Cybersecurity

Your insurer asked for a penetration test. What do they actually want?

In most cases they want a scoped, human-led attempt to get into a defined target, followed by a written report of what was found and what was done about it. An automated scan is not that, and carriers increasingly reject one. The scope they care about is usually your external perimeter.

What the request usually means

Carriers and enterprise clients rarely specify what they want, which is why the request causes so much confusion. Read the question closely. If it asks whether you perform regular penetration testing, it means a scoped test with a report. If it asks about vulnerability scanning, that is a different and cheaper control, and answering one with the other is how questionnaires come back.

The second thing to read is the frequency. Annual is the common ask. Some carriers want a retest after remediation, which changes the engagement you should buy.

The three scopes, and which one they mean

Penetration test scopes

ScopeThe question it answersWhen it is the right one
ExternalCan someone reach anything from the internet that they should not?The default for insurance and most client questionnaires. Start here if the request is unspecified
InternalOnce someone is on the network, how far can they get?Where flat networks, shared credentials, or over-privileged accounts are the real concern
Web applicationCan the application itself be abused, and can one customer reach another customer’s data?Any portal, customer login, or product you built and host

If the questionnaire does not say, external is nearly always the answer. It is also the scope where findings translate most directly into work you can finish before the renewal date.

A scan report is not a test report

Automated scanners are useful, and they belong in an ongoing program. What they produce is a list of things that look wrong, sorted by a severity score, with a meaningful share of it inapplicable to how your systems are actually configured.

A test report says what a person tried, what worked, what that access made possible, and how it was fixed. That difference is the reason a carrier asked in the first place. It is also why anything advertised as costing nothing is almost always a scan with a report template on top.

What should be in the report

  • The agreed scope and the dates, written plainly enough that your carrier or client can read it.
  • The method, including whether the testers were given credentials or worked blind.
  • Findings ranked by what they would actually let an attacker do in your environment, not only by a generic score.
  • Evidence for each finding, so remediation is not guesswork.
  • Remediation guidance specific to your systems.
  • A retest option, so you can show the finding was closed rather than only acknowledged.

How the engagement runs here

A test is scoped against a defined target, run against agreed rules of engagement and a window that does not take production down, then written up with an optional retest. It sits under Cybersecurity & MSSP rather than being sold as a product on its own, because a finding you cannot fix is not worth much.

If the honest situation is that nobody has looked at the environment yet, a test is the wrong first step. An IT assessment costs less and tells you where you stand. Then test the perimeter once the obvious gaps are closed, so you are paying for depth rather than for a list you already knew.

Questions we hear first

How often do we need one?

Annually is the common requirement, and after any significant change to what you expose to the internet. New office, new firewall, new customer-facing application, or a migration all change the answer to the question a previous test answered.

Will it take our systems down?

It should not, and avoiding that is part of scoping. Rules of engagement, a testing window, and an escalation contact are agreed before anything starts. Denial-of-service style techniques are excluded unless you specifically ask for them.

Is a vulnerability scan enough for our insurer?

Sometimes, if the question is about scanning. If the question uses the words penetration test, a scan report is likely to come back. Read the wording, and if it is ambiguous, ask your broker what evidence they will accept before you buy anything. See Penetration Testing for how the scoped version works.

Can you test something your team also manages?

We can, and we will tell you where that overlap sits so you can decide. Some carriers and larger clients require independence from whoever runs the environment. If yours does, we will scope around it or point you to an independent tester.

What does it cost?

It depends on the scope: how many external addresses, how large the application, and whether a retest is included. It is priced as a defined project rather than a monthly fee. Start at Become a Client or call (513) 657-1800 with the questionnaire in front of you.

Cincinnati skyline and Ohio River bridge at dusk

Let's talk about the work.

One conversation covers IT, marketing, or both. We use it to work through goals and what belongs in the first engagement.

Mailing address

6809 Main St · Cincinnati, OH 45244

Email

[email protected]