- Usual trigger
- Renewal questionnaire
- Underwriters check
- Accreditation, recency, scope
- Also asked
- MFA, backups, patching
- Free
- Questionnaire review
Why insurers started asking
Cyber claims rose sharply and underwriters responded by pricing on controls rather than on turnover alone. Renewal questionnaires now ask detailed questions about multi-factor authentication, backups, patching timeframes and independent security testing.
That is broadly good news for organisations that have done the work, because it means the controls are worth something commercially rather than just being a cost.
What underwriters look for
- Independent testing rather than self-assessment.
- An accredited provider. CREST accreditation gives an underwriter a recognised standard to assess against, rather than taking a provider's word for the quality of the work.
- Recency, usually within twelve months.
- Evidence findings were addressed. A report with open critical findings can be worse than none — you have documented a known unremediated weakness.
Cyber Essentials frequently appears in the same questionnaire, and some UK insurers include automatic cover for smaller organisations that hold it. If you are answering these questions anyway, it is usually the cheaper thing to get first.
The part that matters at claim time
Be accurate. Insurance operates on the information you provide, and a renewal questionnaire answered optimistically is a problem waiting for the worst possible moment. If you state that you conduct annual penetration testing and a claim investigation finds a single scan from three years ago, that is a materially worse position than having answered honestly in the first place.
The same applies to scope. "We penetration test our systems" while having tested only a marketing website is the kind of statement that gets examined closely after an incident.
We are not insurance advisers and cannot tell you how a specific policy would respond. What we can do is make sure the testing you describe is the testing you actually have.
Check the panel requirement now
Many cyber policies require you to use a provider from the insurer's panel for incident response, and may decline costs incurred elsewhere. That does not usually restrict who does your penetration testing, but it is worth knowing before an incident rather than during one.
On buying the cheapest test to tick the box
Tempting, and the logic is understandable — the test is being bought to answer a question rather than to find problems. But this is precisely the situation where a cheap test creates risk rather than reducing it: you end up describing a level of assurance to your insurer that the underlying work does not support.
If budget is tight, a properly scoped external infrastructure test from an accredited provider is more defensible than a broad, shallow scan. Narrower and real beats wider and nominal.
Common questions
Will penetration testing reduce our premium?
It can contribute, alongside multi-factor authentication, tested backups and patching discipline. Insurers weight controls differently and we cannot predict a specific outcome. What we can say is that the questions are being asked, and being able to answer them accurately is worth having.
Our insurer asks for testing 'by a reputable provider'. What does that mean?
Deliberately vague. CREST accreditation is the safest interpretation because it is a recognised, independently verifiable standard. If the wording matters commercially, ask your broker to confirm what the underwriter will accept.
Should we get Cyber Essentials first?
Usually, yes. It is cheaper, it addresses the controls that stop the attacks that actually happen, it answers a large portion of the questionnaire, and some UK insurers include automatic cover for smaller organisations that hold it.
What if our report has open findings at renewal?
Better to have addressed them, which is why retesting is included as standard with us. If you are mid-remediation, a documented plan with dates is a considerably better answer than either an open finding or silence.
Can you tell us how our policy would respond to a claim?
No. We are not insurance advisers and would be doing you a disservice by guessing. Your broker can. What we can do is ensure the testing you describe to them is accurate.
Related
Solusec
Typically replies within one business day
Hi 👋 Need a hand with pen testing, Cyber Essentials, or something urgent? Pick whichever suits you:
💬 WhatsApp usQuick questions, quick answers 📞 Call us
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day