Skip to content
Coverwright
← Notes
August 16, 2026 · 6 min read

Why every cyber insurance renewal is suddenly asking about MFA

Multi-factor authentication went from a line in the fine print to the question that decides whether a carrier will quote you at all. What changed, where MFA usually still has gaps even when someone thinks it’s “done,” and what to check before the renewal lands.

If this year’s renewal application asked more directly about multi-factor authentication than last year’s did, that wasn’t your carrier being thorough for its own sake. Credential theft — a stolen or guessed password, used to walk straight into an account — is behind a large share of the incidents insurers actually pay claims on, and MFA is the one control that stops most of those attempts cold even after the password itself is compromised. Underwriters know this, so the question moved from “do you have security measures” to a specific, answerable yes or no.

Why this one control, specifically

Most of the controls an insurance application asks about are hard to verify from the outside and take real effort to put right — endpoint protection, staff training, patching discipline. MFA is different: it’s binary, it’s checkable, and turning it on for a given account is a same-day fix rather than a months-long program. That combination — high impact against the most common attack path, low cost to verify, fast to remediate — is exactly what makes it the first thing an underwriting questionnaire narrows in on, and increasingly the first thing that decides whether a policy gets priced normally, priced with a surcharge, or declined outright.

Where it’s still missing, even when someone thinks it’s “done”

The most common gap isn’t “no MFA anywhere” — it’s MFA on the account everyone thinks of first, email, and nowhere else. A renewal application usually asks about several logins separately, and each one is a real, distinct answer:

  • Email — the one most businesses turn on first, and the one most applications ask about explicitly by name.
  • Administrator and privileged accounts — the login that manages everyone else’s access is the one an attacker wants most, and is disproportionately likely to be the account still using a password alone.
  • Online banking — outside IT’s usual view entirely, since it’s often one person’s login rather than something the business manages centrally.
  • Remote access — VPNs, remote desktop, anything reaching internal systems from outside the office, which is exactly the kind of access that turns one stolen password into full network access.

A business that answers “yes, we have MFA” honestly means email, and answers every other row on the application from memory rather than from having actually checked, is answering a form it hasn’t verified — which is a worse position at claim time than a form that says “partial” and names what’s still outstanding.

What to check before the renewal lands

The fastest honest audit is a short walk through the accounts above, one at a time, confirming — not assuming — that a second factor is actually required, not just available and unused. Where it isn’t on somewhere yet, the useful next step isn’t panic, it’s a plan: who’s responsible for turning it on, and by when. A rollout in progress, written down, reads very differently to an underwriter than either a false “yes” or a silent gap.

What it doesn’t do

MFA lowers the odds of the single most common way an account gets taken over; it doesn’t make a business immune to every attack, and having it in place doesn’t guarantee a specific carrier’s acceptance, a specific premium, or that a claim gets paid — coverage decisions stay with the insurer, on the facts of the actual application and the actual incident. What a written security policy adds on top is the honest record: which accounts have it, which don’t yet, and what the plan is for the gap — which is what the free check below is built to surface in under a minute, using the same questions an application asks.