surable

Phishing-resistant MFA

In one sentence

A stronger form of MFA (like a hardware security key or passkey) that can't be tricked by a fake login page.

Ordinary MFA codes can still be phished: an attacker relays the code you type into a fake site. Phishing-resistant methods (FIDO2 security keys, passkeys) bind the login to the real website, so a fake page gets nothing usable.

Why it's on your cyber insurance application

Increasingly favored by carriers for administrator and high-risk accounts; recommended by CISA for privileged users.

How the Readiness Check scores it

The free Check asks the same question a carrier will. Here it is, why it's asked, and the fix if today's honest answer is no. The full application question list has the rest.

MFA & identity

Is MFA required for remote access (VPN, remote desktop) and administrator accounts?

Why carriers ask: Stolen credentials are the most common way attackers get in. Nearly every carrier now requires MFA on email, remote access, and admin accounts as a condition of coverage.

If the answer is no: Inventory every remote entry point (VPN, RDP, remote-support tools) and privileged account; enforce MFA on each or shut it off.

The written evidence carriers accept

A “yes” on the application needs a document behind it. In the Readiness Pack, that document is:

Related terms

Would you pass this question today?

The free Readiness Check scores you across the ten control domains carriers probe, in five minutes, no email required for the score.

← All terms