The people, the certifications, the insurance

Pre-mobilisation review meeting, three weeks before the manufacturer's service team is scheduled to begin commissioning work. The asset owner's HSE and security teams are present. The manufacturer's project manager has prepared the standard mobilisation pack — medical certificates for the engineers travelling to site, copies of their passports and visas, evidence of safety training, occupational health clearance, the personnel deployment list.

The asset owner's security team has additional questions. Has each engineer on the list been subject to a background check under the asset owner's vetting standard? What evidence of cybersecurity competency does each hold — relevant certifications, training records, prior experience on similar equipment? What insurance does the manufacturer maintain that covers cybersecurity incidents specifically — not the general professional indemnity, but the cyber-specific coverage with stated limits and clearly defined named perils?

The manufacturer's project manager works through the list with the asset owner's team. About half of the requested information is available immediately. The medical and safety training is documented. The visas and passport records are in order. The background checks are flagged as not previously requested at this depth, but the manufacturer can run them through their compliance partner with two to three weeks of notice. The cybersecurity competency evidence is sparse — most of the engineers have manufacturer-internal training records but few hold the independent certifications the asset owner expects to see. The cyber insurance question requires the manufacturer to come back with the policy schedule rather than the certificate summary that was attached to the mobilisation pack.

The meeting ends with action items running on the manufacturer's side, not the asset owner's. The mobilisation date slips while the gaps are closed.

The principle behind this review is that the operational assurance for the project rests on three connected foundations: the people who do the work, the qualifications that verify they are competent to do it, and the insurance that responds when things go wrong despite the qualifications and competence. Each layer depends on the others. An audit trail linking the three is the evidence base that satisfies the lender's compliance function, the asset owner's risk management, and the regulator's expectations under NIS2.

This is the human and commercial assurance loop. The technical pieces in this series have addressed the cybersecurity architecture of the project — what the equipment must do, how it must be configured, how it integrates with the asset owner's infrastructure. This article addresses the layer that operates the architecture in practice: the engineers who configure, maintain and update the equipment; their competency to do so; and the financial backstop that responds when their work, despite their competence, results in an incident.

The people: vetting, named disclosure, subcontracting

Background checks. The asset owner's vetting standard for engineers with access to OT systems typically includes identity verification, right to work in the project country, criminal record check covering the previous five to ten years depending on jurisdiction, reference checks, and, for engineers with privileged access, sometimes a financial probity check. For projects classified as critical infrastructure under host-country law, additional vetting may apply — formal security clearance in some jurisdictions, equivalent processes administered by national authorities in others.

The vetting standard varies by jurisdiction and by the asset owner's group policy. NIS2 essential entities are expected to apply appropriate due diligence to personnel with access to network and information systems; Article 21 paragraph 2(i) lists human resources security among the risk management measures essential entities must implement. Some EU member states have specific frameworks for vetting personnel in critical infrastructure roles — the BSI (Bundesamt für Sicherheit in der Informationstechnik) in Germany for cybersecurity-specific vetting, with constitutional-level clearances administered through the relevant federal authorities where required, similar functions in France through SGDSN, the National Protective Security Authority in the United Kingdom. The asset owner's vetting practice typically aligns with the host country framework and the group policy, with the higher standard prevailing where they differ.

Named personnel disclosure. The asset owner requires advance disclosure of which specific engineers will be performing work on site or remotely. "Manufacturer's service team" as a generic descriptor is not acceptable; named individuals are identified, with their roles, certifications and vetting status documented. The named engineers are the people who receive identities in the asset owner's identity and access management infrastructure described earlier in this series; the personnel disclosure feeds directly into the identity provisioning workflow.

Subcontracting. The manufacturer's organisation often uses subcontractors — specialised technical services, local technicians in the host country, agency engineers for surge capacity, third-party operations and maintenance providers for specific functions. Subcontracting requires written consent from the asset owner, with the subcontractor's personnel subject to the same vetting and certification standards as the manufacturer's direct employees. Undisclosed subcontracting is a contractual breach that the asset owner's audit function will surface; the appropriate practice is for the manufacturer to maintain a disclosed roster of approved subcontractors and to request specific consent for any work performed outside that roster.

The personnel pool that emerges from these requirements is typically smaller and more stable than the manufacturer's general service organisation. A handful of engineers, or a few dozen for a larger project, vetted, certified, named, and maintained as the project's approved pool. Manufacturers who serve EU-financed projects in volume maintain such pools as a standing capability rather than building them for each project.

The certifications: competency evidence

What the asset owner expects to see, beyond the manufacturer's own internal training records, is independent evidence of cybersecurity competency held by the engineers performing security-critical work. The competency landscape is well-developed.

For OT-specific cybersecurity work, the most commonly recognised certifications are the IEC 62443 Cyber Security Expert (CSE) certificates issued by accredited bodies including TÜV SÜD, TÜV Rheinland, ISA, exida, and several others. The ISA/IEC 62443 certification path runs through fundamentals, specialist and expert levels, with the expert level being the typical expectation for engineers responsible for security-critical work on industrial control systems. GIAC, the certification body affiliated with the SANS Institute, offers two industrial control specific certifications — the Global Industrial Cyber Security Professional (GICSP) and the Response and Industrial Defense (GRID) certification — both well-recognised in the OT community.

For broader cybersecurity foundations, the Certified Information Systems Security Professional (CISSP) from ISC2 and the Certified Information Security Manager (CISM) from ISACA are commonly held by security architects and managers. The general SANS/GIAC certifications — GIAC Security Essentials (GSEC), Certified Incident Handler (GCIH), Certified Forensic Analyst (GCFA) — appear in the engineering teams responsible for incident response and forensic analysis.

For specific role areas, additional certifications apply. Network engineering for OT environments has industry-specific certifications from Cisco, Juniper, and the major OT networking vendors. Industrial protocol expertise comes through vendor certifications and through specialist training programmes. Safety-instrumented system engineering has its own certification ladder under TÜV functional safety programmes, separate from but adjacent to the cybersecurity certifications.

Country-specific equivalents exist and are usually recognised alongside the international certifications. The Bundesamt für Sicherheit in der Informationstechnik in Germany maintains training schemes; the Agence nationale de la sécurité des systèmes d'information in France operates national certification programmes; the National Cyber Security Centre in the United Kingdom maintains a certified cyber professional scheme; equivalent national programmes exist across the EU and in major non-EU jurisdictions.

The asset owner does not expect every engineer in the pool to hold every certification. The expectation is that the engineering team as a whole has the competency mix appropriate to the work, with specific individuals identified as the technical authorities for specific areas — a lead architect with CISSP and 62443 CSE, a senior incident responder with GCIH and GRID, an industrial network specialist with GICSP and vendor-specific certifications. The certifications are evidence; the underlying competency is what they signal.

The insurance: cyber liability beyond the standard policy

Standard professional indemnity insurance covers errors and omissions in the manufacturer's professional services. Standard product liability insurance covers defects in the products themselves. Neither typically covers the specific risks of cybersecurity incidents arising from the manufacturer's products or services in the way the lender requires.

Cyber liability as a distinct coverage emerged in the early 2000s for IT companies and has evolved to address industrial contexts. The lender's specification for cyber coverage typically requires several named elements. Named cyber coverage, explicitly identified as a separate line item in the policy rather than bundled into general professional indemnity. Third-party damages, covering damages to the asset owner arising from cyber incidents traced to the manufacturer's equipment or services. Ransomware response, covering forensics costs, negotiation support and remediation expenses, with appropriate sub-limits and clearly defined trigger conditions. Regulatory fines coverage, where insurable under the applicable law of the jurisdictions in which the manufacturer operates (some jurisdictions do not permit insurance for regulatory fines, in which case the policy should explicitly note the exclusion). Business interruption coverage for the asset owner's losses during outages caused by cyber incidents. Network security and privacy liability covering breaches that affect personal data or the asset owner's network beyond the manufacturer's specific scope.

The "silent cyber" issue is worth specific mention. Lloyd's Market Bulletin Y5381, issued in August 2022, required Lloyd's syndicates to address cyber risk in all policies — affirming coverage explicitly where it was intended, excluding it explicitly where it was not. The Bulletin took effect for new policies from January 2023. Parallel guidance from other insurance regulators followed, with similar effect — notably the Prudential Regulation Authority's consultations on cyber underwriting in the United Kingdom, and corresponding statements from EU national regulators — reinforcing that the silent-cyber tightening is now market-standard rather than Lloyd's-only. The result was a tightening of cyber coverage in non-cyber-specific policies (which previously sometimes carried "silent cyber" exposure that responded to incidents the underwriters had not specifically priced) and a sharpening of exclusions in cyber-specific policies, particularly around acts of war, state-sponsored activity, and infrastructure attacks attributed to nation-state actors.

For the manufacturer, the practical implication is that their existing professional indemnity policy may not adequately cover cyber-specific incidents, and that standalone cyber policies require careful review of exclusions. The war and state-sponsored exclusions in particular have become broad enough in some policies that incidents involving sophisticated threat actors may fall outside coverage entirely. The lender's adviser examines the policy schedule rather than the certificate summary to confirm what is actually covered, with particular attention to the exclusions section.

Stated limits. The lender specifies the minimum cyber liability limit based on the project's risk profile. For utility-scale renewable energy projects in EU-financed structures, the minimum is typically in the tens of millions of euros for third-party damages, with sub-limits for ransomware response, regulatory fines, business interruption, and the other named elements. The limits are negotiated between the manufacturer's broker and the underwriter; the asset owner's adviser confirms that the limits as bound meet the project specification.

The three layers — people, qualifications, insurance — work together when each has documented evidence and the evidence is linked through the project's record-keeping.

For each named engineer in the project pool, the documented record includes the vetting record (background check completion, dates of completion, scope of the check), the competency record (certifications held with issuing bodies, expiry dates, scope of each certification), the authorisation record (what the engineer is authorised to do on the project, against which equipment, under whose supervision), and the activity record (what the engineer actually does, generated through the audit trail from the identity infrastructure described earlier in this series and the SIEM discussed alongside). The audit evidence is the documentation that ties an engineer's vetting status to their certifications to their authorisations to their actual activity. Without that linkage, the asset owner cannot evidence — to a regulator, to a lender, to an auditor — that the work performed on the deployed equipment was performed by appropriately qualified, vetted, authorised personnel.

The manufacturer's contribution to the audit evidence runs throughout the contract life. Maintaining current records for each named engineer in the project pool. Notifying the asset owner promptly when records change — an engineer leaves the manufacturer, a certification expires, a vetting result needs to be updated, a new engineer joins the pool and needs to be onboarded. Cooperating with the asset owner's periodic audit of the personnel records. Providing the insurance certificate renewal each policy year, with the policy schedule attached when changes have been made to the coverage. Responding to specific audit requests from the asset owner's compliance function or the lender's adviser within the timelines agreed in the contract.

The audit evidence is rarely scrutinised in detail — most of the time, the records sit in the asset owner's compliance archives and are referenced only at periodic audit points. When an incident occurs, the audit evidence becomes central. The investigation traces what happened, when, by whom, under whose authority, with what supporting credentials and qualifications. An incident response where the audit trail is complete, the credentials are current, the certifications are documented and the insurance responds is an incident that resolves cleanly. An incident response where any of those layers is missing or out of date becomes an incident the lender's compliance function reports differently than the asset owner would prefer.

At proposal stage

A manufacturer's bid that addresses the human and commercial assurance layer — that proposes a named pool of vetted, certified engineers for the project, attaches their certification evidence, describes the manufacturer's cyber liability insurance with the policy schedule attached for the lender's review, and outlines the audit evidence the manufacturer will maintain throughout the contract — is a bid that has anticipated the conversation. The lender's compliance team and insurance adviser review the materials, identify specific items requiring clarification, and the conversation proceeds.

A bid that treats personnel as a deployment-stage detail to be resolved after contract signature, or that addresses insurance only through a certificate summary without policy schedules, signals a gap that the late-stage review will surface. The gap is closeable, but the work involves the manufacturer's HR function (for vetting and personnel records), the manufacturer's professional development organisation (for certification evidence), and the manufacturer's risk management and broker relationships (for insurance restructuring). Three separate workstreams, all reaching procurement at the same late stage, all needing to complete before mobilisation can proceed.

The deeper observation: the human and commercial assurance layer often arrives later in the procurement process than the technical pieces. By the time the lender's insurance adviser is reviewing the policy schedule, the technical conversations have largely concluded and the deal is close to signature. The personnel and insurance work, if not anticipated, becomes the late-stage bottleneck that can stall an otherwise-ready project. Manufacturers who address it during the bid, alongside the technical submissions, find that the assurance layer is operationally straightforward — well-developed certification programmes, established vetting providers, mature cyber insurance markets. The work is procurable from established suppliers; the manufacturer's task is to recognise that the work is required.

The next article is the closing synthesis of the series — a procurement matrix that maps every topic across the seventeen substantive pieces to the procurement gate at which the conversation should be raised, from the initial request for information through mid-life review. The matrix gives a procurement team the operational tool the prose articles have been building toward.


This article reflects the regulatory, certification and insurance landscape at publication. The Cyber Resilience Act's implementing acts continue to evolve through 2026 and 2027; certification programmes are revised periodically by their issuing bodies; cyber insurance market conditions shift as underwriters respond to claims experience. Named certification bodies, training programmes and insurance market references are illustrative rather than endorsements; specific arrangements should be reviewed by qualified counsel and brokers. If a citation has rotted or a clause has moved, LinkedIn is the way to flag it.