Support Center | ☎︎ Call us: (845) 440-5000 | info@vjnetworks.com
Back to Blog

What Cyber Insurers Actually Require in 2026: MFA “Enforced” vs “Available”

Cybersecurity
Last updated: July 24, 2026

Cyber insurers don’t treat all MFA the same in 2026. “Enforced” means every account that touches email, remote access, or admin systems requires it, no exceptions, and CISA itself ranks the method you use from phishing-resistant down to SMS, the weakest option on the list.

Two different questions get collapsed into one on most applications. Is MFA turned on? And is it the kind that actually holds up? Different questions. Different answers, usually. A business can pass the first and fail the second without realizing either one mattered separately.

“Enforced” and “Available” Are Different Words to an Underwriter

Available means someone could turn MFA on. Enforced means they can’t log in without it. That gap is where most applications get flagged. A new hire gets set up with MFA on day one because onboarding includes it. The other thirty people on staff, the ones who joined before that checklist existed, never got looped back in. Nobody decided that on purpose. It just never got finished.

An underwriter reading “MFA enforced” on an application means every single account touching email, remote access, financial systems, and admin tools, not the handful somebody remembered to configure two years ago and never revisited. Not most. Every one. Partial enforcement reads close to no enforcement at all once someone actually checks.

Not All MFA Is Equal, and CISA Ranked Them

Here’s the part most owners never hear. CISA’s own fact sheet ranks MFA methods strongest to weakest, and the gap between the top and bottom of that list is bigger than most people assume.

MFA TypeCISA’s RankingWhat It’s Vulnerable To
FIDO/WebAuthn or PKI-based (security keys, smart cards)Phishing-resistant, the gold standardNone of the attacks in this table apply
App-based OTP or push with number matchingStrong second choice for small businessesPhishing, in rarer cases
Push notification without number matchingWeaker, common defaultPush bombing and user error
SMS or voice codesWeakest, last resort onlyPhishing, SIM swapping, carrier network exploits

Most small businesses run somewhere in the bottom half of that table without knowing a top half exists. That’s not a judgment. It’s just where the defaults land when nobody’s asked the question yet.

IT technician examining a PKI-based smart card used for phishing-resistant authentication

Push Bombing: How “Available” MFA Gets Bypassed Anyway

Here’s a specific attack most owners have never heard of, and it targets exactly the MFA type most businesses actually run. Push bombing, sometimes called push fatigue. An attacker who already has your password sends approval requests to your phone over and over. Dozens, sometimes. Most people eventually tap “Approve” just to make it stop, not realizing they just handed over the account.

Number matching closes this specific gap by requiring one extra deliberate step. Instead of a single tap, the user has to actually read a code shown on the login screen and type that same code into the phone prompt before access gets granted. Small change. Real difference. CISA calls it out by name as the fix for exactly this attack, and it works on the same app most businesses already use.

Business owner reacting to repeated push notifications, illustrating a push bombing attack

What New York Actually Ties to Regulation

This isn’t just underwriting preference here in the Tri-State area. New York’s Department of Financial Services requires MFA for remote access to the network and any externally exposed application, under 23 NYCRR 500.12. That’s binding regulation for DFS-covered entities, not a recommendation sitting in a PDF nobody reads. For everyone else, it’s still the exact control an underwriter’s questionnaire is going to ask about by name.

A related question, EDR coverage, gets the same yes-or-no treatment on most applications. VJNetworks covered what actually separates EDR from antivirus in more depth, since the same “technically true, thin in practice” problem shows up there too.

Where to Start, If You’re Starting From Zero

CISA’s own advice here is more useful than most vendor pitches. Don’t try to move everyone to phishing-resistant MFA at once.

  • Start with email, remote access, and admin accounts. Those are the accounts attackers actually target first.
  • If phishing-resistant options aren’t realistic yet, move everyone off SMS to app-based push with number matching. That single change closes the push bombing gap.
  • Identify your actual high-value accounts, the ones with access to financial systems, sensitive files, or the ability to create new user accounts. Those get priority for the strongest method available.
  • Confirm coverage in writing. “Everyone has MFA” and a list showing which accounts actually have it enforced are two different documents.
  • Revisit the list whenever someone new joins or a system gets added. Coverage gaps grow quietly, not all at once.
Small business owner reviewing a printed MFA enforcement checklist

What Owners Actually Ask Me About This

We use SMS codes for our MFA. Does that hold up on an application?
It counts as MFA, technically. CISA ranks it the weakest option on the list, vulnerable to phishing and SIM swap attacks specifically. Fine as a last resort. Not where you want to stay.
Is a physical security key really necessary, or is app-based push good enough?
Push with number matching is a genuinely solid second choice for most small businesses. Security keys are the gold standard specifically because nothing on CISA’s threat list touches them. Start with number matching if a full rollout isn’t realistic yet.
What’s actually happening when someone gets “push bombed”?
An attacker who already has the password sends repeated approval requests until someone taps accept out of frustration or confusion. Number matching stops it, since a lucky tap alone can’t approve the login anymore.
Do we need phishing-resistant MFA on every account, or just the important ones?
Start with the important ones. Email, remote access, admin, and anything touching money or sensitive files. CISA’s own guidance recommends a phased rollout, not an all-at-once switch that stalls before it finishes.
How would an insurer even know which type of MFA we’re actually running?
Some ask directly on the application now. Others verify independently before binding a policy. Either way, a vague “yes, we have MFA” answer holds up a lot less than it used to.

Two questions, not one. Is MFA enforced everywhere it should be, and is it the kind that actually resists the attacks insurers are pricing against? VJNetworks has helped small businesses across the Tri-State area answer both for over 20 years, through cybersecurity work built around VJNetworks’ managed IT services, not a one-time setup that quietly falls behind. A free assessment checks exactly where your own MFA coverage actually stands.

Further reading: CISA’s “Implementing Phishing-Resistant MFA” fact sheet covers the full ranking and rollout guidance in detail.

Find Out Where Your MFA Actually Stands

A free assessment checks enforcement and method strength against what your next insurance application will actually ask. No obligation, no sales pitch.

Get Your Free IT Assessment →

Or call (845) 440-5000