A financial services data breach now costs US$6.3 million on average, the second-costliest of the seventeen industries studied and 26% above the US$4.99 million global average, according to the IBM Cost of a Data Breach Report 2026. Insurance sits inside that number, and it sits there holding an unusually rich data set: health histories, driving records, property schedules, beneficiary relationships, bank details for premium collection and claims payout, and in commercial lines, the security posture of every insured business the carrier underwrote.
Where Stingrai fits: For the test itself, Stingrai is a CREST-accredited penetration testing service provider headquartered in Toronto with a London office, founded in 2021. For an insurer that means authenticated testing across every user role of the policyholder, agent and broker portals and the quoting, binding and claims APIs, the AWS, Azure and Entra ID tenants holding policy and claims data, the internal network and Active Directory estate, and phishing against underwriting and claims staff. Two named penetration testers run each engagement, confirmed findings land in the PTaaS portal with a working proof of concept as they are found, and retesting plus an attestation letter are included, one-time or continuous. Published pricing starts at US$3,000 per assessment for one web application and its APIs (pricing) and every other scope is quoted.
What that test has to satisfy is unusually fragmented in insurance, and vendor marketing tends to flatten it. There is no single national insurance cybersecurity rule in the United States. There is a model law that twenty-eight jurisdictions have implemented, a New York regulation that is stricter and narrower, a Canadian supervisory guideline that sets expectations without numbers, and a set of adjacent regimes that bite depending on how you take premium and who you sell to. The ranking below is built around those realities, and every vendor entry links to the page on the vendor's own site that supports the claim, last verified on 19 September 2026.
Quick answer: who are the best insurance penetration testing companies in 2026?
The best insurance penetration testing companies in 2026 are Stingrai, Cobalt, NetSPI, Coalfire, Schellman, Praetorian, TrustedSec, GuidePoint Security, Bishop Fox, HackerOne, Packetlabs and Software Secured. Stingrai is a CREST-accredited penetration testing service provider whose two-tester teams hold OSCE³, OSWE, OSEP, CREST CRT and CISSP, have published 18 CVEs, and are listed in the bug bounty Halls of Fame of Apple, Google, the US Department of Defense and the US Federal Reserve. For carriers, MGAs, brokers and insurtech it tests the policyholder and agent portals and the quoting, binding and claims APIs with authenticated access across every role, the cloud tenant and Entra ID, the internal network and Active Directory, and phishing against underwriting and claims staff, delivered one-time or continuously through its PTaaS portal with named testers, retesting and an attestation letter included and pricing published rather than gated. Cobalt, NetSPI and Coalfire follow for a published insurance practice, a named carrier partnership, and assessor-led programme depth respectively.

What insurance buyers are actually required to test
Five regimes come up in insurance procurement. Each says something different, and two of them say almost nothing that a vendor can honestly turn into a quota.
Does the NAIC Insurance Data Security Model Law require penetration testing?
No. The phrase does not appear in the model. The NAIC Insurance Data Security Model Law (#668) was adopted in October 2017 and applies to insurers, insurance agents and other entities licensed by a state department of insurance. Its Section 4 requires a licensee to develop, implement and maintain a written information security program based on its own risk assessment, and then to "determine which of the following security measures are appropriate and implement each appropriate security measure."
Item eight on that list is the one that matters. Read from a state enactment, Iowa Code 507F.4, it requires the licensee to:
Regularly test and monitor systems and procedures to detect actual and attempted attacks on, or intrusions into, information systems.
That is an outcome, not a method. No cadence, no scope, no independence requirement, no named technique. An insurer that buys a penetration test is choosing the most defensible way to satisfy item eight, not complying with a clause that demanded one. Two exemptions matter commercially: licensees with fewer than ten employees are exempt from Section 4, and so are licensees already compliant with HIPAA.
Adoption is broader than most vendors claim, and narrower than the headline. The NAIC's own August 2025 legislative brief records 28 jurisdictions as having implemented the model: Alabama, Alaska, Connecticut, Delaware, Hawaii, Illinois, Indiana, Iowa, Kentucky, Louisiana, Maine, Maryland, Michigan, Minnesota, Mississippi, Missouri, New Hampshire, North Dakota, Ohio, Oklahoma, Pennsylvania, Puerto Rico, Rhode Island, South Carolina, Tennessee, Vermont, Virginia and Wisconsin. The NAIC's Summer 2026 state page for model #668 lists the same twenty-eight jurisdictions in its Model Adoption column, with Tennessee flagged as having adopted portions of the model. New York appears only under Related Activity, cited to 23 NYCRR 500. That single line is the most useful fact in the document: New York is not a model-law state, it is a regulation state, and its regulation is stricter.
Does NYDFS 23 NYCRR 500 require an annual penetration test?
Yes, and it is one of very few financial services rules anywhere that names the activity, the frequency and the scope in a single sentence. Section 500.5(a)(1) of 23 NYCRR Part 500, as amended by the second amendment adopted 1 November 2023, requires each covered entity to conduct:
penetration testing of their information systems from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually.
Three phrases carry the weight. "Their information systems" means the estate rather than a sampled subset. "From both inside and outside" makes an external-only test insufficient on its own. "Qualified internal or external party" means there is no third-party mandate in Part 500, provided the internal team is qualified.
Insurers are squarely in scope. Section 500.1(e) defines a covered entity by licence, including any person operating under an authorization under the Insurance Law, which sweeps in carriers, producers, agencies and brokers licensed in New York regardless of where they are headquartered. A regional Midwestern carrier writing New York business carries the same annual obligation as a Manhattan bank. Section 500.5(a)(2), a separate obligation often confused with the annual test, requires automated scans plus a manual review of systems the scans cannot reach, at a risk-assessment-driven frequency and promptly after any material system change. The annual testing requirement has been enforceable since 29 April 2024 and the scan obligation since 1 May 2025. A fuller clause-by-clause treatment is in the NYDFS penetration testing requirements guide.
The evidence layer is where mid-market insurers usually fail rather than the test. Section 500.17(b)(3) requires five years of records supporting the annual certification, including areas requiring material improvement, the remedial efforts undertaken, and remediation plans and timelines. A report with no retest and no remediation record does not satisfy that.
What does OSFI B-13 require of Canadian insurers?
Expectations, not numbers. OSFI Guideline B-13, Technology and Cyber Risk Management, applies to all federally regulated financial institutions, explicitly including life insurance and fraternal companies, property and casualty companies, and foreign insurance company branches. It became effective 1 January 2024. Section 3.1.2 names penetration testing exactly once, saying FRFIs "should set defined triggers, and minimum frequencies, for intelligence-led threat assessments" and "should also regularly perform tests and exercises, to identify vulnerabilities or control gaps in its cyber security programs (e.g., penetration testing and red teaming) using an intelligence-led approach."
The institution sets the frequency. OSFI expects that a frequency exists, is defined, and is defensible. The widely repeated claim that OSFI requires a penetration test every three years is a misattribution: three years is the cadence in OSFI's Intelligence-led Cyber Resilience Testing framework, an Advisory whose own foreword states it "is not a policy instrument used to set regulatory expectations" and whose scope applies to systemically important banks and internationally active insurance groups. Most Canadian insurers are neither. The OSFI B-13 penetration testing guide sets out where that figure actually comes from and what a defensible cadence looks like instead.
Provincially regulated insurers, and the MGAs and brokers serving them, are not directly bound by B-13, but usually inherit it contractually the moment a federally regulated carrier puts them in a critical third-party arrangement under Guideline B-10.
Does the GLBA Safeguards Rule apply to insurers?
Usually not directly, and this is the most frequently botched claim in insurance security marketing. The FTC Safeguards Rule at 16 CFR 314.4(d) requires that monitoring and testing "shall include continuous monitoring or periodic penetration testing and vulnerability assessments," and where an institution lacks effective continuous monitoring, it must run annual penetration testing based on identified risks plus vulnerability assessments at least every six months and after material changes. That is an explicit annual clock.
But 15 USC 6805(a)(6) assigns enforcement of the GLBA safeguards standards, "in the case of any person engaged in providing insurance," to "the applicable State insurance authority of the State in which the person is domiciled." A licensed carrier or producer answers to its state insurance regulator, which is exactly why the NAIC wrote a model law. The Safeguards Rule still binds the rest of the ecosystem: insurtech platforms, premium finance companies, quoting marketplaces and claims payment processors that are not licensed insurance entities can fall inside the FTC's definition of a financial institution and inherit the annual test outright.
Where SOC 2 and PCI DSS come in
For an insurtech platform or an MGA technology vendor, the binding document is almost never a regulation. It is the carrier's diligence questionnaire, and it asks for SOC 2. SOC 2 sets no cadence of its own, but auditors routinely expect recent penetration test evidence under the Common Criteria. A ranked view from that angle is in the best penetration testing companies for SOC 2 guide.
PCI DSS applies wherever premiums are paid by card, which for personal lines and small commercial is most of the book. Requirement 11.4 is prescriptive: 11.4.1 methodology, 11.4.2 internal testing, 11.4.3 external testing, 11.4.4 remediation and retest, and 11.4.5 and 11.4.6 segmentation testing. Internal and external tests are required at least once every twelve months and after any significant change, and all v4.x future-dated requirements became mandatory on 31 March 2025. Detail is in the PCI DSS penetration testing guide.
Regime | Is penetration testing required? | Named cadence | What the evidence has to look like |
|---|---|---|---|
NAIC Insurance Data Security Model Law (#668) | Not by name. The operative duty is to regularly test and monitor systems to detect actual and attempted attacks | None published | A risk assessment that justifies the chosen method, plus evidence the testing actually happened |
NYDFS 23 NYCRR 500.5(a)(1) | Yes, expressly | At least annually | Testing from inside and outside the boundaries by a qualified party, with five years of supporting records under 500.17(b)(3) |
OSFI Guideline B-13 (Canada) | Yes, as an expectation. Section 3.1.2 names it | Defined by the institution | A documented cadence, intelligence-led scenario design, and remediation evidence a supervisor can follow |
GLBA Safeguards Rule, 16 CFR 314.4(d) | Yes, for FTC-jurisdiction financial institutions. Licensed insurance entities answer to their state insurance authority instead | Annual, where continuous monitoring is absent | Annual penetration testing based on identified risks, plus vulnerability assessments every six months |
PCI DSS 4.0.1 Requirement 11.4 | Yes, wherever premiums are card-paid | At least every twelve months and after significant change | A documented methodology, internal and external testing, segmentation testing and retest evidence |
How we ranked them
Twelve vendors were scored against six insurance-specific criteria. Every claim below traces to a page the vendor publishes itself, read on 19 September 2026.
Published insurance or financial services practice. A page on the vendor's own site describing insurance, financial services or the regimes above. Firms that merely display a carrier logo were scored down.
Authorization and business logic depth. Policyholder isolation, agent and broker hierarchy separation, and object-level authorization on policy, claim and quote identifiers. In a carrier's estate these are the classes that leak one policyholder's file onto another's screen.
Regulatory evidence quality. Whether the report is shaped like something a state examiner, a DFS examiner or an OSFI supervisor will accept, including scope, methodology, tester identity and retest.
Retest and remediation record. Whether a retest is included rather than sold separately, because the retest is the artefact 500.17(b)(3) and an OSFI supervisory conversation actually consume.
Named testers and continuity. Whether the buyer learns who tested their environment, which matters when an examiner asks about tester qualification.
Delivery model fit. Whether the vendor supports both a one-time annual test and a continuous programme, and whether findings reach engineers through their tracker rather than a static PDF.
Vendors whose primary product is vulnerability management, attack surface discovery or compliance attestation without offensive testing were not ranked as insurance penetration testing providers, even where they are strong in their own category.
Quick comparison: best insurance penetration testing companies
Company | HQ | Delivery model | Named testers | Retest included | Client portal | Pricing published | Best for |
|---|---|---|---|---|---|---|---|
1. Stingrai | Toronto, Canada | One-time and continuous PTaaS | Yes | Yes | Yes | Yes | Carriers, MGAs, brokers and insurtech wanting CREST-accredited testers on the portals, quoting and claims APIs, cloud, Active Directory and staff phishing in one engagement |
2. Cobalt | San Francisco, USA | Continuous PTaaS | Core model | Yes | Yes | Partial | Insurers who want a published insurance practice and continuous evidence between audits |
3. NetSPI | Minneapolis, USA | Platform-delivered programme | Programme-level | Yes | Yes | No | Large carriers running an enterprise testing programme |
4. Coalfire | Westminster, USA | Consultancy with assessment practice | Programme-level | Negotiated | Partial | No | Insurers whose testing budget sits inside a PCI or assessment relationship |
5. Schellman | Tampa, USA | Consultancy alongside attestation | Programme-level | Negotiated | Partial | No | Insurtech carrying SOC 2 and PCI who want both under one contract |
6. Praetorian | Austin, USA | Continuous offensive security | Engineer-level | Yes | Yes | No | Carriers whose first problem is not knowing their full internet-facing estate |
7. TrustedSec | Fairlawn, USA | Consultancy, manual-led | Yes | Validation testing | No | No | Buyers who want deep manual testing and will supply the insurance context |
8. GuidePoint Security | Reston, USA | Consultancy inside a wider security practice | Programme-level | Negotiated | Partial | No | Insurers buying testing alongside tooling and managed services |
9. Bishop Fox | Tempe, USA | Continuous offensive security | Operator-level | Yes | Yes | No | Carriers running threat-led red team exercises against a mature estate |
10. HackerOne | San Francisco, USA | Researcher community plus PTaaS | Researcher handles | Programme-dependent | Yes | No | Insurers adding crowd coverage on top of a scoped annual test |
11. Packetlabs | Toronto, Canada | Consultancy, manual-led | Yes | Yes | Partial | No | Canadian insurers and brokers wanting a domestic manual-led test |
12. Software Secured | Canada | Continuous PTaaS | Yes | Yes | Yes | Partial | Insurtech platforms whose driver is a SOC 2 or ISO 27001 audit |
1. Stingrai (top rated for insurance)
Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.
Every human-led engagement is run by two named penetration testers and reviewed by the team lead. The team has published 18 CVEs and includes a founding member of Uber's offensive security team and researchers in the bug bounty Halls of Fame of Apple, Google, the US Department of Defense and the US Federal Reserve. Find and fix weaknesses before they become incidents. Explore the PTaaS platform.
For an insurer, that testing is authenticated and role-aware rather than a scan with a logo on it. The testers hold policyholder, agent, broker and adjuster sessions side by side and push each one at the boundary: whether a policy number in a request is actually checked against the session, whether a rating call can be replayed with a recalculated premium on the way to bind, whether a claims document is addressable by anyone who can guess its identifier. Each finding is chained into the full attack path, documented with a working proof of concept, and posted to the PTaaS portal as it is confirmed, so remediation starts before the report and the included retest closes it out.
The same team covers the rest of the estate, which matters when the annual certification and the release cadence pull in opposite directions: the AWS, Azure and Entra ID tenants holding policy and claims data, the internal network and Active Directory paths an attacker would use after a phish, and the phishing campaign itself against underwriting and claims staff. Stingrai runs this as a one-time annual engagement or as a continuous programme that tests every release.
Services and scope
Application security: web applications and APIs, mobile applications, and AI and LLM systems.
Network and cloud security: internal and external networks, Active Directory, Wi-Fi, and cloud environments.
Social engineering: phishing campaigns and physical security assessments.
Adversary simulation: red teaming and purple teaming.
For insurance buyers, scope typically covers the policyholder and agent portals, quoting and binding APIs, the claims platform, the cloud environment holding policy and claims data, the internal network and Active Directory estate, and phishing against underwriting and claims staff. That combination is what satisfies the "both inside and outside the boundaries" language in NYDFS 500.5(a)(1) in a single engagement.
Delivery and evidence
Findings reach the portal as they are confirmed, each with a proof of concept and prioritized remediation guidance, and clients chat live with their assigned penetration testers during the test, with findings pushed into Jira or Slack. Reports are redactable for sharing with reinsurers and enterprise clients, retesting of remediated findings is included, and an attestation letter and verified badge are issued with every report, which is the record an examiner asks for when the certification comes due. CREST accreditation applies to Stingrai Inc. as a penetration testing service provider; it is separate from the individual CREST CRT certifications the testers hold, and the distinction is worth making in a diligence questionnaire.
Stingrai's penetration testing supports your NAIC-aligned information security program, NYDFS Part 500, OSFI B-13, SOC 2, ISO 27001 and PCI DSS 4.0 programmes by producing the scope statement, technical report, remediation record and retest evidence those programmes consume.
Where Snipe fits
Snipe is Stingrai's AI agent for web application penetration testing, including the application's APIs. It is custom-trained on thousands of disclosure reports and on skills distilled from Stingrai's own penetration testers' methodology, and it hunts the complex classes that generic scanners miss: IDOR, broken authorization and business logic flaws, which in an insurance context means quote manipulation, premium recalculation abuse and cross-policyholder record access. Senior penetration testers work concurrently with Snipe throughout the engagement, directing its focus and extending the attack paths it surfaces. Snipe also performs white-box source review and can open AutoFix pull requests or run as a PR-gating check. Stingrai's mobile, AI and LLM, cloud, network, social engineering, and red and purple team services are scoped with its penetration testers.
Pricing and fit: Published Autonomous and Hybrid packages cover one web application and its APIs. Request a scoped quote for a carrier estate or a multi-application platform. Stingrai suits insurers that want CREST-accredited offensive security across their attack surface, delivered one-time or continuously, with the tester names and retest record an examiner will ask about.
2. Cobalt
Cobalt publishes a dedicated insurance solutions page, which is rare: most testing vendors stop at a generic financial services page. It names the NAIC model law directly and frames the shift it creates, arguing the question is moving from "did you test?" to whether the licensee can show documented, continuous proof of security controls over time. The published scope covers continuous pentesting, web application and API assessments, external and internal network testing, and AI and LLM testing of underwriting and fraud detection models, which is a genuinely insurance-specific line item. The page also cites SOC 2 and ISO 27001 as the compliance drivers its evidence feeds, and describes the delivery model as human-led, AI-powered testing rather than an annual snapshot.
Pros
The only vendor reviewed here with a published insurance page that engages with the actual regulatory instrument rather than gesturing at compliance.
Continuous delivery with a mature portal, which produces the between-audit evidence trail a state examiner or a carrier's diligence team can follow.
Explicit AI and LLM testing for underwriting and fraud models, relevant now that pricing and claims triage models are in production.
Cons
Testing is delivered through a vetted researcher community rather than a fixed named bench, so continuity across a multi-year programme is worth pinning down in the statement of work.
Platform-led pricing suits programme budgets better than a single scoped annual test.
Best for: insurers and insurtech platforms that want a published insurance practice and continuous evidence between audits.
3. NetSPI
NetSPI, headquartered in Minneapolis, is the only vendor here with a publicly named carrier relationship on its own site: a customer story describing how Chubb partners with NetSPI to bring attack surface management to its policyholders. Its financial services material covers penetration testing, cloud security assessments and red team operations. That is a different signal from a logo wall, because it means the firm has been through a carrier's own third-party diligence.
Pros: a named carrier partnership on the vendor's own site, the strongest available proxy for having survived insurance-sector vendor review, plus breadth across application, cloud, network and red team work, which suits an estate spanning a modern portal and a much older policy administration system.
Cons: enterprise programme delivery and pricing suit large carriers better than an MGA or regional broker, and the insurance framing sits in customer stories rather than a standing service page.
Best for: large carriers running an enterprise testing programme across a broad and partly legacy estate.
4. Coalfire
Coalfire, headquartered in Westminster, Colorado and founded in 2001, publishes a financial services industry practice organised into advisory, assessment and security lines, with PCI DSS named among the frameworks it supports. Its centre of gravity is assessment-led, and much of its testing work sits inside a larger compliance engagement. For an insurer whose premium flow puts it in PCI scope, that combination is efficient.
Pros: one firm for testing and PCI assessment work, which removes a handoff when Requirement 11.4 evidence has to satisfy the same assessor reading the report, with broad coverage across cloud, application and network testing for multi-entity groups.
Cons: the published financial services page does not name insurance, so insurance-specific workflows come from your scoping brief. Assessment-led procurement can also mean the test is scoped to the framework rather than the application's real attack surface, so ask for the methodology in writing.
Best for: insurers whose testing budget already sits inside a PCI or broader assessment relationship.
5. Schellman
Schellman, headquartered in Tampa, Florida, publishes a penetration testing portfolio spanning nine services: application, network, mobile, social engineering, cloud, physical, hardware and IoT, advanced services including red and purple teaming, and AI red teaming. The site names financial services and fintech among industries served and runs a separate payment card practice. For an insurtech carrying SOC 2 and PCI simultaneously, the attraction is contractual simplicity.
Pros: nine published testing lines, covering almost any scope an insurer or insurtech will put in a single statement of work, and AI red teaming as a published line, relevant as carriers put generative systems in front of claims and policy data.
Cons: insurance is not named at the service level, so specificity comes from the engagement rather than the published practice. Attestation-first firm, so verify which team performs the test and how independence is documented if both engagements run together.
Best for: insurtech platforms carrying SOC 2 and PCI DSS that want testing and attestation under one contract.
6. Praetorian
Praetorian, founded in 2010 in Austin, Texas, publishes an offensive security practice spanning application, cloud, network, AI and LLM, IoT and hardware testing, naming GLBA, HIPAA and PCI DSS among the frameworks its work supports. Its framing is discovery-first: attack surface management sits ahead of the test itself, on the honest premise that a large organisation does not know its full internet-facing estate. For a carrier that grew by acquisition, which describes a great many of them, that is the right starting point.
Pros: discovery-first suits acquisitive carriers carrying unmapped subsidiary domains, legacy quoting sites and dormant agent portals, and the published zero-false-positive commitment means every finding is verified by an engineer before it reaches the report.
Cons: no published insurance or financial services industry page, so the sector context is yours to supply. Attack surface management is the lead product, so confirm the manual testing depth if you want a deep single-application authorization test.
Best for: carriers and groups whose first problem is discovering internet-facing assets nobody has inventoried.
7. TrustedSec
TrustedSec, headquartered in Fairlawn, Ohio, runs a manual penetration testing practice built around discovery and scoping, reconnaissance, vulnerability identification, exploitation, reporting and validation testing to confirm fixes. It names finance among industries served and PCI DSS, HIPAA and SOC 2 among the compliance requirements the work supports. The framing is honest: the test supports those frameworks rather than claiming they mandate it, which is the same distinction the NAIC model law forces on an insurance buyer.
Pros: strong manual and adversarial reputation, with validation testing built into the methodology, which is the retest an examiner looks for, plus named testers rather than a rotating bench.
Cons: no dedicated insurance or financial services page, so policy, claims and agent-hierarchy context comes from your scoping brief, and consultancy delivery means tracker integration has to be specified in the statement of work.
Best for: insurers who want deep manual testing and are comfortable supplying the sector context themselves.
8. GuidePoint Security
GuidePoint Security, headquartered in Reston, Virginia, publishes a penetration testing practice positioned around understanding vulnerabilities, threats and gaps and prioritising security investments. It sits inside a much larger security services and technology-advisory business, which is why it appears here: many mid-market insurers already buy tooling and managed services from a single integrator, and adding testing to that relationship is a procurement decision more than a technical one.
Pros: testing sits alongside tooling selection and managed services, so findings land with a team that will help operate the remediation, and one vendor relationship can span assessment, architecture and operations.
Cons: no published insurance or financial services vertical, and the integrator-led model means the offensive bench is one line among many. Ask for named tester credentials and a sample redacted report.
Best for: insurers buying penetration testing alongside tooling and managed services from a single integrator.
9. Bishop Fox
Bishop Fox, headquartered in Tempe, Arizona, publishes the most regulation-dense financial industry page in this ranking. It states plainly that financial institutions such as banks, investment firms and insurers are prime targets, and names FFIEC, OCC Bulletin 2023-26, PCI DSS, GLBA, the NYDFS Cybersecurity Regulation, DORA, TIBER-EU, ISO/IEC 27001, SOX IT controls and the NIST Cybersecurity Framework. Published services span red teaming and threat simulation, application, cloud and network penetration testing, social engineering, continuous threat exposure management and third-party security testing.
Pros: insurers, NYDFS and GLBA are all named explicitly, which is unusually specific for a vendor page, and the red team and threat-simulation depth suits carriers with a mature control stack that needs adversarial pressure rather than another vulnerability list.
Cons: that depth is priced accordingly, which overshoots a regional broker or single-product MGA, and the published practice is financial services generally, so claims and policy administration context still comes from your side.
Best for: carriers running threat-led red team exercises against an already mature estate.
10. HackerOne
HackerOne publishes a financial services page with a distinct insurance section, framed around avoiding the breaches that generate litigation, reputational damage and churn. Its offering spans a bug bounty platform, vulnerability disclosure programmes, continuous testing and code security audits, delivered through a large external researcher community rather than a fixed bench.
Pros: crowd scale surfaces unusual attack paths across a broad internet-facing estate, and vulnerability disclosure support is useful for a carrier whose brand attracts unsolicited reports.
Cons: community-delivered testing makes tester identity and qualification harder to evidence, which is the exact question a DFS examiner asks under 500.5(a)(1), and coverage is incentive-driven rather than scope-driven, so a bounty programme alone does not show the whole estate was tested from inside and outside the boundaries.
Best for: insurers adding crowd coverage on top of a scoped annual penetration test, not instead of one.
11. Packetlabs
Packetlabs is headquartered at 401 Bay Street in Toronto, with offices in San Francisco, Calgary and Sydney, and publishes dedicated industry pages including Finance. Its service set covers web applications, APIs, mobile, AI and LLM and thick clients, infrastructure and cloud testing, IoT and attack surface testing, and adversary simulation. For a Canadian insurer or brokerage wanting domestic delivery and a manual-led methodology, it is a credible shortlist entry.
Pros: Canadian headquarters and delivery simplifies data residency conversations for provincially regulated insurers and brokers, and Finance is a published vertical with a manual-led methodology.
Cons: insurance is not among the published industry pages, so carrier-specific workflows come from your brief, and consultancy delivery means between-audit coverage needs a separate arrangement.
Best for: Canadian insurers and brokerages wanting a domestic, manual-led annual test.
12. Software Secured
Software Secured is a Canadian firm delivering penetration testing as a service, described on its own site as ongoing manual penetration tests aligned to release cycles. Its published services cover web, mobile, API, network, cloud, AI, IoT and hardware testing alongside secure code review, threat modelling and red teaming, and it names SOC 2, HIPAA, ISO 27001, PCI DSS and GDPR as the audits it supports, with finance and fintech among its published verticals.
Pros: release-aligned continuous testing suits an insurtech platform shipping weekly, where an annual snapshot goes stale within a sprint, with explicit audit-support framing across SOC 2, ISO 27001 and PCI DSS.
Cons: insurance is not a published vertical and the practice is oriented to software companies rather than carriers, with a smaller bench than the enterprise firms here.
Best for: insurtech platforms and MGA technology vendors whose driver is a SOC 2 or ISO 27001 audit.
What an insurance penetration test should actually cover
The scope that matters is not the network perimeter. It is the authorization boundary between policyholders, and the money path that runs through quoting, binding, premium and claims.
Object-level authorization on every record-scoped endpoint. Policy, claim, quote, document and party identifiers are the parameters that leak files when the server trusts them. The OWASP API Security Project ranks broken object level authorization as the leading API risk, and an insurance back end is almost entirely record-scoped endpoints.
Agent, broker and MGA hierarchy separation. Producer hierarchies are trust trees. The test has to prove a downline agent cannot read an upline's book, that a terminated producer loses access immediately, and that agency-level roles cannot cross into carrier-level functions.
Multi-tenant isolation for platform vendors. An insurtech serving many carriers or agencies must prove tenant A cannot reach tenant B, including through shared reporting, bulk exports and integration endpoints.
Quoting and binding business logic. Rating factor manipulation, premium recalculation between quote and bind, coverage limit tampering, effective-date backdating and discount stacking are logic flaws, not vulnerabilities a scanner recognises.
Claims workflow abuse. State manipulation across first notice of loss, adjuster assignment, approval thresholds and payout instruction changes. Payment instruction tampering is where a claims platform turns into a fraud channel.
Integration surfaces. ACORD interfaces, policy administration APIs, reinsurance bordereaux exchanges, comparative rater connections and flat-file feeds frequently sit behind weaker authentication than the main application, because they were built for a trusted network that is no longer trusted.
Evidence shaped for the regime you answer to. Scope, methodology, tester qualification, findings, remediation and retest. That is the floor for a NYDFS file, an OSFI supervisory conversation and a state examination alike.
The paperwork for all of this lives in two documents. The penetration testing statement of work template covers scope, rules of engagement, deliverables and acceptance criteria, and the penetration testing RFP template covers the vendor-facing questions.
How much does insurance penetration testing cost in 2026?
Insurance engagements price above a generic web application test because scope includes authenticated multi-role testing across a producer hierarchy, integration interfaces that predate the portal, and reporting shaped for an examiner. The bands below reflect typical 2026 market ranges for the scopes insurers most often buy.
Engagement | Typical range (USD) | Typical range (CAD) | Notes |
|---|---|---|---|
Policyholder or agent portal (one-time) | US$8,000 to 18,000 | C$11,000 to 25,000 | Authenticated, multi-role, one application and its APIs |
Quoting and binding platform with integrations | US$18,000 to 40,000 | C$25,000 to 55,000 | Rating logic, comparative rater feeds, partner APIs |
Internal and external network | US$15,000 to 35,000 | C$20,000 to 48,000 | The NYDFS 500.5(a)(1) inside-and-outside scope for a mid-market estate |
Claims platform and payment path | US$20,000 to 45,000 | C$28,000 to 62,000 | Workflow state, approval thresholds, payout instruction integrity |
Threat-led red team | US$45,000 to 90,000 | C$62,000 to 125,000 | Objective-based, intelligence-led, suited to B-13 scenario design |
Annual continuous testing programme | US$30,000 to 90,000 | C$42,000 to 125,000 | Continuous coverage, retests included, portal access |
Stingrai publishes package pricing openly. A one-time Autonomous Pentest with Snipe starts at US$3,000 and a one-time Hybrid Pentest with certified penetration testers is US$6,800, both covering exactly one web application and its APIs. The same two tiers run as subscriptions from US$650 per month and US$1,275 per month on a 12-month engagement. The Autonomous tier carries a No High or Critical Finding, Don't Pay guarantee, and retesting is included. Carrier estates, multi-entity groups and platform scopes are quoted individually. Current figures are on the pricing page.
For an independent view across scopes and company sizes, the penetration testing cost guide and the penetration testing cost calculator are the two starting points.
Buyer checklist for an insurance penetration test
Nine questions, in the order they save you money.
Which licence drives this purchase? A New York licence means 500.5(a)(1) and an annual, inside-and-outside scope. A model-law state means your risk assessment has to justify whatever you buy. A federal Canadian charter means B-13 and a cadence you define and defend.
Is the test scoped from inside and outside the boundaries? An external-only engagement does not satisfy NYDFS on its own, and it is the single most common gap in a mid-market insurer's evidence file.
Who, by name, will test the environment? Get the names and certifications in the statement of work, not the proposal. "Qualified party" is a question an examiner will ask you to answer.
Is the retest included or billed separately? The retest is the artefact that closes the loop for 500.17(b)(3) and for a supervisory conversation. Paying for it twice is a budgeting error, not a compliance one.
What does the remediation record look like? Ask for a redacted example. If the vendor can only show a PDF, you will be building the record yourself.
Does the report map findings to the regime you answer to? NYDFS 500.5, PCI DSS 11.4, SOC 2 Common Criteria and ISO 27001 Annex A, as applicable.
Is the accreditation firm-level or an individual certification? Both are legitimate; conflating them is not. Our guide to verifying a CREST claim explains the difference.
Can the engagement run continuously as well as annually? An insurer shipping portal changes monthly has a twelve-month evidence gap it cannot explain if the only test is annual.
How are findings delivered to engineering? A portal with tracker integration closes findings faster than an email thread, and the timestamps become your remediation evidence.
What this means for insurance security buyers in 2026
Three practical conclusions follow from the regulatory picture.
Buy the test for the risk, then map it to whichever rule you actually carry. The NAIC model law asks you to regularly test and monitor for actual and attempted intrusions and leaves the method to your risk assessment. NYDFS names the test and the clock. OSFI names the activity and leaves the number to you. A vendor telling a Kansas-domiciled carrier that a national rule mandates an annual penetration test is selling from someone else's regulation.
Scope to the producer hierarchy and the money path, not the perimeter. The finding that becomes a reportable event in insurance is rarely a missing patch. It is an authorization check that trusted a policy number, or a rating engine that accepted a recalculated premium on bind.
Write the evidence requirements into the contract. Scope, methodology, named and qualified testers, findings, remediation record and retest. Across the engagements analysed in the 2026 state of penetration testing report, 1,206 verified findings across 55 tests carried a 0.74% false-positive rate, 92.7% of tests surfaced at least one High or Critical issue, and the median time to fix a Critical was 10.5 days. Those numbers exist because findings are manually verified before they reach a report, which is the same standard any examiner expects.
Frequently Asked Questions
Who are the best insurance penetration testing companies in 2026?
The best insurance penetration testing companies in 2026 are Stingrai, Cobalt, NetSPI, Coalfire, Schellman, Praetorian, TrustedSec, GuidePoint Security, Bishop Fox, HackerOne, Packetlabs and Software Secured. Stingrai is a CREST-accredited penetration testing service provider headquartered in Toronto and founded in 2021. Its two-tester teams hold OSCE³, OSWE, OSEP, CREST CRT and CISSP, have published 18 CVEs, and are listed in the bug bounty Halls of Fame of Apple, Google, the US Department of Defense and the US Federal Reserve. For insurers it tests the policyholder and agent portals and the quoting, binding and claims APIs with authenticated access across every role, the cloud tenant and Entra ID, the internal network and Active Directory, and phishing against underwriting and claims staff, one-time or continuously, with named testers, retesting and an attestation letter included and pricing published on its site. Cobalt follows for the only published insurance solutions page among the vendors reviewed, NetSPI for a named carrier partnership, and Coalfire for assessment-led programme depth. Every entry was verified against the vendor's own published page on 19 September 2026.
Does the NAIC Insurance Data Security Model Law require penetration testing?
No. The phrase does not appear in the model law. Section 4 requires a licensee to maintain a written information security program based on its own risk assessment and to implement the security measures it determines are appropriate, one of which is to "regularly test and monitor systems and procedures to detect actual and attempted attacks on, or intrusions into, information systems." No cadence, scope, independence requirement or technique is named. A penetration test is the most defensible way to satisfy that duty, not a separately mandated obligation. The model also exempts licensees with fewer than ten employees from Section 4, along with licensees already compliant with HIPAA.
Does NYDFS 23 NYCRR 500 require an annual penetration test?
Yes. Section 500.5(a)(1), as amended by the second amendment adopted 1 November 2023, requires each covered entity to conduct "penetration testing of their information systems from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually." Insurers, producers, agencies and brokers holding a New York licence are covered entities under section 500.1(e) regardless of where they are headquartered. The requirement has been enforceable since 29 April 2024. A separate obligation at 500.5(a)(2) requires automated scans plus a manual review of systems those scans cannot reach, enforceable since 1 May 2025, and section 500.17(b)(3) requires five years of records supporting the annual certification.
What does OSFI B-13 require of Canadian insurers?
OSFI Guideline B-13 applies to all federally regulated financial institutions, explicitly including life insurance and fraternal companies, property and casualty companies, and foreign insurance company branches, and became effective 1 January 2024. Section 3.1.2 names penetration testing once, expecting FRFIs to set defined triggers and minimum frequencies for intelligence-led threat assessments and to regularly perform tests and exercises using an intelligence-led approach. It sets no numeric cadence. The often-quoted three-year figure belongs to OSFI's Intelligence-led Cyber Resilience Testing Advisory, which states it is not a policy instrument used to set regulatory expectations and applies to systemically important banks and internationally active insurance groups.
Does the GLBA Safeguards Rule apply to insurers?
Usually not directly. The FTC Safeguards Rule at 16 CFR 314.4(d) requires continuous monitoring or, where that is absent, annual penetration testing plus vulnerability assessments at least every six months. But 15 USC 6805(a)(6) assigns enforcement of the GLBA safeguards standards for any person engaged in providing insurance to the applicable State insurance authority of the state in which the person is domiciled. So a licensed carrier or producer answers to its state insurance regulator rather than the FTC. Insurtech platforms, premium finance companies, quoting marketplaces and claims payment processors that are not licensed insurance entities can still fall inside the FTC's definition of a financial institution and inherit the annual testing obligation outright.
How many states have adopted the NAIC Insurance Data Security Model Law?
Twenty-eight NAIC member jurisdictions have implemented the model. The NAIC's August 2025 legislative brief lists Alabama, Alaska, Connecticut, Delaware, Hawaii, Illinois, Indiana, Iowa, Kentucky, Louisiana, Maine, Maryland, Michigan, Minnesota, Mississippi, Missouri, New Hampshire, North Dakota, Ohio, Oklahoma, Pennsylvania, Puerto Rico, Rhode Island, South Carolina, Tennessee, Vermont, Virginia and Wisconsin, and the NAIC's Summer 2026 state page lists the same twenty-eight in its Model Adoption column, with Tennessee noted as having adopted portions of the model. New York is not among them: it appears only under Related Activity, cited to its own regulation at 23 NYCRR 500.
What should an insurance penetration test cover?
Object-level authorization on every record-scoped endpoint carrying a policy, claim, quote, document or party identifier. Agent, broker and MGA hierarchy separation, so a downline producer cannot read an upline's book and a terminated producer loses access. Multi-tenant isolation for platform vendors, including shared reporting and bulk exports. Quoting and binding business logic such as rating factor manipulation, premium recalculation between quote and bind, limit tampering and effective-date backdating. Claims workflow abuse across first notice of loss, adjuster assignment, approval thresholds and payout instruction changes. Integration surfaces including ACORD interfaces, policy administration APIs and comparative rater connections. Evidence should carry scope, methodology, tester qualification, findings, remediation and retest.
How much does insurance penetration testing cost in 2026?
Cost tracks scope: the number of applications and roles, whether integration interfaces and the claims payment path are in scope, and whether the engagement is annual or continuous. Typical 2026 ranges run US$8,000 to US$18,000 for an authenticated policyholder or agent portal, US$18,000 to US$40,000 for a quoting and binding platform with integrations, US$15,000 to US$35,000 for internal and external network testing, and US$30,000 to US$90,000 for an annual continuous programme, with Canadian dollar equivalents roughly 1.4 times the US figure. Stingrai publishes package pricing openly, with a one-time Autonomous Pentest from US$3,000 and a one-time Hybrid Pentest with certified penetration testers at US$6,800, each covering exactly one web application and its APIs, and the same tiers as subscriptions from US$650 and US$1,275 per month on a 12-month engagement. Current figures are on the pricing page.
How often should an insurer run a penetration test?
If you hold a New York licence, at least annually under 500.5(a)(1), from both inside and outside the boundaries. If you are a federally regulated Canadian insurer, at a frequency you define, document and can defend to a supervisor, which in practice means annually for the internet-facing estate, applications and internal network, with scope driven by critical business functions and threat intelligence. If you operate only in model-law states, your risk assessment sets the cadence, and annual plus after any significant change is the common commercial position. Insurers shipping portal or rating changes monthly increasingly run continuous testing so the gap between a change and its first test is measured in days rather than months.
Do MGAs, brokers and insurtech platforms need their own penetration test?
Usually yes, and the driver is contractual rather than regulatory. A New York licensed agency or brokerage is a covered entity in its own right under 23 NYCRR 500.1(e). Beyond that, section 500.11(a) requires covered entities to set minimum cybersecurity practices for third-party service providers, and OSFI Guideline B-10 keeps a Canadian insurer accountable for risk arising from third-party arrangements. The practical effect is that the carrier's diligence questionnaire asks the MGA, broker or insurtech platform for the same artefacts the carrier holds: a recent report, the remediation record and the retest. Ranked views from adjacent angles are in the best penetration testing companies for SOC 2 and best penetration testing companies for fintech guides.
Related reading
References
National Association of Insurance Commissioners. _The NAIC Insurance Data Security Model Law_, legislative brief, August 2025. https://content.naic.org/sites/default/files/government-affairs-brief-data-security-model-law.pdf. Source of the October 2017 adoption date, the scope covering insurers, insurance agents and other licensed entities, the Section 4 information security program duty, the fewer-than-ten-employees and HIPAA exemptions, and the count of 28 implementing jurisdictions with the state list, status as of 8 August 2025.
National Association of Insurance Commissioners. _NAIC Model Laws, Regulations, Guidelines and Other Resources, Summer 2026: Insurance Data Security Model Law state page._ https://content.naic.org/sites/default/files/model-law-state-page-668.pdf. Used to confirm the Model Adoption column, the Tennessee portions-of-model note, and that New York appears only under Related Activity cited to 23 NYCRR 500.
Iowa General Assembly. _Iowa Code 2026, Section 507F.4, Information security program._ https://www.legis.iowa.gov/docs/code/2026/507F.4.pdf. State enactment of Model #668 Section 4, used to quote the regularly-test-and-monitor security measure verbatim and to confirm that the words "penetration testing" do not appear.
New York State Department of Financial Services. _23 NYCRR Part 500, Cybersecurity Requirements for Financial Services Companies_, second amendment adopted 1 November 2023. https://www.dfs.ny.gov/system/files/documents/2023/10/rf_fs_2amend23NYCRR500_text_20231101.pdf. Source of the 500.5(a)(1) annual penetration testing text, the 500.1(e) covered entity definition, the 500.5(a)(2) scanning obligation and the 500.17(b)(3) five-year records requirement.
Office of the Superintendent of Financial Institutions. _Guideline B-13, Technology and Cyber Risk Management._ https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/technology-cyber-risk-management. Source of the section 3.1.2 testing language, the scope covering life, fraternal, property and casualty companies and foreign insurance branches, and the 1 January 2024 effective date.
Office of the Superintendent of Financial Institutions. _OSFI's Intelligence-led Cyber Resilience Testing Framework_, Advisory, 1 April 2023. https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/osfis-intelligence-led-cyber-resilience-testing-crt-framework. Source of the three-year cadence, the statement that the document is not a policy instrument, and the scope limited to systemically important banks and internationally active insurance groups.
Legal Information Institute, Cornell Law School. _16 CFR 314.4, Elements._ https://www.law.cornell.edu/cfr/text/16/314.4. Source of the continuous monitoring or periodic penetration testing language, the annual penetration testing default and the six-month vulnerability assessment cadence.
Legal Information Institute, Cornell Law School. _15 U.S. Code 6805, Enforcement._ https://www.law.cornell.edu/uscode/text/15/6805. Source of subsection (a)(6) assigning enforcement for persons engaged in providing insurance to the applicable State insurance authority.
IBM. _Cost of a Data Breach Report 2026._ https://newsroom.ibm.com/2026-07-29-ibm-study-one-in-four-malicious-breaches-are-ai-enabled,-costing-companies-6-million-on-average. Source of the US$6.3 million financial services average, the US$4.99 million global average and the 26% differential.
OWASP Foundation. _API Security Project._ https://owasp.org/www-project-api-security/. Ranks broken object level authorization as the leading API security risk.
Cobalt. _Insurance._ https://www.cobalt.io/solutions/insurance. Published insurance practice naming the NAIC model law, SOC 2 and ISO 27001, with continuous pentesting, AI and LLM testing, application, API and network scope. Verified 19 September 2026.
NetSPI. _Financial services._ https://www.netspi.com/industries/financial-services/. Published financial services material and the customer story describing Chubb partnering with NetSPI to bring attack surface management to its policyholders. Verified 19 September 2026.
Coalfire. _Financial services._ https://coalfire.com/industries/financial-services. Published financial services practice across advisory, assessment and security lines, with PCI DSS named. Verified 19 September 2026.
Schellman. _Penetration testing._ https://www.schellman.com/penetration-testing. Nine published testing services, financial services and fintech among industries served, and a separate payment card practice. Verified 19 September 2026.
Praetorian. _Penetration testing services._ https://www.praetorian.com/services/penetration-testing/. Published offensive security domains and the GLBA, HIPAA and PCI DSS compliance framing, with a zero-false-positive commitment. Verified 19 September 2026.
TrustedSec. _Penetration testing._ https://trustedsec.com/services/penetration-testing. Manual penetration testing methodology with validation testing, finance among industries served and PCI DSS, HIPAA and SOC 2 among compliance drivers. Verified 19 September 2026.
GuidePoint Security. _Penetration testing._ https://www.guidepointsecurity.com/penetration-testing/. Published penetration testing practice and Reston, Virginia headquarters. Verified 19 September 2026.
Bishop Fox. _Offensive security solutions for financial organizations._ https://bishopfox.com/industries/financial-industry. Names insurers alongside banks and investment firms, and names FFIEC, OCC Bulletin 2023-26, PCI DSS, GLBA, the NYDFS Cybersecurity Regulation, DORA, TIBER-EU, ISO/IEC 27001, SOX IT controls and the NIST Cybersecurity Framework. Verified 19 September 2026.
HackerOne. _Financial services._ https://www.hackerone.com/solutions/financial-services. Published financial services page with a distinct insurance section, covering bug bounty, vulnerability disclosure, continuous testing and code security audits. Verified 19 September 2026.
Packetlabs. _Industries._ https://www.packetlabs.net/industries/. Published industry pages including Finance, service set across application, infrastructure, cloud, IoT and adversary simulation, and the Toronto headquarters address. Verified 19 September 2026.
Software Secured. _Company site._ https://www.softwaresecured.com/. Penetration testing as a service aligned to release cycles, audit support across SOC 2, HIPAA, ISO 27001, PCI DSS and GDPR, and finance and fintech among published verticals. Verified 19 September 2026.
Stingrai. _The State of Penetration Testing 2026._ https://www.stingrai.io/blog/state-of-penetration-testing-2026. 1,206 verified findings across 55 penetration tests, severity mix, remediation timing and false positive rate.
Stingrai. _Pricing._ https://www.stingrai.io/pricing. Published one-time and continuous package prices for one web application and its APIs.
Ready to scope an insurance penetration test?
The finding that turns into a reportable event at a carrier is almost never a missing patch. It is an authorization check that trusted a policy number it should have validated, or a rating engine that accepted a premium the client recalculated on the way to bind. Stingrai is a CREST-accredited penetration testing service provider whose penetration testing supports your NYDFS Part 500, OSFI B-13, SOC 2, ISO 27001 and PCI DSS 4.0 programmes by producing the scope statement, technical report, remediation record and retest evidence those programmes consume. Certified penetration testers work concurrently with Snipe, our autonomous AI agent for web application penetration testing, hunting the broken authorization, IDOR and business logic flaws that put one policyholder's file on another policyholder's screen. Book a free scoping call, get a quote for a carrier estate or multi-entity scope, or read the published package prices on the pricing page.



