Multi-factor authentication is no longer optional
Most Canadian cyber-insurance policies now treat MFA as a precondition. Here is how to roll it out without a revolt.
ITSIGN Administrator · November 5, 2025 · 2 min read
Almost every incident we are called into begins the same way: a valid username and password, used by someone who should not have them.
Underwriters have moved MFA from the discount column to the eligibility column. Remote access, email, and privileged accounts first. Then everyone else, with conditional access so you are not prompted to death.
Done properly, users notice it for about three days. We implement it in cloud and Microsoft 365 and evidence it for GRC.
Related reading
A board briefing that fits in ten minutes
Residual risk, open highs, last restore test, last simulation. Then stop talking.
2 min read
Vendor questionnaires that waste a week
Keep a living packet: MFA, backup, pentest date, policies. Answer from the packet, not from memory.
2 min read
SOC 2 readiness for a 40-person firm
You do not need a 20-person GRC team. You need owners, evidence locations, and a scope that matches the customer who asked.
2 min read
Want this applied to your environment?
A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.
