Penetration testing for cyber insurance

Your cyber insurance application or renewal form has a question about penetration testing. Answering "yes, within the last 12 months" takes a real test and a dated report. This page explains what insurers ask, why a scan is not the same thing, and how to get a report before your renewal date.

Penetration testing for cyber insurance

What insurers ask

Forms differ by carrier, but the questions are similar:

  • Do you conduct penetration testing?
  • How often?
  • Which kinds: external network, internal network, web application?
  • Is it done by an outside party?

Insurers generally want to see testing within the last 12 months.

Why the answer matters

The application becomes part of your policy. An answer that turns out to be inaccurate can cause problems when you file a claim. If you have only run vulnerability scans, say so, or get a penetration test and answer yes with a report to back it up.

A scan is not a penetration test

A vulnerability scan lists known weaknesses. A penetration test attempts to exploit them and shows how far an attacker could get. Insurers ask about them separately.

Get the report before your renewal

Each test starts the same day, includes retests after you fix findings, and ends with an executive summary and a technical report.

If your carrier wants an engineer-led test

Requirements vary by insurer, so ask your broker what your carrier accepts. If they ask for a test led by a named engineer, our managed penetration testing team does that.

See pen test pricing and buy online · Talk to a specialist

Related: SOC 2, HIPAA, ISO 27001, PCI DSS 11.4, penetration test cost

Ready when you are

Ready to get your pen test done this week?

Automated penetration testing from Clone Systems starts at $1,995 for an external test and $2,995 for an internal test. Buy it online, start in minutes, and retest for free within your 30-day window.