Travelers' MFA Supplement, Question by Question
Every question on Travelers' Multi-Factor Authentication Supplement (CYB-14306), what a true Yes takes, and the evidence to have ready before you sign.
Read articleCompliance
Who signs a cyber insurance application, what the signature represents, and why the signer must check the security answers with IT first.
On Travelers' Multi-Factor Authentication Supplement, CYB-14306 (Rev. 03-23), the application is signed by an Executive Officer. The form defines the term: "Executive Officer is defined as the applicant's chief executive officer, chief financial officer, chief information security officer, risk manager, in-house general counsel, or the functional equivalent." The same form then asks the signer to confirm one more thing: "The signer of this form has done so with the assistance of the person in charge of IT security."
That is the whole problem in two sentences. The person who signs is an executive. The questions they are signing about are technical. The form expects both people to have been in the room.
Other carriers word their signature blocks differently. This article quotes Travelers because it is the form we checked line by line, so read the signature block on yours before you rely on anything here.
Source: Travelers, Multi-Factor Authentication Supplement, CYB-14306 Rev. 03-23 (PDF)
The form does not say. Plenty of 12-person practices have no chief information security officer and no chief financial officer. The definition ends with "or the functional equivalent", and the form leaves it there.
Don't guess. Ask your broker, in writing, who may sign for your firm, and keep the answer with the application. It takes one email.
Here is the representation the Executive Officer signs on CYB-14306, word for word:
"The undersigned Executive Officer represents that to the best of his or her knowledge and belief, and after reasonable inquiry, the statements provided in response to this Application are true and complete, and, except in North Carolina may be relied upon by Travelers as the basis for providing insurance."
Three phrases in that sentence do the work.
The signature block has a second sentence:
"The Applicant will notify Travelers of any material changes to the information provided."
The answers have to stay true after you sign. If a control you answered Yes to changes, the carrier needs to hear it, and your broker can route it.
That is a plain-English reading, not legal advice. If a phrase matters to a decision you are making, ask counsel.
Question 4 on CYB-14306 is one line: "The signer of this form has done so with the assistance of the person in charge of IT security."
It ties the signature to the security answers. If your IT is outsourced, the person in charge of IT security may be someone at your IT provider. Name them, put them in the room, and go through the answers together. Then write down who helped and when. If anyone later asks how the answers were reached, that note is your answer.
The MFA questions on the same supplement cover email, remote network access, and administrator access to directory services, backups, network infrastructure, and endpoints and servers.
Read that list again. Four of the six are administrator access. An email MFA report says nothing about the administrator accounts on the backup console, the firewall or the servers. Those are the answers to check with your IT person before anyone signs.
Each question, with what a true Yes takes and the evidence to have ready, is in Travelers' MFA supplement, question by question.
In July 2022, Travelers asked a federal court in Illinois to rescind a cyber policy it had issued to International Control Services: Travelers Property Casualty Co. of America v. International Control Services, Inc., C.D. Ill. No. 22-cv-2145. According to Insurance Journal, the company's president had signed the application and its MFA attestation that March, and Travelers argued the misrepresentation "materially affected the acceptance of the risk and/or the hazard assumed by Travelers." Travelers said it learned of it after a ransomware attack at ICS in May. Lockton's summary of the case says ICS used MFA on its firewall and on no other digital asset.
In August 2022 the parties agreed to end it. Insurance Journal reported that the policy was declared "null and void, from its inception," and Lockton reported that the case was dismissed with judgment entered for Travelers.
The rescission was agreed, not decided on the merits, so the case is not a court's ruling on what "reasonable inquiry" requires. What it shows is the order of events every signer should plan against: the application is signed, a loss happens, and then the answers are compared with the network.
Sources: Insurance Journal, "Travelers, Policyholder Agree to Void Current Cyber Policy," August 30, 2022; Lockton, "Travelers v. ICS underscores need to respond carefully to cyber insurance application questions," September 15, 2022
Travelers' signature sentence says the answers, "except in North Carolina", may be relied upon as the basis for providing insurance. We don't interpret what those words change. That is a legal question, not a security one. If your firm is in North Carolina, ask NC counsel or your broker before you treat them as meaning anything for you.
We review the security questions and the evidence behind each answer. We don't complete or sign applications: the answers and the signature belong to the applicant. Obsidian Ridge is not an insurance producer, broker, or agent. We do not sell, place, or advise on insurance products.
If a renewal questionnaire is on your desk, send it for a free review before anyone signs. If the review turns up gaps you need closed and documented, the Cyber Insurance Readiness Sprint builds the evidence pack mapped to your carrier's form. If the gaps are in sign-in protection, Protected includes managed identity threat detection on Microsoft 365 and Google Workspace.
This article is general information, not legal or insurance advice. Carrier forms change. It quotes Travelers CYB-14306 Rev. 03-23 as published at the link above.
Last updated
September 25, 2026. We refresh this content as the threat landscape and tools evolve.
FAQ
On Travelers' Multi-Factor Authentication Supplement, CYB-14306 (Rev. 03-23), an Executive Officer signs: the applicant's chief executive officer, chief financial officer, chief information security officer, risk manager, in-house general counsel, or the functional equivalent. Other carriers word their signature blocks differently, so read the one on your form.
Not on that Travelers form. The signature belongs to an Executive Officer of the applicant. The IT provider's role is the one question 4 describes: the signer completes the form with the assistance of the person in charge of IT security. If you are unsure who may sign your carrier's form, ask your broker before anyone signs.
In plain English, the signer is saying the answers are true to the best of their knowledge and belief after asking and checking, not from memory. It is legal language, so ask counsel what it means for your firm.
No. Obsidian Ridge reviews the security questions and the evidence behind each answer. The applicant answers and signs. Obsidian Ridge is not an insurance producer, broker, or agent, and does not sell, place, or advise on insurance products.
Related reading
Every question on Travelers' Multi-Factor Authentication Supplement (CYB-14306), what a true Yes takes, and the evidence to have ready before you sign.
Read articleCyber insurance carriers stopped accepting 'we have antivirus' years ago. Here is what they ask about endpoint protection and how each term maps.
Read articleA hands-on deep-dive on cyber-insurance control #15 — link rewriting, time-of-click URL analysis, and attachment sandboxing.
Read article