly $10.2 million in the most recent IBM Cost of a Data Breach study, with the 2026 report showing costs climbing again.
  • Business email compromise (wire fraud). A convincing fake email — a “vendor” changing bank details, a “boss” ordering an urgent transfer — and your money is gone. No malware required. This is the single most common way small and mid-size operational businesses lose real cash.
  • OT / ICS attacks & supply-chain compromise. Attacks that cross from the office network into the operational network — SCADA, PLCs, control systems — or that come in through a trusted software vendor. This is the category that turns a nuisance into a shutdown, and it’s rising fastest in exactly the sectors we serve.

Not sure whether your current program has a cyber gap? A 20-minute policy review usually finds one.

Call Steve: (818) 974-8117

Why it matters in your industry

The threat is universal; the exposure is not. Here’s how it lands sector by sector.

Oil & gas & control of well

Oil & gas ransomware ↑ ~935% in one year Worst IT/OT segmentation of any sector (29% of findings)

Upstream and midstream operations run on increasingly automated, digitized control systems — and that expanding attack surface is precisely why the sector saw an estimated 935% surge in ransomware in a single 12-month window. Analysts tracking industrial threats found oil & gas has the poorest IT/OT network separation of any sector, meaning once an attacker is in the office side, they can move laterally toward the process side with little resistance. The reference point everyone remembers is the 2021 Colonial Pipeline shutdown: a ransomware hit on the business systems took a 5,500-mile pipeline offline and disrupted fuel across the East Coast, with a multi-million-dollar ransom paid.

Your real exposure: operational downtime (a shut-in well or halted pipeline is measured in safety risk and environmental exposure, not just lost barrels), control-of-well complications if monitoring is compromised, and a growing stack of federal reporting obligations (TSA security directives, CIRCIA incident reporting). The coverage that matters is cyber business interruption tied to OT, plus a policy structured to address cyber-triggered physical damage rather than exclude it.

Underground storage tank (UST) operators & environmental risk

Leak-detection & ATG systems are now networked Cyber-triggered release = a pollution event

Storage tank risk has quietly gone digital. Automatic tank gauging, leak-detection, and inventory-reconciliation systems are network-connected — often through the same remote-monitoring vendors across dozens of sites. A compromised or spoofed monitoring system doesn’t just cost you data; it can mask or trigger a release, which converts instantly into an environmental and regulatory problem. And here’s the trap: a cyber-caused pollution incident can fall between your environmental/pollution policy (which may not contemplate a cyber cause) and your cyber policy (which typically excludes bodily injury and property damage from pollution). That seam has to be closed on purpose.

Your real exposure: tampered or disabled leak detection, false readings that delay a response, ransomware on site-management platforms, and dependent business interruption when a shared monitoring vendor is hit. UST accounts should look at cyber alongside their environmental placement, not in isolation.

Cell tower & telecom contractors

9+ major U.S. carriers breached (Salt Typhoon) Called “the worst telecom hack in our nation’s history”

Telecommunications is the number-one nation-state target on the map right now. The Salt Typhoon campaign — attributed to Chinese state-sponsored actors — compromised at least nine major U.S. carriers including AT&T, Verizon, and T-Mobile, sat undetected in some networks for years, and reached call records and location data for over a million users. As of early 2026, carriers had not confirmed full remediation. You might reasonably ask: if the carriers are the ones getting hacked, why does a tower contractor care?

Because you’re in the supply chain they’re now scrutinizing. Tower and telecom contractors hold carrier network credentials, site access data, and integration into systems that lead straight to the target. Master lease and vendor agreements from the carriers and tower companies increasingly carry cyber and data-security requirements, and a contractor who becomes the entry point for a supply-chain attack faces contractual liability, remediation costs, and lost prequalification standing. Your exposure is credential theft, third-party liability to the carrier, and BEC on your own AR/AP — plus meeting the cyber terms your contracts already require.

Mining & metals

Reported attacks tripled: 10 → 30 in one year ~80% financially-motivated ransomware

Mining used to be an afterthought for attackers; it isn’t anymore. Sector information-sharing data shows reported cyberattacks jumped roughly threefold in a single year, and about 80% of them were financially-motivated ransomware aimed at forcing a shutdown. The anchor case is Norsk Hydro, whose 2019 ransomware attack forced a global switch to manual operations and cost an estimated $52 million in the first quarter alone. More recently, rare-earth and gold producers have been named on extortion sites, and one industry survey found 43% of mining respondents paid ransoms of $1 million or more to resume operations. There’s also an espionage angle: geological data, exploration models, and resource maps are targets in their own right, particularly around critical minerals.

Your real exposure: OT-driven production stoppage (ventilation, haulage, processing all run on control systems), theft of proprietary exploration and reserve data, and third-party service providers as the weak link. Mining and support contractors alike should treat cyber BI and OT coverage as core, not optional.

Specialty & general contractors

Construction is a top-5 ransomware target Wire fraud losses in the billions annually

Contractors are targeted for a simple reason: large payments, lots of vendors, and lean back offices. The dominant loss isn’t a dramatic hack — it’s a fake email. Business email compromise (a spoofed subcontractor changing its banking details, a fraudulent “change order” payment request) drives billions in reported annual losses, and construction has climbed into the top tier of ransomware-targeted industries. Add mobile devices, jobsite Wi-Fi, and project-management platforms full of client data, and the exposure is broader than most contractors assume.

Your real exposure: funds-transfer fraud on progress payments, ransomware that locks your bidding and scheduling systems mid-project, and breach liability for the owner and employee data you hold. The single most valuable control costs nothing: a mandatory callback to a known number before any payment or banking-detail change is actioned. The FBI’s Internet Crime Complaint Center tracks these losses, and they run into the billions every year.

Every account we place is different. Let’s look at where your program is exposed.

Email Steve for a policy review

Which policy pays? The coverage grid

When a loss happens, the first fight is often which policy responds. Here’s the honest picture of how a standard General Liability policy, a Crime/Fidelity policy, and a purpose-built Cyber policy line up against the events that actually hit our industries. “Maybe” means it depends on a specific endorsement or sublimit — which is exactly where you want a broker reading the form.

The eventGeneral LiabilityCrime / FidelityCyber
Ransomware locks your systems or halts OT/productionNoNoYes
Lost income during a system/operations shutdownNoNoYes
Hacker steals employee, vendor, or client dataNoNoYes
Notification, forensics & credit-monitoring costsNoNoYes
Third-party lawsuit over your leaked dataNoNoYes
Hacker manipulates your system to move money (computer fraud)NoMaybeYes
Employee tricked into wiring funds (social engineering)NoMaybe*Maybe*
Cyberattack physically damages equipmentNoNoMaybe*
Regulatory response (state privacy, TSA/CIRCIA)NoNoYes

*Only with the right endorsement, and usually subject to a sublimit and specific conditions. This is where placements succeed or fail.

Cyber is a layer, not a panic buy

One last thing, because it’s how we approach this at CVI: we don’t sell mono-line cyber, and we don’t think you should buy it that way. Cyber belongs on a real commercial program — structured alongside your GL, property, environmental, and professional coverage so the seams between them are deliberate instead of accidental. For a physical-risk operation, the goal isn’t a certificate that says “cyber.” It’s a program where a ransomware event, a bad wire, or a breach lands cleanly on a policy that was built to pay it. That’s a brokering job, and it’s the one we do.

Frequently asked questions

Does my general liability policy cover a cyberattack or data breach?

No. Modern commercial general liability forms carry an electronic-data / access-or-disclosure exclusion that carves out loss of, damage to, or exposure of data. Both your own cleanup costs and a third-party suit over leaked data fall outside GL. This is the single most common misconception we correct.

We don’t take credit cards or hold much personal data — why would we need cyber coverage?

Because the modern loss isn’t about your data — it’s about your operations and your money. Ransomware that halts production, a fraudulent wire that drains an account, or a shutdown that idles a crew costs far more than a stolen contact list. Operational businesses with minimal PII are now prime targets precisely because a shutdown is worth more to an extortionist than data.

What’s the difference between cyber insurance and crime/fidelity coverage?

Crime covers employee theft and, in some forms, computer fraud (a hacker directly manipulating your systems). Cyber covers the broader network, breach-response, and business-interruption exposure. The critical gap is social engineering — an employee deceived into authorizing a payment. Many crime forms treat that as “voluntary parting” and decline it; it has to be added by endorsement, often with a low sublimit.

If a cyberattack shuts down our operations, won’t our property policy cover the lost income?

Usually not. Most property forms now include a cyber exclusion, so a shutdown with a cyber cause is carved out on the property side — while a bare cyber policy may exclude the resulting physical damage. Bridging that “cyber-physical” gap matters most for OT-heavy operations like oil & gas, mining, and tank fields, and takes deliberate structuring.

What is ransomware, and what does cyber insurance do about it?

Ransomware encrypts your files or the systems that run your equipment, and the attacker extorts you to unlock them. A cyber policy funds the negotiation, the ransom where legally permitted, forensic recovery, data restoration, and the business income you lose while you’re down — which is typically the largest cost of all.

What is business email compromise, and is it covered?

BEC is a fraudulent email that tricks someone into sending money or changing payment details — a fake vendor bank change, a spoofed executive request. No malware is needed. Whether it’s covered depends on having the right social-engineering / funds-transfer endorsement; it’s frequently sublimited and conditioned on verification steps, so the fine print matters as much as the limit.

Are industrial control systems (SCADA/ICS) covered under cyber?

Standard cyber policies were written around IT and data, not operational technology. Covering a control-system compromise — and any physical damage or process disruption it causes — generally requires OT-specific extensions or a specialty structure. For rigs, mines, pipelines, and tank fields, this is a placement to get right, not assume.

Do cell tower and telecom contractors really need cyber if it’s the carriers getting hacked?

Yes. Contractors in the telecom supply chain hold carrier credentials and site access, making them a pathway into the primary target — which is why master lease and vendor agreements increasingly impose cyber requirements. Your exposure is credential theft, contractual/third-party liability to the carrier, wire fraud on your own books, and loss of prequalified standing.

How much does cyber insurance cost for a specialty operator or contractor?

It varies with revenue, controls, and the coverage you actually need, but as a package layer on an existing commercial program it’s often a modest addition relative to the exposure it closes — far less than the deductible-plus-downtime of a single ransomware event. We’ll quote it in the context of your whole program, not as a line item in a vacuum.

Can cyber be added to my current program, or does it have to be standalone?

It can and, in our view, should be built into your broader commercial program so the coverage seams are intentional. We place cyber as part of a structured package alongside GL, property, and environmental — not as a mono-line product bought under pressure.

Hard-to-place risk is what we do. Let’s make sure your cyber exposure isn’t the gap in an otherwise solid program.

(818) 974-8117   steve@cvins.com

Steve McClure is Principal Broker at Crescenta Valley Insurance (CVI), a division of the FCIS Group, specializing in surplus lines and hard-to-place commercial risk across oil & gas, mining, environmental, storage tank, and specialty contractor programs. CA License #0G58010. This article is general information, not a coverage opinion or legal advice; policy terms, exclusions, and conditions govern any actual claim. Statistics are drawn from public 2025–2026 industry reporting (IBM, Dragos, FBI IC3, Zscaler, MM-ISAC, CISA, and sector press).



Leave a Reply

Discover more from CVI

Subscribe now to keep reading and get access to the full archive.

Continue reading

Verified by MonsterInsights