When a pentest is really for the insurance form
Be honest about the audience. Then still do the work so the form is not the only thing you get.
ITSIGN Administrator · February 26, 2025 · 2 min read
Plenty of firms book a test because the broker asked. That is a valid reason. It is a poor reason to accept a shallow scope.
Ask the broker which questions the report must answer. Then add the one system you actually worry about.
If the underwriter also wants MFA, backups and EDR evidence, that is GRC and security audit work sitting next to the test.
Related reading
Why the retest is the part you should not skip
A finding list without a retest is homework you never marked. Insurers and customers notice.
2 min read
Scoping a pentest without wasting money
Narrow the crown jewels. Write rules of engagement. Budget the retest. Everything else is theatre.
2 min read
Pentest vs vulnerability scan: stop mixing them up
Scans are continuous. Pentests are point-in-time and manual. You need both, and they answer different questions.
2 min read
Want this applied to your environment?
A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.
