Home › Guides

Does your cyber insurance require MFA, and how do you prove it?

By Greg Mitchell · Squared Away Tech · October 11, 2026

If you have renewed a cyber-insurance policy recently, you have probably seen the question: “Do you require multi-factor authentication (MFA) for email and remote access?” Many owners check “yes” because they get a code on their phone sometimes. That may not be the same thing the insurer is asking about.

Here is what the question usually means, where small offices get caught out, and how to show that your answer is true.

What is MFA, in plain terms?

Multi-factor authentication means a password alone is not enough to sign in. After the password, the person also has to approve a prompt in an app, enter a code, or use a security key. If someone steals a password through a fake sign-in page, MFA is what stops them from using it.

Insurers ask about it because stolen passwords are one of the most common ways attackers get into business email. MFA is one of the most effective, lowest-cost protections a small office can put in place.

Does my policy require it?

Only your policy and application can answer that, and requirements vary by carrier and by year. Many insurers now ask specifically about MFA for:

Read the exact wording on your application. If the question says MFA is required for “all users” or “all remote access,” a partial setup may not match your answer. If you aren’t sure, ask your agent what the carrier expects.

Why “yes” can be the wrong answer

The application is part of your policy. If you answer that MFA is in place and it turns out it wasn’t, that can create problems when you file a claim. These are the gaps I see most often in small offices:

How to actually prove it

If an insurer, auditor or attorney ever asks, “show me,” you want more than a verbal yes. Good documentation for a small office looks like this:

  1. A list of every user in Microsoft 365, showing which ones have MFA registered. The admin tools can produce this report.
  2. The policy that requires it. In Microsoft 365, MFA can be enforced through security defaults or Conditional Access policies. A screenshot or export showing that the rule covers all users, with any exceptions explained, is strong evidence.
  3. Proof that older sign-in methods are blocked, so the MFA rule can’t be bypassed.
  4. Sign-in logs showing that recent sign-ins actually completed an MFA check.
  5. A short written summary, dated, describing what is in place, who is covered, and any exceptions with the reason for each.

Keep this with your policy paperwork and update it before each renewal. It turns a stressful questionnaire into a ten-minute task.

Exceptions aren’t automatically bad. Sometimes a scanner or an old line-of-business app needs a special account. What matters is that the exception is known, limited, and written down, not forgotten.

Rolling out MFA without chaos

Owners often put off MFA because they’re afraid of a Monday morning where nobody can get into email. That fear is reasonable, and it is avoidable. A careful rollout looks like this: tell staff what is coming and why, help each person register their phone ahead of time, turn on the requirement in stages, and keep an emergency administrator account protected and stored safely. Done that way, most staff spend a few minutes on it and then forget about it.

The bottom line

MFA is worth having whether or not your insurer asks. But if your application says you have it, make sure it is true for every account and every way of signing in, and keep proof on file. I help small offices roll out MFA in stages on evenings and weekends, and I also help answer the technical questions on cyber-insurance applications. I can’t promise any carrier will approve a policy, but I can make sure your answers match what is actually set up.

Want a second set of eyes? Greg offers a free 15-minute quick look at your Microsoft 365 sign-in and email forwarding settings. No cost, no obligation. Call or text (941) 479-1075 or email greg@squaredawaytechfl.com.

Book a quick look

Squared Away Tech serves offices of 5 to 100 people in Ellenton, Bradenton, Sarasota and Tampa Bay, with remote service anywhere in the U.S. Mon–Fri 5–9 PM and Sat 9 AM–5 PM (Eastern Time). Daytime and Sunday appointments available on request; daytime calls get a same-evening callback. Back to the home page · More guides

This guide is general information, not legal or insurance advice. Every office’s setup is different.