Why Remote Risk Assessment Misses The Physical Layer
- 2 days ago
- 7 min read
Remote scans and self-completed questionnaires have become the default way to assess an asset's risk. They are quick and cheap, but they see only the digital surface. This article explains what a site visit reveals that a form cannot, why the physical and human layers still drive real loss, and how verified evidence changes the score an underwriter relies on.

The Issue
Assessing the risk of an asset used to mean visiting it. Over the past decade, the work has moved to the desk. Outside-in cyber-rating platforms scan an organisation's internet-facing systems. Property-data platforms read building footprints from aerial and satellite imagery. Insurers and brokers lean on self-completed questionnaires and desktop modelling. The appeal is obvious: these methods are fast, inexpensive and easy to run at portfolio scale.
The trouble is that the losses have not moved to the desk with them. In its 2026 report, IBM put the global average cost of a data breach at a record $4.99 million, a rise of about 12% on the previous year. Verizon’s 2026 Data Breach Investigations Report found that the human element was present in 62% of breaches, up slightly from 60% in the previous year’s dataset. Breaches involving a third party increased by 60%, accounting for 48% of all breaches.
Neither of those figures describes something a remote scan can see. People, procedure, and connected sites are where a large share of loss begins, and they sit almost entirely behind the perimeter. Physical failures are not a rounding error either. Physical risks also feature in IBM’s taxonomy of initial attack vectors. Its 2025 Cost of a Data Breach Report includes physical theft or security issues among its initial attack vectors, with these breaches carrying an average cost of $4.07 million.

Verizon DBIR edition | Breaches involving a third party |
2024 | 15% |
2025 | 30% |
2026 | 48% |
Source: Verizon Data Breach Investigations Report, 2024, 2025 and 2026 editions (figures describe successive reporting periods).
How Remote Assessment Works, And What It Can See
It helps to be precise about the three main remote methods and their limits.
Outside-in cyber ratings probe the systems an organisation exposes to the internet: open ports, expired certificates, misconfigured services, and leaked credentials. This is useful for the external attack surface, but it stops at the firewall. It cannot see an internal network, an operational technology system, a camera, a door, or a member of staff.
Self-attestation questionnaires ask the insured to declare its controls. The answer records what the respondent believes to be true, not what an inspection would find. The distinction matters more than it sounds, as a later section shows.
Aerial and property data platforms read roofs, footprints, and neighbouring hazards. They are strong on construction and exposure to flood or wildfire, and silent on access control, network design or operating discipline.
Each method is a genuine tool. None of them, alone or together, observes the physical layer of a site or the behaviour of the people who run it.
What Is Often Missed In Remote Risk Assessment
The physical layer is not an afterthought in security frameworks. ISO/IEC 27001, the international standard for information security management, devotes a dedicated set of controls to it. Annex A.7 of the 2022 edition lists fourteen physical controls, covering security perimeters, physical entry, and, for the first time, continuous physical security monitoring. A questionnaire can tick every one of them. Only a visit can tell whether they work.
Three areas are routinely overlooked.
The physical estate: A form asks whether a site has closed-circuit television and access control. It rarely asks whether the cameras record, how long footage is retained, whether they cover the doors that matter, or whether a fire exit is habitually propped open past the card reader. Evidence retention decides whether an incident can later be proven and a claim defended. That is invisible remotely.
Operational technology: Industrial control systems, building-management systems and site machinery often run on flat, legacy networks that never touch the public's internet, so an outside-in scan sees nothing. Yet these are frequently the systems whose failure halts production. The common weakness is a bridge that should not exist: a guest wireless network, a contractor laptop or an unsegmented link that quietly connects the office network to the plant.
People and procedures: Multi-factor authentication that is declared enterprise-wide but enforced only on email; passwords shared between shifts; staff who hold a secure door for a stranger. With the human element present in nearly two thirds of breaches, this layer decides whether good systems hold up in practice

There is a fourth gap, and it is structural. The site most likely to be the way in is often the one nobody assessed: a peripheral depot, a franchise, a joint-venture plant or a supplier. In 2017, the NotPetya malware spread worldwide through compromised Ukrainian accounting software. It froze operations at shipping group Maersk, which had to reinstall roughly 4,000 servers and 45,000 computers. Maersk initially estimated the financial impact at $200 million to $300 million, later reporting an impact of $250 million to $300 million. The White House called NotPetya the most destructive and costly cyberattack in history, while a White House assessment subsequently confirmed to Wired estimated total worldwide damage at more than $10 billion.
The lesson is not about one strain of malware. It is that a weakly controlled connected site is everyone else's front door.
Why The Gap Between Declared and Observed Matters
The difference between a claimed control and a verified one is not academic. In 2022, US insurer Travelers asked a US federal court to rescind a cyber policy issued to electronics manufacturer International Control Services. The company had stated in its application that it used multi-factor authentication for administrative or privileged access. Following a ransomware attack, Travelers alleged that an investigation found MFA protected only the company’s firewall and no other digital assets. The parties subsequently agreed to have the policy rescinded and declared null and void from inception, meaning no coverage would be available for past, present or future claims under the policy.
The case turned on a cyber control, but the principle applies just as sharply to physical ones. A camera that does not record, a gate that does not lock, and a patrol that does not happen are the same failure in a different form.
Verification closes that gap. It replaces a declared control with an observed one, and in doing so it changes the risk position from an assumption into evidence.
How YAVA Approaches It
YAVA was built around this problem. Rather than scoring an asset from a distance, it sends engineers to the site and assesses it as it operates. The work is intended for operators and their insurers dealing with complex, high-value or hard-to-reach assets; the kind that a remote model tends to price on assumption.
An engagement moves through a defined sequence: scoping, a remote pre-review of what can be seen from outside, an on-site inspection, scoring, a written report and, where the client wants it, remediation. On-site teams verify the physical estate and the operating discipline in person. Remote teams handle the pre-review and turn the findings into a consistent, comparable report.

The assessment is organised around three layers. The external layer covers the physical perimeter, access control, surveillance coverage and evidence retention. The internal layer covers network design and segmentation, identity and privileged access, operational technology, backup, and recovery. The human layer covers credential handling, multi-factor discipline, incident response, and everyday procedure. Each layer is scored, and the three combine into a single composite figure that an underwriter can rely on, and a client can track each review.
The outputs are practical: a scored report, a loss-pathway map that ties each finding to the consequence it could cause, a prioritised action plan, and a brief written for the people who price the risk. Because the same team can design and carry out the fixes, a finding does not end with a note in a report. It leads to a change on the ground, after which the asset is scored again. YAVA works for the operator, and findings can be held back from an insurer until the gaps are repaired.
Practical Application
The following scenario is illustrative and is not an account of an actual YAVA engagement.
A logistics operator submits a strong questionnaire for a regional depot: closed-circuit television throughout, card access on external doors, a segmented network, multi-factor authentication in force. On paper, the site scores well.
A visit tells a different story. The cameras record but overwrite after 48 hours, so any incident older than two days cannot be evidenced. A side door is wedged open each morning for deliveries, bypassing the card reader that the form relied on. The guest wireless network, meant for drivers, reaches the warehouse-management system. Multi-factor authentication is enforced on email but not on the remote-access tool an administrator uses from home. None of this is visible from outside the fence. The composite score falls; the remediation is costed at a modest figure relative to the exposure, and the underwriter now prices what is there rather than what was claimed.
What Decision-Makers Should Consider
A short set of questions separates a declared risk position from a verified one:
Does our assessment verify controls on site, or does it accept what the applicant declares?
Do we know whether the cameras record, how long footage is retained, and which doors they cover?
Is multi-factor authentication enforced on every system, or only on email?
Are the operational technology and guest networks genuinely separated, and has that been tested?
Have the peripheral and connected sites been assessed at all, or only the flagship asset?
Would our declared controls survive a claims investigation?
Conclusion
Remote assessment is efficient, and it has a proper place in any modern risk programme. What it cannot do is see the physical layer, the operational systems behind the perimeter or the people who run them, and that is where a large share of loss still originates. A site visit does something a scan cannot: it replaces assumptions with evidence, and it changes the score accordingly. For operators and insurers weighing a complex or remote asset, that difference is worth understanding before a loss makes it obvious. YAVA is glad to talk it through.





Comments