All insights
Cybersecurity4 min read

MFA isn't a nice-to-have anymore: your insurer already decided that

Multi-factor authentication moved from best practice to table stakes. Here's what changed, and what happens at renewal if you haven't turned it on.

Let's be real: nobody enjoys typing a six-digit code. But the argument about whether multi-factor authentication is worth the friction is over, and it wasn't your IT provider who ended it. It was your insurer.

What actually changed

Cyber insurance applications used to ask whether you had antivirus. Now they ask whether MFA is enforced on email, on remote access, and on administrative accounts, and they ask you to attest to it. Answer yes when it isn't true and you have a coverage problem the day you need the policy most.

The reason is simple arithmetic. The overwhelming majority of business email compromise starts with a stolen password. MFA breaks that chain cheaply, which is why it became the first thing underwriters check.

Where firms get caught

  • MFA is on for most staff, but the two accounts with the most access are exempt because the exemption was 'temporary' in 2023.
  • Email is protected, but the VPN or remote desktop into the server isn't.
  • Legacy authentication protocols are still enabled in Microsoft 365, which quietly lets an attacker skip MFA entirely.
  • Nobody can produce evidence that any of it is configured, which is a compliance failure even when the security is fine.

What to do this month

Turn MFA on everywhere, close the exemptions, disable legacy authentication, and export the configuration report so you have proof. That last step is the one people skip, and it's the one your renewal questionnaire asks about.

Security is the control that protects you. Compliance is proving the control exists to someone who's asking. You need both, and they're not the same job.

If you're not sure where your exemptions are, that's the audit to run first, before someone else runs it for you.

bNetworked Inc. · Serving Nova Scotia, New Brunswick, PEI, and Newfoundland & Labrador

Next step

Want to know how this applies to your business?

Book a Cyber Strategy Session. Thirty minutes, no pitch deck.