🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Cyber Insurance

Cyber Insurance and Penetration Testing: What Underwriters Actually Ask

Quick Answer

Cyber insurance requirements around penetration testing vary by insurer and policy — there is no single universal rule. Many renewal questionnaires ask whether you've tested in the last 12 months and want evidence, not just a yes/no answer. We are not a broker and don't sell policies; we provide the testing and documentation that answers those questions. Always confirm your specific policy's requirements with your broker or underwriter.

Why Insurers Ask About Testing

Cyber insurance underwriters price policies based on assessed risk, and unpatched, untested internet-facing systems are a well-documented driver of ransomware and business-email-compromise claims. Rather than take an applicant's word for their security posture, many renewal and new-business questionnaires now ask specific, evidence-backed questions about testing, patching, MFA, and backups. This isn't a formality — insurers increasingly use the answers to price policies, set sub-limits (particularly for ransomware), and in some cases as a condition of coverage. What counts as sufficient evidence, and whether testing is mandatory at all, depends entirely on your specific insurer and policy — we don't have visibility into any individual insurer's underwriting rules and won't speculate about them here.

Typical Renewal Questionnaire Topics

These are common categories seen across cyber insurance applications generally — your specific insurer's questionnaire may differ.

TopicWhat's typically asked
External vulnerability scanningFrequency of automated external scans of internet-facing IPs/domains
Penetration testingWhether an independent test was performed in the last 12 months, and by whom
Patch managementTime-to-patch for critical vulnerabilities, especially internet-facing systems
MFA coverageMFA on email, VPN/remote access, and privileged/admin accounts
Backup strategyOffline/immutable backups and last successful restore test
Endpoint detection & response (EDR)Whether EDR/XDR is deployed across endpoints and servers
Incident response planExistence of a written IR plan and last tabletop exercise date
Employee security trainingPhishing simulation and security awareness training cadence

Questions That Need an Artefact, Not Just an Answer

Some questionnaire answers can be self-attested. Others increasingly require a dated document you can produce on request — from your insurer, an auditor, or during a claims investigation.

"Have you had a penetration test in the last 12 months?" — needs a dated report, not a verbal yes
"Were critical findings remediated?" — needs a retest report or remediation evidence, not a promise
"Do you have MFA everywhere?" — needs a screenshot/config export, not an assumption
"Is your incident response plan tested?" — needs tabletop exercise minutes or a dated report
"Are backups tested for restore?" — needs a dated restore-test log

If You've Never Had a Penetration Test

You don't need a multi-week enterprise engagement to answer a renewal questionnaire. A focused, external Vulnerability Assessment — typically 5 business days — covers your internet-facing systems and produces a dated report with an Attestation Letter suitable for underwriter review. It's a realistic starting point if your renewal is approaching and you have no prior test on file.

Start now if your renewal is within 60 days — there's time to test, remediate, and retest before the deadline.

Start with Vulnerability Assessment — €539

What Goes in Our Attestation Letter

Testing dates (start and end) and the name of the testing organisation
Scope tested — hostnames, IP ranges, or application URLs, explicitly listed
Methodology reference (e.g., OWASP WSTG v4.2, PTES)
Summary of findings by severity (critical / high / medium / low), without exposing exploit detail to a third party
Confirmation of retest status for critical/high findings
Signature and contact details of the testing provider, for underwriter verification

Renewal Preparation Timeline

90 days before renewal

Review your last questionnaire answers and identify any that changed (new systems, new vendors, past incidents). Flag gaps early rather than at the deadline.

60 days before renewal

If you don't have a test from the last 12 months, schedule one now. A 5-day Vulnerability Assessment fits comfortably in this window with time to remediate before renewal.

30 days before renewal

Have your Attestation Letter and remediation evidence ready to attach to the questionnaire response. Brokers report smoother renewals when evidence is submitted proactively rather than in response to a follow-up query.

What We Don't Do

We are not an insurance broker and do not sell, arrange, or advise on insurance policies.
We do not guarantee, estimate, or promise any specific premium reduction from testing.
We do not guarantee that a completed test will prevent a claim denial — claims decisions are made solely by your insurer under your policy's terms.
We do not have disclosed partnerships with specific insurers or brokers, and don't claim otherwise.

This page is general information, not insurance or legal advice. Speak with your broker or underwriter about your specific policy's requirements.

Frequently Asked Questions

Does cyber insurance require a penetration test?+
It depends entirely on your policy and insurer — there's no universal rule. Many insurers ask about testing on the application/renewal questionnaire and may price the policy, or specific sub-limits like ransomware coverage, based on your answer. Some require a test as a condition of coverage above certain limits; others simply ask and adjust pricing accordingly. Check your specific policy wording or ask your broker — we are not a broker and cannot tell you what your policy requires.
Will a penetration test lower my premium?+
We can't say, and we won't claim it will. Premium is set by your insurer based on many factors (industry, revenue, claims history, overall risk posture) and we have no visibility into or influence over that calculation. What a test does reliably provide is documented evidence of your security posture, which is one input insurers may consider.
What if I've never had a penetration test?+
A first test doesn't need to be a multi-week enterprise engagement. A focused 5-business-day Vulnerability Assessment (from €539) is often enough to answer the specific questions on a renewal questionnaire and produce your first Attestation Letter, with time to remediate before your renewal date.
What's in an Attestation Letter?+
A dated summary covering testing dates, scope tested, methodology reference, findings by severity, retest/remediation status, and the testing provider's signed contact details — enough for an underwriter to verify the test happened and understand its scope, without disclosing exploit-level detail to a third party.
Can you guarantee my claim won't be denied?+
No — and any vendor who tells you this is not being honest with you. Claim decisions are made solely by your insurer based on your policy terms, the specific incident, and your compliance with the representations made in your application. We provide security testing and documentation; we do not provide insurance advice, broker services, or any guarantee about claims outcomes.
How far in advance of renewal should we test?+
We recommend starting the process at least 60 days before your renewal date — enough time to complete testing, remediate critical/high findings, and have a retest and Attestation Letter ready to submit alongside your renewal questionnaire.
Are you an insurance broker?+
No. We are a security testing provider. We do not sell insurance policies, provide brokerage services, or advise on policy selection or coverage limits. For questions about what your specific policy requires or how testing affects pricing, speak with your insurance broker or underwriter directly.
Do you work with our broker directly?+
We're happy to have your broker or underwriter contact us directly to verify a report or ask clarifying questions about scope and methodology. We don't have existing partnerships with specific brokers or insurers to disclose, and we don't claim otherwise.

Get Renewal-Ready Before Your Deadline

€539 · 5 business days · Signed Attestation Letter for your questionnaire