Cyber insurers don’t treat all MFA the same in 2026. “Enforced” means every account that touches email, remote access, or admin systems requires it, no exceptions, and CISA itself ranks the method you use from phishing-resistant down to SMS, the weakest option on the list.
Two different questions get collapsed into one on most applications. Is MFA turned on? And is it the kind that actually holds up? Different questions. Different answers, usually. A business can pass the first and fail the second without realizing either one mattered separately.
“Enforced” and “Available” Are Different Words to an Underwriter
Available means someone could turn MFA on. Enforced means they can’t log in without it. That gap is where most applications get flagged. A new hire gets set up with MFA on day one because onboarding includes it. The other thirty people on staff, the ones who joined before that checklist existed, never got looped back in. Nobody decided that on purpose. It just never got finished.
An underwriter reading “MFA enforced” on an application means every single account touching email, remote access, financial systems, and admin tools, not the handful somebody remembered to configure two years ago and never revisited. Not most. Every one. Partial enforcement reads close to no enforcement at all once someone actually checks.
Not All MFA Is Equal, and CISA Ranked Them
Here’s the part most owners never hear. CISA’s own fact sheet ranks MFA methods strongest to weakest, and the gap between the top and bottom of that list is bigger than most people assume.
| MFA Type | CISA’s Ranking | What It’s Vulnerable To |
|---|---|---|
| FIDO/WebAuthn or PKI-based (security keys, smart cards) | Phishing-resistant, the gold standard | None of the attacks in this table apply |
| App-based OTP or push with number matching | Strong second choice for small businesses | Phishing, in rarer cases |
| Push notification without number matching | Weaker, common default | Push bombing and user error |
| SMS or voice codes | Weakest, last resort only | Phishing, SIM swapping, carrier network exploits |
Most small businesses run somewhere in the bottom half of that table without knowing a top half exists. That’s not a judgment. It’s just where the defaults land when nobody’s asked the question yet.

Push Bombing: How “Available” MFA Gets Bypassed Anyway
Here’s a specific attack most owners have never heard of, and it targets exactly the MFA type most businesses actually run. Push bombing, sometimes called push fatigue. An attacker who already has your password sends approval requests to your phone over and over. Dozens, sometimes. Most people eventually tap “Approve” just to make it stop, not realizing they just handed over the account.
Number matching closes this specific gap by requiring one extra deliberate step. Instead of a single tap, the user has to actually read a code shown on the login screen and type that same code into the phone prompt before access gets granted. Small change. Real difference. CISA calls it out by name as the fix for exactly this attack, and it works on the same app most businesses already use.

What New York Actually Ties to Regulation
This isn’t just underwriting preference here in the Tri-State area. New York’s Department of Financial Services requires MFA for remote access to the network and any externally exposed application, under 23 NYCRR 500.12. That’s binding regulation for DFS-covered entities, not a recommendation sitting in a PDF nobody reads. For everyone else, it’s still the exact control an underwriter’s questionnaire is going to ask about by name.
A related question, EDR coverage, gets the same yes-or-no treatment on most applications. VJNetworks covered what actually separates EDR from antivirus in more depth, since the same “technically true, thin in practice” problem shows up there too.
Where to Start, If You’re Starting From Zero
CISA’s own advice here is more useful than most vendor pitches. Don’t try to move everyone to phishing-resistant MFA at once.
- Start with email, remote access, and admin accounts. Those are the accounts attackers actually target first.
- If phishing-resistant options aren’t realistic yet, move everyone off SMS to app-based push with number matching. That single change closes the push bombing gap.
- Identify your actual high-value accounts, the ones with access to financial systems, sensitive files, or the ability to create new user accounts. Those get priority for the strongest method available.
- Confirm coverage in writing. “Everyone has MFA” and a list showing which accounts actually have it enforced are two different documents.
- Revisit the list whenever someone new joins or a system gets added. Coverage gaps grow quietly, not all at once.

What Owners Actually Ask Me About This
We use SMS codes for our MFA. Does that hold up on an application?
Is a physical security key really necessary, or is app-based push good enough?
What’s actually happening when someone gets “push bombed”?
Do we need phishing-resistant MFA on every account, or just the important ones?
How would an insurer even know which type of MFA we’re actually running?
Two questions, not one. Is MFA enforced everywhere it should be, and is it the kind that actually resists the attacks insurers are pricing against? VJNetworks has helped small businesses across the Tri-State area answer both for over 20 years, through cybersecurity work built around VJNetworks’ managed IT services, not a one-time setup that quietly falls behind. A free assessment checks exactly where your own MFA coverage actually stands.
Further reading: CISA’s “Implementing Phishing-Resistant MFA” fact sheet covers the full ranking and rollout guidance in detail.
A free assessment checks enforcement and method strength against what your next insurance application will actually ask. No obligation, no sales pitch.
