What a pentest proves
A pentest records what was tested, when it was tested, how the tester reached each finding, and what the business fixed. It gives an underwriter better evidence than a one-word answer such as “yes” beside “Do you test your applications?”
The report only covers its stated scope and test dates. It does not certify the whole company. Keep the scope, rules of engagement, final report, fix records, and retest letter together.
Prepare evidence for the application
Answer the insurer's own form. Do not copy last year's answers. Ask the system owner to confirm each control and attach a dated record.
Identity and access
List where MFA is enforced, which accounts remain exempt, who reviews privileged access, and how fast access ends after a staff exit.
Backups and recovery
Record backup locations, access rules, retention, the last restore test, and the time needed to restore a core payment service.
Testing and remediation
Give the last penetration test date, tested assets, open findings, owners, due dates, and retest results. State every scope limit.
Use the report without exposing secrets
Start with the executive summary, scope, test date, severity totals, remediation status, and retest result. Share the full technical report only through an approved secure channel. It can contain endpoints, system names, screenshots, and steps that help an attacker.
Ask the insurer or broker who needs the report, how it will be stored, and how long it will be kept. Remove customer data, live secrets, and unrelated internal details before sharing.
Keep the application true after submission
A control can change after the form is signed. A new cloud account may lack MFA. A product launch may add an API outside the last test. A backup job may stop. Track these changes and follow the notice rules in the policy and application.
For renewal, compare each old answer with current records. Add new products to the test scope. Close expired staff accounts. Retest critical and high findings. Record accepted risks with an owner and review date.
Match every answer to evidence
Create one row for each application question. Record the answer, control owner, evidence link, check date, known gap, and next review date. This makes false or stale answers easy to find before the form is signed.
Need a pentest and retest package for a cyber insurance application or renewal?
Request a security reviewFrequently asked questions
What does Cyber Liability Insurance cover?
Coverage comes from the policy wording. A policy may cover incident response, legal work, customer notices, business interruption, or third-party claims. Limits, exclusions, deductibles, and conditions control what the insurer pays.
Can a Nigerian startup buy Cyber Insurance?
Yes. The insurer reviews the business, systems, data, controls, loss history, and answers in the application. Prepare clear records for MFA, backups, access control, incident response, security testing, and past incidents.
How does a penetration test lower insurance premiums?
A pentest gives the underwriter current evidence about tested systems and fixed findings. The insurer still sets the premium from its own model. A pentest does not promise a lower price.
Will insurance pay out if we were negligent?
The policy wording and the facts of the claim control payment. False application answers can put coverage at risk. Keep each answer exact, record the evidence behind it, and report control changes during renewal.
Related reading
Blog: Cost of a Data Breach · M&A Due Diligence
Guides: CBN Compliance Guide · Fintech Security Checklist
Services: Penetration Testing · Vulnerability Assessment