SE Security

June 29, 2026
BY PHILIP ROBB
6 MIN READ

All posts

SMS MFA Is About to Fail Your Cyber Insurance Renewal

Carriers are tightening MFA rules for 2026. What counts as phishing-resistant MFA, the app and FIDO2 alternatives, and the rollout order for a small office.

The renewal application lands in the office manager’s inbox in late summer. Most of it looks like last year. One box does not. Where the form used to ask “Do you use multi-factor authentication,” it now asks whether that MFA is “phishing-resistant,” and a text-message code no longer counts as a yes.

For a lot of small offices, that single change is the difference between a clean renewal and a non-renewal letter. Here is what carriers are asking for, why the rules moved, and the order to fix it in before your renewal date.

Why text-message codes stopped counting

SMS MFA was always the weak version. The code travels over the phone network in the clear, and attackers have two reliable ways around it. One is the SIM swap, where they talk your carrier into moving your number to their phone. The other is the real-time phishing page that asks for the code and replays it before it expires. Both are common enough now that cyber underwriters have been tightening what counts as a yes, and on the questions that matter most a texted code increasingly does not.

Your own application is the thing to read. Requirements differ by carrier and change year to year, so what mattered at your last renewal may not be what the form asks this time.

The same logic hit voice-call codes and email codes. If an attacker who already has your password can intercept the second factor, it was never a second factor.

What “phishing-resistant” means

Think of MFA as three steps up a ladder, weakest to strongest.

  • SMS, voice, and email codes. Being phased out. Still better than a password alone, but no longer a checkbox answer on the hardening questions.
  • Authenticator apps. A code or a push approval from an app on the phone (Microsoft Authenticator, Google Authenticator, Duo). Number-matching push, where you type a number shown on screen into the app, closes the approve-by-accident hole. This clears the bar for most carriers today.
  • FIDO2 security keys and passkeys. A hardware key (YubiKey) or a passkey tied to the device and the website. The login only works on the real site, so the fake page gets nothing to replay. This is the phishing-resistant tier the strictest carriers and the federal guidance point to.

Most small offices do not need a security key on every desk. They need authenticator apps everywhere and hardware keys on the accounts that would end the business if they fell: the domain administrator, the email tenant admin, the bank, and the practice-management or case-management login.

The rollout order for a small office

A 15-person office can get this done in a few weeks without a help-desk meltdown. The order matters, because doing it backward is how you lock yourself out.

  1. Inventory the accounts that take a login. Email, the bank, the line-of-business app, the file storage, the remote-access tool. You cannot protect what you have not written down.
  2. Turn on enforcement at the identity provider, not the inbox. Microsoft 365 Conditional Access or Google Workspace 2-step enforcement pushes the rule to everyone at once. Per-user opt-in always leaves a hole.
  3. Roll out the authenticator app to staff first. Give people a week and a short walkthrough. Expect the front desk to need a hand. Real humans answer that question better than a PDF does.
  4. Put hardware keys on the crown-jewel accounts. Two keys per critical account, one in use and one in the safe, so a lost key is an annoyance and not a lockout.
  5. Kill the SMS fallback. This is the step everyone skips. If a user can still fall back to a texted code, an attacker can force that fallback. Turn it off once the stronger method is working.
  6. Save the proof. A screenshot of the enforcement policy and a short written summary. That is what the carrier wants to see, and it is what keeps a claim from getting denied later for a control you said you had.

The mistake that turns a premium into a lawsuit

Answering “yes” to phishing-resistant MFA when the real answer is “we send texts” is not a paperwork shortcut. It is a misrepresentation, and carriers read the access logs after a breach. A denied claim costs more than the premium ever would. If you are not sure your answer is defensible, find out before you sign, not after.

The free Cyber Score checks where your domain and your exposed accounts stand and emails you a written report. If you want a real plan to close the gap before renewal, the IT Blueprint Assessment walks the office, the accounts, and the controls, and leaves you a written punch list. We set up the security stack on every managed plan, or as a one-time project in the weeks before your renewal date. Public number: (806) 370-4700.

01 Start here

Find out where you actually stand.

Like a credit score, but for your business's cybersecurity.

It is free and takes about two minutes. You get a grade and a written report by email.

Owner-operated in Lubbock · (806) 370-4700

Call Get Score