The basics
Since 2023, multifactor authentication (MFA) on email, remote access, and privileged accounts has gone from 'recommended' to 'required' for cyber insurance. In 2026, carriers will not bind a policy — or will impose 50-80% retention increases — if MFA is missing.
Why it matters in 2026
The required MFA scope keeps expanding. Current standard for SMB cyber policies: MFA on all email accounts, MFA on remote network access (VPN, RDP, virtual desktops), MFA on all privileged/admin accounts, and MFA on backup systems and cloud-management consoles.
How it actually works
Beyond MFA, underwriters now scan for endpoint detection and response (EDR/MDR) tools, immutable offsite backups tested in the last 90 days, an incident response plan, security awareness training within the last 12 months, and patching cadence on internet-facing systems.
Common pitfalls
Carriers using automated outside-in scans (Coalition, At-Bay, Resilience, Cowbell) will flag exposed RDP, unpatched Citrix or Fortinet vulnerabilities, missing DMARC/SPF on email, and other red flags. Remediate before applying — a single open RDP port can drop you from preferred pricing into the non-renewal pile.
Practical recommendations
For businesses still ramping security, a 'cyber starter' policy with sub-limits and higher retentions is available from carriers like Coalition, Corvus, and Travelers. Use it as a bridge while you implement the controls a full policy requires.
Key takeaways
- Understand the structure before you shop.
- Compare quotes from at least three carriers.
- Document everything and revisit coverage annually.
- Pair with related coverage for full protection.
Related reading on InsureLab
Sources & further reading
Frequently asked questions
Why is MFA required for cyber insurance?+
Compromised credentials are the #1 entry vector in ransomware and BEC claims. MFA dramatically reduces successful attacks, so carriers now require it for binding.
Where exactly do I need MFA?+
All email accounts, all remote access (VPN, RDP, virtual desktops), all privileged/admin accounts, and backup systems and cloud-management consoles.
Will my cyber policy be canceled if I don't add MFA?+
Mid-term cancellation is rare, but at renewal you'll see either large retention increases, premium hikes, or non-renewal until MFA is implemented.
Can I still get cyber insurance with weak controls?+
Yes — cyber starter policies exist with sub-limits and higher retentions. Use one as a bridge while implementing controls a full policy requires.
Found this helpful?
Share it with a friend who's about to renew their policy — and browse our other guides while you're here.