Does Your Cyber-Insurance Renewal Require MFA and EDR? What It Means
Why does your cyber-insurance renewal suddenly require MFA and EDR?
Because insurers now treat multi-factor authentication (MFA) and endpoint detection and response (EDR) as the two controls that most reliably stop ransomware and email fraud claims. After years of heavy payouts, carriers made these table stakes: if your renewal questionnaire shows you lack them, you'll face higher premiums, coverage exclusions, or a flat-out declined policy.
What is MFA, in plain English?
Multi-factor authentication means logging in takes more than just a password. You add a second proof of identity, usually a code from an app on your phone or a hardware key. That way a stolen or guessed password alone can't open the door. Insurers care because credential theft is the number-one way attackers get in, and MFA blocks the overwhelming majority of those automated attacks.
When the questionnaire asks about MFA, it usually wants it in three specific places:
- Email (Microsoft 365 or Google Workspace) — the most common target.
- Remote access — your VPN, remote desktop, or any way staff log in from outside the office.
- Admin and privileged accounts — the powerful logins that control your systems.
"We turned on MFA for a few people" won't cut it. Carriers increasingly want it enforced across all users, and they may ask you to attest to it in writing. A managed provider handling your Microsoft 365 support can enforce it tenant-wide and pull a report proving coverage.
What are EDR and MDR, and how are they different from antivirus?
EDR — endpoint detection and response — is the modern replacement for traditional antivirus. Old antivirus matched known virus signatures. EDR watches how programs actually behave on each laptop and server, flags suspicious activity like a process trying to encrypt your files, and can isolate the machine before the damage spreads. Tools like SentinelOne, CrowdStrike, and Microsoft Defender for Endpoint fall in this category.
MDR — managed detection and response — is EDR plus a human security team watching the alerts around the clock. Software catches the signal; people investigate it and respond at 2 a.m. when no one on your staff is awake. Many insurers now specifically favor or require MDR, because an alert nobody sees is an alert that doesn't stop anything.
If you're weighing whether you need the software alone or the full monitored service, our guide on MSP vs MSSP breaks down who does what, and managed cybersecurity covers the 24/7 monitoring most questionnaires now expect.
What else is on the typical cyber-insurance questionnaire?
MFA and EDR get the headlines, but the application digs deeper. Expect questions on a familiar set of controls, and expect the carrier to check some of them against a scan of your public-facing systems. Common items include:
- Backups — do you have tested, offline or immutable backups you could restore from without paying a ransom?
- Email filtering — spam and phishing protection on your inbox.
- Patching — how quickly you apply security updates to servers and software.
- Security awareness training — do you train staff to spot phishing?
- Incident response plan — a written plan for what happens during a breach.
- Privileged access management — limiting who holds admin rights.
Here's the trap: these forms are legal attestations. If you check "yes" on MFA or backups and a claim later reveals it wasn't true, the carrier can deny the claim or void the policy. That makes accuracy on the questionnaire a business-survival issue, not paperwork. Solid backup and disaster recovery and a real incident-response process are what let you answer honestly.
Why is this landing on renewals right now?
Ransomware claims spiked, insurers lost money, and the market corrected. Carriers discovered that a handful of controls — MFA, EDR/MDR, tested backups — separate the companies that survive an attack from the ones that file a total-loss claim. So they moved those controls from "nice to have" to "condition of coverage." The upshot: implementing them is almost always cheaper than the alternative, which is a denied claim or absorbing a breach with no coverage at all — far more than the cost of a single incident.
Certain sectors feel this hardest. Law firms, for example, hold highly sensitive client data and face strict confidentiality duties, so carriers scrutinize their controls closely — see how we approach IT for legal firms. Whatever your field, a provider offering cybersecurity services can map your current setup against the questionnaire before you submit it, so there are no surprises and no false attestations.
Frequently asked questions
Can I get cyber insurance without MFA and EDR?
It's getting rare. Some carriers will still quote you, but expect much higher premiums, lower coverage limits, or exclusions that gut the policy's value. Most standard markets now treat MFA and EDR (or MDR) as minimum requirements to be quoted at all.
Does Microsoft 365 Business Premium count as EDR?
Its Defender for Endpoint component can qualify as EDR when it's properly licensed, deployed, and actually monitored — not just switched on. Many small businesses own the license but never fully configure it, which is exactly the gap an insurer or attacker finds. Have someone confirm it's genuinely active across every device.
What happens if I say "yes" to a control I don't actually have?
A false attestation gives the insurer grounds to deny your claim or rescind the policy after an incident. Answer truthfully, and if you can't yet answer "yes," close the gap before you submit rather than hoping it never gets tested.
Renewing soon and not sure you'll pass the questionnaire? Compare vetted providers — free and get your controls in shape before you submit.
