Currently dealing with a breach or active incident?Call 406-924-3731×
≡
Blog

What a penetration test report should include for your cyber insurer

Cyber insurers now use penetration test reports to underwrite policies and settle claims. The seven sections a carrier-ready report needs, and when to test before renewal.

By Big Sky Support

What a penetration test report should include for your cyber insurer
PUBLISHED
March 4, 2026
READING TIME
7 min read
CATEGORIES
Penetration Testing
Compliance
Small Business
Insurers read your report
Pentest reports now drive underwriting, pricing, and claim decisions.
Seven sections, minimum
Scope, methodology, tools, findings, proof, remediation, and an executive summary.
Test 60 to 90 days early
Leave time to fix critical issues and retest before your renewal.

Serious findings aren't what worries an underwriter. Serious findings with no remediation plan are.

Cyber insurers no longer accept "we're secure, trust us" on a checkbox questionnaire. They want evidence. A penetration test report is now one of the main documents underwriters and claims teams use to decide whether to insure you, what to charge, and whether to pay when something goes wrong.

If you run a Montana healthcare organization, law firm, or business, the quality of your next pentest report can directly affect your insurability, your premiums, and how your carrier treats you after a breach.

Why insurers care so much about your pentest report

Insurers have taken heavy losses on cyber claims in recent years, and they've tightened up in response. They no longer trust self-reported questionnaires without proof. Your report matters at two moments.

Underwriting and renewal. Underwriters use the report to assess your real risk, understand your external and internal weaknesses, and confirm that controls like MFA, segmentation, and incident response actually exist, not just on paper. Strong, recent testing can improve eligibility and often helps with better terms.

Claims after a breach. When you file a claim, carriers may review past pentest reports to see what you knew and what you did about it. If a breach exploited a critical vulnerability that was documented and never fixed, expect tough questions and possible coverage disputes.

For Montana organizations, that makes a pentest report more than internal security documentation. It's part of your financial defense when a cyber crisis hits.

Seven sections every insurer-ready report needs

  1. Scope and objectives. A clear list of the systems, networks, applications, and environments tested, along with testing dates, locations, and whether the engagement was external, internal, web application, cloud, or a mix. This lets carriers match the report to the assets on your insurance application.
  2. Methodology. A high-level description of the phases, from reconnaissance and vulnerability analysis through exploitation, post-exploitation, and reporting, with reference to recognized standards like NIST SP 800-115 or the OWASP Web Security Testing Guide.
  3. Tools and techniques. A summary of the major tools and frameworks used, with enough detail for an insurer to see the test went beyond a simple vulnerability scan.
  4. Findings ranked by risk. Vulnerabilities rated Critical, High, Medium, or Low, often with CVSS scores, and prioritized by what would actually hurt your business rather than by severity score alone, with clear impact statements like "allows unauthenticated access to PHI" or "permits lateral movement toward domain controllers."
  5. Proof of concept evidence. Screenshots, logs, or excerpts showing how issues were found or exploited, which proves the vulnerabilities are real and the test was conducted as described.
  6. Remediation guidance and priorities. Concrete recommendations for fixing each issue, like configuration changes, patches, or architectural improvements, with a prioritized plan and suggested timelines by severity.
  7. Executive summary. One to three pages explaining overall risk, the top issues, and remediation progress in plain language. This is what underwriters, executives, and boards read first.

If your existing reports are missing any of these, expect your insurer to push back or ask for more detailed documentation during underwriting or a claim.

Mapping the report to frameworks and your policy questions

Insurers think in frameworks and controls, not tool names. The more your report lines up with how they see the world, the easier things get. Strong reports increasingly map findings to NIST or ISO 27001, reference OWASP categories for web and API issues, and tie findings directly to common questionnaire items, like MFA on remote access and privileged accounts, segmentation between critical systems and user networks, and logging, monitoring, and incident response capability.

For our clients, we typically align reports with both industry frameworks and a checklist that mirrors what carriers and brokers are asking right now.

Timing: how recent does the report need to be?

Most carriers only consider a pentest report relevant if it's recent. In general, underwriters want at least one full penetration test within the last 12 months, some carriers prefer a 6- to 12-month cadence for higher-risk industries like healthcare and financial services, and a report older than a year may trigger a request for new testing or evidence of ongoing vulnerability management.

In practice, schedule penetration testing 60 to 90 days before renewal. Use that window to fix critical issues and, where possible, get a short retest report confirming the high-risk findings were remediated. Your renewal package then shows not just that you found problems, but that you fixed them and verified the fix.

Common report problems that frustrate insurers

Plenty of pentest reports work fine for internal IT but cause trouble with insurers:

  • Scan-only deliverables. The "pentest" turns out to be a vulnerability scan with no exploitation, no attack path analysis, and little human insight.
  • No severity or prioritization. Long lists of issues with no risk ratings or guidance on what to fix first, leaving underwriters no way to gauge real exposure.
  • Unclear scope. No clear statement of what was tested, on what dates, and with what level of access.
  • No remediation dates or status. No indication of which findings were fixed, accepted, or still open when the report was submitted.
  • Over-redaction. Redaction is good practice, but remove too much and the carrier can't verify the test was meaningful.

Insurers aren't looking for perfection. They're looking for honesty, structure, and progress. A messy report with no prioritization can raise more questions than it answers.

How to share reports securely with brokers and carriers

A penetration test report is sensitive. It tells the reader exactly how to hurt you. You need to share it, but share it carefully:

  • Use secure portals. Many carriers and brokers offer encrypted upload portals or secure messaging. Use them instead of email attachments.
  • Share the summary and targeted sections. Often the executive summary, scope, and a list of critical findings with remediation status is enough, without the full technical appendix.
  • Redact specific exploit details where appropriate. It's reasonable to remove IP addresses, hostnames, and sensitive exploit payloads while keeping enough context for underwriters to assess risk.
  • Keep a distribution log. Track who received which version of the report, for both security and legal defensibility.

We frequently work directly with brokers to balance what the insurer needs to see with keeping your environment secure.

Turning your report into an asset at renewal

For many Montana organizations, the penetration test report has lived on the IT side of the house as a technical artifact. Today it's a business document that affects your ability to transfer risk and survive a major incident.

We design penetration tests with cyber insurance and crisis response in mind, and structure reports so brokers, carriers, executives, and regulators all see the same thing: you're serious about finding weaknesses before attackers do, and about fixing them quickly when you find them.

FAQ

Common questions

Short answers to the questions we hear most about this topic.

Can we send a redacted penetration test report to our insurer?

Usually, yes. Most carriers accept redacted copies as long as they still include the scope and methodology, severity-ranked findings, and remediation status with dates. You can often remove highly sensitive technical details and exploit payloads. Coordinate with your broker on how much detail is enough.

Do pentesting-as-a-service platforms produce acceptable evidence for insurers?

They can. Platforms that produce structured reports with clear scope, methodology, severity ratings, and remediation tracking are usually acceptable. If the report is a raw scan dump or a dashboard screenshot, expect questions. Insurers care more about depth and clarity than about how the test was delivered.

What if our penetration test report has really bad findings?

Serious findings aren't the problem for underwriters. Serious findings with no remediation plan or progress are. Document what you fixed, when, and how you validated it, be ready to share a short retest summary, and tell the story in your favor: you found the issue, fixed it quickly, and changed the process so it won't happen again.

Insurers know no environment is perfect. They reward organizations that find, fix, and learn.

How do cyber insurers look at penetration testing frequency?

Carriers increasingly expect at least annual testing and view more frequent testing favorably for high-risk environments. They also look for testing after major changes or incidents, and for evidence that findings were actually fixed.

Glossary

Terms used in this article

Plain definitions, so nothing above needs a second search.

Cyber Insurance
Insurance that helps cover the costs of a cyber incident, like investigation, recovery, notification, and legal fees. Carriers increasingly require specific security controls before they'll issue or renew a policy.
Penetration Testing
A manual, authorized attempt to break into your systems the way a real attacker would, to find out which controls actually hold. Distinct from automated scanning.
CVSS
Common Vulnerability Scoring System. A standard 0-to-10 score for how severe a vulnerability is, used to rank findings in scan and penetration test reports.
Proof of Concept
Evidence, like screenshots or logs, showing that a vulnerability was actually exploited during testing. It proves a finding is real, not theoretical.
Scope
The agreed list of what a penetration test covers, such as specific networks, locations, applications, or cloud accounts. A tighter scope costs less and keeps the test focused on your highest-risk systems.
Remediation
The work of actually fixing what a scan or test finds, such as applying patches, changing configurations, or shutting off exposed services. Findings don't reduce risk until they're remediated.
TALK TO US

Get a pentest report your insurer will actually accept.

Same day onsite for contract clients. Everyone else pays $165 an hour, with no emergency surcharge, and gets forensic imaging before remediation.

See penetration testing pricingAll articles