Network, logging and monitoring

Does the Applicant conduct regular penetration testing? In-house or outsourced?

The report is not the deliverable that matters to an underwriter. The remediation record is.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking whether you commission penetration tests, how often, and whether they are performed internally or by a third party. Some forms ask for the date of the last test and whether findings were remediated.

Why it is underwritten

Testing demonstrates that controls have been examined by someone trying to defeat them rather than someone confirming they exist. Independent testing carries more weight than internal, and evidence of remediation carries more weight than either.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Testing engagements and reports are attested. Their findings frequently concern configuration that is measurable, which is where remediation can be evidenced.

PlatformWhere the setting livesWhat has to be true
Test reportsLast test date, scope, and methodologyA recent test with a scope that covers what matters, by a named provider. Attested
Remediation recordsFindings tracked to closure with datesEvidence that findings were fixed, which is the artefact carriers actually want
RetestVerification that remediation workedA retest or verification step, since remediation asserted is not remediation confirmed
ScopeWhat was excluded from the testExclusions understood, since a test scoped to a single application says nothing about the estate
Cloud configurationConfiguration findings and their current stateWhether the configuration findings from the last report are still present, which is directly checkable
An old report with open findings is negative evidence

A two-year-old test with unremediated high-severity findings documents that you knew about a weakness and did not fix it. That is worse than not having tested, both for underwriting and for any subsequent litigation.

What a defensible yes requires

  • Testing happens on a defined cadence, at least annually for internet-facing systems.
  • Scope covers the external perimeter and the systems that matter, with exclusions stated.
  • Findings are tracked to closure with dates.
  • High-severity findings are retested rather than closed on assertion.
  • The provider is independent for at least the external test.

How this answer goes wrong

A test was performed three years ago as part of a compliance requirement, the report sits in a folder, and several findings remain open. The answer is yes, and the supporting evidence argues against the organisation rather than for it.

Frequently asked

How often should we test?

Annually for the external perimeter, and after significant changes. More frequent testing suits organisations with rapid change or high exposure.

Is a vulnerability scan a penetration test?

No, and carriers ask about them separately. Scanning finds known weaknesses; testing chains them into a demonstrated path.

In-house or external?

External carries more weight for the perimeter because of independence. Internal testing between engagements is valuable and complementary.

Do carriers ask for the report?

Rarely at underwriting and sometimes for larger placements. They ask about remediation more often than about findings.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture