Blog · C.29 · Buyer Trigger

Your cyber insurance requires a penetration test — what to do

Your insurer or broker has asked for a recent penetration test to bind or renew your cyber policy. Here is why they want it, what actually satisfies them, how testing affects your premium and coverage, and the claim-denial trap to avoid.

Cyber InsurancePremiumCoverageRiskClaims
Cyber Insurance: Recent Independent Test · Findings Remediated · Lower Premium · Higher Limits · Avoid Claim Denial · Answer the Application Truthfully Cyber Insurance: Recent Independent Test · Findings Remediated · Lower Premium · Higher Limits · Avoid Claim Denial · Answer the Application Truthfully
// TL;DR

Cyber insurers increasingly require a recent, independent penetration test as a condition of coverage or of a better premium, because it gives them evidence you actively manage cyber risk. They want a third-party test — not a scan or self-assessment — that is current (usually within 12 months) and shows findings were remediated. A good testing record can lower your premium, raise your limits and broaden coverage; being unable to show basic controls does the opposite. The trap to avoid is misrepresenting your security on the application: attesting to testing or controls you do not have can lead to a reduced or denied claim after a breach. The safe move is simply to get a real penetration test so you can answer the insurer's questions truthfully.

// 01 Why your cyber insurer wants a penetration test

Cyber insurance is priced on risk, and the insurer's core problem is that they cannot easily see how well you defend yourself. A penetration test solves that: it is independent evidence that you test your defences the way a real attacker would, find weaknesses, and fix them. To an underwriter, a company with a recent clean-ish pentest and a remediation track record is a materially lower risk than one that has never tested — and they price accordingly.

This is why the request has become routine, especially as insurers tightened requirements after years of ransomware losses. For meaningful policy limits, many now treat a recent penetration test as table stakes, alongside controls like MFA and backups. The request usually comes through your broker during a new application or a renewal, and it is not negotiable in the way a nice-to-have would be — it gates the policy or the price.

// 02 What insurers actually require

The specifics vary by insurer, but the pattern is consistent. They want evidence that mirrors what an enterprise customer wants — and for the same reason, that it was done properly and recently.

RequirementWhat they want
IndependenceThird-party firm, not a self-assessment
RecencyUsually within the last 12 months
Real testA penetration test, not just an automated scan
RemediationFindings fixed or on a plan
ScopeYour key external and application systems

Most insurers accept a standard external and web application test; some, particularly for larger risks, may specify scope or ask about internal testing too. You generally provide a summary or attestation rather than the full technical report — the same shareable artefact a customer would accept.

// 03 How a pentest affects your premium and coverage

Testing is not just a hurdle to clear; it is a lever on price and terms. Because a mature security programme reduces the insurer's expected loss, demonstrating regular penetration testing with remediation can earn you a lower premium, higher coverage limits, or broader terms. In a hard cyber market, it can be the difference between obtaining adequate coverage and being unable to get it at all. Conversely, being unable to show basic controls and testing pushes your premium up or shrinks what insurers will offer. Viewed that way, a penetration test frequently pays for itself in reduced premium alone, before you count the security value.

// 04 The claim-denial trap

This is the part that catches companies out, and it is worth taking seriously. Cyber insurance applications ask detailed, specific questions about your controls — whether you conduct penetration testing, how often, whether you remediate findings. Those answers become part of the contract. If you attest to testing you did not perform, or controls you do not actually have, and a breach later occurs through exactly that gap, the insurer can argue material misrepresentation and reduce or deny the claim. The very moment you most need the policy is when the accuracy of your application gets scrutinised.

The safe path is simple: do not answer the application optimistically — answer it truthfully, and make it true. If the form asks whether you conduct penetration testing and you want to answer yes, get a real penetration test so that you can. It is far cheaper than a denied claim.

// 05 What to get tested

Scope to what the insurer cares about and what carries your real risk — typically your internet-facing systems and the applications that hold sensitive data. For most organisations that means an external network test plus a web application (and API) test; add internal testing if your insurer asks or your risk warrants it. If you are also subject to a compliance framework, scope one engagement to satisfy both — our requirements finder shows what each needs, and our cost guide covers pricing. Get retesting included so you can evidence that findings were closed, which is exactly what the insurer wants to see.

// 06 Frequently asked questions

Why does my cyber insurer require a pentest?

To get evidence you actively manage cyber risk. A recent independent test lowers your assessed likelihood of a claim, and many insurers now require one for coverage or better premiums.

What kind do they accept?

A recent, independent, third-party test — not a scan or self-assessment — usually within 12 months, with findings remediated.

Can it lower my premium?

Often yes. A mature testing programme can earn lower premiums, higher limits or broader coverage by reducing the insurer's expected loss.

Can a claim be denied over my application?

Yes. Attesting to testing or controls you don't have can lead to a reduced or denied claim through material misrepresentation. Get a real test so you can answer truthfully.

UG

Usama Gul

Founder & Penetration Testing Lead, CyberFortify

Helps companies meet cyber-insurance testing conditions with right-scoped, independent penetration tests and shareable attestation reports built for underwriters and brokers.

Insurer waiting on a test?

We'll scope a penetration test to satisfy your insurer's conditions, prioritise it to hit your renewal date, and give you a shareable attestation summary alongside the technical report — retest included.

Get testing scheduled → See the cost →