MFA Is Not Optional Anymore: What Your Insurer Actually Requires
Every cyber insurance renewal questionnaire now has an MFA section, and it isn’t a yes/no checkbox anymore. Carriers want to know where multi-factor authentication is enforced, not just whether you have it somewhere. Answer that section wrong, on purpose or by accident, and you may find out at the worst possible moment: when you file a claim.
1. What “MFA” means in one sentence
Multi-factor authentication (MFA) means logging in requires two different types of proof, usually a password plus something on your phone or a hardware key, so a stolen password alone isn’t enough to get in. That’s the whole concept. The complexity is all in where it’s applied.
2. What carriers are actually asking for
Renewal applications typically break MFA into categories, and they ask about each one separately: email access (especially webmail), remote access into the network (VPN, RDP), and privileged or administrator accounts. An attestation is a statement you sign confirming a control is in place. If you attest to MFA “everywhere” and it’s actually only on email, that’s the gap that shows up later.
3. Why SMS codes are losing favor
Text-message codes were the first widely-adopted form of MFA, and some carriers still accept them. Others are moving toward requiring an authenticator app or a hardware key instead, because SMS can be intercepted through SIM-swapping. Check your specific renewal document rather than assuming last year’s answer still qualifies. Carrier requirements vary, and the policy document governs, not general industry practice.
4. What “we have MFA” usually means versus what it needs to mean
Most businesses that say “we have MFA” mean it’s turned on for email, because that’s the default nudge from Microsoft or Google. Remote access tools and admin accounts, the ones an attacker actually wants, often get missed because they were set up by whoever installed them, not audited later. “We have MFA” and “MFA is enforced everywhere it needs to be” are two different claims, and only one of them is what the questionnaire is asking about.
5. The four places to check this week
Before you sign anything: confirm MFA is enforced (not just available) on your email platform, on every remote access path into your network, on every account with administrator rights, and on any VPN connection. “Available” and “enforced” are different states. A setting that exists but isn’t required of every user is not MFA in practice, it’s MFA as an option nobody chose.
6. What happens at claim time if the attestation was wrong
An attestation that turns out to be inaccurate at the time of a breach can affect how a claim is handled or even whether it’s paid, depending on the specific policy language. This isn’t a scare tactic, it’s why the section exists on the form in the first place. If you’re not certain your last renewal attestation was accurate, that’s worth confirming before the next one, not after an incident. It’s the same gap we walked through in what a cyber insurance application actually asks you.
The straightforward move
This isn’t a compliance exercise for its own sake. It’s a fifteen-minute audit of four settings that determines whether your insurance actually covers you the way you think it does. Book a call and we’ll check all four with you.
Leave a Reply