United States
The MFA requirement for cyber insurance
Multi-factor authentication is the condition cyber applications ask about first: for email and cloud services, for remote access, and for every administrator account. Each line below shows the rule behind it in each jurisdiction, and lands at day 30 on the default schedule.
The controls
- Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication
- Remote access (VPN, remote desktop) and every administrator account use multi-factor authentication
- Customers who log in to an online service you run that holds their sensitive data are offered or required to use multi-factor authentication
- The multi-factor authentication staff use is phishing-resistant (security keys or passkeys rather than codes)
Start from the template, or mark the controls in the control list. How the schedule works.
Questions
- Does this page say the business can be covered?
- No. It shows the gaps and the rule behind each; cover is the insurer's decision.
- What does it cost?
- One applicant on screen is free in any jurisdiction. Saving clocks and the applicant link are on Solo.