Cyber-Insurance Readiness
Renewing or applying for cyber insurance and the questionnaire is asking about penetration testing? We run the test and hand you a clean, dated report plus an attestation letter that answers what carriers ask, with a prioritized fix list and a retest so the gaps are closed before you sign the application.
Manual and automated testing. Transparent pricing from $4,000. Retest included.
Get a fair, fixed quote
Most carriers do not flatly require a penetration test, but a growing number ask about testing by name, and your answers on the application shape your premium, your limits, and how smoothly a claim goes. That is the honest starting point, and we wrote up the full picture in our guide to whether cyber insurance requires a penetration test. This engagement exists for the moment the question stops being theoretical: the questionnaire is on your desk, the renewal date is set, and you need a real answer you can attest to.
The questionnaire
What the application actually asks, and where this test fits
Cyber-insurance applications have largely converged on the same handful of questions. Here are the ones we see most, and what this engagement does about each. The exact wording varies by carrier, so bring yours to the scoping call.
"Do you perform penetration testing at least annually, or after major changes?"
The question this engagement answers directly, with a dated report and attestation.
"Is multi-factor authentication enforced on email, remote access, and admin accounts?"
The test verifies it in practice. If MFA is missing or bypassable somewhere, it shows up on the fix list while there is still time to close it before you sign the application.
"Are backups kept offline or otherwise protected, and are restores tested?"
When internal testing is in scope, we check whether backups are reachable from the network an attacker would be standing on. Reachable backups are often the finding that decides how a ransomware event ends.
"Is unsupported or end-of-life software in use?"
Old systems have a way of hiding in plain sight. The test inventories what is actually exposed and running, not what the asset list says.
"Do you have endpoint protection and an incident response plan?"
Not what we sell, and we will not pretend otherwise. But the report gives your IT provider the evidence to close these honestly before you sign the application.
One thing worth saying plainly: having a VPN, a firewall, or a remote-access portal on the internet is not a problem by itself, and it is not what carriers are worried about. They are worried about whether those things are patched, configured right, and behind multi-factor authentication. That is exactly what a real test checks.
How it works
Working back from your renewal date
Most small and mid-sized engagements run one to two weeks from scoping to report. The part people forget to budget for is the fixing, so we plan the whole arc with you: test, fix, retest, attest, with room to spare before the application is due. Starting a month or more out is comfortable.
- 01
Scope
A short call to agree what we test and when, with the scope put in writing before anything starts. Bring the questionnaire or the renewal application if you have it; we scope the test around what your carrier is actually asking.
- 02
Test
Automated tooling plus real hands-on manual testing. Carriers increasingly ask for manual, human-led testing by name, and the difference shows in the report.
- 03
Report
A clear report in plain English: what we found, how serious each item really is, and proof. An executive summary your leadership can read and a technical section your IT team can act on.
- 04
Fix list
A prioritized, do-this-first remediation list. Your team or your existing IT provider makes the fixes; we are happy to walk them through it in plain language.
- 05
Retest and attest
We retest your fixed findings, included in every tier, then issue the attestation letter: tested, fixed, retested, dated. That is the document your renewal wants.
What you walk away with
The report stays with you. The attestation goes to the carrier.
This distinction saves first-time buyers real grief. The full report is a map of your weaknesses with proof, and you usually should not hand it to third parties at all. What the carrier gets is the attestation letter. We wrote a plain guide to what a penetration test report looks like, section by section, if you want to see what you are buying before you buy it.
The full report
Executive summary in plain English, scope and dates, every finding ranked by how exploitable it really is with proof, and a prioritized fix list. Treat it as sensitive; it is a map of your weaknesses.
The attestation letter
A short letter stating a test was performed, when, what was in scope, and the outcome at a high level, including that findings were fixed and retested. This is typically what you hand the carrier, not the full report.
The retest, included
Once your team fixes the findings, we check the work and update the record. Every tier includes the retest, so the story you attest to is tested, fixed, retested, dated.
Pricing
What an insurance-driven test costs
Most insurance-driven engagements land in one of two tiers. If the carrier is asking about your internet-facing exposure, the Small External test starts at $4,000. If the questionnaire asks about internal testing too, the Medium Full test, external plus internal, starts at $6,500. The retest is included in every tier, not billed back as an upsell.
We publish our prices, which most firms will not do, so you can budget before the renewal conversation instead of during it. The final number depends on the size of your environment and what is in scope, and the quote is fixed once we agree it.
Being sold a scan somewhere else?
The cheapest "penetration test" on the market is often an automated scan with a logo on the report, and many carriers now ask for manual, human-led testing by name. If you are comparing quotes before a renewal, our plain guide to the difference is worth five minutes.
Penetration test vs vulnerability scanFAQ
Cyber insurance and penetration testing: common questions
- Does cyber insurance require a penetration test?
- Sometimes, and it is trending toward yes. Some carriers ask about penetration testing by name, others price coverage as though you should have one, and higher limits or ransomware coverage make a recent test matter more. It depends on your carrier and policy, so bring the questionnaire to the scoping call.
- Will this satisfy my carrier’s questionnaire?
- It answers the penetration testing question directly, with a dated report and an attestation letter, and it gives your IT provider honest evidence for several of the others, like MFA coverage and backup exposure. We scope the test around what your specific carrier is asking.
- Is a vulnerability scan enough for cyber insurance?
- Often not on its own. Many carriers now ask for manual, human-led testing by name, and a scan is an automated tool pass without a person chaining findings together. If your carrier only asks for a scan, that is worth knowing too, and we will say so rather than sell you more test than you need.
- What do I actually send my insurance carrier?
- Usually the attestation letter or the executive summary, not the full report. The full report is a map of your weaknesses with proof, and it should be treated as sensitive. The attestation proves you were tested, when, and what the outcome was, without publishing the details.
- What if the test finds problems right before my renewal?
- That is normal, and it is the point of doing this before the deadline rather than after. You get a prioritized fix list, your team or IT provider closes the findings, we retest, and the attestation reflects the fixed state. Findings that were found, fixed, and retested generally read well to an underwriter.
- How long does this take, and when should I start?
- Most small and mid-sized engagements run one to two weeks from scoping to report. Add time for your team to make fixes and for the retest, so starting a month or more before the renewal date is comfortable. If the deadline is closer than that, ask anyway; we will tell you honestly what fits.
Get ready before the renewal date, not after
Tell us your renewal date and what the questionnaire is asking, and we will come back with a scope, a timeline that leaves room for fixes, and a fair, fixed quote. No pressure, no sales theater.