A method requiring several distinct proofs of identity to access a system, now an almost systematic underwriting requirement in cyber insurance.
Multi-factor authentication requires, in order to access a system, at least two proofs of identity of different kinds, classically something you know such as a password, something you have such as a phone or a physical key, and sometimes something you are such as a fingerprint. The idea is that an attacker who has stolen a password will still be unable to access the account, lacking the second factor. This simple measure has proved among the most effective at countering credential theft, which is one of attackers' main routes of entry. This is why, since the hardening of the cyber market around 2021, it has become an all but unavoidable underwriting requirement, the absence of multi-factor authentication on sensitive access points, email, remote access, administrator accounts, frequently leading to a refusal of cover or to degraded terms. For the insurer, it is both an instrument of concrete risk reduction and a signal of the insured's security maturity, thereby helping to mitigate adverse selection by distinguishing serious organizations from the rest.
A cyber insurer declines to cover a company whose remote access is protected only by a password. After multi-factor authentication is deployed across all critical access points, the same submission is accepted on markedly more favorable terms.
MFA, 2FA, authentification à deux facteurs, double authentification