Cyber Insurance for First-Time SMB Buyers: What the 2026 Questionnaire Actually Asks and How to Pass It
A practical walkthrough of cyber insurance for first-time SMB buyers in 2026 — what the policy covers, what the questionnaire asks.
Read articleCompliance
A hands-on deep-dive on cyber-insurance control #15 — link rewriting, time-of-click URL analysis, and attachment sandboxing.
Cyber-insurance control #15 asks a simple yes/no: does your inbound mail include link rewriting, time-of-click URL analysis, and attachment sandboxing?
The honest answer is often "yes, because it's licensed" when the truthful answer is "no, because it's not enforced." That mismatch is exactly what carriers unwind after a loss.
This piece is the deep-dive on control #15. It sits under the broader 22 cyber-insurance controls underwriters ask about in 2026 and complements the architecture-level email security for SMBs in 2026: gateway vs API vs built-in buyer guide.
For every claim below, the goal is the same: pass control #15 honestly, produce evidence a carrier accepts, and avoid the "controls warranty" clawback after a claim.
The typical questionnaire language on control #15 varies. Common phrasings:
Behind the language, the carrier is testing three specific capabilities on inbound mail:
Static filtering catches known-bad URLs and attachment hashes at scan time. Phishing payloads increasingly weaponize after delivery — links that flip to bad, attachments that reveal payload on open. That's the gap this control is testing.
CISA's phishing guidance calls the pattern out explicitly: attackers use links and attachments that appear legitimate at first inspection, so recognizing and reporting matters at every layer.
For most SMB tenants on Microsoft 365, Defender for Office 365 is the built-in tier that satisfies control #15. Safe Links handles the URL rewriting and time-of-click analysis. Safe Attachments handles the sandboxing.
Sources: Safe Links in Microsoft Defender for Office 365, Safe Attachments in Microsoft Defender for Office 365
To answer "yes" honestly, the tenant needs all of the following:
Microsoft's preset security policies (Standard, Strict) are the fastest path to a defensible configuration for most SMBs because they turn on Safe Links, Safe Attachments, anti-phishing, and impersonation protection with vetted defaults.
Source: Preset security policies in Defender for Office 365
The honest-yes checklist for Microsoft 365 is: policy exists, scope is tenant-wide, exceptions are documented, the protection is running today (not "will be enabled next quarter").
For Google Workspace tenants, the built-in tier that satisfies control #15 is the advanced phishing and malware protection settings plus the Security Sandbox.
Sources: Advanced phishing and malware protection in Google Workspace, Security Sandbox in Google Workspace
To answer "yes" honestly:
Google's advanced phishing and malware protection covers the link-scanning half of control #15. Security Sandbox is the answer to the attachment-sandboxing half. For a small business on a Google Workspace Business tier without Security Sandbox, the honest answer to control #15 depends on whether the carrier accepts advanced protection without pre-delivery attachment detonation — some do, some don't.
An API-integrated third-party layer or a secure email gateway can satisfy control #15 with its own URL detonation and attachment analysis, running on top of or in front of the built-in tier.
Cases where a third-party layer becomes the right answer:
Naming a specific third-party product on the questionnaire is a commitment. If the carrier asks for a named layer, use the vendor's exact product name from the license, and be ready to produce configuration evidence for that product, not the built-in tier.
The architecture-level buyer guide walks through when the third-party decision earns its cost. For control #15 specifically, the question is narrower: does the layer you named actually do URL rewriting, time-of-click analysis, and attachment sandboxing on inbound mail?
A "yes" without evidence is a "yes" the carrier can unwind at claim time.
The evidence pack for control #15, in practice:
The evidence doesn't need to be a compliance-platform export. A dated screenshot with the policy name, scope, and current settings is defensible for most SMB questionnaires.
Carriers audit controls warranties after a loss. Control #15 has a small number of common failure modes that come up in post-claim reviews:
The pattern in every one: the license or the technology existed, but the enforcement, the scope, or the maintenance didn't. The underwriter's post-loss investigation reads the difference clearly.
URL rewriting has a documented abuse vector. Starting in mid-2024, researchers tracked phishing campaigns that launder links through the rewrite domains of email-security vendors: the attacker compromises an account at a company using a rewriting gateway, emails themselves a clean link so the gateway wraps it in the vendor's trusted domain, then reuses that wrapped link in phishing sent to other victims. Downstream filters — and trained users — see the security vendor's domain and relax. Proofpoint, Mimecast, INKY, and Sophos rewrite domains were all documented in the campaign wave.
Sources: Perception Point research, Mimecast threat intelligence
Two practical consequences. First, rewriting still protects your own tenant — the time-of-click check fires when your users click links your own gateway rewrote, so answering "yes" on control #15 with rewriting enforced remains correct. Second, train the other direction explicitly: a link wrapped in a security vendor's domain is not evidence the destination is safe. If your awareness training teaches "hover and check the domain," teach that exception too.
Some vendors answer this control with pre-delivery dynamic analysis and browser-level protection instead of rewriting. Carriers accept either — the questionnaire is testing whether post-delivery weaponization gets caught, not which mechanism catches it.
Before the next renewal cycle, run this fast pass:
That's 15 minutes and it changes the answer to control #15 from "we think so" to a defensible "yes, and here's the current-dated evidence."
The Sprint is the operational version of this deep-dive across the full 22-control questionnaire. In 7 business days, we map the current tenant configuration against the carrier's exact questionnaire, close the gaps that are cheap to close, and deliver a signed evidence pack with dated screenshots and policy exports for every control the carrier is asking about — including a defensible control #15 answer.
The promise is the deliverable, not the insurer's decision:
7 days. Flat fee. Signed evidence pack mapped to your carrier's questionnaire — delivered, or we keep working at no additional cost until it is. We don't control underwriter decisions. We control whether you walk in with the evidence they ask for.
If control #15 is one of the answers you're unsure about, scope a Cyber Insurance Readiness Sprint. If the tenant is closer to the renewal than 90 days, book a 30-minute briefing and we'll triage the answer before we scope the Sprint.
For a broader control map — MFA, EDR/MDR, backups, incident response, identity monitoring — the 10 control areas underwriters score and the full 22-control questionnaire breakdown are the natural companion reads. If the current gap is at the cheap-controls layer (MFA, callback rule, SPF/DKIM/DMARC), BEC and phishing on a budget is where to start.
It asks whether inbound email includes URL rewriting, time-of-click URL analysis, and attachment sandboxing. The carrier is testing whether phishing payloads that weaponize after delivery — links that were benign at scan time, attachments that reveal payload at open time — will still get caught by your mail platform.
Yes, when it is licensed and actually enforced. Safe Links rewrites URLs, performs a check at click time, and can block or warn based on the verdict; Safe Attachments detonates attachments in an isolated environment before delivery. Both must be enabled by policy, applied to the users in scope, and not carved out by exceptions that quietly disable the protection.
Yes, when the advanced phishing and malware settings are enabled at the tenant level and the Security Sandbox is turned on where the license permits (Enterprise Standard and above). Google's advanced protection covers link scanning and pre-delivery attachment analysis; Security Sandbox adds pre-delivery detonation.
Configuration screenshots or policy exports showing the setting is enabled and the scope covers all mailboxes, plus a dated record of when it was turned on. A generic "we have Microsoft 365" or "we use Google Workspace" answer usually does not survive a claim if the protection was licensed but not enforced.
The protection is licensed but not enabled by policy, or the policy has an exception list that carves out the executives, finance, or the accounts that get targeted the most. Anti-phishing and Safe Links policies with "do not rewrite" entries for specific users or domains are a common failure mode.
Not for most SMBs. Defender for Office 365 or Google Workspace advanced protection is generally accepted by carriers for control #15. A third-party layer is the right answer when the built-in tier is not licensed for the tenant, when the carrier specifically wants a named third-party, or when the built-in tier is on and still missing detections in the environment's real threat pattern.
Seven business days. Flat fee. The output is a signed evidence pack mapped to your carrier's questionnaire, delivered or we keep working at no additional cost until it is.
Last updated
July 18, 2026. We refresh this content as the threat landscape and tools evolve.
FAQ
Control #15 asks whether inbound email includes URL rewriting, time-of-click URL analysis, and attachment sandboxing. The carrier is testing whether phishing payloads that weaponize after delivery — links that were benign at scan time, attachments that reveal payload at open time — will still get caught by your mail platform.
Yes, when it is licensed and actually enforced. Safe Links rewrites URLs, performs a check at click time, and can block or warn based on the verdict; Safe Attachments detonates attachments in an isolated environment before delivery. Both must be enabled by policy, applied to the users in scope, and not carved out by exceptions that quietly disable the protection.
Yes, when the advanced phishing and malware settings are enabled at the tenant level and the Security Sandbox is turned on where the license permits (Enterprise Standard and above). Google's advanced protection covers link scanning and pre-delivery attachment analysis; Security Sandbox adds pre-delivery detonation.
Configuration screenshots or policy exports showing the setting is enabled and the scope covers all mailboxes, plus a dated record of when it was turned on. A generic 'we have Microsoft 365' or 'we use Google Workspace' answer usually does not survive a claim if the protection was licensed but not enforced.
The protection is licensed but not enabled by policy, or the policy has an exception list that carves out the executives, finance, or the accounts that get targeted the most. Anti-phishing and Safe Links policies with 'do not rewrite' entries for specific users or domains are a common failure mode.
Not for most SMBs. Defender for Office 365 or Google Workspace advanced protection is generally accepted by carriers for control #15. A third-party layer is the right answer when the built-in tier is not licensed for the tenant, when the carrier specifically wants a named third-party, or when the built-in tier is on and still missing detections in the environment's real threat pattern.
Related reading
A practical walkthrough of cyber insurance for first-time SMB buyers in 2026 — what the policy covers, what the questionnaire asks.
Read articleThe 22 cyber-insurance underwriting controls carriers ask about in 2026 — what each one asks, why carriers care.
Read articleWhat dental cyber insurance actually covers in 2026, the underwriting questionnaire controls carriers review.
Read article