This website uses cookies to ensure you get the best experience on our website. Learn more
Cyber Insurance MFA Requirements: What You Need to Know
Table of Contents
Multi-factor authentication (MFA) is quickly becoming a key requirement for cyber insurance, and of keeping that cover valid when a claim is made.
The City of Hamilton, Ontario, offers a clear example of what is at stake. A ransomware attack in February 2024 disrupted large parts of the city’s network, with recovery costs of CAD $18.3 million. The city later disclosed that its insurer had denied its claim because MFA had not been fully implemented. Under the policy, losses were not covered where the absence of MFA was the root cause of the breach.
The key lesson is not that MFA guarantees an organization will avoid an attack. It is that partial deployment can leave both security and insurance gaps. Organizations therefore need to understand exactly what the MFA requirements are for cyber insurance, including which users and systems must be covered, and what evidence the insurer may expect during underwriting or a claim.
Does Cybersecurity Insurance Require MFA?
There is no universal rule stating that every organization must use MFA to obtain cyber insurance. However, while specific MFA requirements vary, it has become a standard part of cyber insurance underwriting.
As was shown in the City of Hamilton incident, insurers may refuse cover, limit the policy, increase the premium or apply specific exclusions when an applicant cannot show that MFA protects its most exposed accounts and systems.
Insurers are particularly likely to ask whether MFA is enforced for:
- Remote network access, including VPNs and remote desktop services
- Privileged and administrative accounts
- Cloud email and productivity platforms
- Externally accessible applications
- Access to backups, security tools and other critical systems
These reflect the routes attackers commonly use to enter a network or escalate privileges. CISA similarly advises organizations to enable MFA wherever possible, highlighting privileged or administrative access as starting points.
What Guidance Do Regulations Provide?
MFA requirements do not come from one law or framework. They appear across government guidance, industry standards and regulatory assessment tools, each with a different scope. None of these frameworks automatically defines the terms of a cyber insurance policy, but insurers may use them as evidence of accepted security practice.
NIST
The US National Institute of Standards and Technology addresses MFA through its Digital Identity Guidelines, particularly NIST Special Publication 800-63B. NIST organizes authentication requirements into three Authentication Assurance Levels:
- AAL1 permits single-factor authentication, although applications are encouraged to offer an MFA option.
- AAL2 requires users to prove control of two distinct authentication factors. This can involve one multi-factor authenticator or two separate single-factor authenticators.
- AAL3 also requires two factors, with stronger controls intended for higher-risk systems.
Under the current NIST guidance, applications assessed at AAL2 must offer a phishing-resistant authentication option. This is an important distinction: not every form of MFA provides the same protection. Attackers can capture one-time codes sent by SMS or entered from an authenticator app through phishing or prompt bombing, whereas methods such as security keys and passkeys are designed to resist it.
NCSC Cyber Assessment Framework
The UK National Cyber Security Centre’s Cyber Assessment Framework (CAF) helps organizations assess how effectively they manage risks to essential services. It is particularly relevant to operators of essential services, such as healthcare and energy providers, as well as government bodies. However, its principles offer a useful benchmark for any organization reviewing its controls.
Under Principle B2, the CAF expects organizations to verify, authenticate, and authorize access to systems supporting essential functions. To meet its “partially achieved” criteria, organizations should use additional authentication mechanisms, such as MFA, for privileged access and individually authenticate remote users.
The stronger “achieved” standard extends MFA to all user access, including remote access, across systems supporting essential functions. Access rights should also be kept to the minimum necessary and reviewed at least every six months.
For insurers, alignment with the CAF can provide evidence that MFA forms part of a broader, well-managed identity and access control program.
PCI DSS
The Payment Card Industry Data Security Standard applies to entities that store, process or transmit payment account data. Unlike broad security guidance, PCI DSS contains specific, assessable MFA requirements for access to the cardholder data environment.
Under PCI DSS v4.0.1, Requirement 8.4 requires MFA for:
- All access into the cardholder data environment by personnel with administrative access.
- All access into the cardholder data environment originating from outside the organization’s network.
- All access into the cardholder data environment for applicable personnel, not just administrators.
The broader requirement covering user access to the cardholder data environment became effective on 31 March 2025. PCI guidance defines MFA as requiring at least two separate forms of authentication before access is granted; entering one factor and gaining access before supplying the second does not meet that intent. Many of the requirements mirror what cyber insurers mandate, meaning a strong security posture satisfies both.
What Else Do Insurers Look For?
MFA is only one part of the underwriting process. Insurers commonly ask about a broader set of controls, including:
- Endpoint detection and response (EDR)
- Regular vulnerability scanning and patch management
- Offline, encrypted and tested backups
- Privileged access management
- Network segmentation
- Email filtering and anti-phishing controls
- Security awareness training
- Incident response and business continuity plans
- Centralized logging and security monitoring
- Controls for remote access and third-party suppliers
- Regular penetration testing
- Data encryption at rest and in transit
The exact requirements will depend on the insurer, the organization’s size and sector, and the type of cover being requested. Insurers will usually pay particular attention to controls that reduce the likelihood or impact of an attack. You can read more about cyber insurance in our guide here.
How Can Your Organization Meet Insurance MFA Requirements?
Organizations should start by enforcing MFA for privileged accounts and remote access, as these are two areas insurers commonly examine. That means protecting administrator accounts, VPN access and RDP connections, not just cloud applications such as email.
However, there is no single standard that applies to every policy. Insurers may set different requirements based on your industry, size, systems, and risk profile, so review the proposal form and policy wording carefully and confirm any unclear terms with your broker or insurer.
How Specops Helps
Specops helps organizations align their MFA policies with regulatory and insurer expectations through Specops Secure Access. This adds a strong second layer of protection to Windows logon, RDP, and VPN access, enabling a range of authentication options depending on user and security needs.
With support for SSO via OpenID Connect and SAML, as well as an offline mode, Specops Secure Access gives IT teams a practical way to strengthen access decisions without adding unnecessary complexity.
If you’re interested in seeing how Specops can help you evolve your MFA, contact us today.
Last updated on August 5, 2026