Compliance & Governance

MFA, WISP & Cyber Insurance Readiness

Prevvi Team

MFA, WISP & Cyber Insurance Readiness

Client

A multi-location restaurant group in Massachusetts

Industry

Hospitality

What was delivered

  • Google Workspace MFA rollout
  • Written Information Security Program
  • Acceptable Use Policy
  • Cyber insurance readiness assessment
  • Security control documentation

Hospitality businesses run on thin margins, high staff turnover, and technology that has to work during the dinner rush. Security programs designed for office companies tend to die on contact with that reality. A multi-location restaurant group engaged Prevvi to build a security foundation that would actually hold: multi-factor authentication across the organization, a Massachusetts-aligned Written Information Security Program, clear technology rules for staff, and readiness for cyber insurance control reviews.

The challenge

The group operated multiple restaurant locations with a mix of corporate staff, managers, and hourly employees, all using company Google accounts alongside operational platforms like the Toast point-of-sale system. Three needs converged at once:

  • Accounts needed MFA, rolled out to a workforce that includes seasonal staff and shift workers, without locking anyone out mid-service
  • Massachusetts expects a WISP. The state’s data security regulation, 201 CMR 17, sets expectations for any business holding personal information about Massachusetts residents, and the group needed a program aligned to it
  • Cyber insurance was asking hard questions. Insurers now verify security controls, and the answers on the application need to match what is actually running

What we delivered

Google Workspace MFA rollout

  • A full account inventory across the organization
  • Employee communications, enrollment deadlines, and adoption support written for restaurant staff, not IT professionals
  • Exception handling and authentication troubleshooting through the transition
  • Coordination of MFA across Google, Toast, and the group’s other systems, so protection did not stop at email

A Massachusetts-aligned Written Information Security Program

The WISP was written for the operational reality of a growing hospitality company, covering:

  • Definitions of personal information and technology assets in scope
  • Security roles and responsibilities
  • BYOD and portable-device controls, because restaurant work happens on phones
  • Encryption expectations and least-privilege access requirements
  • Incident response responsibilities and service provider requirements

Acceptable Use and Technology Policy

A companion policy established clear, realistic rules for employees and contractors: corporate information handling, authentication credentials, personal-device use, software and SaaS usage, email and internet use, security incident reporting, and minimum-necessary access.

Cyber insurance readiness assessment

We reviewed the controls insurers actually ask about: MFA verification, identity and access management, backups, endpoint security, network security, email protection, security policy documentation, and vendor and SaaS risk. The goal was to close the gap between what the insurance application says and what the environment does.

How we approached it

Security that survives the dinner rush

Every control was tested against a simple question: does this work for a shift manager at 7 PM on a Saturday? MFA enrollment came with deadlines, plain-language instructions, and real support. Policies used language employees could follow rather than legal boilerplate. A security program that ignores operations gets bypassed, and a bypassed program is worse than none, because it produces false confidence.

Policy and practice as one deliverable

A WISP that describes controls nobody runs is a liability in an audit or a breach. We built the documentation and verified the practices together: the MFA the WISP requires is the MFA that was rolled out, and the answers going to the insurer match both.

What a WISP is, and who needs one

A Written Information Security Program is a documented set of administrative, technical, and physical safeguards for protecting personal information. In Massachusetts, 201 CMR 17 requires businesses that own or license personal information about state residents to maintain one. A practical WISP defines:

  • What personal information the business holds and where
  • Who is responsible for the program
  • The controls protecting that data: access management, encryption, device rules, vendor requirements
  • How the business responds when something goes wrong

Insurers, enterprise customers, and regulators increasingly ask for it, and writing one forces the useful discipline of knowing your own environment.

The outcome

MFA reached the organization’s accounts without disrupting daily operations. The group now runs under a WISP and an Acceptable Use Policy that fit how restaurants actually work, and its cyber insurance answers are backed by verified controls rather than optimism. Security moved from an unaddressed risk to a documented, operating program. This is the heart of our IT compliance services, built on the same controls as our cybersecurity practice.

Key takeaways

  • Roll out MFA with communications and deadlines designed for the least technical user, not the most.
  • A WISP must describe the controls you actually run; verify practice while you write policy.
  • Cyber insurance applications are audits in disguise; treat every answer as a claim you may need to prove.
  • In hospitality, the security program that fits the operation is the one that survives.

Frequently asked questions

A Written Information Security Program documents the administrative, technical, and physical safeguards protecting personal information. Massachusetts regulation 201 CMR 17 requires businesses that own or license personal information about state residents to maintain one, which covers essentially any Massachusetts employer or business with Massachusetts customers.

It reviews the controls insurers actually ask about on applications: MFA coverage, identity and access management, backups, endpoint and network security, email protection, documented security policies, and vendor risk. The goal is to make every application answer provable, because a claim can be challenged when the answers do not match the environment.

Inventory every account first, then run enrollment with plain-language instructions, real deadlines, exception handling, and live support through the transition. Communications should be written for the least technical shift worker, not for IT staff, and coordination has to extend past email into operational platforms like the point-of-sale system.

Corporate information handling, authentication credentials, personal-device use, software and SaaS usage, email and internet use, security incident reporting, and minimum-necessary access. The best test of an AUP is whether a busy employee can actually follow it; rules written as legal boilerplate get ignored.

Yes. Restaurants and hospitality groups hold employee personal information, payment operations, and cloud accounts that attackers target precisely because defenses tend to be thin. A right-sized program, MFA, clear policies, and verified insurance answers, covers the essentials without an enterprise budget.

Have a similar project in mind?

Talk to a real engineer about your environment: no sales script, just straight answers on how we would approach it.