main logo icon

Published on

August 7, 2026

|

10 min read

Does a Pentest Lower Your Cyber Insurance Premium? What Underwriters Actually Ask

Cyber insurers publish no pentest discount. What real carrier applications and ransomware supplementals grade, how shallowly they ask about testing, why a wrong answer is a coverage problem not a paperwork one, and what to attach at renewal.

Arafat Afzalzada

Arafat Afzalzada

Founder

Advisories

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

No cyber carrier publishes a rate-card discount for holding a penetration test report, and Marsh reported global cyber insurance rates fell 4 percent in Q2 2026, the twelfth consecutive quarterly decline with the US down 2 percent, so a softer renewal is market direction rather than proof your test worked. The AXIS Cyber Application (form AXIS 1012098 0122) asks whether the applicant conducts regular penetration testing, how frequently, and whether testing is in-house or outsourced, and the 0623 revision breaks the question out by testing type with a dedicated web application row carrying its own frequency. The AXIS Cyber Ransomware Supplemental Application (form AXIS 1012729 0122) never raises penetration testing again, while grading EDR coverage separately across endpoints and servers, MFA across five named access categories, privileged access management, and backup immutability and recovery testing. On AIG Australia's CyberEdge Ransomware Supplemental Questionnaire, penetration testing is named exactly once, as one option inside a question about validating control effectiveness, alongside breach and attack simulation and an external threat-actor simulation performed in the last year. Application answers are representations the insurer relies on, not warranties: UK Insurance Act 2015 section 9(2) stops a representation being converted into a warranty in a non-consumer contract, so the live risk is rescission or a proportionate remedy. In Travelers Property Casualty Company of America v. International Control Services, Inc., No. 2:22-cv-02145 (C.D. Ill.), the parties stipulated on 26 August 2022 to a judgment rescinding a cyber policy after the insurer alleged the applicant misstated its multi-factor authentication coverage. The defensible attachment set is four documents: a completion letter with dates, a scope statement naming what was and was not tested, remediation status by severity, and a retest date.

Six to ten weeks before renewal, someone forwards you the ransomware supplemental and asks whether buying a penetration test now will bring the premium down. No carrier publishes a rate credit for holding a pentest report, and the forms show why. Carriers do ask about testing, but shallowly: a yes or no, a frequency band, and on the better forms a testing type. MFA coverage, endpoint detection breadth, privileged access and backup recoverability are graded question after question, across whole pages.

That does not make testing pointless. It changes what testing is for. A pentest buys the ability to answer the security questions truthfully and to attach evidence when an underwriter or, later, a claims adjuster asks you to prove it. The failure mode on these forms is not a higher premium. It is a rescinded policy.

The honest answer on premium: what actually moves the number

Start with the market, which is doing most of the work. Marsh's Global Insurance Market Index for Q2 2026, published 23 July 2026, reported cyber insurance rates down 4 percent globally, the twelfth consecutive quarter of declines, with the US down 2 percent. The Q1 2026 index recorded a 5 percent global decline. If your renewal comes in flat or lower, the base case is competition and capacity, not your report.

The NAIC's Report on the Cybersecurity Insurance Market, drawing on the 2024 Cyber Supplement, records the first ever reduction in US cyber direct written premium: roughly $9.14 billion in 2024, a 7 percent decrease from $9.84 billion in 2023 including alien surplus lines. Reported claims rose almost 40 percent over the same period, to nearly 50,000. Falling premium against rising claim frequency makes underwriters more selective about controls, not more generous about testing, and the NAIC is explicit about what earns underwriter favour: continued investment in cybersecurity controls.

The same ordering shows up in a real form. AXIS puts cyber applicants through two documents: the AXIS Cyber Application, form AXIS 1012098 0122, and the AXIS Cyber Ransomware Supplemental Application, form AXIS 1012729 0122, signed by an authorized officer of the entity named on the main application. Penetration testing is asked about once, on the main application. The supplemental, the document that exists to price ransomware risk, never raises it again. Here is what it grades instead.

The AXIS supplemental grades

Granularity it demands

EDR deployment

Separate percentages for endpoints and for servers, plus the product name

MFA

Yes or no across five access categories: remote access, critical information, personal devices, third party and vendor access, and non-critical applications, plus whether the second factor is SMS or lands on a non-corporate device

Privileged access

Whether a PAM tool exists, whether PAM access is itself behind MFA, and the count of accounts in the Domain Admin group

Patching

Critical patch target in bands from under 24 hours to over 7 days, plus a routine band

Backups

Immutability, offline and offsite storage, whether encryption keys are held offline, whether backup credentials are separate, and how often a full recovery is tested

Recovery

Recovery time objective band, and whether it was validated in the last 12 months

Penetration testing

Not raised. The word does not appear on the supplemental at all

Now compare that with the main application. Under a heading of "Testing & Scanning", AXIS asks whether the applicant conducts regular penetration testing, how frequently, and whether it is in-house or outsourced. Three lines, and that is the whole of it. Carriers do not ignore testing; they ask it as a single yes with a frequency band attached, while the controls beside it are interrogated to the percentage point. A pentest earns you the right to write that yes. It is not a lever on the rate.

AXIS's later revision, form AXIS 1012098 0623, treats testing more granularly than any other form in this sample. Section 5.2, headed "Pen Testing", asks which types the applicant runs and a frequency for each: external network, internal network, social engineering, physical and web application, against quarterly, twice a year, annually, ad hoc or never, plus whether testing is internal or outsourced. If your revenue runs through a web application and you have only ever bought an external network test, the gap shows up in one row.

Where testing does show up on the form

AXIS is not unusual in asking. What varies is the framing, and AIG's makes testing interchangeable with tooling. AIG Australia's CyberEdge Ransomware Supplemental Questionnaire runs roughly 17 pages of control questions across eight domains, from data security and business continuity through identity and access management, security monitoring and incident response, risk management, phishing and malware defence, and perimeter defence.

Penetration testing is named exactly once, in the security monitoring and incident response section, in a question asking how the applicant validates the efficiency and effectiveness of its security controls. Three responses are on offer: breach and attack simulation software; having a red team on staff, or at least annually engaging experts to perform a "penetration test focused on internal systems"; and having engaged an external party to simulate threat actors and test security controls in the last year. A separate question in the malware defence section asks whether the applicant has run an exercise simulating the tactics, techniques and procedures of ransomware actors in the last year. Adversary simulation therefore appears in two sections; penetration testing is named in one.

Three things follow. Penetration testing is one of several interchangeable ways to evidence control validation, with simulation tooling scoring alongside it. The wording is time-bound twice over, at least annually for the standing arrangement and within the last year for the external simulation. And the penetration testing option specifically is scoped to internal systems, so a web application test answers the AXIS web application row rather than this one; the external simulation option carries no such limit.

Note the form's default too. AIG reads a blank response as a no, or as not having that control, unless the question itself offers a No, Don't Know or None of the Above option. Where it does not, silence is not neutral.

Warranty, misrepresentation and rescission: why a wrong answer is a coverage problem

It is common to hear that application answers become warranties. In the UK that is now legally wrong; in the US it is imprecise. The real mechanism is misrepresentation, and it is worse, because it reaches the whole policy rather than one claim.

The AXIS representations section is the model. The signatory represents that the statements submitted are true, accurate and complete; that no facts material to the risk have been misstated or concealed; that those representations are a material inducement to the insurer; and that any policy is issued in reliance on them. The application and everything submitted with it is deemed part of the policy, and a named officer must sign, from chief executive through CIO, CSO or general counsel. Not a form the security team fills in anonymously.

Jurisdiction

Mechanism

Consequence of a material misstatement

US

Misrepresentation, policy issued in reliance on it

Rescission: the policy can be declared void from inception, so no claim under it is payable

UK (non-consumer)

Insurance Act 2015 section 3, duty of fair presentation

Deliberate or reckless breach lets the insurer avoid the contract, refuse all claims and keep the premium. Otherwise Schedule 1 gives graduated remedies: avoidance with the premium returned if the insurer would not have written the risk at all, the contract treated as written on the terms the insurer would have imposed, or a reduced percentage paid

UK (non-consumer)

Insurance Act 2015 section 9(2)

A representation cannot be converted into a warranty by a basis-of-contract clause or otherwise, so the warranty framing does not survive

Australia

Duty of disclosure, per the AIG CyberEdge documentation

The insurer may cancel the contract, reduce what it pays, or both. Where the failure is fraudulent it may refuse the claim and treat the contract as if it never existed

The US mechanism is not theoretical. In Travelers Property Casualty Company of America v. International Control Services, Inc., No. 2:22-cv-02145 in the Central District of Illinois, Travelers sought rescission of a cyber policy after a ransomware incident, alleging the insured had represented that MFA was required across email, remote network access, endpoints, servers and directory services when in practice it protected only the firewall, not the attacked server. On 26 August 2022 the parties stipulated to a judgment rescinding the policy from inception, and the case was dismissed with prejudice. The insured did not lose an argument about how much cover applied. It lost the policy.

The obligation continues after signature. The AXIS representations include a duty to report immediately, in writing, any material change to the answers between the application date and the policy effective date, with the insurer free to modify or withdraw its proposal. A critical finding landing inside that window may be a disclosure event, not just an engineering ticket.

The four-document evidence pack to attach at renewal

Underwriters rarely specify a document list, so applicants attach nothing, or attach the full technical report, which should not leave the organisation. Four items survive a claims-time review.

  1. Completion letter with dates. One page naming the testing firm, its accreditation, the engagement type, start and end dates and an overall risk statement, with no exploitable detail. See pentest completion letter vs full report.

  2. Scope statement naming what was and was not tested. This is the item that protects you. A letter saying testing was completed invites the adjuster's later question of whether the tested scope included the breached system.

  3. Remediation status by severity. Counts by severity, how many are closed, and target dates for the rest. An open critical with a dated plan reads better than an unexplained gap.

  4. Retest date. Evidence the fixes were verified rather than claimed.

Scan vs pentest: a distinction the forms themselves draw

When the form asks about testing and the budget is gone, the temptation is to submit a vulnerability scan as a penetration test. Do not: carriers already separate the concepts on the same form. On the AIG questionnaire, the risk management section asks whether the applicant runs a vulnerability scanning programme covering its vital assets, and the perimeter section asks separately about regular scanning of externally exposed assets and whether it happens at least monthly. Penetration testing sits in a different section entirely, in the security monitoring and incident response control validation question. A carrier that asks about scanning three times and names testing once has plainly not confused them.

AXIS draws the same line inside a single heading: its "Testing & Scanning" subsection asks about regular penetration testing and its frequency, then separately about regular vulnerability scanning and its frequency. Two questions, two independent frequency ladders.

The practical test: a scanner reports that a condition exists; a penetration test demonstrates what an attacker reaches by chaining conditions, with a named tester on the report. If your evidence has no exploitation narrative, it answers the scanning questions, not the testing one. For the compliance-side version, see penetration testing vs vulnerability assessment.

What "annual testing" means when your last test was 14 months ago

The AIG wording answers this without ambiguity. The standing-arrangement option is phrased as at least annually; the external simulation option as within the last year. Fourteen months is outside both, and on that form there is no partial-credit box.

AXIS puts the same horizon in ladder form and does give you a box for the truth: its 0623 application offers quarterly, twice a year, annually, ad hoc or never for each testing type. Fourteen months is not annually. "Ad hoc" is the honest selection, and it reads very differently in the underwriter's file.

This is stricter than the compliance version of the question. An auditor assesses a control over a period and may accept a documented slip; an insurance answer is a point-in-time statement relied on in issuing a policy. If the report is stale on the day you sign, the honest answer is no. More on report shelf life: is your pentest report still valid.

Timing: how far ahead of renewal to test

Work backwards from the submission date, not the renewal date, leaving room for remediation.

Weeks before renewal

Action

10 to 12

Pull last year's application and supplemental. Identify every answer you could not evidence today

8 to 10

Commission testing covering the scope your answers claim. Fix the control gaps the form grades hardest, because MFA coverage and backup recovery testing move the file most

4 to 6

Retest, close what can be closed, write the remediation status by severity

2 to 4

Assemble the four-document pack and brief the broker on the control narrative

Inside 2

Answer accurately, disclose the scheduled test, and treat any material change before the effective date as a reporting obligation

If you are already inside the window, improve the risk before the next cycle rather than the answer before this one. A rescinded policy costs vastly more than a slightly higher premium; the arithmetic of testing continuously is in the budget case for continuous penetration testing.

What to tell your broker so the submission reads as a better risk

Lead with the controls the forms grade, in the order they grade them: MFA coverage by access category, EDR split between endpoints and servers, privileged access management including the domain admin account count, backup immutability with the date of the last full recovery test, and the RTO with the date it was last validated. Then present testing as evidence those controls hold under attack, naming the types you run and the frequency of each, because that is the shape the AXIS form asks for, with the four-document pack behind it.

Ask which exclusions apply too, because coverage scope can matter more than price: Lloyd's Market Bulletin Y5381, issued 16 August 2022, required state-backed cyber-attack exclusions in standalone cyber-attack policies from 31 March 2023 at inception or renewal, and the Lloyd's Market Association published model clauses LMA5564 to LMA5567 that differ materially in what they claw back. If you have had an incident in the period, get the facts straight before the form goes in; see ransomware payout statistics and emergency pentest after a security incident.

Stingrai is a CREST-accredited penetration testing service provider at firm level, with 18 published CVEs and 5.0 out of 5.0 across 19 Clutch reviews. Our Snipe agent tests web applications and APIs autonomously, black-box and white-box, and opens AutoFix pull requests with PR-gating so findings close inside the development cycle. Hybrid engagements add human validation of every finding, which is what makes the completion letter and scope statement defensible when an adjuster reads them a year later. Autonomous testing starts at US$3,000 one-time or US$450 per month, hybrid at US$6,800 one-time or US$1,275 per month on a 12-month engagement; terms are on the pricing page. The deliverables support your insurance submission and your SOC 2 or ISO 27001 programme.

Buy the test because you intend to answer a question truthfully. The premium will do what the market tells it to.

Frequently Asked Questions

Does cyber insurance require a penetration test?

Not as a universal precondition to coverage, but carrier applications do ask directly, so plan to answer. The AXIS Cyber Application, form AXIS 1012098 0122, asks whether the applicant conducts regular penetration testing, how frequently, and whether testing is in-house or outsourced; its 0623 revision breaks the question out by testing type including a dedicated web application row. AIG Australia's CyberEdge ransomware supplemental instead names penetration testing once, as one option in a question about validating control effectiveness. How much the answer weighs depends on the carrier's form.

How much does a pentest reduce cyber insurance premiums?

There is no published rate credit for holding a penetration test report, and any specific percentage quoted to you is a sales claim rather than a filed rate. Marsh reported global cyber rates fell 4 percent in Q2 2026, the twelfth consecutive quarterly decline, with the US down 2 percent. What testing changes is which answers you can defend with evidence.

What documents does a cyber insurance underwriter want from a pentest?

Underwriters rarely specify a list, so submit four items: a completion letter naming the testing firm, engagement type and dates; a scope statement listing what was and was not tested; remediation status by severity; and a retest date proving fixes were verified. Never send the full technical report, which carries reproduction steps and belongs inside your organisation.

Can an insurer deny a claim because of a wrong answer on the application?

It can go further and rescind the policy entirely. In Travelers Property Casualty Company of America v. International Control Services, Inc., No. 2:22-cv-02145 in the Central District of Illinois, the parties stipulated on 26 August 2022 to a judgment rescinding a cyber policy after Travelers alleged the applicant had misstated its multi-factor authentication coverage. In the UK the Insurance Act 2015 gives graduated remedies under Schedule 1: for a deliberate or reckless breach the insurer may avoid the contract, refuse all claims and keep the premium; for other breaches it may avoid and return the premium if it would not have written the risk at all, or else apply the contract on different terms or reduce the payout proportionately.

Is a vulnerability scan enough for a cyber insurance application?

It is enough for the scanning questions and not for the testing question. AIG Australia's CyberEdge supplemental asks about a vulnerability scanning programme in its risk management section and about external scanning frequency in its perimeter section, while naming penetration testing only in its security monitoring and incident response section. The AXIS Cyber Application puts both under one "Testing & Scanning" heading as two separate questions with two separate frequency ladders. Answering the testing question with scan output misstates a matter the insurer keeps distinct.

How recent does a penetration test have to be for insurance?

Where carriers time-bound the question they use a twelve-month horizon. AIG Australia's CyberEdge supplemental phrases its options as at least annually for a standing arrangement and as within the last year for an external threat-actor simulation, with no partial-credit option. The AXIS 0623 application offers quarterly, twice a year, annually, ad hoc or never for each testing type. A fourteen-month-old report is not annual testing, so the honest answers are no on the AIG form and ad hoc on the AXIS one.

Do I need a pentest before renewing cyber insurance?

You need it only if you intend to answer yes to a testing question, and you should commission it eight to ten weeks before submission so there is time to remediate and retest. Buying a test purely to lower the premium is a weak business case, because these forms grade MFA coverage, endpoint detection, privileged access and tested backups in far more detail. Buying it so your answers are defensible is a strong one.

What is a ransomware supplemental application?

It is an additional questionnaire attached to a cyber insurance application, focused on the controls that determine ransomware outcomes. The AXIS version covers intrusion detection, EDR coverage percentages for endpoints and servers, multi-factor authentication across five access categories, privileged access management, patching timelines, network segmentation, phishing simulation results, backup immutability and recovery testing, and recovery time objectives. It is signed by a named senior officer and forms part of the policy.

References

  1. Marsh. Global commercial insurance rates fall 6% in Q2 2026. 23 July 2026. https://www.corporate.marsh.com/news-events/2026/july/global-commercial-insurance-falls-6-percent-q2-2026.html

  2. Marsh. Global commercial insurance rates fall 5% in Q1 2026. 22 April 2026. https://www.marsh.com/en/about/media/global-commercial-insurance-rates-fall-5-percent-in-q1-2026.html

  3. NAIC. Report on the Cybersecurity Insurance Market (2024 data year). https://content.naic.org/sites/default/files/inline-files/2025_Cybersecurity_Insurance%20Report.pdf

  4. AXIS Insurance. AXIS Cyber Application, form AXIS 1012098 0122. https://www.axiscapital.com/docs/default-source/default-document-library/axis-1012098-0122.pdf

  5. AXIS Insurance. AXIS Cyber Technology and MPL Application, form AXIS 1012098 0623. https://www.axiscapital.com/docs/default-source/resources/axis-1012098-0623-axis-cyber-technology-mpl-application-7-20-23.pdf

  6. AXIS Insurance. AXIS Cyber Ransomware Supplemental Application, form AXIS 1012729 0122. https://www.axiscapital.com/docs/default-source/default-document-library/axis-1012729-0122.pdf

  7. AIG Australia Limited. CyberEdge Ransomware Supplemental Questionnaire. https://www.aig.com.au/content/dam/aig/apac/australia/documents-new/financial-lines/cyber/aig-au-cyberedge-ransomware-supplementary-proposal-form.pdf.coredownload.pdf

  8. US District Court, Central District of Illinois. Travelers Property Casualty Company of America v. International Control Services, Inc., No. 2:22-cv-02145. https://dockets.justia.com/docket/illinois/ilcdce/2:2022cv02145/86760

  9. US District Court, Central District of Illinois. Complaint (Dkt. 1), Travelers Property Casualty Company of America v. International Control Services, Inc., No. 2:22-cv-02145. 6 July 2022. https://storage.courtlistener.com/recap/gov.uscourts.ilcd.86760/gov.uscourts.ilcd.86760.1.0.pdf

  10. Insurance Journal (secondary, trade press). Travelers, Policyholder Agree to Void Current Cyber Policy. 30 August 2022. https://www.insurancejournal.com/news/national/2022/08/30/682564.htm

  11. UK Parliament. Insurance Act 2015, section 9. https://www.legislation.gov.uk/ukpga/2015/4/section/9

  12. UK Parliament. Insurance Act 2015, Schedule 1. https://www.legislation.gov.uk/ukpga/2015/4/schedule/1

  13. Lloyd's. Market Bulletin Y5381: State backed cyber-attack exclusions. 16 August 2022. https://assets.lloyds.com/media/35926dc8-c885-497b-aed8-6d2f87c1415d/Y5381%20Market%20Bulletin%20-%20Cyber-attack%20exclusions.pdf

  14. WTW (secondary). Client alert: Lloyd's requirements for state backed cyber attack exclusions. https://www.wtwco.com/en-sg/insights/2022/09/client-alert-lloyds-requirements-for-state-backed-cyber-attack-exclusions

0 views

0

X

Related reading

Does ISO 42001 Require Penetration Testing of Your AI System?
LLM SecurityAdvisories

Does ISO 42001 Require Penetration Testing of Your AI System?

ISO/IEC 42001 has no penetration testing clause. Here is where the AI security testing expectation really comes from and what auditors ask to see.

13 min read

Does NIS2 Require Penetration Testing or Red Teaming? What Article 21 Actually Says
AdvisoriesNetwork Security

Does NIS2 Require Penetration Testing or Red Teaming? What Article 21 Actually Says

NIS2 never mandates a pentest. What Article 21(2) really says, where Implementing Regulation 2024/2690 makes testing binding, and what supervisors ask to see.

12 min read

Does CMMC Require a Penetration Test? Level 1, 2 and 3 (2026)
AdvisoriesNetwork Security

Does CMMC Require a Penetration Test? Level 1, 2 and 3 (2026)

CMMC Levels 1 and 2 require no penetration test. Only Level 3 does, via CA.L3-3.12.1e. Here is what 32 CFR part 170 and NIST actually say in 2026.

16 min read

Contents

X