Skip to main content
Back to Blog
Cyber Insurance 5 min read 24 February 2026

Why Your Cyber Insurer Now Requires MFA on Everything

MFA is no longer optional if you want cyber insurance. We explain what insurers are actually checking — and what "MFA on everything" really means.

The shift in cyber insurance underwriting

In 2021, cyber insurers began adding MFA as a hard requirement on renewal questionnaires — initially for privileged access and email. By 2024, the leading UK cyber insurers (Beazley, CFC, Coalition, Hiscox) had standardised on requiring MFA for all remote access, all admin accounts, and all email platforms. Policies that omit or misrepresent MFA coverage are subject to coverage denial at claim time.

What "MFA on everything" actually means

When insurers say MFA is required, they specifically mean:

  • Remote access (VPN, RDP, Citrix): Any remote session must require a second factor. Legacy VPN clients that pass only username/password are insufficient.
  • Email (Microsoft 365, Google Workspace): All user accounts, not just admins. SMS-based MFA is acceptable but authenticator apps or FIDO2 keys are preferred.
  • Admin and privileged accounts: All accounts with admin privileges across servers, network devices, cloud consoles, and identity platforms.
  • Cloud console access (AWS, Azure, GCP): Root/owner accounts and all IAM users with console access.
  • Backup systems: Admin access to backup platforms must be MFA-protected. This is now a specific underwriter focus given ransomware attacks targeting backup infrastructure.

What happens if you claim without MFA in place?

If a ransomware incident is traced to a compromised account that lacked MFA — and your questionnaire indicated MFA was in place — the insurer may deny the claim under misrepresentation provisions. Even if the questionnaire answer was honestly given, a gap between stated controls and actual implementation is a material risk.

Implementation priorities

If you are not fully MFA-enabled, the priority order is:

  1. Email accounts (highest attack surface)
  2. VPN and RDP remote access
  3. Admin accounts in Active Directory and Entra ID
  4. Cloud console access
  5. Backup administration

Need help with this?

Our team can help you assess where you stand and build a practical remediation plan. Free 30-minute consultation — no obligation.

Book a Free Consultation

Related Articles