Back to Blog

If you've renewed a cyber insurance policy in the last year, you've probably noticed something: the applications are longer, the questions are more specific, and the requirements are stricter. Carriers are no longer satisfied with a checkbox that says "yes, we have security." They want proof. And increasingly, that proof means a penetration test.

This shift has caught a lot of businesses off guard. Here's what's happening, why it matters, and how to navigate it.

Why Carriers Are Getting Stricter

The math is simple. Cyber insurance claims have skyrocketed over the past several years. Ransomware attacks, business email compromise, data breaches, and wire fraud have cost carriers billions. In response, the insurance industry has done what it always does when losses spike: tighten underwriting standards.

Five years ago, a cyber insurance application might have asked whether you use antivirus and have a firewall. Today, carriers are asking about multi-factor authentication on every account, endpoint detection and response tools, network segmentation, incident response plans, and third-party penetration testing. They've learned that companies without these controls are dramatically more likely to file claims, and they're pricing their policies accordingly.

28%
of cyber claims denied for inadequate security controls
~15%
average premium reduction with a clean pentest report
3x
increase in carrier pentest requirements since 2023

The Denial Problem

Here's the number that should get your attention: roughly 28% of cyber insurance claims are being denied. That's more than one in four. The most common reason? The policyholder's actual security posture didn't match what they represented on their application.

When you fill out a cyber insurance application, you're making representations about your security. If you check the box that says you have multi-factor authentication on all remote access, but your VPN still allows password-only logins, that's a material misrepresentation. If an attacker uses that exact gap to break in, your carrier has grounds to deny the claim.

A penetration test protects you in two ways. First, it identifies these gaps before an attacker finds them, giving you time to fix them. Second, it creates a documented record that you took reasonable steps to test and improve your security, which is exactly what carriers want to see.

What Carriers Want to See in a Pentest Report

Not all penetration test reports are created equal in the eyes of an insurance carrier. Underwriters are getting more sophisticated about what they review, and a generic vulnerability scan report won't cut it. Here's what they're looking for:

Scope and methodology

Carriers want to see that the test covered your actual environment, not just a subset. They want to know what was tested (internal network, external perimeter, web applications, cloud infrastructure) and how the testing was conducted. A clearly documented methodology signals professionalism and thoroughness.

CVE mapping and severity ratings

Findings should be mapped to specific CVE identifiers where applicable and rated using a recognized severity framework like CVSS. This gives underwriters a standardized way to assess your risk level. A report that says "we found some issues" isn't useful. A report that says "CVE-2024-21762, CVSS 9.8, exploitable from the internet" tells the carrier exactly what they need to know.

Evidence of exploitation

This is what separates a real pentest report from a repackaged vulnerability scan. Carriers want to see that vulnerabilities were actually tested, not just identified by automated tools. Screenshots, command output, and narrative descriptions of attack chains demonstrate that a human professional tested your defenses.

Remediation recommendations

Carriers don't just want to see what's wrong. They want to see that you have a path to fix it. Clear, prioritized remediation steps show that the findings are actionable and that your organization knows what to do next.

Remediation evidence (for renewals)

If this isn't your first pentest, carriers increasingly want to see what you fixed since the last one. A retest that shows previously identified vulnerabilities have been resolved is powerful evidence that your security program is mature and improving.

How a Pentest Helps You Get Better Coverage

The relationship between penetration testing and insurance goes beyond just meeting a requirement. A well-executed pentest can actively improve your insurance position in several ways:

Lower premiums

Companies that can demonstrate regular third-party security testing typically see premium reductions of around 15%. Some carriers offer even steeper discounts when the pentest is combined with other security controls like endpoint detection and response, security awareness training, and a documented incident response plan. Over the course of a policy term, these savings can offset a significant portion of the pentest cost.

Broader coverage

Some carriers restrict coverage for companies that can't demonstrate adequate security testing. You might get a policy, but with exclusions for certain types of incidents or lower coverage limits. A clean pentest report (or one that shows you've remediated the findings) can unlock broader coverage terms.

Smoother claims process

If you do experience an incident, having a recent pentest report on file demonstrates that you were proactive about security. This makes it much harder for a carrier to argue that you were negligent or that you misrepresented your security posture on the application. It won't guarantee a claim gets paid, but it removes one of the most common grounds for denial.

Stronger negotiating position

When you approach carriers or brokers with a recent pentest report in hand, you're not just another applicant. You're a demonstrably lower-risk policyholder. This gives your broker more leverage to negotiate better terms, lower deductibles, and more favorable pricing.

Timing Your Pentest Around Your Policy

The most effective approach is to schedule your penetration test two to three months before your policy renewal. This gives you enough time to receive the report, remediate any critical findings, and present the results (along with evidence of remediation) to your carrier or broker during the renewal process.

If you're applying for cyber insurance for the first time, having a recent pentest report ready when you submit your application can make a meaningful difference in the quotes you receive. Some brokers will tell you it's not necessary for a first application. That may have been true a few years ago. In 2026, it gives you a competitive advantage.

What Happens If You Don't Test

You can still get cyber insurance without a penetration test. Not every carrier requires one yet. But you'll likely face:

The trend is clear: what's optional today will be mandatory tomorrow. Companies that get ahead of this curve are rewarded with better coverage at lower prices.

Penetration Testing for Insurance Agencies and Brokerages

Everything above is written for the business buying a policy. But insurance agencies and brokerages sit on the other side of the desk with a problem of their own: they hold enormous volumes of client PII — SSNs, dates of birth, medical histories, financial records, and full property inventories — on behalf of hundreds or thousands of insureds. That makes an agency a high-value target that is usually defended like a small office.

Agencies are also increasingly regulated on this point. Most states have now adopted a version of the NAIC Insurance Data Security Model Law, which requires licensees to maintain a written information security program based on a documented risk assessment, and in many adopting states to perform penetration testing and vulnerability assessments as part of it — typically with an exemption for the smallest agencies. Agencies licensed in New York fall under NYDFS Part 500, which is more explicit still: annual penetration testing and twice-yearly vulnerability assessments unless the licensee qualifies for a limited exemption. Ohio agencies operate under the Ohio Insurance Data Security Act. Because thresholds, exemptions and testing language vary by state, confirm your specific obligations with your compliance counsel — but the direction of travel is the same everywhere.

There is a practical asymmetry worth naming: agencies spend their working lives telling clients to take security seriously as a condition of coverage. Being the agency that suffered a breach because nobody tested its own network is a uniquely difficult conversation to have with a book of business.

What an agency-focused pentest actually scopes

The deliverable is the same report format described above, which means one test satisfies two purposes at once: your own regulatory obligation as a licensee, and the evidence your own E&O and cyber carriers want to see at renewal.

Insurance and Penetration Testing FAQ

Do insurance agencies need penetration testing?

In most states, yes — at least in effect. The majority of states have adopted a form of the NAIC Insurance Data Security Model Law, which requires licensees to run an information security program grounded in a documented risk assessment, and many adopting states name penetration testing and vulnerability assessment as part of that program. Agencies licensed in New York are covered by NYDFS Part 500, which requires annual penetration testing outright unless a limited exemption applies. Smallest-agency exemptions exist in most states, so confirm your specific threshold with compliance counsel.

What is the difference between a pentest for cyber insurance and a pentest for compliance?

The testing work is largely the same; the reporting emphasis differs. A carrier-facing test needs to demonstrate that findings were identified, rated, and remediated, because the carrier is underwriting your risk going forward. A compliance-facing test needs to demonstrate that testing happened on the required cadence, with scope and methodology documented well enough to withstand a regulator's review. A well-built report serves both, which is why we structure every report to cover scope, methodology, severity, evidence, and remediation status in one document.

How often should an insurance brokerage get a penetration test?

Annually is the working standard, and it is the explicit requirement under NYDFS Part 500. Test again ahead of schedule after any material change — an acquisition or book roll-in, an AMS migration, a move to a new office or cloud environment, or a significant shift to remote producers. Agencies growing by acquisition should treat each acquired network as untested until it has been tested, because inherited infrastructure is where the surprises tend to be.

What does a penetration test cost for an insurance agency?

Cost tracks the size of the environment rather than the industry: the number of live hosts, locations, and externally reachable systems in scope. A single-office agency with a straightforward network sits at the lower end of the range; a multi-location brokerage with several acquired networks and heavy remote access sits higher. We scope from an asset inventory and quote a fixed fee before any testing begins, so the number is known up front.

RevealSec Reports Are Built for This

We designed our reporting format specifically to meet the requirements of cyber insurance carriers. Every RevealSec penetration test report includes:

Our reports have been accepted by every major cyber insurance carrier. We've worked with brokers and underwriters to understand exactly what they need to see, and we build that into every engagement from the start. Want to see the difference between a real pentest report and a repackaged scan? Read our breakdown of penetration tests vs vulnerability scans.

Get a Pentest Report Your Carrier Will Accept

Schedule a free consultation. We'll discuss your insurance timeline, scope your environment, and make sure your report is ready when your carrier needs it.

Book a Free Consultation