MFA used to be a nice-to-have. Now insurers just say no without it

"Now it's probably an outright no": how multi-factor authentication went from negotiable to non-negotiable

MFA used to be a nice-to-have. Now insurers just say no without it

Cyber

By Matthew Sellers

There's a particular kind of underwriting conversation that used to happen fairly often in UK cyber insurance: a broker submits a risk without multi-factor authentication in place, and an insurer offers terms anyway, perhaps with a modest loading. According to a panel of UK cyber brokers speaking to Insurance Business TV, that conversation barely happens any more.

"I've looked at the last two years," said Selorm Kofi Domeh, broking manager at Talbot Jones. Insurers who would previously have engaged on a quote request without MFA in place would now, in his experience, give an outright no. "Now it's probably an outright no," he said, describing a shift where what used to be negotiable simply isn't any more.

Colin Fox, cyber insurance consultant at Integrity, part of Hayes Parsons, laid out the wider list insurers now expect as baseline. MFA remains "top of the list and remains top of the list," in his words, alongside the principle of least privilege, endpoint detection and response (EDR), and privileged access management (PAM). A handful of insurers will still write a risk without MFA, he said, but that's become "quite a rarity these days" rather than a viable underwriting strategy.

The reasoning behind the emphasis on identity controls is fairly stark. Ethan Godlieb, associate partner for cyber and fintech at Consilium Insurance Brokers, cited a statistic he attributed to most insurers: cybercrime remains the leading category of claims by incident type, at around 30% of the total, with roughly 95% of cyber attacks involving some element of human error. "It's much easier to hack us than it is to hack purpose-built systems," he said, which is precisely why identity and access management, rather than network architecture, has become the underwriting priority.

That emphasis shows up in real incidents the market has had to respond to. Insurance Business recently reported on how Russian hackers exploited weak credential hygiene in the FortiBleed breach, recycling stolen credentials and using brute-force techniques against devices that lacked MFA, ultimately exposing logins tied to UK government networks. Fortinet confirmed the exploit relied on poor password hygiene rather than a new product vulnerability, exactly the kind of basic control failure this panel's underwriting checklist is designed to close off.

Daniel Winn, a development broker at Jensten London Markets specialising in technology, media and cyber, said MFA remains the baseline requirement across the board, but noted insurers are layering on more. EDR with active monitoring, in particular, is becoming close to mandatory for clients seeking higher limits, in his experience around the £5 million to £10 million mark. Incident response plans and backups matter too, he said, but only if they're tested regularly. A plan that's never been rehearsed doesn't tell an insurer much about how quickly a client will actually recover when something goes wrong.

Godlieb added a wrinkle worth flagging for brokers advising financial or payment-heavy clients specifically. Because cybercrime is often sub-limited under a standard cyber policy, a standalone crime policy with a social engineering extension may be the more appropriate structure for organisations handling large payments, rather than relying on the cyber policy alone.

There's a broader threat backdrop making all of this more urgent. AXA XL has previously warned that AI-driven attacks are making MFA bypass increasingly viable, with threat actors developing more convincing phishing campaigns designed specifically to circumvent multi-factor checks. MFA remains close to table stakes for getting a quote at all, but brokers advising clients increasingly need to talk about which kind of MFA, not just whether one exists.

The picture that emerges from the panel isn't one of insurers suddenly discovering identity risk. It's one where a slow-building consensus has finally hardened into an underwriting line that brokers can no longer talk their way around. For a sense of which carriers are actually applying that discipline well, rather than just ticking the MFA box, Insurance Business's 5-Star Cyber research gives brokers a broker-rated view of how insurers compare on underwriting expertise and risk mitigation support.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!