Do I need a pentest for cyber insurance?
Short answer: Usually not by law, and many policies do not require one, but some carriers ask for a penetration test or evidence of regular testing at higher coverage levels. The real gate is the carrier's security questionnaire (MFA, EDR, tested backups, an incident response plan). Answer it honestly, because a material misstatement can let an insurer deny or void a claim.
It depends on the carrier, and anyone who gives you a flat yes or no has not read your application. There is no law that says a business must run a penetration test to buy cyber insurance. What exists instead is a market of carriers, each with its own questionnaire, its own required controls, and its own thresholds. Whether a pentest is on your list depends on which insurer you approach and how much coverage you want. Here is how to think about it.
The real requirement is the application, not the pentest
Modern cyber insurance runs on a security questionnaire. Before a carrier quotes you, they want to know how you defend yourself, because the answers predict how likely you are to file a claim. Across the market, the questions cluster around a well-known set of controls:
- Multi-factor authentication, especially on email, remote access, and privileged accounts. Since the hard market of the early 2020s, MFA has become close to a baseline expectation across carriers, and its absence can sink an application on its own.
- Endpoint detection and response on laptops and servers.
- Backups that are tested and kept offline or otherwise protected from ransomware.
- A written incident response plan.
- Patch and vulnerability management.
Penetration testing may or may not appear on that list. Some carriers ask whether you conduct regular testing. Some ask for evidence, like an executive summary of your last report. Others do not ask at all at smaller coverage levels. The pattern, broadly, is that the appetite for a pentest rises with the size of the policy: the more you want covered, the more likely an insurer is to want proof that someone competent has tried to break in.
Because this varies so much, the only reliable answer to "do I need one" is: read the specific application in front of you, and ask your broker what this carrier expects at this coverage level. That is not a dodge. It is the actual mechanism.
Why the honesty of your answers matters more than most buyers realize
Here is the part that turns a paperwork exercise into a real risk, and it is the reason we care about this topic at all.
An insurance application is a legal representation. When you attest that you have MFA everywhere, tested backups, and EDR deployed, you are making statements the carrier relies on to price and issue the policy. If those statements are wrong, even by accident, an insurer can dispute or deny a claim later, and in some cases rescind the policy, on the grounds of material misrepresentation. This is not a cyber-specific trick. It is ordinary insurance law, and it applies here with full force.
That is where testing earns its keep, independent of whether the application demands it. A questionnaire asks you to attest that a control exists. It does not check whether the control actually works. You can honestly believe MFA is enforced on every remote access path and be wrong, because a forgotten VPN, a legacy login, or a service account slipped through. The gap between "we configured it" and "it actually holds" is exactly the gap an attacker uses, and it is exactly the gap that turns an attested control into a denied claim.
What a pentest actually does for your insurance position
Used honestly, testing helps in three concrete ways:
- It verifies your attestations before you sign them. If you are about to swear that your external access is locked down, having someone confirm that from the attacker's side is cheap insurance on your insurance.
- It can lower friction, and sometimes cost. Carriers reward demonstrable security. A recent, credible test can smooth underwriting and, with some insurers, improve terms. We will not promise a specific discount, because that depends entirely on the carrier and is not ours to guarantee.
- It reduces the odds of the claim in the first place. The best outcome of cyber insurance is never using it.
What a pentest does not do is make you uninsurable-proof or breach-proof. It is a point-in-time exercise against the scope agreed. It says nothing about the system you deploy next month, and it is not a substitute for the operational controls, the MFA and backups and patching, that carriers actually weigh most heavily.
The practical sequence
If cyber insurance is what is prompting this question, do it in this order. First, get the specific application from your broker and read what this carrier requires at your target coverage. Second, close the obvious control gaps, MFA and backups and EDR, because those move underwriting more than anything. Third, if the application asks for testing, or if you simply want to know your attestations are true before you sign them, scope a test that fits.
And before you commit to a full engagement, it is worth seeing what an attacker already sees from the outside, so you are not attesting to controls that a stranger could disprove in an afternoon. That will not replace a full penetration test if your carrier demands one, and we will tell you so plainly.
Our $100 check is that first look: a focused review of your external attack surface, run on scope you have verified you own and authorized in writing, reviewed by a senior operator, and delivered with a 30-minute readout. It ends the guessing about what an attacker sees, which is the honest place to start before you sign your name to a questionnaire.
Cyber insurance and penetration testing: quick answers
Do I need a penetration test for cyber insurance?
It depends on the carrier. No law requires one and many policies do not, but some carriers ask for a penetration test or evidence of regular testing at higher coverage levels. Read the specific application in front of you.
What do cyber insurance applications require?
A security questionnaire centered on controls: multi-factor authentication on email, remote, and privileged access; endpoint detection and response; tested and protected backups; a written incident response plan; and patch and vulnerability management.
Can a penetration test lower my cyber insurance premium?
Sometimes. Carriers reward demonstrable security, and a recent credible test can smooth underwriting, but any discount depends on the carrier and is not guaranteed.
What happens if I answer the insurance questionnaire incorrectly?
An application is a legal representation. A material misstatement can let the insurer dispute, deny, or rescind a claim later, which is why verifying your attested controls before you sign matters.
Related reading
Know what you are attesting to.
Our $100 check verifies what an attacker sees from the outside before you sign an insurance questionnaire. It will not replace a full pentest your carrier demands, and we will tell you so.
Book a $100 check