1. Cyber insurance concerns SMBs too
Cyber insurance covers the consequences of an incident: business interruption, remediation costs, handling a data breach, sometimes liability toward third parties. Long reserved for large organisations, it is now spreading to SMBs, as they increasingly become regular targets.
At the same time, insurers have tightened their conditions. Taking out a policy is no longer a simple administrative formality: the insurer wants to understand your exposure before setting a price — or accepting the risk. That is where a penetration test comes in.
2. How insurers assess the risk
Most insurers rely on an underwriting questionnaire. It generally covers security measures considered essential, for example:
- multi-factor authentication (MFA) on sensitive access;
- your backup policy and restore testing;
- patch and update management;
- vulnerability testing and detection practices.
The answers to this questionnaire influence the insurer's decision and the terms offered. The precise requirements and their weighting vary from one insurer to another: there is no universal scale, and this article does not replace the terms of your own contract.
3. Self-declared answers don't prove security
The questionnaire has a structural limit: it is self-declared. Answering "yes, we apply patches" says nothing about the real state of the system at a given moment. A forgotten configuration, a service exposed by mistake or a vulnerable component can coexist with perfectly honest answers.
This difference matters. In the event of a claim, an insurer may check the accuracy of the statements made when the policy was taken out. Having objective evidence of your security level — and not only declarations — protects your file on both sides: when subscribing and after an incident.
4. What a penetration test demonstrates
A penetration test does not merely list theoretical flaws: it actually attempts to exploit them, the way an attacker would. At pentestaas, the engine runs four phases — reconnaissance, exploitation, post-exploitation and pivot — drawing on more than 200 attack modules, with every result mapped to the MITRE ATT&CK framework.
The deliverable is a report (HTML, PDF, JSON) that ranks risks by severity and proposes remediation steps. For an insurance file, this report brings three things a questionnaire does not:
- a dated snapshot of your real exposure;
- the distinction between theoretical flaws and genuinely exploitable ones;
- a record of the fixes applied, by re-running the test after remediation.
5. Using the report in your insurance file
In practice, a penetration test report can support your insurance process in several ways:
- When subscribing: documenting that you really test your exposure, not just tick boxes.
- In negotiation: demonstrating an active security approach can support more favourable terms. The final price, however, remains in the insurer's hands and depends on your whole risk profile — a pentest guarantees no specific reduction.
- After an incident: proving that reasonable, documented measures were in place at the time.
A test replayed at regular intervals reinforces this further: it shows not a one-off effort but a continuous approach to reducing risk — exactly what an insurer-policyholder relationship values over time.
6. Where to start
You don't need an in-house security team to produce a first actionable report. pentestaas offers the test on a self-service basis, starting at €350 excl. VAT per month: you declare the authorised scope, the engine runs the phases, and the report turns the results into prioritised actions — usable both to fix issues and to support your insurance file.
Going further: see how the product works or compare plans and pricing.
This article is published for informational purposes and does not constitute insurance advice. Coverage, requirements and pricing conditions depend on each insurer and on your contract. A penetration test must always be run within an authorised, documented scope.