surable

Credential stuffing

In one sentence

Attackers trying username/password pairs leaked from other breaches, betting people reused them.

Because people reuse passwords, attackers take credentials leaked from one site and try them everywhere else automatically. Unique passwords (a password manager) plus MFA defeat it.

Why it's on your cyber insurance application

Part of why MFA and password hygiene are baseline application requirements.

How the Readiness Check scores it

The free Check asks the same question a carrier will. Here it is, why it's asked, and the fix if today's honest answer is no. The full application question list has the rest.

MFA & identity

Is multi-factor authentication (MFA) required on all business email accounts?

Why carriers ask: Stolen credentials are the most common way attackers get in. Nearly every carrier now requires MFA on email, remote access, and admin accounts as a condition of coverage.

If the answer is no: Enable enforced MFA in Microsoft 365 / Google Workspace today. Built-in, free, typically an afternoon including user comms.

The written evidence carriers accept

A “yes” on the application needs a document behind it. In the Readiness Pack, that document is:

Related terms

Would you pass this question today?

The free Readiness Check scores you across the ten control domains carriers probe, in five minutes, no email required for the score.

← All terms