Who Signs a Cyber Insurance Application?
Who signs a cyber insurance application, what the signature represents, and why the signer must check the security answers with IT first.
Read articleCompliance
Every question on Travelers' Multi-Factor Authentication Supplement (CYB-14306), what a true Yes takes, and the evidence to have ready before you sign.
On Travelers' Multi-Factor Authentication Supplement (CYB-14306), a Yes means multi-factor authentication is required, not just available: for email, for all remote access to the network, and for administrator access to directory services, backups, network infrastructure, and endpoints and servers, vendors included.
The supplement is short: four questions, the third split into four parts, and a signature. Below, each question is paraphrased from the form, with Travelers' own words in quotation marks where they matter, followed by what has to be true before you tick Yes and the kind of evidence to have ready when an underwriter asks.
Question 3 covers administrator access in four places, and it says the question includes access given to "3rd party service providers". Your IT provider's and your software vendors' administrator access counts.
If the honest answer to any question is No, the form asks you to explain it in the Additional Information section at the end. Take that at its word. On this form, MFA on most accounts but not all is a No with an explanation, not a Yes.
Source: Travelers, Multi-Factor Authentication Supplement, CYB-14306 Rev. 03-23 (PDF). The questions below are paraphrased from that form. Words in quotation marks are Travelers' own. It is one carrier's form: other carriers word these questions differently, so answer the form in front of you.
Travelers asks whether multi-factor authentication is "required for all employees" when they reach email through a website or a cloud service.
What a true Yes takes. Every employee's mailbox asks for a second factor at sign-in, and a policy enforces it instead of leaving it to each person. MFA that people can turn on but don't have to is not "required". Check that no older sign-in method skips the prompt.
Evidence: your email provider's MFA coverage report and the policy that enforces it.
It asks whether MFA is required for all remote access to your network, whether that access belongs to employees, contractors or "3rd party service providers".
What a true Yes takes. Every way into the office network from outside asks for a second factor: the VPN, remote desktop, and the remote-support tools your IT provider and software vendors use. Contractors' and vendors' access counts too.
Evidence: an inventory of remote-access paths and the MFA setting on each.
It asks whether "internal & remote admin access" to directory services, such as Active Directory, requires MFA.
What a true Yes takes. Administrator sign-ins to the directory need a second factor inside the office as well as outside it. The phrase small firms miss is "internal & remote": an administrator who signs in at the server without MFA makes this a No.
Evidence: the directory administrator list and the setting that enforces MFA for it.
The same question, for administrator access to your backup environment.
What a true Yes takes. The backup console, and the backup provider's web portal if there is one, asks every administrator for a second factor. An intruder with backup administrator rights can delete the copies you would restore from.
Evidence: the backup console's MFA setting and administrator list.
The same question, for administrator access to network equipment: firewalls, routers, switches and the like.
What a true Yes takes. The administrator login on the firewall, router, switches and wireless controller asks for a second factor. Some small-office equipment can't do that. If yours can't, the true answer is No, with the explanation the form asks for.
Evidence: a network device inventory and how each administrator login is protected.
The same question, for administrator access to your computers and servers.
What a true Yes takes. Administrator access to servers and computers asks for a second factor, on site and remote, including through the management tools your IT provider uses.
Evidence: the controls on server administrator access, including your IT provider's remote-management tool.
The signer confirms they completed the form "with the assistance of the person in charge of IT security".
What a true Yes takes. The executive who signs went through the answers with whoever runs IT security, in house or outsourced. If that is an outside IT provider, have them in the room and keep a note of what they confirmed.
Evidence: a dated record of who helped with the answers.
Question 4 ties these answers to the person who signs the form, and on CYB-14306 that is an Executive Officer. What the signature represents, who counts as the signer in a small firm, and how to sign without guessing are in Who signs a cyber insurance application?
Send us your questionnaire before you submit it. We review the security questions and the evidence behind each answer, flag what could get you declined, and reply within one business day, at no cost. Get the free questionnaire review.
If the review turns up gaps to close and document, the Cyber Insurance Readiness Sprint builds the evidence pack mapped to your carrier's form.
We review; we don't complete or sign applications. Obsidian Ridge is not an insurance producer, broker, or agent. We do not sell, place, or advise on insurance products.
This article is general information, not legal or insurance advice. Carrier forms change. It quotes Travelers CYB-14306 Rev. 03-23 as published at the link above.
Last updated
September 25, 2026. We refresh this content as the threat landscape and tools evolve.
FAQ
Travelers' Multi-Factor Authentication Supplement, CYB-14306 (Rev. 03-23), asks whether multi-factor authentication is required for email, for all remote access to the network, and for administrator access to directory services, backups, network infrastructure, and endpoints and servers, including access given to vendors. A fourth question asks the signer to confirm they had the help of the person in charge of IT security.
Answer No and explain it: the form asks for an explanation of any No in its Additional Information section. MFA on most accounts but not all is a No with an explanation, not a Yes.
Related reading
Who signs a cyber insurance application, what the signature represents, and why the signer must check the security answers with IT first.
Read articleCyber insurance carriers stopped accepting 'we have antivirus' years ago. Here is what they ask about endpoint protection and how each term maps.
Read articleA hands-on deep-dive on cyber-insurance control #15 — link rewriting, time-of-click URL analysis, and attachment sandboxing.
Read article