What insurers ask
Forms differ by carrier, but the questions are similar:
- Do you conduct penetration testing?
- How often?
- Which kinds: external network, internal network, web application?
- Is it done by an outside party?
Insurers generally want to see testing within the last 12 months.
Why the answer matters
The application becomes part of your policy. An answer that turns out to be inaccurate can cause problems when you file a claim. If you have only run vulnerability scans, say so, or get a penetration test and answer yes with a report to back it up.
A scan is not a penetration test
A vulnerability scan lists known weaknesses. A penetration test attempts to exploit them and shows how far an attacker could get. Insurers ask about them separately.
Get the report before your renewal
- Automated external penetration test, from $1,995 for a 30-day window (1 external IP or domain).
- Automated internal penetration test, from $2,995 for a 30-day window (up to 25 internal hosts).
- Annual programs from $5,995 per year, so the answer stays "at least annually" every renewal.
Each test starts the same day, includes retests after you fix findings, and ends with an executive summary and a technical report.
If your carrier wants an engineer-led test
Requirements vary by insurer, so ask your broker what your carrier accepts. If they ask for a test led by a named engineer, our managed penetration testing team does that.
See pen test pricing and buy online · Talk to a specialist
Related: SOC 2, HIPAA, ISO 27001, PCI DSS 11.4, penetration test cost
