← All Articles

September 2, 2026

Does Insurance Require MFA for Small Businesses?

Illustration of multifactor authentication for insurance readiness: employees verifying sign-ins with phone codes, keys, and checkmarks

A renewal application can make a business owner stop cold with one short question: Does insurance require MFA? For many cyber insurance policies, the practical answer is yes - or at least, it is rapidly becoming a condition of getting meaningful coverage at a reasonable price. But checking a box is not the same as having a control that will hold up after an incident.

Insurers are trying to reduce one of the most common paths into a business: a criminal logs in using a stolen password. Multifactor authentication, usually called MFA, makes that much harder. It asks for something beyond a password, such as an approval in an authenticator app, a security key, or a device-based prompt.

For a small business, the goal is straightforward. Put MFA in the places where a compromised login could expose data, send fraudulent payments, disable defenses, or lock the company out of its own systems. Then make sure the control is actually enabled, used, and documented.

Does insurance require MFA on every account?

Not necessarily. Requirements vary by insurer, policy type, industry, revenue, claims history, and the amount of coverage requested. A lower-limit policy may ask fewer questions than a policy covering a company that handles protected health information, payment data, legal records, or large client funds.

Still, MFA is now one of the most common controls on cyber insurance applications. Insurers often focus on email, remote access, cloud applications, administrative accounts, and financial systems. Those are high-value targets because one compromised identity can give an attacker a way to impersonate an employee, reset other passwords, access files, or launch a business email compromise scam.

Some applications use language such as “multifactor authentication for all remote access,” while others ask whether MFA protects email, privileged accounts, or access to sensitive data. Read the wording closely. If an application says MFA is required for all email accounts, enabling it only for the owner and IT administrator is not enough.

A policy may still be available without MFA in some circumstances. The trade-off can be a higher premium, a lower coverage limit, a cybersecurity exclusion, or a declined application. More importantly, inaccurate answers create a serious problem. If a business represents that MFA is in place but employees can bypass it or critical accounts are excluded, the insurer may scrutinize that gap after a claim.

Why insurers care so much about MFA

Passwords are routinely stolen through phishing pages, malware, password reuse, and breached websites. A strong password helps, but it cannot stop someone who has already captured it from trying it on Microsoft 365, a VPN, a payroll portal, or a cloud accounting system.

MFA adds a second barrier. A criminal who knows a password must also complete the additional verification step. That does not make an account invulnerable. Attackers can use prompt fatigue, social engineering, token theft, and session hijacking. But MFA stops a large share of basic account-takeover attempts and raises the cost of more advanced attacks.

That matters to insurers because login-based incidents often become expensive fast. A compromised mailbox can be used to redirect an invoice payment. An exposed remote-access account can become a foothold for ransomware. A hijacked administrator account can create new users, turn off protections, and make recovery slower.

MFA is not simply an insurance formality. It is a practical control against the incidents that can interrupt payroll, client service, accounting, and operations.

Where MFA should be enabled first

Start with the systems that can cause the greatest damage if someone gets in. For most small businesses, that means business email and the identity platform behind it, such as Microsoft 365 or Google Workspace. Email is often the reset point for other accounts and the source of information attackers use to make convincing fraud requests.

Next, protect remote access. This includes VPNs, remote desktop tools, cloud desktops, and remote-management platforms. If an employee, outside IT provider, or vendor can reach company systems from outside the office, MFA should be part of that path.

Administrative accounts deserve separate attention. Anyone who can add users, reset passwords, change security settings, access backups, or manage endpoint tools has elevated access. Admin accounts should use MFA even when the person works primarily from the office. Whenever practical, people should use a standard account for everyday work and a separate protected account for administrative tasks.

Then consider financial, payroll, accounting, customer relationship management, file-sharing, and line-of-business applications. Prioritize systems that hold sensitive information, initiate payments, or connect to many other services. A quick inventory often uncovers forgotten portals, former employee accounts, and vendor tools that were set up years ago without a clear owner.

What counts as MFA for an insurance application?

The answer depends on the policy language, but not every second factor is equally strong. Authenticator apps and hardware security keys are generally stronger choices than text-message codes. SMS can still be better than password-only access, but phone numbers can be targeted through social engineering or SIM-swapping attacks.

Push notifications are convenient, but employees need training not to approve a prompt they did not initiate. Repeated unexpected prompts are a warning sign, not an inconvenience to clear away. Number matching, location details, and phishing-resistant security keys can provide stronger protection where the platform supports them.

Be cautious with exceptions. A company may believe MFA is universal while shared accounts, legacy email protocols, service accounts, emergency administrator accounts, or mobile devices have been left outside the policy. Some exceptions are technically necessary, but each one should have an owner, a documented reason, and compensating controls.

A remembered device setting can also complicate the answer. It may be acceptable for a managed device under certain conditions, but it should not become a way to avoid MFA indefinitely on personal or unmanaged computers. When in doubt, ask the insurer or broker how they interpret the specific question before submitting the application.

How to document MFA without creating a paperwork project

Insurance applications often require an attestation rather than a stack of evidence, but you should be able to support your answer. Good documentation protects the business, helps with renewals, and gives your IT provider or security partner a clear standard to maintain.

Keep a short written MFA policy that states which systems require MFA, who is covered, which methods are permitted, and how new users are enrolled. Pair it with a current list of key systems and the administrator responsible for each one.

Your technology team should be able to show configuration reports or screenshots demonstrating that MFA is enforced, not merely available. They should also review enrollment regularly, especially after employee departures, role changes, or new software deployments. A policy that says MFA is required does little good if a terminated employee’s account remains active.

Documentation should also include your response process when a user reports suspicious login prompts or a lost authentication device. Speed matters. Disable sessions, reset credentials if needed, review sign-in activity, and confirm that recovery methods have not been changed by an attacker.

MFA is one control, not the whole insurance answer

Cyber insurers commonly ask about backups, security awareness training, endpoint protection, patching, access management, incident response, and monitoring alongside MFA. That can feel like a long list, but the controls work together.

MFA can stop a stolen password from becoming a breach. Patching reduces the chance that an attacker can exploit a known weakness. Managed endpoint detection and response can identify suspicious activity that gets past preventive controls. Tested backups help restore operations if ransomware still lands. A response plan gives people a starting point when the pressure is highest.

This is where standalone antivirus often falls short. It may detect something suspicious, but an insurance-ready security posture requires someone to investigate the alert, determine whether it is real, contain the threat, and document what happened. Detection is only useful when someone responds.

For businesses that already have an IT provider, this does not require replacing that relationship. IT can continue managing users, systems, and day-to-day technology while a focused security provider handles endpoint monitoring, threat investigation, containment, remediation, and reporting. PC Vax is built around that operational layer, including managed endpoint protection and optional patch management.

Before you answer the renewal question

Do not let the insurance application become the first time your company checks its security controls. Review it with the person responsible for IT and security before the deadline. Translate each question into a specific system, setting, process, or report that can be verified.

If MFA is incomplete, fix the highest-risk gaps first: email, remote access, administrative accounts, and financial platforms. Communicate the change clearly to employees, give them a simple enrollment process, and establish a support path for lost devices or login trouble. Security controls fail when people are left to figure them out alone.

The helpful mindset is not “What answer will get us through the form?” It is “If a criminal has an employee’s password tomorrow, what stops them next?” A clear answer to that question can strengthen your insurance application - and, more importantly, help keep one stolen credential from becoming a business disruption.

PC Vax provides cybersecurity services, not insurance advice. Cyber insurance requirements vary by carrier, policy, and applicant, and PC Vax does not guarantee insurance eligibility, approval, coverage, or premiums.


Professional Cybersecurity. Made Simple.

Get Protected