Multi-factor authentication (MFA)
A second check at sign-in for email, remote access and admin accounts. We configure it for every user.
We check what you told your insurer against what’s actually running on your systems, fix the gaps, and keep it that way at every renewal.
The problem
When you apply or renew, you answer a security questionnaire: do you use MFA, how are backups kept, do you have endpoint protection, are systems patched. Often it’s filled out quickly, in good faith, by whoever has the form.
The answers get checked when you make a claim. If investigators find your systems didn’t match what you told the insurer, the insurer can deny the claim or void the policy. You’ve paid for coverage that isn’t there when you need it.
We review the technical and security requirements in your policy. We’re not an insurance broker or a lawyer, so coverage and legal questions stay with them.
A real case
A US manufacturer told its insurer it used multi-factor authentication. After a ransomware attack, the insurer checked.
One answer on one form.
Travelers v. International Control Services, U.S. District Court, Central District of Illinois, 2022.
The company confirms it uses MFA to protect administrator access.
Coverage is bound based on the answers in the application.
The company files a claim. The insurer investigates.
Nothing else, including the servers, was protected by MFA.
Both sides agree the policy is void from the start. No coverage for that claim, or any other.
What insurers typically require
Every insurer’s form is different, but the same controls come up again and again. Here’s what they mean, and how we cover them.
A second check at sign-in for email, remote access and admin accounts. We configure it for every user.
Security software on every computer and server that stops attacks, not just known viruses. Included in every plan.
Learn moreCopies kept away from your main systems and tested, so ransomware can’t take them too. Available as an add-on.
Learn moreFiltering for phishing and fake invoices. Check Point email security is included in every plan.
Learn moreSecurity updates applied on a schedule, with a record that shows it.
Many insurers also ask about staff training and an incident response plan. We’ll tell you what yours asks for.
What we do
01
We read your policy and your application, and list every technical and security commitment you’ve made.
02
We compare each one against what’s actually running on your systems.
03
A plain-language report: where you match, where you don’t, and what it takes to close each gap.
04
We close the gaps the policy actually requires, and document it so you can show it.
At renewal
Insurers update their questions, and your business changes between renewals: new staff, new systems, new ways of working. An answer that was true last year may not be true now.
Before each renewal, we go through the new questionnaire with you and confirm every answer matches what’s running. You sign knowing it’s accurate.
Your EDR, email security, MFA and patching are already managed by us on our plans, so most of the evidence is on hand when the form arrives.
Straight answer
We fix what the policy actually asks for. We don’t use a review to sell you a security stack you don’t need.
Fair questions
Common reasons include controls on the application that weren’t actually in place, like MFA or backups, and exclusions in the policy. We can review the technical side. Coverage questions are for your broker or lawyer.
It varies, but most applications ask about MFA, endpoint protection (EDR), backups, email security, patching, and often staff training and an incident response plan.
Yes. If the application misstated your security and that mattered to the insurer’s decision, the policy can be voided, as it was in Travelers v. International Control Services in 2022.
No. Your broker handles the policy and coverage. We make sure your systems match what the application says, and we’re happy to work with your broker directly.
Renewing soon?
A short call, no sales pitch. If your systems already match what you told your insurer, you’ll hear that from us.