Most cyber insurance policies do not name penetration testing as a strict box to tick. But a growing number of UK insurers ask for evidence of one before they quote a serious policy. After a claim, some point to the absence of testing as a reason to cut or refuse the payout. If you are buying or renewing cover for ransomware, a data breach or lost trading time, cyber insurance penetration testing is worth understanding properly. It matters as much as the price of the premium.

Table of Contents
What cyber insurance penetration testing actually means
Insurers and brokers often use the word “testing” loosely. That is where most of the confusion starts. The National Cyber Security Centre defines penetration testing as a way of checking a system’s security. Testers try to break in, using the same tools and tricks a real attacker might use. The NCSC compares it to a financial audit. It is quite different from a vulnerability scan, which just flags known weaknesses on a list.
A vulnerability scan is cheap and fast. Run it often. A penetration test is slower and costs more. A tester actively chains weaknesses together, the way a real attacker would. When your insurer’s form asks if you “test” your systems, read the wording with care. Some insurers accept a recent scan. A growing number now ask for manual, hands-on testing before they offer real ransomware or business interruption cover.
When a penetration test becomes a condition of cover
Cyber insurance penetration testing is not required on every policy from day one. There is no single UK-wide rule here. The threshold depends on your insurer, your sector, and how much cover you want. Even so, a clear pattern has emerged. Once your premium or coverage limit passes a certain size, underwriters tend to ask for a dated penetration test report. The same is true once you handle card data, health records or client money. A simple self-assessment form is no longer enough.
The gap between demand and reality is wide. The government’s Cyber Security Breaches Survey 2025/2026 found that 47% of UK businesses carry some form of cyber insurance. Only 13% had carried out a penetration test in the past year. Many policyholders are, in effect, buying cover for a level of assurance they have not actually put in place. That gap is exactly where a claim can unravel.
Scan or test: how insurers tell the two apart
| Question | Vulnerability scan | Penetration test |
|---|---|---|
| Who runs it | An automated tool, often unattended | A qualified human tester, working by hand |
| What it finds | Known, catalogued weaknesses | Real attack chains a scanner would miss |
| Usually accepted for | Lower-limit or lower-risk policies | Higher-limit, ransomware or business interruption cover |
| What the report proves | A list of flagged issues | Someone actually tried to break in, and what happened next |
Insurers rarely publish one fixed rule for what counts as cyber insurance penetration testing. Use this table as a starting point when you read your own questionnaire. If the wording says “independent” or “adversarial,” assume they mean the right-hand column: real penetration testing, not a scan.
Does business size change what insurers expect?
A little, though not the way most owners assume. The same government survey found that 42% of micro businesses and 46% of small businesses had a breach or attack in the past year. That compares to 65% of medium and 69% of large businesses. Bigger firms get hit more often simply because they are a wider target. Insurers tend to raise their testing expectations as coverage limits rise, not as headcount rises. A ten-person firm with a high policy limit can face the same bar as a much larger one. Do not assume your size alone keeps you below the threshold.
What happens if you skip cyber insurance penetration testing
Cyber policies often include a warranty. This is a promise you made about your security when you applied. If that promise turns out to be untrue, the insurer can cut or refuse your payout. Say your renewal form claims you test regularly, but you have never actually commissioned a test. That gap becomes a real liability the moment you file a claim. Insurers look closely at the circumstances of a breach. A gap between what you declared and what you can prove is a common reason cover gets disputed.
The Association of British Insurers is pushing the opposite message to UK SMEs. Take up more cover, not less. Risk is high, but take-up still lags behind it. Their guidance treats testing and insurance as partners, not as substitutes. A test will not replace good patching or staff training. But it gives you, and your insurer, dated and independent proof that your defences were actually checked.
What your report needs to show an insurer
Good cyber insurance penetration testing produces a report that survives insurer checks. It usually needs a few specific things:
- A scope that covers your internet-facing systems, not just one internal server.
- A test date inside the last 12 months. Older reports carry little weight once you have changed your infrastructure.
- Proof that findings were actually fixed, not just listed. A retest or written confirmation both work.
- A named, credentialed provider, ideally CREST-accredited or working to a recognised standard.
If your business already holds Cyber Essentials or Cyber Essentials Plus, do not assume it is the same evidence. CE+ relies on automated scanning and configuration checks. It does not involve a tester actively exploiting your systems. Most insurers who specifically ask for a penetration test will not accept a CE+ certificate in its place.
Getting ready for renewal
Start by reading your policy wording or questionnaire literally. Do not guess what “testing” means. Then work out what scope actually matches your risk. An external network test alone will not reassure an insurer if your real exposure sits in a customer-facing web application or an API that takes payments. Aardwolf Security can scope a penetration test around what your insurer’s questionnaire is actually asking for. The report you get back should answer the underwriter’s question the first time. Get in touch with our team before you renew, and we can talk through exactly what to commission.
Frequently asked questions
Do all cyber insurance policies require a penetration test?
No. Smaller policies often accept a self-assessment questionnaire or a vulnerability scan instead. Cyber insurance penetration testing becomes a real condition once you want larger limits, sit in a higher-risk sector, or want enhanced ransomware cover.
How often do insurers expect a new test?
Once a year is the common baseline. Most underwriters also want a fresh test after any big change to your systems, such as a new external service or a cloud migration.
Will a vulnerability scan satisfy my insurer?
Sometimes, for lower-risk policies. Once an insurer specifically asks for penetration testing, a scan alone is unlikely to pass. It does not involve a tester actually exploiting weaknesses the way an attacker would.
What if my last penetration test is more than a year old?
Treat it as expired for insurance purposes. An old report will not reflect changes made to your systems since. If an insurer finds this out during a claim, they may challenge your cover on that basis.
Does the type of test matter for insurance?
Yes. Match the scope to your real exposure, whether that means external network, web application or cloud configuration. Do not just commission whatever test is cheapest.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.