Usually not in those words. Carriers ask questions instead. The application asks about MFA, remote access, backups, patching and scanning, and some ransomware supplements ask whether anyone has tested your controls in the last year. Every answer you give becomes part of the basis for the policy. A penetration test is how you know the answers are true before you sign them.
The short answer
- Some carriers ask directly about testing. Others ask about the controls a test checks. Either way, “yes” needs evidence behind it.
- A wrong answer can cost you the policy. In 2022, Travelers asked a federal court in Illinois to rescind a policy after a ransomware claim. It alleged the insured had attested to MFA for privileged access but used MFA only on its firewall. The parties agreed to a judgment declaring the policy void from its inception. (Insurance Journal, July 2022; August 2022)
- The test is cheap next to the claim. NetDiligence puts the average small and mid-size company incident at $264,000 (see our claims statistics). An external test starts at $4,200 at a fixed price, with a free retest, and it checks the exact controls the application asks about.
What applications actually ask
Applications differ by carrier and by company size. Carriers use short forms for smaller companies; Travelers, for example, offers its CyberRisk short form to companies with revenue of $50 million and below, and publishes a separate MFA supplement. (Travelers) Three published forms show the range:
- Beazley’s short questionnaire for companies under £20 million in revenue asks whether MFA protects webmail and remote access. It then lists optional controls, including regular scanning of internet-facing services and simulated phishing, that it says can discount the base premium by up to 20%. (Beazley questionnaire, PDF)
- AIG’s ransomware supplemental questionnaire (the published Australian version) asks how the applicant validates its security controls. The options include engaging experts at least annually for a penetration test focused on internal systems, and engaging an outside party to simulate threat actors in the last year. The same form asks about monthly scanning of internet-facing systems and annual simulated phishing. (AIG supplemental questionnaire, PDF)
- AXIS’s ransomware supplemental application goes deep on remote desktop exposure, MFA for remote and privileged access, and whether backups are segmented and protected by their own credentials. (AXIS supplement, PDF)
The pattern is consistent. Carriers ask about how attackers actually get in: exposed services, stolen credentials, phishing, and an internal network that lets one compromised laptop reach everything. Those are the things a penetration test checks.
Which test answers which question
| What the application asks about | The test that gives you evidence | Invadel price |
|---|---|---|
| Internet-facing systems, open RDP, VPN and remote access | External network penetration test: every exposed host and service, with MFA coverage on remote access checked | From $4,200, free retest |
| Internal testing, ransomware readiness, how far an attacker could get once inside | Internal network penetration test: from one compromised workstation toward Domain Admin, backups and critical systems. A ransomware readiness assessment adds backup reachability and a detection review for ransomware supplements | From $6,000, free retest |
| Simulated phishing and staff awareness | Phishing campaign with click, submission and reporting rates by department | From $3,600 (no retest: a campaign produces no findings to retest) |
| MFA on webmail, email security, Microsoft 365 or Google Workspace settings | Microsoft 365 security assessment: Conditional Access and MFA gaps, legacy sign-in, admin roles, mail forwarding rules and external sharing | From $4,200, free retest |
| Regular vulnerability scanning | Validated vulnerability scan, false positives removed by an analyst | $1,500 up to 250 devices, $2,500 up to 1,000 |
| Customer data in a web application or portal | Web application penetration test with accounts in every role | From $5,200, free retest |
Start with the external test. It covers the questions the forms above ask first: what is exposed, whether remote access is protected, and whether an outsider can get in. Add the internal test if the application or supplement asks how far an attacker could go once inside. Add phishing if it asks about simulated campaigns. Our pages on penetration testing for small businesses and cybersecurity for nonprofits cover the same choices for smaller teams.
Carrier scans are not a penetration test
Some carriers watch your internet-facing footprint themselves. Coalition, for one, describes continuous monitoring of the attack surface as part of its policies. (Coalition) If your broker forwards a carrier scan with red items on it, take it seriously: it is what the underwriter sees.
A carrier scan and a penetration test answer different questions.
- A typical outside-in scan sees open ports, software versions and known vulnerabilities. It does not try to break in.
- It cannot see whether MFA covers every remote access path, whether a leaked password still works, or what an attacker could reach from inside.
- A penetration test does all of that, proves what is exploitable, and gives you a report and an attestation letter you can put in front of the underwriter.
If a carrier scan flags something, fix it, and ask your tester to confirm the fix. On our engagements that confirmation is the free retest.
Timing: test two to three months before renewal
The worst answer on a renewal form is “tested, fixes in progress.” Plan so you can write “tested, serious findings fixed and verified.”
- Scope early. Testing typically starts within a week of scoping, and onboarding begins within 24 hours of a signed proposal.
- Test. A standard external or internal scope takes about a week of hands-on testing, followed by the report.
- Fix. This is the part that takes the longest, and it is on your side. Reserve the time before the test starts.
- Retest, free. We verify every remediated finding and update the report.
- Send the letter. The attestation letter states the scope, dates, methodology and outcome. It comes with the report, and after the retest we update it to show the serious findings closed.
Start two to three months before the renewal date and the retest lands before the application is due. Our guide to how long a penetration test takes walks through each phase.
What to send the broker
Send the attestation letter, not the full report. The letter states what was tested, when, by whom, against which standards, and the status of the findings after the retest. That is what an underwriter needs. The full technical report contains exploit detail that should not travel through email chains. If a carrier asks for more, our third-party testing deliverables include a summary that is safe to share.
Answer the application from the evidence. If MFA covers remote access but not every administrative account, say so, and fix the gap. The Travelers case turned on an MFA answer that did not match reality.
How often to test for insurance
The forms above ask about the last year, so test at least annually. Test again after significant changes: a new remote access platform, a merger, a cloud migration or an office move. Scan between tests; a vulnerability management program runs validated scans monthly or quarterly and tracks each fix to closure. Our guide to how often you should do a penetration test sets out the cadence framework by framework.
A typical engagement
Take a 25-person accounting firm whose renewal application asks whether the network has been penetration tested and whether MFA covers remote access. We would run an external test of the firm’s perimeter, a review of its Microsoft 365 tenant and a phishing baseline across the staff. The firm would get a report and an attestation letter for the broker, its fixes ranked by urgency, and a free retest of the network findings once they are done. Our page on penetration testing for accounting and CPA firms describes engagements like this one.
For brokers
If a client needs evidence before a renewal date, send them to our pricing page. Every price is published, so the client can budget before the first call. The deliverable they will hand back to you is the attestation letter from our third-party penetration testing engagements. Brokers who refer clients regularly can also look at our partner program.
Frequently asked questions
Is a penetration test required to buy cyber insurance? It depends on the carrier, the policy and the limit. Carriers set their own underwriting questions, and some ask directly whether an outside party tested your controls in the last year.
Will a penetration test lower my premium? It can help. Some carriers price or discount on the controls the application asks about, and Beazley’s short form says satisfactory answers on its optional controls can reduce the base premium. The larger benefit is that your answers are true and you can prove them.
Does a vulnerability scan count? It answers the scanning question. A question about penetration testing or simulated attacks asks for something a scan does not do: an attempt to break in.
What does a test for insurance cost? At Invadel an external network test starts at $4,200 and an internal test at $6,000, each at a fixed price with a free retest. Phishing starts at $3,600, and a Microsoft 365 security review at $4,200. Validated scans are $1,500 up to 250 devices.
Fixed price, fixed scope, free retest. Scope your test and get a written price within one business day.
Written by
Invadel Team
Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →