Authentication mechanism requiring at least two distinct verification factors, drastically reducing the risk of account compromise even when credentials are stolen.
Multi-factor authentication (MFA) is an access-control mechanism that requires, in addition to a password, at least one additional verification factor belonging to a different category: something you possess (a hardware token, a mobile phone receiving an OTP, a FIDO2 key), something you are (biometrics), or something you know (secret question, PIN code). By combining two factors from different categories, MFA renders a stolen password alone unusable, neutralizing the vast majority of credential-stuffing and ordinary phishing attacks. Modern standards advocate phishing-resistant factors such as FIDO2/WebAuthn keys, which cannot be intercepted by a phishing site substituting itself for the legitimate service. For cyber underwriting, MFA has become an absolute prerequisite on remote access (VPN, RDP) and administrator accounts, and its absence on these access points can lead to a coverage denial or partial exclusion. Some contracts include a partial forfeiture clause if a loss occurs without MFA being active on the exposed access points.
In 2024, a cyber broker compares two cohorts of 200 SMEs: those that have deployed MFA on all remote access report no claims related to credential compromise, versus a 8 percent loss rate in the cohort without MFA, confirming the direct protective effect of this control.
MFA, multi-factor authentication, authentification à deux facteurs, 2FA, FIDO2, OTP