Manav.id
Vertical · 4 min read

Signing the MFA question is a representation someone will test

Signing the MFA question is a representation someone will test

The person signing the questionnaire believes the answer. The gap between that belief and the environment is discovered by an attacker, and then re-discovered by a coverage lawyer.

Is MFA really enforced everywhere?

Almost certainly not, and the person signing the questionnaire believes it is. Legacy authentication protocols, service accounts, break-glass paths, third-party access and unmanaged systems are the standing exceptions in nearly every estate, and they are the paths attackers use.

Key takeaways
  • Application answers are representations, and material inaccuracy can affect coverage — in some cases severely.
  • 'Everywhere' almost never means everywhere: legacy protocols, service accounts, break-glass paths and unmanaged systems are the usual gaps.
  • Measuring coverage before signing turns a belief into a number, and a number can be qualified honestly.

The five places MFA is not enforced

Legacy authentication protocolsclients cannot present a second factorService and machine accountsno human to promptBreak-glass accountsdeliberately exemptThird-party and contractor pathsdifferent controlsUnmanaged or shadow systemsnot in the IdP at all
Each exists for a defensible reason. Together they are the attack surface.

An organisation that has genuinely deployed MFA broadly will still typically have these, and they are the paths attackers use.

GapWhy it exists
Legacy authentication protocolsOlder clients and integrations cannot present a second factor
Service and machine accountsNo human to prompt; authenticated by secret
Break-glass and emergency accountsDeliberately exempt so they work when identity systems fail
Third-party and contractor accessOften via a different path with different controls
Unmanaged or shadow systemsNot in the identity provider at all

Rows two and five are the largest by count in most estates, and row one is historically the most exploited.

Why the answer is still 'yes'

Because the person answering is describing the policy, and the policy says MFA is required. The exceptions live in configuration, in integration accounts, and in systems the identity team does not own.

There is also a commercial pressure: a no answer affects premium or eligibility, so an answer with caveats feels costly. That pressure is real and it is precisely what creates the later dispute.

What happens after an incident

  1. The insurer's forensic team establishes the intrusion path.
  2. If it involved an account without MFA, the application answer becomes relevant.
  3. Coverage counsel examines whether the answer was materially inaccurate and whether the insurer relied on it.
  4. Depending on jurisdiction and wording, the consequence ranges from nothing to reduced recovery to rescission.

The range in item four is wide and jurisdiction-dependent, which is itself the problem: the board has an exposure it cannot size.

Measuring before signing

# What can be reported before answering the question

  Identity provider accounts:        4,182
    with phishing-resistant MFA:     3,918   (93.7%)
    with app or push MFA:              201   ( 4.8%)
    with SMS only:                      41   ( 1.0%)
    with no second factor:              22   ( 0.5%)

  Legacy protocol authentication:   disabled tenant-wide
  Service accounts (no MFA):           312   — secret-based,
                                             IP-restricted
  Break-glass accounts:                  2   — documented,
                                             monitored, alerting
  Third-party access paths:              7   — 4 with MFA

That is a defensible answer. It is more work than ticking a box and it cannot be characterised later as a misrepresentation, because it says what is true.

What a board should ask

Three questions, before the questionnaire is signed rather than after.

The third is the one that removes the exposure. An insurer who was told about the service accounts cannot later say they were not told.

The counter-intuitive commercial point

Qualified answers are not obviously worse commercially. An underwriter reading measured figures with documented compensating controls is looking at an organisation that knows its own environment, which is a positive signal.

An unqualified yes from an organisation that clearly cannot have measured it is worth less than it appears, and experienced underwriters discount it accordingly.

This describes insurance principles at a general level and is not legal advice. The effect of application inaccuracy varies substantially by jurisdiction and wording; take specifics to counsel and to your broker.

A measured answer instead of a tick

  Identity provider accounts:        4,182
    phishing-resistant MFA:          3,918   (93.7%)
    app or push MFA:                   201   ( 4.8%)
    SMS only:                           41   ( 1.0%)
    no second factor:                   22   ( 0.5%)

  Legacy protocol auth:   disabled tenant-wide
  Service accounts:          312 — secret-based, IP-restricted
  Break-glass:                 2 — documented, alerting
  Third-party paths:           7 — 4 with MFA

That is a defensible answer. It takes more work than ticking a box and it cannot later be characterised as a misrepresentation, because it says what is true.

Objections and honest limits

“A qualified answer will cost us premium.” Not necessarily. An underwriter reading measured figures with documented compensating controls sees an organisation that knows its environment, which experienced underwriters value over an unqualified yes they know cannot have been measured.

“The consequence of an inaccurate answer is unclear.” It is, and that uncertainty is the board-level exposure. Outcomes range from nothing to rescission depending on jurisdiction and wording.

Before signing the application

  1. Establish who answers the technical questions and on what basis. Usually a risk manager relaying what they were told.
  2. Measure rather than assert. Counts and percentages, per category.
  3. Disclose the qualifications. An insurer told about the service accounts cannot later say they were not.
  4. Have the signer see the exceptions. They carry the exposure.

Terms used here

Legacy authentication
Older protocols that cannot present a second factor, historically the most exploited MFA gap.
Material misrepresentation
An inaccurate application statement the insurer relied on, with consequences varying by jurisdiction.
Compensating control
An alternative measure where the primary control cannot apply — worth disclosing rather than hiding.

Frequently asked questions

Where is MFA usually not enforced? Legacy authentication protocols, service and machine accounts, break-glass accounts, third-party access paths, and systems not in the identity provider at all.

Why do people answer yes anyway? They are describing the policy, not the configuration. There is also commercial pressure, since a qualified answer feels like it will cost premium.

What is the consequence of an inaccurate answer? It varies by jurisdiction and wording, from nothing to reduced recovery to rescission. The uncertainty is itself the board-level exposure.

Do qualified answers hurt pricing? Not necessarily. Measured figures with documented compensating controls signal an organisation that knows its environment, which underwriters value.

Where this fits in Manav

Manav produces the artefact underwriting and claims both lack: a per-transaction receipt an adjuster can verify without contacting the insured, and a measurable coverage rate across a defined scope.

See the evidence a claim needs →

Sources and further reading