A cyber insurance application is now a security audit you sign. It covers identity, endpoints, email, backups, vulnerability management and testing.
Every answer becomes a statement the carrier relies on when you file a claim. This guide is built from published carrier applications from Corvus and Beazley, and covers what underwriters ask, where penetration testing appears, and the evidence to have ready.
What a pentest solves here: Most application questions are self-attested checkboxes. A third-party penetration test is one of the few pieces of evidence that shows whether those controls hold up under a real attack, which is the question the carrier is really pricing.
What Do Cyber Insurers Require Before They Issue a Policy?
Carriers word their questions differently, but the published forms cluster into the same control areas. The table below maps each area to the questions on two real applications.
The sources are the Corvus Smart Cyber Insurance Application (version 3.2, September 2024) and Beazley's Ransomware Supplemental Application (May 2022 edition).
Control area | What the applications ask | Where it appears |
|---|---|---|
Multi-factor authentication | MFA on remote network access, webmail, privileged and domain admin accounts, and critical applications | Corvus Q11, Beazley Q10, Q11, Q13 |
Endpoint protection | Which of EPP, NGAV, EDR, MDR or XDR you run, with the vendor named | Corvus Q13, Beazley Q27 |
Email security | Filtering, attachment and link sandboxing, SPF, DKIM, DMARC, legacy protocols disabled | Corvus Q9, Beazley Q4, Q9 |
Backups | Offline or air-gapped copies, immutability, encryption, MFA on backups, restore test frequency | Corvus Q10, Beazley Q38 to Q44 |
Privileged access | Separate admin accounts, PAM tooling, service accounts with domain admin rights | Corvus Q12, Beazley Q14 to Q26 |
Vulnerability management | Scan coverage and frequency, time to fix critical CVEs, end-of-life software | Beazley Q19, Q34 to Q36 |
Penetration testing | Whether you test at least annually, or how often | Corvus Q17, Beazley Q37 |
Planning and people | Continuity plans, tabletop exercises, phishing training, payment verification | Corvus Q15, Q18, Q19, Beazley Q5, Q45, Q46 |
Penetration testing sits on the list as one control among eight. It's also the only item that checks whether the other seven work.
The list tracks federal guidance closely. The FBI's 2025 IC3 annual report, published in 2026, recommends MFA on webmail, VPNs and critical systems, EDR, network segmentation, prompt patching and offline, immutable backups.
MFA Requirements for Cyber Insurance Go Beyond Email
MFA gets more questions than any other control on both forms. Beazley asks about remote network access, webmail and domain administrator accounts in three separate questions.
Corvus splits it four ways: remote access, privileged accounts, email on every device, and all critical applications. A "yes" for email alone leaves three of those four unanswered. Beazley also treats service accounts separately. It asks how many hold domain admin rights, whether they follow least privilege, and whether interactive logins are denied.
Carriers generally accept SMS and push codes as MFA. CISA's phishing-resistant MFA guidance recommends FIDO or PKI-based methods for privileged and remote access, since weaker methods can be phished or push-bombed.
Before you answer, pull an MFA coverage report from your identity provider. List every exception in the free-text section both carriers provide, because an undisclosed gap is worse than a disclosed one.
Your Application Answers Become Part of the Policy
Beazley's form states that the application and everything submitted with it becomes part of the policy if one is issued. It also obliges you to tell the insurer if your answers change before the policy starts.
AXIS goes a step further on signatures. Its ransomware supplemental must be signed by an officer such as the CEO, CIO, CTO, CSO, CFO or general counsel. The consequence of a wrong answer is on the public record. In July 2022, Travelers asked a federal court in Illinois to rescind a cyber policy it had issued to International Control Services (No. 22-cv-2145, C.D. Ill.).
Travelers alleged the application claimed MFA protected administrative access. The server hit in a May 2022 ransomware attack had none. ICS agreed to rescission, and in late August 2022 the court declared the policy void from inception. That is insurance language for "the policy you paid for never existed."
Answer each question as though the carrier will ask for the evidence after a breach. That is exactly when it will.
Does Cyber Insurance Require a Penetration Test?
No law requires a penetration test to buy cyber insurance. Carriers ask about it, though, and the answer feeds underwriting.
Corvus asks a single yes or no question, whether you conduct penetration testing of your network at least annually. Beazley asks how often you, or a third party on your behalf, test. Beazley's answer options are never, annually, two to three times a year, or quarterly or more often. The form separates annual testing from quarterly testing, so frequency carries weight with the underwriter.
Corvus defines the term in its glossary. A penetration test is a simulated attack, typically performed by an authorized third party, to find vulnerabilities and misconfigurations before attackers exploit them. That definition matters if your only testing is an internal vulnerability scan. Answering "yes" to the penetration testing question stretches it, and Beazley asks about scanning separately in Q34 and Q35.
Whether a pentest is a hard condition of coverage depends on the carrier, the limit you're buying and your industry. Ask your broker whether a missing test changes eligibility, terms or ransomware sublimits in the market you're approaching.
Scan, Automated Pentest or Manual Pentest for Your Application
The three testing types answer different questions on the form. Use the one that matches what you're attesting to.
Attribute | Vulnerability scan | Automated or AI pentest | Manual pentest |
|---|---|---|---|
What it proves | Known vulnerabilities and misconfigurations exist | Which findings are exploitable, with proof-of-concept evidence | Exploitability plus business logic flaws and chained attacks explored by hand |
Answers the pentest question honestly | No, it answers the scanning questions | Yes, when it attempts exploitation and produces a report | Yes |
Cadence it supports | Continuous to monthly | Per release to quarterly | Usually annual |
Evidence for your broker | Scan coverage percentage and remediation times | Report with proof-of-concept exploits and retest results | Report and attestation letter |
A quarterly answer on the Beazley form is only realistic with testing you can rerun without scoping a new engagement each time.
That's the gap automated testing fills. CodeAnt AI runs black box, white box and gray box penetration tests and delivers an audit-grade report within 48 hours, so the quarterly tier stops being aspirational.
For the tradeoffs in depth, see VAPT and how scanning differs from pentesting, how automated penetration testing works, and continuous vs annual penetration testing.
What Your Pentest Report Should Show the Underwriter
A report that satisfies your engineers can still stall an application. Underwriters read for scope, recency and closure.
Include these elements:
Tester identity and independence: who performed the test, and that they're independent of the team that built the systems.
Scope: internet-facing applications, remote access and systems holding customer data, since those map to the MFA and data questions. Define it with a written penetration testing scope of work.
Test date: within the last 12 months, to match "at least annually" wording.
Severity breakdown: finding counts by severity, with CVSS scores.
Remediation and retest status: critical and high findings closed and verified by a penetration test retest. This also supports your answer to Beazley's question on critical CVE remediation time.
Executive summary: a short version you can hand to the broker without exploit detail.
Send the executive summary and an attestation letter to the broker. Keep the full technical report internal unless the carrier asks for it under confidentiality terms.
Carriers Also Test You From the Outside
Your answers aren't the only input. Corvus states on its application that it scans the applicant's primary corporate website and affiliated sites, and includes high-level results in the quote.
The underwriter may therefore see your external exposure before reading a single answer. Beazley also asks directly whether remote desktop software such as RDP is exposed to the internet.
Finding out about an exposed RDP port from your insurance quote is an expensive way to learn about your own network. Run an external penetration test before you apply, so nothing in the carrier's scan comes as a surprise.
How to Prepare for Your Next Renewal
Start about 90 days before the renewal date. That leaves time to fix findings and retest before you sign.
Get the current forms. Ask your broker for the carrier's latest application and every supplemental, since questions change between editions.
Assign an owner per control area. Each owner collects dated evidence, such as EDR deployment percentage, an MFA coverage report and a backup restore test log.
Test, fix and retest. Run external and application testing, then an internal penetration test if the form asks about lateral movement controls such as segmentation. Close critical and high findings, prioritized with CVSS, EPSS and CISA KEV.
Reconcile every answer with evidence. Where coverage is partial, say so and explain it in the free-text section.
Keep the package current. Beazley's form requires you to report changes before inception, so re-check the evidence after any major infrastructure change.
The same report often doubles as evidence for other audits. See how it maps to SOC 2 penetration testing requirements and compliance penetration testing more broadly.
Where This Leaves You
Cyber insurance requirements come down to controls you can prove on the day you sign. MFA, EDR, backups and patching get the most questions, and a recent penetration test is the evidence that ties them together.
Start 90 days out, match your evidence to the exact questions on your carrier's form, and treat every answer as part of the contract. For budgeting the testing piece, see penetration testing cost in 2026.


