Multi-factor authentication (MFA)
Also called: 2FA, two-factor authentication, two-step verification
In one sentence
A second step at sign-in beyond your password (an app prompt, code, or security key), so a stolen password alone can't get in.
MFA requires a second proof of identity when you log in: a tap on a phone app, a one-time code, or a physical security key. Because attackers usually have only your password (from a leak or a phishing page), that second factor stops the vast majority of account takeovers.
Why it's on your cyber insurance application
The single most-required control on cyber applications. Carriers ask whether MFA is enforced on email, remote access, and admin accounts. A 'no' is the most common reason a small business is declined.
How the Readiness Check scores it
The free Check asks the same question a carrier will. Here it is, why it's asked, and the fix if today's honest answer is no. The full application question list has the rest.
MFA & identity
Is multi-factor authentication (MFA) required on all business email accounts?
Why carriers ask: Stolen credentials are the most common way attackers get in. Nearly every carrier now requires MFA on email, remote access, and admin accounts as a condition of coverage.
If the answer is no: Enable enforced MFA in Microsoft 365 / Google Workspace today. Built-in, free, typically an afternoon including user comms.
MFA & identity
Is MFA required for remote access (VPN, remote desktop) and administrator accounts?
Why carriers ask: Stolen credentials are the most common way attackers get in. Nearly every carrier now requires MFA on email, remote access, and admin accounts as a condition of coverage.
If the answer is no: Inventory every remote entry point (VPN, RDP, remote-support tools) and privileged account; enforce MFA on each or shut it off.
The written evidence carriers accept
A “yes” on the application needs a document behind it. In the Readiness Pack, those documents are:
- Password & Multi-Factor Authentication Policy (preview its opening sections)
- Training One-Pager: Passwords & MFA
Guides that cover this
What MFA do cyber insurance carriers actually require?
Carriers require enforced multi-factor authentication in three places: all business email accounts, all remote access (VPN and remote desktop), and all administrator accounts. Here's exactly what 'enforced' means, how to set it up free in an afternoon, and how to answer the application questions accurately.
Cybersecurity 101: the basic precautions insurers actually notice
A plain-English starter guide to the cybersecurity basics that move the needle on a cyber insurance application: MFA, EDR, tested backups, patching, email protection, training, and a written incident response plan — most fixable in an afternoon.
Cyber insurance for construction contractors: what carriers require in 2026
Contractors face the same seven cyber insurance requirements as everyone else, plus sharper questions about wire fraud, because construction's payment flows make it a top target for funds-transfer fraud. Here's the contractor-specific readiness list.
Related terms
Would you pass this question today?
The free Readiness Check scores you across the ten control domains carriers probe, in five minutes, no email required for the score.