SMS MFA Is About to Fail Your Cyber Insurance Renewal
Carriers are tightening MFA rules for 2026. What counts as phishing-resistant MFA, the app and FIDO2 alternatives, and the rollout order for a small office.
Carriers are tightening MFA rules for 2026. What counts as phishing-resistant MFA, the app and FIDO2 alternatives, and the rollout order for a small office.
The renewal application lands in the office manager’s inbox in late summer. Most of it looks like last year. One box does not. Where the form used to ask “Do you use multi-factor authentication,” it now asks whether that MFA is “phishing-resistant,” and a text-message code no longer counts as a yes.
For a lot of small offices, that single change is the difference between a clean renewal and a non-renewal letter. Here is what carriers are asking for, why the rules moved, and the order to fix it in before your renewal date.
SMS MFA was always the weak version. The code travels over the phone network in the clear, and attackers have two reliable ways around it. One is the SIM swap, where they talk your carrier into moving your number to their phone. The other is the real-time phishing page that asks for the code and replays it before it expires. Both are common enough now that cyber underwriters have been tightening what counts as a yes, and on the questions that matter most a texted code increasingly does not.
Your own application is the thing to read. Requirements differ by carrier and change year to year, so what mattered at your last renewal may not be what the form asks this time.
The same logic hit voice-call codes and email codes. If an attacker who already has your password can intercept the second factor, it was never a second factor.
Think of MFA as three steps up a ladder, weakest to strongest.
Most small offices do not need a security key on every desk. They need authenticator apps everywhere and hardware keys on the accounts that would end the business if they fell: the domain administrator, the email tenant admin, the bank, and the practice-management or case-management login.
A 15-person office can get this done in a few weeks without a help-desk meltdown. The order matters, because doing it backward is how you lock yourself out.
Answering “yes” to phishing-resistant MFA when the real answer is “we send texts” is not a paperwork shortcut. It is a misrepresentation, and carriers read the access logs after a breach. A denied claim costs more than the premium ever would. If you are not sure your answer is defensible, find out before you sign, not after.
The free Cyber Score checks where your domain and your exposed accounts stand and emails you a written report. If you want a real plan to close the gap before renewal, the IT Blueprint Assessment walks the office, the accounts, and the controls, and leaves you a written punch list. We set up the security stack on every managed plan, or as a one-time project in the weeks before your renewal date. Public number: (806) 370-4700.
Like a credit score, but for your business's cybersecurity.
It is free and takes about two minutes. You get a grade and a written report by email.
Owner-operated in Lubbock · (806) 370-4700