Cyber insurance is a commercial contract, not a public licence. No UK statute says every organisation must commission a penetration test before buying cover. In practice, brokers and underwriters often ask about independent testing on proposal forms and at renewal, especially as cover limits rise or the sector risk profile hardens.
This article explains the evidence insurers commonly look for, how that sits alongside NCSC guidance and the Insurance Act 2015 duty of fair presentation, and how to commission a test that helps you answer questionnaires honestly. It does not guarantee that any insurer will offer cover, improve terms, or pay a claim.
Key points
- Underwriters often ask about recent independent testing; requirements vary by insurer and limit.
- NCSC guidance frames insurance as support after good baseline controls, not a substitute for them.
- Accurate disclosure matters under the Insurance Act 2015 duty of fair presentation.
- A dated report with clear scope, methodology and remediation status is usually more useful than a marketing certificate.
- Penetration testing does not guarantee cover or claim payment.
What the NCSC actually says
The National Cyber Security Centre's cyber insurance guidance is clear on priorities:
- Put fundamental safeguards in place (Cyber Essentials and Cyber Essentials Plus are cited as examples).
- Insurance will not prevent a breach and is not a shortcut past security work.
- Insurers may ask for information about your controls when you buy or renew.
- Most policies are reassessed around every twelve months; you are expected to keep security details accurate and current.
- Claiming measures are in place when they are not can leave you exposed if you later claim.
The NCSC does not publish a single mandatory "annual pentest for all insured firms" rule. Treat penetration testing as one form of evidence among others, driven by your insurer's questions and your own risk decisions.
What underwriters often ask for
Wording differs between markets. In UK practice, questionnaires and broker requests often probe some combination of the following. None of this is universal.
Controls questions that sit beside testing
- Multi-factor authentication on remote access and privileged accounts
- Patching cadence for internet-facing systems
- Offline or immutable backups and restore testing
- Endpoint detection, email filtering and privileged access management
- Incident response retainers or playbooks
- Certifications such as Cyber Essentials / Plus, or ISO 27001 where relevant
Testing-related evidence that often appears at higher limits or higher risk
- Confirmation that an independent penetration test (or equivalent assessment) was completed within a stated period, commonly within the last twelve months
- Preference for internet-facing or external infrastructure coverage, since exposed remote access is a commonly reported route into organisations
- Interest in whether critical and high findings were addressed, not only whether a PDF exists
- Occasional requests for a summary letter or attestation alongside the full report
- In some placements, expectation that the testing firm meets a named accreditation (company CREST membership is sometimes cited)
If your broker's wording says "CREST penetration test", clarify whether they mean company membership, individual CREST certifications, or simply a recognised quality bar. Attack Vector lead credentials include Cyber Scheme Team Leader (CSTL), from The Cyber Scheme, and Chartered Cyber Security Professional (ChCSP), the UK Cyber Security Council's chartered title.
Fair presentation: accuracy beats optimism
Under the Insurance Act 2015, a business buying insurance must make a fair presentation of the risk to the insurer before the contract is entered into. In plain terms: do not describe your security posture in glowing language that a claim investigation will later contradict.
Examples of fragile answers:
- Saying you run "annual penetration tests" when the only artefact is a three-year-old scan
- Describing all critical findings as "remediated" when they remain open
- Treating a developer unit test or bug bounty triage as equivalent to an agreed pentest scope
Better practice:
- Answer the questionnaire with the scope, date and supplier you actually have
- Attach or offer a summary that matches the report
- If remediation is in progress, say so and give realistic dates
- Update the insurer when material circumstances change, as your policy requires
Which kind of test helps insurance conversations?
| Evidence need | Test type that often aligns | Caveat |
|---|---|---|
| "Have you tested internet-facing systems?" | External infrastructure | Confirm IP completeness |
| "Have applications handling customer data been assessed?" | Web application and/or API | Roles and environments must be stated |
| "Can an insider or phished user reach crown jewels?" | Internal infrastructure | Not every insurer asks this up front |
| "Do you validate fixes?" | Retest of prior highs/criticals | Useful when questionnaires ask about closure |
Start from the exact questions on your proposal form. Do not assume a large red team is required when the underwriter asked about external testing of public IPs.
What a useful evidence pack looks like
When brokers ask for "the pen test", they usually need something an underwriter can skim:
- Cover or summary page: dates, supplier, scope in one paragraph, severity counts
- Full report under NDA if requested: methodology, findings, evidence, remediation guidance
- Remediation tracker: status of critical/high items with owners and dates (your document, not the tester's marketing)
- Retest note if major issues were closed
- Optional attestation letter if the insurer's process wants a one-pager
Attack Vector identifies security weaknesses and reports them so your team can prioritise remediation. We do not claim that commissioning a test obtains cover, improves premiums, or remediates your systems on your behalf.
The attack paths behind claims
Insurance transfers some financial impact. It does not remove attack paths. Underwriters care about paths that drive claims: ransomware via remote access, business email compromise, data exfiltration from misconfigured cloud storage, privilege abuse after phishing.
A penetration test that evidences those surfaces, and a remediation programme that shortens the time high-severity issues stay open, is aligned with both security and underwriting conversations. A test bought only as a tick box, then filed unread, helps neither.
Finance, healthcare, media and technology firms face different claim narratives, but the paperwork pattern is similar: controls questions first, independent testing evidence when risk or limit justifies it.
What testing will not do for your policy
- This article cannot predict any insurer's decision.
- Penetration testing is not legally mandatory for cyber insurance in the UK as a general rule.
- Providing a report does not guarantee cover, renewal, better terms, or claim payment.
- Open critical findings can worry underwriters; hiding them is worse than managing them transparently.
- Company accreditation requirements are placement-specific. Do not assume one badge fits every policy.
- NCSC guidance should be read in full for buying decisions; this post is not a substitute for broker advice.
If renewal is approaching and the questionnaire mentions independent testing, scope the smallest engagement that honestly answers the question, then plan remediation time before the renewal date.
Indicative effort: instant quote calculator. Questions: email [email protected]. Pricing context: UK cost guide. Related services: infrastructure testing and industry-aligned testing. Engagements start from £1,500 for a small, well-defined job.
FAQ
Do we legally need a penetration test to buy cyber insurance?
No general UK legal rule requires it. Insurers set their own underwriting questions. Your duty is to present the risk fairly and accurately.
Will a penetration test lower our premium?
The NCSC notes that some insurers offer discounts for recognised defences such as Cyber Essentials. Any premium effect from testing is possible, not promised.
Is Cyber Essentials enough on its own?
It is valuable baseline evidence and is highlighted by the NCSC. Many higher-limit placements still ask additional questions, which may include independent testing.
How recent should the report be?
Many conversations use a twelve-month window because policies are often reassessed annually. Check your insurer's wording rather than assuming.
Should we send the full report to the insurer?
Follow broker advice. Some accept a summary; some want the full document under controlled sharing. Redact secrets that are unnecessary for underwriting if agreed.
What if we cannot afford a full estate test before renewal?
Scope to the question asked (often external/public systems), document exclusions honestly, and schedule deeper work on a defined plan. Honesty beats an inflated claim of coverage.
Suggested Resources
Ready to strengthen your security?
Talk to our consultants about your penetration testing requirements, or get a fast, transparent quote.