Why MFA decides your insurance renewal

Most of a cyber-insurance application is narrative. A few questions are not: they are binary, and they are the ones that move the decision.

The questions that are actually binary

  • Multi-factor authentication. Not “do you use MFA” but where: email, remote access, privileged accounts, and the administrative consoles of your cloud providers. Partial coverage is the usual reality and the usual problem.
  • Endpoint detection and response. Deployed on what proportion of endpoints, and who watches it. A console nobody logs into is a licence, not a control.
  • Backups that are immutable and tested. Immutable means an attacker with administrative access cannot delete or encrypt them. Tested means someone restored from them and wrote down the date and the result.

Where the honest answer gets difficult

The gap is rarely that a control is missing entirely. It is that it covers eighty percent of the estate and the application asks a yes-or-no question. The service accounts are exempted. The legacy mail protocol is still enabled. The backup is immutable in the console but the retention lock was never turned on.

Answering these accurately requires going and looking, not asking the person who set it up what they remember configuring. That is the bulk of what an evidence pack engagement does.

What I will not tell you

I will not tell you what your policy does if an answer turns out to be wrong. That is a question for your broker and your lawyer, and advising on it requires a licence I do not hold. What I can do is make sure the answers you sign are true and that you can show why.

← All writing