Estimated reading time: 7 minutes
Two security leaders explain why binary questionnaire items produce honest answers and denied claims, and what insurers could ask instead.
The latest CINI podcast opens with a question I thought had an obvious answer. It does not.
Julien Richard, vice president of information security at Lastwall, spent part of the hour describing a company that tells its cyber insurer it uses multi-factor authentication. The statement is true. The protection covers the badge reader on the front door.
Then the finance system gets breached. Nobody lied. Nobody gets paid either.
Richard’s version of the conversation that follows is short. The insurer says you told us you had MFA. The insured says we did, on that system, not the one that was breached.
His colleague Isabel Castillo, lead information security operations engineer at Lastwall, does not soften it. She says the scope is the whole question. Not whether the control exists, but where it is implemented, how, on what, and why.
That is the hour. Two practitioners explaining why the industry’s most common underwriting question collects true answers and prices nothing.
Get The Show Here
YouTube
Spotify
Amazon
Apple
The Problem With Binary Questions
Richard has no patience for yes-or-no items on a security questionnaire. He calls them the worst kind of question, because the answer is always going to be yes.
His alternative is not a better checkbox. It is a different conversation. Ask what systems the organization runs. Ask what data sits in each one. And ask how each is protected and whether it uses a shared identity provider or its own access controls.
That is more work for an underwriter. It is also the difference between a policy you can price and a policy you will argue about in claims.
Castillo makes the same point from the security side. Both agree that the coverage map matters more than the control’s presence. Inconsistent deployment is where she sees organizations fail most often. Staff have it. Administrators do not. Contractors do not. Executives got an exception because they complained.
Attackers only need the exception.
Multi-Factor Versus Multi-Step
Richard noted a definitional error that shows up constantly in questionnaires and audit responses.
A factor is something you know, something you have, or something you are. Three things you have is not multi-factor. It is multi-step. The words are nearly identical. The security outcomes are not.
If your application language does not distinguish between them, you are collecting answers that sound compliant and mean very little.
How Attackers Walk Past the Code
Most bypasses assume the attacker already has the password. Richard says credential reuse and past breaches make that assumption safe.
The technique worth understanding is adversary-in-the-middle. The victim receives a link to a lookalike domain. Richard’s example is a bank at bank.com and a fake at bonk.com. The victim enters credentials. The fake site relays them to the real bank in real time. The bank asks for a code. The victim supplies it. The fake site passes it along.
What the attacker takes is not the password or the code. It is the session token, the thing your browser holds to prove you are still you. Steal the session and the login is irrelevant.
Phishing-resistant credentials break this because there is no credential for “bonk.com” to steal.
Richard also noted that SIM-swap attacks, which target text-message codes, have become less common in his experience as telecom carriers tightened their identity checks. That datapoint is worth carrying into underwriting conversations.
What Evidence Actually Looks Like
Castillo’s answer to the verification question is the most immediately usable material in the episode.
Logs and configurations. Conditional access policies. Login records. Records of failed logins and the reasons they failed. Her point is that an organization can demonstrate whether multi-factor authentication succeeded or failed on a given attempt, which turns a claimed control into an observable one.
She adds a caution that matters for claims work. Logs can be altered. Anyone reconstructing an incident timeline needs to assess whether the record itself survived intact.
The Dashboard Idea
The most forward-looking suggestion in the hour came from Richard, and it is aimed squarely at carriers.
Point-in-time audits produce what he calls the paved section. The road is smooth during the audit window and reverts to dirt afterward. His alternative borrows from continuous authorization to operate, the model used in the federal cloud authorization program.
Insureds upload sanitized logs on a set cadence. Logs are machine-readable by nature. A control being switched off generates an entry. The carrier runs a dashboard across its book. Red items get a phone call. A documented exception turns the item green.
Then, in Richard’s framing, if you hit all the controls, you can give whatever rebates you want.
That is a live product idea, not a metaphor. Any carrier already collecting security telemetry for scanning has most of the plumbing.
Why One Control Does Not Earn a Discount
Asked directly whether passwordless authentication should reduce a premium, Richard declined to say yes.
Strong authentication is worthless if the device behind it is unpatched and exploitable. He is skeptical that a rebate for any single technology makes sense. He wants audited controls across the estate, weighted by importance.
His line for it, which he credits to a colleague in the field: eat your cybersecurity fruits and vegetables. Foundations first. A well-written policy does not protect an unpatched VPN sitting open on the internet.
Castillo’s framing of the goal is narrower and more honest than most vendor language. Security continuously reduces risk. It does not eliminate it. Eliminate all risk, and you have no network.
The Question to Ask Your CISO
Both guests were asked what a board member or executive should ask first about their firm’s cyber resilience.
Castillo would ask whether the security program can keep up with modern and evolving attacks.
Richard would ask whether the technical team knows everything on the network. Visibility first. You cannot protect what you do not know exists. He also notes what the answer tells you. Anyone claiming total certainty is wrong, and anyone admitting they are not sure has just told you where the money should go.
For anyone writing this risk, Richard’s question is the one that maps to loss. An organization that cannot inventory its own estate cannot tell you what it is protecting, and neither can you.
FAQ – Cyber Insurance MFA Question
No. Coverage depends on where the control was deployed. An organization can truthfully report multi-factor authentication and still see a claim fail if the breached system was not covered by it.
A login method that cannot be relayed to a fake site. The credential is bound to one specific domain or application. Passkeys and FIDO2 security keys qualify. Text-message codes and authenticator app codes do not.
Multi-factor requires two different categories of proof: something you know, something you have, or something you are. Multi-step stacks several proofs from the same category. Multi-step is weaker and often reported as multi-factor.
The attacker hosts a convincing fake login page and relays credentials and codes to the real site in real time. The prize is the session token, which lets the attacker use the account without logging in again.
Configuration records, conditional access policies, login logs, and failure records showing when and why authentication was rejected. Claims and incident teams should also check whether the logs themselves were altered.
Richard argues against rebating any single technology, because strong authentication does not compensate for unpatched internet-facing systems. He favors discounts tied to audited performance across a full control set.
Transcript – Confirm elements against recording to be certain of content.
Related Cyber Insurance Posts
- Terra Sends AI Agents Into The Internal Network. The Liability Question Stays Outside
- 7 Essential Cyber Insurance Requirements You Can’t Ignore(Opens in a new browser tab)
- A Good Cyber Report Card Can Earn Companies Insurance Discounts: SecurityScorecard & Measured Analytics(Opens in a new browser tab)
- K-12 Cyber Insurance Reshapes School Security: “Cybersecurity Incidents” Hit Half Of U.S. Districts(Opens in a new browser tab)