Penetration testing for cyber insurance

If your insurance application or renewal asks for an external penetration test or phishing testing, we run either one or both.

You get a letter you can give your broker or insurer, plus a full report for your IT team.

Last reviewed October 2026

Does cyber insurance require a pen test?

It depends on your insurer and your policy. Applications and renewals may ask about penetration testing, vulnerability scanning, or phishing tests. Send us the questions, and we’ll scope a test that answers them.

Email us the questions

What we test

  • Your external network: everything the internet can reach, including VPNs, remote-access portals, firewalls, and other edge devices
  • Email phishing: clicks, credentials entered, and reports to IT, as trends by department and role
  • Optional: phone (vishing) and text message (smishing) pretexts

Why these two tests

An external test looks for the flaws attackers use to get in. A phishing test shows whether your people spot and report a convincing email.

Verizon 2026 DBIR: “Exploitation of vulnerabilities is now the most common initial access vector for breaches. It has risen to 31%.”[1]

2026 Breach Impact Study (US cyber-insurance): “half of all the reviewed paid-out claims had a financial impact greater than $83,000, with the top 10% having a more than $920,000 impact.”[2]

What your insurer may ask about

  • When testing happened and what it covered
  • Whether serious findings were fixed
  • Whether you run phishing tests

What you can give your broker or insurer

An attestation letter with the test dates, scope, method, and a summary of results, plus a full report for your IT team. We walk your team or IT provider through the findings on a call. After you fix the findings, one retest of reported findings within 90 days of the final report is included in the price, and the letter is updated.

See an example attestation letter

What we need from you

  • Your public IP ranges and domains
  • A contact on your IT team or at your managed IT provider, so our testing isn’t mistaken for an attack
  • Approval of the phishing scenarios and the list of recipients
  • Your application or renewal date

Working back from your renewal

  1. Tell us your renewal or application date. We reply to every request within one business day and set up a free scoping call.
  2. You get a fixed-fee proposal and rules of engagement to sign. Testing can usually start within 5 business days of signing.
  3. An external network test typically takes one to three weeks, and a phishing campaign two to four weeks. Critical findings are reported within 24 hours of confirmation, not held for the report.
  4. Final report delivered within 5 business days after testing ends. The attestation letter comes with it.
  5. Fix, then retest. One retest of reported findings within 90 days of the final report, included in the price, with an updated letter.

Start dates are agreed during scoping, so tell us your deadline when you ask for a quote.

What it costs

External network tests start at $5,000.

Phishing campaigns: quoted for your scope. Minimum project $5,000.

Starting prices in US dollars for the smallest scope of each service, reviewed October 2026. Your price is a fixed fee, set in a written proposal after a free scoping call.

All testing is performed by HackNow’s own US-based testers. We never pass your test to another firm.

See starting prices for every service

Questions about testing for cyber insurance

Is a vulnerability scan enough?

Sometimes. Some applications ask only about scanning, and some ask for a penetration test. Send us the form and we’ll tell you which fits.

Which test should we pick?

If the form asks about your internet-facing systems, start with an external network test. Add a phishing campaign if it asks about phishing or staff training.

What evidence should we keep?

The final report, the attestation letter, the retest report, and the testing dates.

Will you coordinate with our IT team or managed IT provider?

Yes. We agree on testing windows and source IP addresses with your IT team or provider before we start, and you can pause testing at any time with one message.

Renewal coming up?

We reply to every request within one business day. Every engagement is a fixed fee after a free scoping call.