Six to ten weeks before renewal, someone forwards you the ransomware supplemental and asks whether buying a penetration test now will bring the premium down. No carrier publishes a rate credit for holding a pentest report, and the forms show why. Carriers do ask about testing, but shallowly: a yes or no, a frequency band, and on the better forms a testing type. MFA coverage, endpoint detection breadth, privileged access and backup recoverability are graded question after question, across whole pages.
That does not make testing pointless. It changes what testing is for. A pentest buys the ability to answer the security questions truthfully and to attach evidence when an underwriter or, later, a claims adjuster asks you to prove it. The failure mode on these forms is not a higher premium. It is a rescinded policy.
The honest answer on premium: what actually moves the number
Start with the market, which is doing most of the work. Marsh's Global Insurance Market Index for Q2 2026, published 23 July 2026, reported cyber insurance rates down 4 percent globally, the twelfth consecutive quarter of declines, with the US down 2 percent. The Q1 2026 index recorded a 5 percent global decline. If your renewal comes in flat or lower, the base case is competition and capacity, not your report.
The NAIC's Report on the Cybersecurity Insurance Market, drawing on the 2024 Cyber Supplement, records the first ever reduction in US cyber direct written premium: roughly $9.14 billion in 2024, a 7 percent decrease from $9.84 billion in 2023 including alien surplus lines. Reported claims rose almost 40 percent over the same period, to nearly 50,000. Falling premium against rising claim frequency makes underwriters more selective about controls, not more generous about testing, and the NAIC is explicit about what earns underwriter favour: continued investment in cybersecurity controls.
The same ordering shows up in a real form. AXIS puts cyber applicants through two documents: the AXIS Cyber Application, form AXIS 1012098 0122, and the AXIS Cyber Ransomware Supplemental Application, form AXIS 1012729 0122, signed by an authorized officer of the entity named on the main application. Penetration testing is asked about once, on the main application. The supplemental, the document that exists to price ransomware risk, never raises it again. Here is what it grades instead.
The AXIS supplemental grades | Granularity it demands |
|---|---|
EDR deployment | Separate percentages for endpoints and for servers, plus the product name |
MFA | Yes or no across five access categories: remote access, critical information, personal devices, third party and vendor access, and non-critical applications, plus whether the second factor is SMS or lands on a non-corporate device |
Privileged access | Whether a PAM tool exists, whether PAM access is itself behind MFA, and the count of accounts in the Domain Admin group |
Patching | Critical patch target in bands from under 24 hours to over 7 days, plus a routine band |
Backups | Immutability, offline and offsite storage, whether encryption keys are held offline, whether backup credentials are separate, and how often a full recovery is tested |
Recovery | Recovery time objective band, and whether it was validated in the last 12 months |
Penetration testing | Not raised. The word does not appear on the supplemental at all |
Now compare that with the main application. Under a heading of "Testing & Scanning", AXIS asks whether the applicant conducts regular penetration testing, how frequently, and whether it is in-house or outsourced. Three lines, and that is the whole of it. Carriers do not ignore testing; they ask it as a single yes with a frequency band attached, while the controls beside it are interrogated to the percentage point. A pentest earns you the right to write that yes. It is not a lever on the rate.
AXIS's later revision, form AXIS 1012098 0623, treats testing more granularly than any other form in this sample. Section 5.2, headed "Pen Testing", asks which types the applicant runs and a frequency for each: external network, internal network, social engineering, physical and web application, against quarterly, twice a year, annually, ad hoc or never, plus whether testing is internal or outsourced. If your revenue runs through a web application and you have only ever bought an external network test, the gap shows up in one row.
Where testing does show up on the form
AXIS is not unusual in asking. What varies is the framing, and AIG's makes testing interchangeable with tooling. AIG Australia's CyberEdge Ransomware Supplemental Questionnaire runs roughly 17 pages of control questions across eight domains, from data security and business continuity through identity and access management, security monitoring and incident response, risk management, phishing and malware defence, and perimeter defence.
Penetration testing is named exactly once, in the security monitoring and incident response section, in a question asking how the applicant validates the efficiency and effectiveness of its security controls. Three responses are on offer: breach and attack simulation software; having a red team on staff, or at least annually engaging experts to perform a "penetration test focused on internal systems"; and having engaged an external party to simulate threat actors and test security controls in the last year. A separate question in the malware defence section asks whether the applicant has run an exercise simulating the tactics, techniques and procedures of ransomware actors in the last year. Adversary simulation therefore appears in two sections; penetration testing is named in one.
Three things follow. Penetration testing is one of several interchangeable ways to evidence control validation, with simulation tooling scoring alongside it. The wording is time-bound twice over, at least annually for the standing arrangement and within the last year for the external simulation. And the penetration testing option specifically is scoped to internal systems, so a web application test answers the AXIS web application row rather than this one; the external simulation option carries no such limit.
Note the form's default too. AIG reads a blank response as a no, or as not having that control, unless the question itself offers a No, Don't Know or None of the Above option. Where it does not, silence is not neutral.
Warranty, misrepresentation and rescission: why a wrong answer is a coverage problem
It is common to hear that application answers become warranties. In the UK that is now legally wrong; in the US it is imprecise. The real mechanism is misrepresentation, and it is worse, because it reaches the whole policy rather than one claim.
The AXIS representations section is the model. The signatory represents that the statements submitted are true, accurate and complete; that no facts material to the risk have been misstated or concealed; that those representations are a material inducement to the insurer; and that any policy is issued in reliance on them. The application and everything submitted with it is deemed part of the policy, and a named officer must sign, from chief executive through CIO, CSO or general counsel. Not a form the security team fills in anonymously.
Jurisdiction | Mechanism | Consequence of a material misstatement |
|---|---|---|
US | Misrepresentation, policy issued in reliance on it | Rescission: the policy can be declared void from inception, so no claim under it is payable |
UK (non-consumer) | Insurance Act 2015 section 3, duty of fair presentation | Deliberate or reckless breach lets the insurer avoid the contract, refuse all claims and keep the premium. Otherwise Schedule 1 gives graduated remedies: avoidance with the premium returned if the insurer would not have written the risk at all, the contract treated as written on the terms the insurer would have imposed, or a reduced percentage paid |
UK (non-consumer) | Insurance Act 2015 section 9(2) | A representation cannot be converted into a warranty by a basis-of-contract clause or otherwise, so the warranty framing does not survive |
Australia | Duty of disclosure, per the AIG CyberEdge documentation | The insurer may cancel the contract, reduce what it pays, or both. Where the failure is fraudulent it may refuse the claim and treat the contract as if it never existed |
The US mechanism is not theoretical. In Travelers Property Casualty Company of America v. International Control Services, Inc., No. 2:22-cv-02145 in the Central District of Illinois, Travelers sought rescission of a cyber policy after a ransomware incident, alleging the insured had represented that MFA was required across email, remote network access, endpoints, servers and directory services when in practice it protected only the firewall, not the attacked server. On 26 August 2022 the parties stipulated to a judgment rescinding the policy from inception, and the case was dismissed with prejudice. The insured did not lose an argument about how much cover applied. It lost the policy.
The obligation continues after signature. The AXIS representations include a duty to report immediately, in writing, any material change to the answers between the application date and the policy effective date, with the insurer free to modify or withdraw its proposal. A critical finding landing inside that window may be a disclosure event, not just an engineering ticket.
The four-document evidence pack to attach at renewal
Underwriters rarely specify a document list, so applicants attach nothing, or attach the full technical report, which should not leave the organisation. Four items survive a claims-time review.
Completion letter with dates. One page naming the testing firm, its accreditation, the engagement type, start and end dates and an overall risk statement, with no exploitable detail. See pentest completion letter vs full report.
Scope statement naming what was and was not tested. This is the item that protects you. A letter saying testing was completed invites the adjuster's later question of whether the tested scope included the breached system.
Remediation status by severity. Counts by severity, how many are closed, and target dates for the rest. An open critical with a dated plan reads better than an unexplained gap.
Retest date. Evidence the fixes were verified rather than claimed.
Scan vs pentest: a distinction the forms themselves draw
When the form asks about testing and the budget is gone, the temptation is to submit a vulnerability scan as a penetration test. Do not: carriers already separate the concepts on the same form. On the AIG questionnaire, the risk management section asks whether the applicant runs a vulnerability scanning programme covering its vital assets, and the perimeter section asks separately about regular scanning of externally exposed assets and whether it happens at least monthly. Penetration testing sits in a different section entirely, in the security monitoring and incident response control validation question. A carrier that asks about scanning three times and names testing once has plainly not confused them.
AXIS draws the same line inside a single heading: its "Testing & Scanning" subsection asks about regular penetration testing and its frequency, then separately about regular vulnerability scanning and its frequency. Two questions, two independent frequency ladders.
The practical test: a scanner reports that a condition exists; a penetration test demonstrates what an attacker reaches by chaining conditions, with a named tester on the report. If your evidence has no exploitation narrative, it answers the scanning questions, not the testing one. For the compliance-side version, see penetration testing vs vulnerability assessment.
What "annual testing" means when your last test was 14 months ago
The AIG wording answers this without ambiguity. The standing-arrangement option is phrased as at least annually; the external simulation option as within the last year. Fourteen months is outside both, and on that form there is no partial-credit box.
AXIS puts the same horizon in ladder form and does give you a box for the truth: its 0623 application offers quarterly, twice a year, annually, ad hoc or never for each testing type. Fourteen months is not annually. "Ad hoc" is the honest selection, and it reads very differently in the underwriter's file.
This is stricter than the compliance version of the question. An auditor assesses a control over a period and may accept a documented slip; an insurance answer is a point-in-time statement relied on in issuing a policy. If the report is stale on the day you sign, the honest answer is no. More on report shelf life: is your pentest report still valid.
Timing: how far ahead of renewal to test
Work backwards from the submission date, not the renewal date, leaving room for remediation.
Weeks before renewal | Action |
|---|---|
10 to 12 | Pull last year's application and supplemental. Identify every answer you could not evidence today |
8 to 10 | Commission testing covering the scope your answers claim. Fix the control gaps the form grades hardest, because MFA coverage and backup recovery testing move the file most |
4 to 6 | Retest, close what can be closed, write the remediation status by severity |
2 to 4 | Assemble the four-document pack and brief the broker on the control narrative |
Inside 2 | Answer accurately, disclose the scheduled test, and treat any material change before the effective date as a reporting obligation |
If you are already inside the window, improve the risk before the next cycle rather than the answer before this one. A rescinded policy costs vastly more than a slightly higher premium; the arithmetic of testing continuously is in the budget case for continuous penetration testing.
What to tell your broker so the submission reads as a better risk
Lead with the controls the forms grade, in the order they grade them: MFA coverage by access category, EDR split between endpoints and servers, privileged access management including the domain admin account count, backup immutability with the date of the last full recovery test, and the RTO with the date it was last validated. Then present testing as evidence those controls hold under attack, naming the types you run and the frequency of each, because that is the shape the AXIS form asks for, with the four-document pack behind it.
Ask which exclusions apply too, because coverage scope can matter more than price: Lloyd's Market Bulletin Y5381, issued 16 August 2022, required state-backed cyber-attack exclusions in standalone cyber-attack policies from 31 March 2023 at inception or renewal, and the Lloyd's Market Association published model clauses LMA5564 to LMA5567 that differ materially in what they claw back. If you have had an incident in the period, get the facts straight before the form goes in; see ransomware payout statistics and emergency pentest after a security incident.
Stingrai is a CREST-accredited penetration testing service provider at firm level, with 18 published CVEs and 5.0 out of 5.0 across 19 Clutch reviews. Our Snipe agent tests web applications and APIs autonomously, black-box and white-box, and opens AutoFix pull requests with PR-gating so findings close inside the development cycle. Hybrid engagements add human validation of every finding, which is what makes the completion letter and scope statement defensible when an adjuster reads them a year later. Autonomous testing starts at US$3,000 one-time or US$450 per month, hybrid at US$6,800 one-time or US$1,275 per month on a 12-month engagement; terms are on the pricing page. The deliverables support your insurance submission and your SOC 2 or ISO 27001 programme.
Buy the test because you intend to answer a question truthfully. The premium will do what the market tells it to.
Frequently Asked Questions
Does cyber insurance require a penetration test?
Not as a universal precondition to coverage, but carrier applications do ask directly, so plan to answer. The AXIS Cyber Application, form AXIS 1012098 0122, asks whether the applicant conducts regular penetration testing, how frequently, and whether testing is in-house or outsourced; its 0623 revision breaks the question out by testing type including a dedicated web application row. AIG Australia's CyberEdge ransomware supplemental instead names penetration testing once, as one option in a question about validating control effectiveness. How much the answer weighs depends on the carrier's form.
How much does a pentest reduce cyber insurance premiums?
There is no published rate credit for holding a penetration test report, and any specific percentage quoted to you is a sales claim rather than a filed rate. Marsh reported global cyber rates fell 4 percent in Q2 2026, the twelfth consecutive quarterly decline, with the US down 2 percent. What testing changes is which answers you can defend with evidence.
What documents does a cyber insurance underwriter want from a pentest?
Underwriters rarely specify a list, so submit four items: a completion letter naming the testing firm, engagement type and dates; a scope statement listing what was and was not tested; remediation status by severity; and a retest date proving fixes were verified. Never send the full technical report, which carries reproduction steps and belongs inside your organisation.
Can an insurer deny a claim because of a wrong answer on the application?
It can go further and rescind the policy entirely. In Travelers Property Casualty Company of America v. International Control Services, Inc., No. 2:22-cv-02145 in the Central District of Illinois, the parties stipulated on 26 August 2022 to a judgment rescinding a cyber policy after Travelers alleged the applicant had misstated its multi-factor authentication coverage. In the UK the Insurance Act 2015 gives graduated remedies under Schedule 1: for a deliberate or reckless breach the insurer may avoid the contract, refuse all claims and keep the premium; for other breaches it may avoid and return the premium if it would not have written the risk at all, or else apply the contract on different terms or reduce the payout proportionately.
Is a vulnerability scan enough for a cyber insurance application?
It is enough for the scanning questions and not for the testing question. AIG Australia's CyberEdge supplemental asks about a vulnerability scanning programme in its risk management section and about external scanning frequency in its perimeter section, while naming penetration testing only in its security monitoring and incident response section. The AXIS Cyber Application puts both under one "Testing & Scanning" heading as two separate questions with two separate frequency ladders. Answering the testing question with scan output misstates a matter the insurer keeps distinct.
How recent does a penetration test have to be for insurance?
Where carriers time-bound the question they use a twelve-month horizon. AIG Australia's CyberEdge supplemental phrases its options as at least annually for a standing arrangement and as within the last year for an external threat-actor simulation, with no partial-credit option. The AXIS 0623 application offers quarterly, twice a year, annually, ad hoc or never for each testing type. A fourteen-month-old report is not annual testing, so the honest answers are no on the AIG form and ad hoc on the AXIS one.
Do I need a pentest before renewing cyber insurance?
You need it only if you intend to answer yes to a testing question, and you should commission it eight to ten weeks before submission so there is time to remediate and retest. Buying a test purely to lower the premium is a weak business case, because these forms grade MFA coverage, endpoint detection, privileged access and tested backups in far more detail. Buying it so your answers are defensible is a strong one.
What is a ransomware supplemental application?
It is an additional questionnaire attached to a cyber insurance application, focused on the controls that determine ransomware outcomes. The AXIS version covers intrusion detection, EDR coverage percentages for endpoints and servers, multi-factor authentication across five access categories, privileged access management, patching timelines, network segmentation, phishing simulation results, backup immutability and recovery testing, and recovery time objectives. It is signed by a named senior officer and forms part of the policy.
References
Marsh. Global commercial insurance rates fall 6% in Q2 2026. 23 July 2026. https://www.corporate.marsh.com/news-events/2026/july/global-commercial-insurance-falls-6-percent-q2-2026.html
Marsh. Global commercial insurance rates fall 5% in Q1 2026. 22 April 2026. https://www.marsh.com/en/about/media/global-commercial-insurance-rates-fall-5-percent-in-q1-2026.html
NAIC. Report on the Cybersecurity Insurance Market (2024 data year). https://content.naic.org/sites/default/files/inline-files/2025_Cybersecurity_Insurance%20Report.pdf
AXIS Insurance. AXIS Cyber Application, form AXIS 1012098 0122. https://www.axiscapital.com/docs/default-source/default-document-library/axis-1012098-0122.pdf
AXIS Insurance. AXIS Cyber Technology and MPL Application, form AXIS 1012098 0623. https://www.axiscapital.com/docs/default-source/resources/axis-1012098-0623-axis-cyber-technology-mpl-application-7-20-23.pdf
AXIS Insurance. AXIS Cyber Ransomware Supplemental Application, form AXIS 1012729 0122. https://www.axiscapital.com/docs/default-source/default-document-library/axis-1012729-0122.pdf
AIG Australia Limited. CyberEdge Ransomware Supplemental Questionnaire. https://www.aig.com.au/content/dam/aig/apac/australia/documents-new/financial-lines/cyber/aig-au-cyberedge-ransomware-supplementary-proposal-form.pdf.coredownload.pdf
US District Court, Central District of Illinois. Travelers Property Casualty Company of America v. International Control Services, Inc., No. 2:22-cv-02145. https://dockets.justia.com/docket/illinois/ilcdce/2:2022cv02145/86760
US District Court, Central District of Illinois. Complaint (Dkt. 1), Travelers Property Casualty Company of America v. International Control Services, Inc., No. 2:22-cv-02145. 6 July 2022. https://storage.courtlistener.com/recap/gov.uscourts.ilcd.86760/gov.uscourts.ilcd.86760.1.0.pdf
Insurance Journal (secondary, trade press). Travelers, Policyholder Agree to Void Current Cyber Policy. 30 August 2022. https://www.insurancejournal.com/news/national/2022/08/30/682564.htm
UK Parliament. Insurance Act 2015, section 9. https://www.legislation.gov.uk/ukpga/2015/4/section/9
UK Parliament. Insurance Act 2015, Schedule 1. https://www.legislation.gov.uk/ukpga/2015/4/schedule/1
Lloyd's. Market Bulletin Y5381: State backed cyber-attack exclusions. 16 August 2022. https://assets.lloyds.com/media/35926dc8-c885-497b-aed8-6d2f87c1415d/Y5381%20Market%20Bulletin%20-%20Cyber-attack%20exclusions.pdf
WTW (secondary). Client alert: Lloyd's requirements for state backed cyber attack exclusions. https://www.wtwco.com/en-sg/insights/2022/09/client-alert-lloyds-requirements-for-state-backed-cyber-attack-exclusions



