After a wave of ransomware claims, cyber insurers have significantly tightened their underwriting policies. Where a questionnaire used to suffice a few years ago, insurers now increasingly ask for concrete evidence that basic security is in order, and a recent pentest report is becoming a hard requirement rather than a nice-to-have.
What insurers now routinely expect
Separate from a pentest specifically, most cyber insurers now look at a fixed set of baseline measures before issuing a policy or setting a premium:
- Multi-factor authentication (MFA) on email, VPN and critical systems.
- Tested backups, preferably offline or immutable, so ransomware can’t encrypt them.
- Endpoint Detection & Response (EDR or MDR) on workstations and servers.
- An incident response plan with a clear escalation path.
- Timely patching and structural security awareness for employees.
If one of these measures is missing at the time of an incident, that can be grounds for an insurer to (partially) deny a payout, even if the policy offered coverage on paper.
Where a pentest fits into this picture
For an insurer, a pentest report is concrete, independent evidence: it shows not just that policy exists on paper, but that the measures taken have actually been tested against a realistic attack scenario. For organisations in a higher risk category — think companies with a lot of personal data, financial data, or a large online presence — more and more insurers explicitly ask for a recent test report as part of the underwriting process or as a condition for higher coverage.
This isn’t limited to taking out a policy. A recent pentest report is also increasingly included as a hard requirement in tenders and contracts with large clients, separate from insurance.
A pentest doesn’t replace the rest
A common misconception is that one pentest report answers all of an insurer’s questions. In practice, a pentest is one piece of a broader picture: it shows how resilient you are against a targeted attack, but says little about whether your backups actually work, whether your staff recognise phishing, or whether your patch policy is applied consistently. Insurers look at the whole picture, and a pentest is most convincing as part of an organisation that can also demonstrably show the other basic measures are in order.
Timing: don’t let your pentest lapse
A two-year-old pentest report says little about the current state of your systems, especially if a lot has changed in the meantime. Insurers who explicitly ask for a test report generally want to see a recent one — in practice usually no older than a year. So don’t schedule your pentest around your policy’s renewal date; make it a fixed, annually recurring part of your security rhythm. See also our explainer on how often you should test.
A scenario that happens more often than you’d hope
An organisation is hit by ransomware and files a claim. During the insurer’s investigation, it turns out MFA had indeed been purchased, but was never fully rolled out to all admin accounts — exactly the accounts the attacker ultimately got in through. The policy covered this scenario on paper, but because a required baseline measure hadn’t actually been implemented everywhere, a dispute arose over the payout. A pentest would likely have exposed this kind of gap beforehand, before it became painfully clear during an actual incident. That’s exactly why insurers increasingly want to see that security measures haven’t just been purchased, but demonstrably work.
How MonkeysICT can help with this
We deliver a report that’s not just technically complete, but also genuinely usable towards an insurer or in a tender: a clear executive summary, concrete findings, and where relevant a mapping to recognised frameworks. Not sure whether your current report is still recent enough for your policy? Feel free to get in touch — that’s quickly checked.
