GetPentest

Cyber insurance and penetration testing

Buying a penetration test to get better cyber insurance terms is usually the wrong order. Underwriters price on controls they can verify from the outside and from your answers, and multi-factor authentication and backups move a Canadian premium far more than a test report does.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Most Canadian cyber insurance applications ask whether you conduct penetration testing and how often. Very few require it, almost none ask to read the report, and no underwriter will price your policy on the strength of your findings. What moves terms is the control set: multi-factor authentication on remote access, email and privileged accounts, tested offline backups, endpoint detection and response, and a patching record. If you have $20,000 CAD and are choosing between a penetration test and rolling out MFA everywhere, roll out MFA.

Asked Testing appears on most applications

Rarely read The report itself, by an underwriter

MFA and backups What actually moves a Canadian premium

What the application actually asks

Typical Canadian cyber application questions, and their weight
QuestionHow much it moves termsWhat proves it
MFA on remote access, email and privileged accountsThe mostConfiguration evidence, sometimes a screen share
Backups, offline or immutable, and tested restoresHighA restore test record with a date
Endpoint detection and response, deployed to what percentageHighConsole coverage figures
Privileged access management and admin account countModerateAn account inventory
Patching cadence for critical vulnerabilitiesModerateTicket records and a written policy
Security awareness training and phishing simulationModerateCompletion rates
Penetration testing, and how oftenModestAn attestation letter with a date
Incident response plan, and whether it has been exercisedModest to moderateA tabletop exercise record

Read that ordering before you spend. Testing is a maturity signal, and maturity signals are worth less than the controls that stop the claims underwriters pay, which in Canada are overwhelmingly ransomware and funds-transfer fraud. Both are addressed by the top three rows.

When testing genuinely changes the answer

  1. You are asking for a high limit. Above roughly $5 million CAD, underwriting gets hands-on and a recent independent test becomes part of a package that includes an architecture conversation.
  2. You are a technology company whose product is the risk. If you host customer data, your own application security is the exposure, and a test of that application is directly relevant in a way that a corporate IT questionnaire is not.
  3. You had an incident. After a claim or a near miss, demonstrating that you tested and remediated is often a condition of continued coverage rather than a discount.
  4. A specific control is being questioned. Where an underwriter doubts your segmentation or your remote access design, a targeted test is a faster answer than an argument.
  5. Your broker says so. Some markets have their own requirements. Ask the broker which carrier and which question, and get the requirement in writing before buying anything.

Answer the application question honestly

Applications are attached to the policy and misrepresentation is a coverage defence. If the question asks whether you perform annual penetration testing and you ran an automated scan, the answer is no, with a note describing what you do. Answering yes on the strength of a scan surfaces during a claim investigation, which is the worst moment to discover the difference. What separates the two is on vulnerability assessment against penetration test.

What to send the underwriter

Not the report. A penetration test report is a map of your weaknesses, and it goes to a broker, an underwriter, a reinsurer and their systems. Send the attestation letter: the firm's name, the dates, the scope, the methodology and a statement that findings were remediated and verified. That is what an underwriting file needs, and it is the same document your customers want. The difference between the two is on report against attestation letter.

If a carrier insists on the report, ask why, ask who will hold it, and ask for it to be returned or destroyed after underwriting. Some will agree. Where a carrier will not, weigh that against the terms on offer. The report is sensitive and copies proliferate.

The Canadian picture

Two things are specific to buying cover in Canada. The first is that a privacy breach involving personal information triggers PIPEDA's reporting obligation to the Office of the Privacy Commissioner and to affected individuals where there is a real risk of significant harm, and Quebec's Law 25 adds its own confidentiality incident regime. Most Canadian policies include breach response costs, and the notification obligation is what drives those costs. Ask whether the policy's breach counsel and notification services are familiar with both regimes, not just US state notification law.

The second is that a Canadian company selling into the United States is usually asked for a penetration test by its customers rather than by its insurer. Buy the test for the customer requirement and treat the insurance question as a by-product. Scoping it for the customer is on how to write a penetration test scope, and the cadence question is on how often you should test.

The order to spend in

Where the next $25,000 CAD goes if the goal is insurability
OrderSpendIndicative cost (CAD)
1MFA on remote access, email and all privileged accounts$0 to $6,000
2Immutable or offline backups, with a tested restore$3,000 to $15,000
3Endpoint detection and response across the fleet$4,000 to $20,000
4An incident response plan and one tabletop exercise$3,000 to $12,000
5External penetration test of the perimeter$7,000 to $16,000
6Application penetration test, if your product holds the data$12,000 to $30,000

Rows five and six move to the top of that list the moment a customer contract asks for them. Then you are not buying insurance terms, you are buying the right to sign a deal.

Work out whether you need a test at all

Six questions, and an honest answer about whether the thing you are being asked for is a test, a scan or a letter.

Which test do you need

Common questions

Does cyber insurance require a penetration test?

Rarely as a condition of cover. Most Canadian applications ask whether you test and how often, and use the answer as one maturity signal among many. Requirements appear at higher limits, for technology companies whose product carries the exposure, and after an incident. Ask your broker which carrier and which specific question before spending.

Will a penetration test lower our cyber insurance premium?

Less than multi-factor authentication, tested backups or endpoint detection and response will. Those three address the claims underwriters actually pay in Canada, which are ransomware and funds-transfer fraud. A test is a maturity signal and is priced like one. If the budget is a straight choice, fix the controls first.

Should we send our pentest report to the insurer?

Send the attestation letter instead. It names the firm, the dates, the scope, the methodology and the remediation status, which is everything an underwriting file needs. The full report is a map of your weaknesses and copies of it spread through brokers, underwriters and reinsurers once you hand it over.

Can we answer yes to the testing question if we run vulnerability scans?

No. The application forms part of the policy and misrepresentation is a coverage defence, so the difference matters at exactly the moment you least want it to. Answer no, and describe what you do run. A well-explained no is treated better by underwriters than a yes that unravels during a claim investigation.

Our insurer asked for evidence findings were fixed. What counts?

A retest letter from the testing firm naming the findings that are now closed. That is stronger than your own ticket export because it is independent, and it is what an auditor asks for as well. Plan the dates so the fixes land inside the included retest window, which is what the retest planner calculates.