Does the Applicant conduct regular penetration testing? In-house or outsourced?
The report is not the deliverable that matters to an underwriter. The remediation record is.
What the carrier is actually asking
The carrier is asking whether you commission penetration tests, how often, and whether they are performed internally or by a third party. Some forms ask for the date of the last test and whether findings were remediated.
Why it is underwritten
Testing demonstrates that controls have been examined by someone trying to defeat them rather than someone confirming they exist. Independent testing carries more weight than internal, and evidence of remediation carries more weight than either.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Testing engagements and reports are attested. Their findings frequently concern configuration that is measurable, which is where remediation can be evidenced.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Test reports | Last test date, scope, and methodology | A recent test with a scope that covers what matters, by a named provider. Attested |
| Remediation records | Findings tracked to closure with dates | Evidence that findings were fixed, which is the artefact carriers actually want |
| Retest | Verification that remediation worked | A retest or verification step, since remediation asserted is not remediation confirmed |
| Scope | What was excluded from the test | Exclusions understood, since a test scoped to a single application says nothing about the estate |
| Cloud configuration | Configuration findings and their current state | Whether the configuration findings from the last report are still present, which is directly checkable |
A two-year-old test with unremediated high-severity findings documents that you knew about a weakness and did not fix it. That is worse than not having tested, both for underwriting and for any subsequent litigation.
What a defensible yes requires
- Testing happens on a defined cadence, at least annually for internet-facing systems.
- Scope covers the external perimeter and the systems that matter, with exclusions stated.
- Findings are tracked to closure with dates.
- High-severity findings are retested rather than closed on assertion.
- The provider is independent for at least the external test.
How this answer goes wrong
A test was performed three years ago as part of a compliance requirement, the report sits in a folder, and several findings remain open. The answer is yes, and the supporting evidence argues against the organisation rather than for it.
Frequently asked
How often should we test?
Annually for the external perimeter, and after significant changes. More frequent testing suits organisations with rapid change or high exposure.
Is a vulnerability scan a penetration test?
No, and carriers ask about them separately. Scanning finds known weaknesses; testing chains them into a demonstrated path.
In-house or external?
External carries more weight for the perimeter because of independence. Internal testing between engagements is valuable and complementary.
Do carriers ask for the report?
Rarely at underwriting and sometimes for larger placements. They ask about remediation more often than about findings.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture