Insurers Stop Negotiating: The New Hard Line on MFA
Not long ago, a UK broker could submit a cyber risk without multi-factor authentication (MFA) and still get a quote—perhaps with a modest premium loading. That conversation, a panel of cyber brokers told Insurance Business TV, has all but vanished. Insurers that would once have engaged are now issuing an outright “no,” according to Selorm Kofi Domeh, broking manager at Talbot Jones. “Now it’s probably an outright no,” he said, signalling a market where what was negotiable is simply not any more.
The new underwriting baseline goes beyond MFA, though it remains “top of the list,” in the words of Colin Fox, cyber insurance consultant at Integrity (part of Hayes Parsons). Insurers now expect the principle of least privilege, endpoint detection and response (EDR), and privileged access management (PAM) as standard. A small number of carriers might still write a risk without MFA, Fox noted, but that is now “quite a rarity,” not a viable placement strategy.
The reasoning is rooted in claims data. Ethan Godlieb of Consilium Insurance Brokers cited statistics attributed to most insurers: cybercrime makes up about 30% of all claims by incident type, and roughly 95% of attacks involve human error. “It’s much easier to hack us than it is to hack purpose-built systems,” he explained, explaining why identity controls, rather than network architecture, have become the underwriting priority. A recent Insurance Business report on the FortiBleed breach, where Russian hackers reused stolen credentials and brute-forced devices lacking MFA, underscores exactly the failure the market is trying to prevent.
What the MFA Mandate Means for Cyber Insurance
The Expanding Underwriting Checklist
While MFA is the gatekeeper, the full set of expected controls now includes EDR with active monitoring, especially for clients seeking higher limits around the £5 million to £10 million mark, according to Daniel Winn of Jensten London Markets. Incident response plans and backups count too, but only if they are tested regularly. A plan that has never been rehearsed tells an insurer little about real recovery speed.
The Claims Story Behind the Shift
Godlieb’s figures—cybercrime driving 30% of claims and human error present in 95% of attacks—anchor the market’s focus on identity and access management. Weak credential hygiene, whether through reused passwords or absent MFA, is the most persistent vulnerability. The FortiBleed incident, where stolen credentials were used against devices without MFA, shows how a basic control failure can cascade into exposure for organisations, including UK government networks.
From “Do You Have MFA?” to “Which MFA?”
The hardening baseline does not end the conversation for brokers. AXA XL has warned that AI-driven phishing is making MFA bypass increasingly viable, so insurers increasingly care about the type of MFA—phishing-resistant methods such as FIDO2 hardware tokens or biometrics become more valuable in an underwriting review than basic SMS codes. Brokers who can articulate this nuance will place risks more successfully than those simply ticking a box.
The Gap for Payment-Heavy Clients
For organisations that handle large volumes of payments, Godlieb flagged an additional structuring point: because cybercrime is often sub-limited under a standard cyber policy, a standalone crime policy with a social engineering extension may offer better protection than relying on the cyber policy alone. Brokers advising financial or payment-focused businesses need to adjust the conversation accordingly.
How Brokers and Businesses Should Respond to the New Baseline
- Verify MFA coverage and quality. Ensure all remote access, email, and critical systems are protected by MFA, and prepare to demonstrate it to underwriters. Phishing-resistant methods (e.g., FIDO2) are becoming the new expected standard, not just any MFA.
- Build the full control suite for higher limits. For clients targeting £5 million+ in cover, deploy EDR with active monitoring and implement privileged access management (PAM) alongside least privilege. These are now close to mandatory.
- Test incident response and backup plans regularly. Unrehearsed plans do not impress underwriters; evidence of tabletop exercises or live recovery drills is needed to demonstrate real resilience.
- Reassess reliance on the cyber policy alone for payment-heavy firms. Consider a standalone crime policy with a social engineering extension to cover gaps left by sub-limits on cyber policies, particularly for financial institutions or businesses handling large transactions.
- Stay ahead of AI-driven bypass risks. Account for the growing threat of AI-enhanced phishing that targets MFA. Brokers should advise clients to monitor emerging controls and consider additional layers like behavioural analytics or zero-trust architectures to maintain insurability.
Risk & Opportunity Assessment
| Commercial Risk | Medium | Insurers that rigidly refuse to quote without MFA may lose premium from smaller businesses unable to afford or deploy the control, potentially ceding market share, while those that relax the requirement risk adverse selection. |
| Competitive Risk | Medium | Carriers that do not enforce MFA as a strict gate attract riskier portfolios. As threat actors increasingly exploit weak credentials, as seen in the FortiBleed breach, their loss ratios could deteriorate relative to disciplined peers. |
| Regulatory Risk | Low | No immediate regulatory change is signalled, but if widespread underwriting failures from poor access-control assessments emerge, regulators could scrutinise insurers’ risk selection practices—though the panel’s consensus suggests the market is self-policing effectively. |
| Reputation Risk | Low | Brokers may initially perceive rigid MFA demands as inflexible, but the panel’s description of a market-wide shift indicates the requirement is now broadly accepted, limiting reputation damage. |
| Technology Disruption | Medium | AI-driven MFA bypass attacks, highlighted by AXA XL, threaten to erode the effectiveness of MFA as a single control. Reliance on traditional MFA as the primary underwriting gate could leave insurers exposed if bypass techniques become routine. |
| Commercial Opportunity | High | Insurers that offer integrated risk mitigation—such as MFA deployment support, EDR services, or tools to improve cyber hygiene—can differentiate themselves with brokers and attract better-quality risks, as suggested by Insurance Business’s 5-Star Cyber research. |
Comments 0