Does your cyber insurance require MFA, and how do you prove it?
If you have renewed a cyber-insurance policy recently, you have probably seen the question: “Do you require multi-factor authentication (MFA) for email and remote access?” Many owners check “yes” because they get a code on their phone sometimes. That may not be the same thing the insurer is asking about.
Here is what the question usually means, where small offices get caught out, and how to show that your answer is true.
What is MFA, in plain terms?
Multi-factor authentication means a password alone is not enough to sign in. After the password, the person also has to approve a prompt in an app, enter a code, or use a security key. If someone steals a password through a fake sign-in page, MFA is what stops them from using it.
Insurers ask about it because stolen passwords are one of the most common ways attackers get into business email. MFA is one of the most effective, lowest-cost protections a small office can put in place.
Does my policy require it?
Only your policy and application can answer that, and requirements vary by carrier and by year. Many insurers now ask specifically about MFA for:
- Email, including access from phones and home computers.
- Remote access to your network, such as VPN or remote desktop.
- Administrator accounts for your systems and cloud services.
- Backups and other critical systems.
Read the exact wording on your application. If the question says MFA is required for “all users” or “all remote access,” a partial setup may not match your answer. If you aren’t sure, ask your agent what the carrier expects.
Why “yes” can be the wrong answer
The application is part of your policy. If you answer that MFA is in place and it turns out it wasn’t, that can create problems when you file a claim. These are the gaps I see most often in small offices:
- MFA is on for some people, not everyone. The owner and office manager were set up years ago, but newer hires never were.
- Shared or service mailboxes like info@ or billing@ that people sign into directly with just a password.
- Older sign-in methods are still allowed. Some older email apps and protocols can sign in with only a password, skipping MFA entirely, even when MFA is “on.”
- Administrator accounts that were created for a past IT provider and never protected or removed.
- “Remember this device” forever, so in practice nobody has been prompted in a very long time.
How to actually prove it
If an insurer, auditor or attorney ever asks, “show me,” you want more than a verbal yes. Good documentation for a small office looks like this:
- A list of every user in Microsoft 365, showing which ones have MFA registered. The admin tools can produce this report.
- The policy that requires it. In Microsoft 365, MFA can be enforced through security defaults or Conditional Access policies. A screenshot or export showing that the rule covers all users, with any exceptions explained, is strong evidence.
- Proof that older sign-in methods are blocked, so the MFA rule can’t be bypassed.
- Sign-in logs showing that recent sign-ins actually completed an MFA check.
- A short written summary, dated, describing what is in place, who is covered, and any exceptions with the reason for each.
Keep this with your policy paperwork and update it before each renewal. It turns a stressful questionnaire into a ten-minute task.
Rolling out MFA without chaos
Owners often put off MFA because they’re afraid of a Monday morning where nobody can get into email. That fear is reasonable, and it is avoidable. A careful rollout looks like this: tell staff what is coming and why, help each person register their phone ahead of time, turn on the requirement in stages, and keep an emergency administrator account protected and stored safely. Done that way, most staff spend a few minutes on it and then forget about it.
The bottom line
MFA is worth having whether or not your insurer asks. But if your application says you have it, make sure it is true for every account and every way of signing in, and keep proof on file. I help small offices roll out MFA in stages on evenings and weekends, and I also help answer the technical questions on cyber-insurance applications. I can’t promise any carrier will approve a policy, but I can make sure your answers match what is actually set up.
Want a second set of eyes? Greg offers a free 15-minute quick look at your Microsoft 365 sign-in and email forwarding settings. No cost, no obligation. Call or text (941) 479-1075 or email greg@squaredawaytechfl.com.
Book a quick lookSquared Away Tech serves offices of 5 to 100 people in Ellenton, Bradenton, Sarasota and Tampa Bay, with remote service anywhere in the U.S. Mon–Fri 5–9 PM and Sat 9 AM–5 PM (Eastern Time). Daytime and Sunday appointments available on request; daytime calls get a same-evening callback. Back to the home page · More guides
This guide is general information, not legal or insurance advice. Every office’s setup is different.