---
title: Why Cyber Insurance Requirements Now Include MFA and Session Monitoring
description: Cyber insurance now demands specific MFA and session monitoring practices to mitigate risks from credential theft. Prepare for 2027 with TMGC!
image: https://www.tmgcinc.com/hubfs/cyber%20insurance%20requirements.webp
---

[Skip to the main content.](https://www.tmgcinc.com/blog/cyber-insurance-requirements-mfa-and-session-monitoring#main-content)

[![TMGC\_Logo\_Main\_V1](https://www.tmgcinc.com/hs-fs/hubfs/Logos/TMGC_Logo_Main_V1.webp?width=130&height=112&name=TMGC_Logo_Main_V1.webp "TMGC_Logo_Main_V1")](https://www.tmgcinc.com/)

[![TMGC\_Logo\_Main\_V1](https://www.tmgcinc.com/hs-fs/hubfs/Logos/TMGC_Logo_Main_V1.webp?width=150&height=129&name=TMGC_Logo_Main_V1.webp "TMGC_Logo_Main_V1")](https://www.tmgcinc.com/)

- [Fractional IT Services](https://www.tmgcinc.com/fractional-it-services)
- What We Do 
    - [Complete IT Management](https://www.tmgcinc.com/fractional-it-services)
    - [Cybersecurity](https://www.tmgcinc.com/managed-cybersecurity-services)
    - [Service Desk](https://www.tmgcinc.com/it-help-desk-services)
    - [Data Protection & Recovery](https://www.tmgcinc.com/data-backup-recovery)
    - [Cloud & Hosting](https://www.tmgcinc.com/managed-cloud-hosting-services)
    - [Compliance Management](https://www.tmgcinc.com/it-compliance-services)
    - [IT Infrastructure](https://www.tmgcinc.com/it-infrastructure-management)
    - [Licensing & Software Management](https://www.tmgcinc.com/it-licensing-management)
    - [Device Management](https://www.tmgcinc.com/it-device-management)
- Industries 
    - [Manufacturing](https://www.tmgcinc.com/managed-it-services-manufacturing)
    - [AEC](https://www.tmgcinc.com/architecture-engineering-construction-it-services)
    - [Financial Services](https://www.tmgcinc.com/it-support-financial-services)
    - [Medical](https://www.tmgcinc.com/managed-it-services-medical-practices)
    - [Defense Contractors](https://www.tmgcinc.com/it-support-defense-contractors)
    - [Private Equity](https://www.tmgcinc.com/it-services-private-equity)
- Resources 
    - [About Us](https://www.tmgcinc.com/about)
    - [Blog](https://www.tmgcinc.com/blog)
    - [Case Studies](https://www.tmgcinc.com/case-studies)
    - [Guide to CMMC Compliance](https://www.tmgcinc.com/cmmc-compliance-everything-defense-contractors-need-to-know-in-2026)
    - [Guide to Workplace AI Security](https://www.tmgcinc.com/workplace-ai-security-guide)
    - [AI Readiness Quiz](https://www.tmgcinc.com/ai-security-readiness-quiz-tmgc)

[GET STARTED](https://www.tmgcinc.com/contact)

Toggle Menu

Toggle Menu

[GET STARTED](https://www.tmgcinc.com/contact)

- [Fractional IT Services](https://www.tmgcinc.com/fractional-it-services)
- What We Do

    - [Complete IT Management](https://www.tmgcinc.com/fractional-it-services)
    - [Cybersecurity](https://www.tmgcinc.com/managed-cybersecurity-services)
    - [Service Desk](https://www.tmgcinc.com/it-help-desk-services)
    - [Data Protection & Recovery](https://www.tmgcinc.com/data-backup-recovery)
    - [Cloud & Hosting](https://www.tmgcinc.com/managed-cloud-hosting-services)
    - [Compliance Management](https://www.tmgcinc.com/it-compliance-services)
    - [IT Infrastructure](https://www.tmgcinc.com/it-infrastructure-management)
    - [Licensing & Software Management](https://www.tmgcinc.com/it-licensing-management)
    - [Device Management](https://www.tmgcinc.com/it-device-management)
- Industries

    - [Manufacturing](https://www.tmgcinc.com/managed-it-services-manufacturing)
    - [AEC](https://www.tmgcinc.com/architecture-engineering-construction-it-services)
    - [Financial Services](https://www.tmgcinc.com/it-support-financial-services)
    - [Medical](https://www.tmgcinc.com/managed-it-services-medical-practices)
    - [Defense Contractors](https://www.tmgcinc.com/it-support-defense-contractors)
    - [Private Equity](https://www.tmgcinc.com/it-services-private-equity)
- Resources

    - [About Us](https://www.tmgcinc.com/about)
    - [Blog](https://www.tmgcinc.com/blog)
    - [Case Studies](https://www.tmgcinc.com/case-studies)
    - [Guide to CMMC Compliance](https://www.tmgcinc.com/cmmc-compliance-everything-defense-contractors-need-to-know-in-2026)
    - [Guide to Workplace AI Security](https://www.tmgcinc.com/workplace-ai-security-guide)
    - [AI Readiness Quiz](https://www.tmgcinc.com/ai-security-readiness-quiz-tmgc)

[Linkedin](https://www.linkedin.com/company/the-millennium-group-computing/)

 6 min read

# Why Cyber Insurance Requirements Now Include MFA and Session Monitoring

[Tony DiDonato](https://www.tmgcinc.com/blog/author/tony-didonato) :  September 25, 2026

[Credential Theft](https://www.tmgcinc.com/blog/tag/credential-theft)

![Why Cyber Insurance Requirements Now Include MFA and Session Monitoring](https://www.tmgcinc.com/hubfs/cyber%20insurance%20requirements.webp)

Cyber insurance requirements are the security controls a carrier expects your business to have in place before it will write or renew a policy. For the last few years, the headline requirement has been multi-factor authentication. Heading into 2027 renewals, that question has gotten a lot more specific: what kind of MFA you use, which accounts it covers, and who's watching your logins after someone signs in.

That shift lines up with everything we've covered in our guide to business credential theft. Attackers stopped breaking in and started logging in, and underwriters noticed. This post closes out that series by looking at the same problem from the carrier's side of the table.

 

## **Key Takeaways**

- Cyber insurance rates have fallen for twelve straight quarters, but carriers are tying the best terms to proof of strong identity controls
- Applications now ask which type of MFA you use and where it's enforced, including admin and service accounts
- A wrong answer on your application can void the entire policy, which is exactly what happened to one Travelers policyholder after a ransomware attack
- Session monitoring is showing up on applications because attackers now steal login tokens to get past MFA
- Email fraud and wire fraud made up 58% of cyber incidents in Coalition's 2026 claims data, which is why identity gets the most scrutiny

 

## **Table of Contents**

1. [How Are Cyber Insurance Requirements Changing?](https://www.tmgcinc.com/blog/cyber-insurance-requirements-mfa-and-session-monitoring#changing)
2. [Why Are Insurers So Focused on MFA?](https://www.tmgcinc.com/blog/cyber-insurance-requirements-mfa-and-session-monitoring#why)
3. ["We Have MFA" Isn't the Answer Carriers Want Anymore](https://www.tmgcinc.com/blog/cyber-insurance-requirements-mfa-and-session-monitoring#have)
4. [What Happens If Your Application Answers Aren't Accurate?](https://www.tmgcinc.com/blog/cyber-insurance-requirements-mfa-and-session-monitoring#answers)
5. [Why Session Monitoring Is Showing Up on Applications](https://www.tmgcinc.com/blog/cyber-insurance-requirements-mfa-and-session-monitoring#monitoring)
6. [How to Get Ready for Your Next Renewal](https://www.tmgcinc.com/blog/cyber-insurance-requirements-mfa-and-session-monitoring#renewal)

 

## **How Are Cyber Insurance Requirements Changing?**

The biggest change as we near the last quarter of the year and prep for 2027 is proof. For the last few years, carriers asked whether you had basic controls like MFA and backups. Now they're asking how those controls are set up, which accounts they cover, and whether you can show it, and they're pricing policies around the answers.

The pricing news is good. Cyber insurance rates dropped 4% globally in Q2 2026, the 12th quarter in a row of declines, with U.S. rates down 2%. That doesn't mean carriers got relaxed. Marsh expects policies to lean further into risk-based segmentation, with favorable terms going to businesses that can show strong defenses. Everyone else tends to see higher deductibles or exclusions written around the controls they're missing.

We laid out the baseline checklist in our post on how cybersecurity gaps put professional liability coverage at risk. Here's how the identity questions on that checklist have changed.

 

| **Application Question** | **What Used to Pass** | **What’s Required Now** |
| --- | --- | --- |
| Do you use MFA? | "Yes" for email | MFA on every user, every remote access path, and every admin account |
| What type of MFA? | Rarely asked | Text codes and push approvals flagged as weaker; phishing-resistant methods preferred, especially for admins |
| Admin accounts | A rough count | How many exist, whether they're separate from everyday accounts, and whether each one requires MFA |
| Service accounts | Not asked | Shared or never-expiring passwords, and whether those accounts are logged |
| Monitoring | "Do you have antivirus?" | Who watches login activity, how suspicious sessions get flagged, and how fast someone responds |
| Backups | "Do you back up?" | Offline or immutable copies, and proof that restores have been tested |

 

## **Why Are Insurers So Focused on MFA?**

Cyber insurance companies focus on MFA because most of what they pay out starts with a stolen or abused login. Coalition's 2026 claims data found email fraud and funds transfer fraud made up 58% of all incidents, and more than half of the funds transfer fraud cases started with a compromised business email account.

The pattern it describes is the same one we walked through in our post on business email compromise: an attacker gets into a real inbox, studies how money moves, and sends a request that looks completely normal.

Getting that first login is easier than most owners think. A ClickFix attack can trick an employee into installing infostealer malware that pulls every saved password off their computer in seconds. From the carrier's point of view, every account without MFA is an open claim waiting to happen.

Partial coverage doesn't earn much credit either. Marsh McLennan's research found that businesses with MFA on all critical data, all remote access, and all admin accounts were less likely to suffer a successful attack. The benefit comes from covering every door. MFA on email alone leaves the side entrances open.

 

## **"We Have MFA" Isn't the Answer Carriers Want Anymore**

A few years ago, checking yes on the MFA box got you through underwriting. Today, the follow-up questions are where most businesses start to sweat.

The first one is usually about type. CISA calls phishing-resistant MFA the gold standard and flags the common alternatives as weaker: text codes can be stolen through SIM swapping, push approvals can be spammed until someone taps yes, and app codes can be phished. We broke down each of those tactics in our post on MFA bypass attacks. Carriers read the same research, and they're asking which method your team uses.

The second question is about reach. Underwriters want to know how quickly a single compromised account could turn into an administrator account. That puts a spotlight on the accounts most small businesses never think about:

- **Admin accounts used for everyday work:** If your IT admin checks email from the same account that manages your whole Microsoft 365 tenant, one phishing email can hand an attacker the keys to everything.
- **Service accounts:** These run background tasks like backups, scanners, and software integrations. They often have old passwords that never expire and no MFA at all.
- **Shared logins:** A single login used by three people can't be tied to one person, which makes MFA hard to enforce and harder to audit.

This is where passkeys come in. Moving your admins and your finance team to passkeys or hardware security keys answers the "what type" question with the strongest answer available, and it's more realistic to roll out than most owners assume.

 

## **What Happens If Your Application Answers Aren't Accurate?**

If your application says you have a control that isn't fully in place, the carrier can deny the claim or void the policy entirely. Your application becomes part of the contract, so a checkbox answered with good intentions can end up being the reason a claim never pays.

The case everyone in the insurance world points to is Travelers v. ICS. International Control Services told Travelers on its application that it used MFA. After a ransomware attack in 2022, Travelers found that ICS only used MFA to protect its firewall, and nothing else. The two sides agreed to have a court void the policy back to the day it started, which left ICS with no coverage for the attack it had bought the policy to cover.

We don't think ICS set out to mislead anyone. In most small businesses, the insurance application lands on the owner's or office manager's desk, and they answer based on what they believe is true. The person who configured the systems never sees it.

That's why we work closely with brokers like Lakeside Insurance, an independent Colorado agency we've partnered with for more than 15 years. When the person answering the questions and the person who built the systems compare notes before the application goes out, the answers hold up when it counts.

 

## **Why Session Monitoring Is Showing Up on Applications**

Session monitoring watches what happens after someone logs in, flagging things like a login token being used from an unfamiliar location or device. Insurers ask about it because attackers can now steal the token issued after MFA, which lets them into an account without ever setting off a second prompt.

That's the attack we covered in our post on session hijacking. MFA checks who you are at the moment you log in, and then steps aside. If an attacker grabs the session token through a fake login page, they walk in as you, and your MFA never knows anything happened.

Carriers have figured out that MFA at the front door doesn't help much if nobody is watching the hallway. So the application questions have moved past "do you have MFA" to "what happens after someone logs in." In practice, that means:

- **Conditional access rules** that block or challenge logins from unexpected countries or devices
- **Impossible travel alerts** that flag the same account signing in from Denver and Eastern Europe twenty minutes apart
- **Token revocation** so a stolen session can be shut down immediately, instead of whenever it expires
- **A real person responding** to those alerts, which is the part most businesses are missing

Plenty of businesses have alerts turned on and nobody reading them. That's the gap a managed cybersecurity setup closes, and it's the answer underwriters want to see when they ask who's watching.

 

## **How to Get Ready for Your Next Renewal**

Most of the work comes down to making sure what's on paper matches what's configured. Start 60 to 90 days before your renewal date so there's time to fix gaps instead of explaining them.

1. **Pull last year's application:** Check every answer against how your systems are set up today, not how they were set up when you first bought the policy.
2. **Map your MFA coverage:** List every user and every admin and service account, then mark which ones have MFA and what type.
3. **Move admins and finance to phishing-resistant MFA:** These are the accounts attackers want first and the accounts underwriters ask about most.
4. **Separate admin accounts from everyday accounts:** Nobody should be reading email from the account that controls your entire environment.
5. **Turn on session monitoring with someone responding:** Alerts nobody reads won't help you at claim time.
6. **Bring your IT partner and broker together:** Have the person who built your systems review the application before it goes to the carrier.

With our fractional IT services, this work is part of the flat monthly rate, so there's no extra project bill for getting ready for renewal. If yours is coming up, we'd love to talk and check every answer against how your systems are set up.

 

Our Story

Our Story

Started in 1999, The Millennium Group Computing is a proud veteran-owned business that is a complete technology solution provider. We are 100% committed to making sure business owners have the most reliable and professional IT service in Denver Metro. Our team of talented IT professionals can solve your IT nightmares once and for all.

###### ![](https://www.tmgcinc.com/hs-fs/hubfs/Logos/TMGC_Logo_Main_V1%20(1).webp?width=125&height=108&name=TMGC_Logo_Main_V1%20(1).webp)

Who We Serve

Who We Serve

- [Manufacturing](https://www.tmgcinc.com/managed-it-services-manufacturing)
- [Engineering](https://www.tmgcinc.com/architecture-engineering-construction-it-services)
- [Defense & Govcon](https://www.tmgcinc.com/it-support-defense-contractors)
- [Financial](https://www.tmgcinc.com/it-support-financial-services)
- [Medical](https://www.tmgcinc.com/managed-it-services-medical-practices)
- [Private Equity](https://www.tmgcinc.com/it-services-private-equity)

Resources

Resources

- [TMGC Blog](https://www.tmgcinc.com/blog)
- [About Us](https://www.tmgcinc.com/about)
- [Contact Us](https://www.tmgcinc.com/contact)
- [Support](https://www.tmgcinc.com/customer-support)

- [Contact Us](https://www.tmgcinc.com/contact)
- [Support](https://www.tmgcinc.com/customer-support)
- [Privacy Policy](https://www.tmgcinc.com/privacy-policy)

© 2026 The Millennium Group Computing - Denver's Leader In IT Tech Services

[Linkedin](https://www.linkedin.com/company/the-millennium-group-computing/)

*Designed by [Warden Strategy](https://www.wardenstrategy.com/)*

Return to top

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Tony DiDonato",
    "url" : "https://www.tmgcinc.com/blog/author/tony-didonato"
  },
  "dateModified" : "2026-09-25T21:31:31.836Z",
  "datePublished" : "2026-09-25T21:31:31.000Z",
  "headline" : "Why Cyber Insurance Requirements Now Include MFA and Session Monitoring",
  "image" : [ "https://www.tmgcinc.com/hubfs/cyber%20insurance%20requirements.webp" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.tmgcinc.com/blog/cyber-insurance-requirements-mfa-and-session-monitoring",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.tmgcinc.com/hubfs/TMGC_Logo_Main_V1.webp"
    }
  }
}
```