Earlier quoted context omitted.
Naively, I would expect that an insurer is less likely to pay out if a basic pen-test suggests negligence on the part of the company.
Sort of. Pentests are a joke - a compliance activity and nothing more. As the client I get to pick the vendor, determine scope and influence the criticality of findings in the final report. Insurers don’t care about anything until you have a breach and a claim. They look to see whether you have the controls mandated in the policy and... Whether your attacker used a nation-state toolkit if so then they don’t have to p…
Definitely seen that one.
I'm curious as to why an insurer wouldn't look at a bottom-tier pen-test for signs of gross negligence. They'll readily turn up things like failing to have authentication on key file shares, no access controls on the network, or no MFA in use. The sort of stuff that's easily exploited and shows utter neglect on the part of the insured.
Basically, it's been my experience that a tick-box pen-test exercise does a reasonable amount to check if the supposed controls are actually there.