Multi-Factor Authentication
Multi-factor authentication records whether privileged, remote and email access to an organisation's systems requires more than one independent authentication factor, a baseline control queried in virtually every cyber insurance proposal form.
- Category
- IT/Cyber
- Data type
- Yes/No
- Risk drivers
- Severity, Frequency, Moral hazard
- Underwriting impact
- Premium, Condition/Warranty, Declinature
Typical proposal-form questions
- Is multi-factor authentication enforced for all remote access to the network, including VPN, RDP and cloud administration consoles?
- Is MFA required for privileged and administrator accounts, and for access to corporate email and backup or recovery systems?
- Which authentication factors are used (e.g. hardware token, authenticator app, SMS) and are any accounts exempted from enforcement?
Evidence
- Identity and access management policy
- Configuration export or screenshot of MFA enforcement scope from the identity provider
- Independent security assessment or penetration test report
Why it matters for underwriting
Compromised credentials obtained through phishing, credential stuffing or password reuse remain the leading initial access vector behind ransomware deployments and business email compromise, two of the most frequent and severe cyber claim types. Multi-factor authentication is the single control most consistently correlated with preventing that initial foothold, because it defeats a stolen or guessed password on its own. Underwriters therefore treat MFA less as one item among many controls and more as a threshold eligibility requirement: as claims experience has hardened, insurers have progressively narrowed appetite so that risks lacking MFA on remote access, privileged accounts or email are frequently declined outright rather than simply rated up. The attribute drives both the accept-or-decline decision at new business and renewal, and, for risks that clear that bar, the base rate applied relative to peers with comparable revenue and data holdings.
Capturing the attribute and evidence
Proposal forms ask specifically where MFA is enforced rather than accepting a single organisation-wide yes/no answer, because gaps in any one area materially change the exposure: remote access such as VPN and RDP, cloud administration consoles, privileged and administrator accounts, corporate email, and backup or recovery consoles are each queried separately. Underwriters corroborate self-declared answers against the applicant’s identity and access management policy, configuration exports or screenshots from the identity provider showing the actual enforcement scope and any exempted accounts, and, for larger or higher-hazard accounts, an independent security assessment, external attack-surface scan or penetration test report. Discrepancies between the declared answer and technical evidence, such as legacy accounts excluded from enforcement, are a common finding during risk engineering reviews and are treated as a material misrepresentation risk if uncovered after a loss.
Effect on coverage, premium and conditions
Full MFA coverage across remote access, privileged accounts, email and backup systems typically unlocks standard policy terms and pricing competitive with the broader market. Partial enforcement, for instance MFA enabled on VPN access but not on privileged or administrator accounts, commonly results in a warranty requiring completion within an agreed remediation period, a ransomware sublimit or coinsurance percentage, or a premium loading pending confirmation. Complete absence of MFA on remote access or privileged accounts is one of the most frequent single reasons for declinature in the current cyber market, since insurers regard it as an unacceptable concentration of moral hazard and frequency exposure regardless of other compensating controls. Insurers reassess this attribute at every renewal, and a control that has lapsed since inception is treated as a material change in risk profile.
Mitigation measures
Insurers, brokers and IT security advisors typically recommend enforcing MFA universally across remote access, privileged and administrator accounts, email and backup consoles rather than selectively, and prioritising phishing-resistant factors such as hardware security keys or authenticator applications over SMS-based one-time codes, which remain vulnerable to SIM-swapping and interception. Where legacy systems cannot support modern MFA, compensating controls such as network segmentation, conditional access policies restricting sign-in by location or device, and enhanced monitoring of the affected accounts are recommended until the gap can be closed. Organisations still transitioning are advised to document a phased rollout plan with target dates by system tier, since insurers increasingly ask for evidence of progress rather than a static point-in-time statement.