Phishing-resistant MFA
In one sentence
A stronger form of MFA (like a hardware security key or passkey) that can't be tricked by a fake login page.
Ordinary MFA codes can still be phished: an attacker relays the code you type into a fake site. Phishing-resistant methods (FIDO2 security keys, passkeys) bind the login to the real website, so a fake page gets nothing usable.
Why it's on your cyber insurance application
Increasingly favored by carriers for administrator and high-risk accounts; recommended by CISA for privileged users.
How the Readiness Check scores it
The free Check asks the same question a carrier will. Here it is, why it's asked, and the fix if today's honest answer is no. The full application question list has the rest.
MFA & identity
Is MFA required for remote access (VPN, remote desktop) and administrator accounts?
Why carriers ask: Stolen credentials are the most common way attackers get in. Nearly every carrier now requires MFA on email, remote access, and admin accounts as a condition of coverage.
If the answer is no: Inventory every remote entry point (VPN, RDP, remote-support tools) and privileged account; enforce MFA on each or shut it off.
The written evidence carriers accept
A “yes” on the application needs a document behind it. In the Readiness Pack, that document is:
- Password & Multi-Factor Authentication Policy (preview its opening sections)
Related terms
Would you pass this question today?
The free Readiness Check scores you across the ten control domains carriers probe, in five minutes, no email required for the score.