Signing the MFA question is a representation someone will test
The person signing the questionnaire believes the answer. The gap between that belief and the environment is discovered by an attacker, and then re-discovered by a coverage lawyer.
Is MFA really enforced everywhere?
Almost certainly not, and the person signing the questionnaire believes it is. Legacy authentication protocols, service accounts, break-glass paths, third-party access and unmanaged systems are the standing exceptions in nearly every estate, and they are the paths attackers use.
- Application answers are representations, and material inaccuracy can affect coverage — in some cases severely.
- 'Everywhere' almost never means everywhere: legacy protocols, service accounts, break-glass paths and unmanaged systems are the usual gaps.
- Measuring coverage before signing turns a belief into a number, and a number can be qualified honestly.
Part of Cyber insurance and risk transfer
The five places MFA is not enforced
An organisation that has genuinely deployed MFA broadly will still typically have these, and they are the paths attackers use.
| Gap | Why it exists |
|---|---|
| Legacy authentication protocols | Older clients and integrations cannot present a second factor |
| Service and machine accounts | No human to prompt; authenticated by secret |
| Break-glass and emergency accounts | Deliberately exempt so they work when identity systems fail |
| Third-party and contractor access | Often via a different path with different controls |
| Unmanaged or shadow systems | Not in the identity provider at all |
Rows two and five are the largest by count in most estates, and row one is historically the most exploited.
Why the answer is still 'yes'
Because the person answering is describing the policy, and the policy says MFA is required. The exceptions live in configuration, in integration accounts, and in systems the identity team does not own.
There is also a commercial pressure: a no answer affects premium or eligibility, so an answer with caveats feels costly. That pressure is real and it is precisely what creates the later dispute.
What happens after an incident
- The insurer's forensic team establishes the intrusion path.
- If it involved an account without MFA, the application answer becomes relevant.
- Coverage counsel examines whether the answer was materially inaccurate and whether the insurer relied on it.
- Depending on jurisdiction and wording, the consequence ranges from nothing to reduced recovery to rescission.
The range in item four is wide and jurisdiction-dependent, which is itself the problem: the board has an exposure it cannot size.
Measuring before signing
# What can be reported before answering the question
Identity provider accounts: 4,182
with phishing-resistant MFA: 3,918 (93.7%)
with app or push MFA: 201 ( 4.8%)
with SMS only: 41 ( 1.0%)
with no second factor: 22 ( 0.5%)
Legacy protocol authentication: disabled tenant-wide
Service accounts (no MFA): 312 — secret-based,
IP-restricted
Break-glass accounts: 2 — documented,
monitored, alerting
Third-party access paths: 7 — 4 with MFA
That is a defensible answer. It is more work than ticking a box and it cannot be characterised later as a misrepresentation, because it says what is true.
What a board should ask
Three questions, before the questionnaire is signed rather than after.
- Who signs our insurance applications, and on what basis do they answer the technical questions?
- Can we produce measured evidence for each control we attest to?
- Where the answer is qualified, is the qualification disclosed to the insurer?
The third is the one that removes the exposure. An insurer who was told about the service accounts cannot later say they were not told.
The counter-intuitive commercial point
Qualified answers are not obviously worse commercially. An underwriter reading measured figures with documented compensating controls is looking at an organisation that knows its own environment, which is a positive signal.
An unqualified yes from an organisation that clearly cannot have measured it is worth less than it appears, and experienced underwriters discount it accordingly.
This describes insurance principles at a general level and is not legal advice. The effect of application inaccuracy varies substantially by jurisdiction and wording; take specifics to counsel and to your broker.
A measured answer instead of a tick
Identity provider accounts: 4,182
phishing-resistant MFA: 3,918 (93.7%)
app or push MFA: 201 ( 4.8%)
SMS only: 41 ( 1.0%)
no second factor: 22 ( 0.5%)
Legacy protocol auth: disabled tenant-wide
Service accounts: 312 — secret-based, IP-restricted
Break-glass: 2 — documented, alerting
Third-party paths: 7 — 4 with MFA
That is a defensible answer. It takes more work than ticking a box and it cannot later be characterised as a misrepresentation, because it says what is true.
Objections and honest limits
“A qualified answer will cost us premium.” Not necessarily. An underwriter reading measured figures with documented compensating controls sees an organisation that knows its environment, which experienced underwriters value over an unqualified yes they know cannot have been measured.
“The consequence of an inaccurate answer is unclear.” It is, and that uncertainty is the board-level exposure. Outcomes range from nothing to rescission depending on jurisdiction and wording.
Before signing the application
- Establish who answers the technical questions and on what basis. Usually a risk manager relaying what they were told.
- Measure rather than assert. Counts and percentages, per category.
- Disclose the qualifications. An insurer told about the service accounts cannot later say they were not.
- Have the signer see the exceptions. They carry the exposure.
Terms used here
- Legacy authentication
- Older protocols that cannot present a second factor, historically the most exploited MFA gap.
- Material misrepresentation
- An inaccurate application statement the insurer relied on, with consequences varying by jurisdiction.
- Compensating control
- An alternative measure where the primary control cannot apply — worth disclosing rather than hiding.
Frequently asked questions
Where is MFA usually not enforced? Legacy authentication protocols, service and machine accounts, break-glass accounts, third-party access paths, and systems not in the identity provider at all.
Why do people answer yes anyway? They are describing the policy, not the configuration. There is also commercial pressure, since a qualified answer feels like it will cost premium.
What is the consequence of an inaccurate answer? It varies by jurisdiction and wording, from nothing to reduced recovery to rescission. The uncertainty is itself the board-level exposure.
Do qualified answers hurt pricing? Not necessarily. Measured figures with documented compensating controls signal an organisation that knows its environment, which underwriters value.
Where this fits in Manav
Manav produces the artefact underwriting and claims both lack: a per-transaction receipt an adjuster can verify without contacting the insured, and a measurable coverage rate across a defined scope.
Sources and further reading
- Federal Acquisition Regulation
- Published coverage disputes involving application representations.
- CISA — Implementing phishing-resistant MFA
- Identity provider documentation on legacy authentication and conditional access.
- FBI IC3 2025 Internet Crime Report
- NAIC — cyber risk resources