Control #15 Deep-Dive: Link Protection and Sandboxing for Inbound Mail
A hands-on deep-dive on cyber-insurance control #15 — link rewriting, time-of-click URL analysis, and attachment sandboxing.
Read articleCompliance
What the SIG Lite questionnaire is, who sends it, how it differs from SIG Core, and how a small business answers it honestly without a security team.
Somewhere in your inbox is a spreadsheet or portal invite called a "SIG Lite," sent by your biggest customer's risk team, with a deadline attached to a contract you care about. This guide covers what it is, why you got it, how it is structured, and how to answer it honestly when nobody at your company has "security" in their job title.
Disclosure: Obsidian Ridge sells a fixed-fee engagement that produces evidence packs for exactly these questionnaires. The method below is complete on its own — you can do all of it without us.
The SIG — Standardized Information Gathering questionnaire — is published by Shared Assessments, a third-party-risk industry body, and updated annually. It exists so that every enterprise does not have to invent its own vendor security questionnaire, and so vendors can answer one standard instead of four hundred bespoke ones. In practice you will still see bespoke ones, but the SIG is the closest thing vendor risk has to a common language.
It comes in two sizes:
Both cover the same territory: roughly twenty risk domains including security policy, organizational security, access control, network and endpoint security, application security, cloud hosting, IT operations, operational resilience, incident management, threat management, human resources security, and privacy.
Getting the Lite version is mildly good news. It usually means their risk model classified you as a smaller or lower-risk vendor, and program-level answers will satisfy them.
Three common triggers:
The blunt commercial reality: the questionnaire is a gate. Nobody reads it for pleasure, and a stalled SIG Lite stalls the contract behind it.
SIG questions are mostly closed-form — yes, no, not applicable — organized by risk domain, with room for comments and evidence. The skill is not in the format; it is in reading what the question is actually asking. Three patterns cover most of the document:
If this sounds familiar, it should: it is the same discipline a cyber insurance questionnaire demands, asked by a customer instead of a carrier. The controls overlap almost completely — MFA scope, EDR coverage and monitoring, backup immutability and restore testing, incident response, security awareness training. Answer one instrument rigorously and you have answered most of the other.
Take the questionnaire and sort every question into three columns:
Then attach evidence for the yeses that matter most to a reviewer:
Exports and screenshots beat policy prose. A reviewer can verify an export; a policy document only tells them what you intended.
Do not answer aspirationally. SIG answers get attached to contracts, and contracts have representation clauses. The failure mode is the same one that voids insurance policies — we documented a carrier rescinding a $1M cyber policy over a misrepresented MFA answer on the questionnaire page. A customer who discovers an aspirational yes during an incident is a former customer with a legal theory.
Do not dump your entire policy binder as a response. Reviewers triage dozens of these. Answer the question asked, attach the specific artifact, move on.
Do not leave the comment fields empty on partial answers. The comment is where a small company wins: it shows you know your own environment, which is the thing the questionnaire is really probing for.
Do not miss the deadline silently. If the answers need three weeks of remediation first, say so. Risk teams extend deadlines for vendors who communicate; they escalate on the ones who go quiet.
The three-column sort, the gap-closing, and the evidence pack are exactly what our Cyber Insurance Readiness Sprint produces — it was built for carrier questionnaires, and a customer security questionnaire is the same job with a different reader. Fixed fee, seven business days, and the evidence pack answers the next questionnaire too, because there will be a next one.
Or answer it yourself with the method above — it is complete. Either way, the deadline on that email is real, and the contract behind it is the point.
Last updated
August 24, 2026. We refresh this content as the threat landscape and tools evolve.
FAQ
SIG Lite is the shortened version of the Standardized Information Gathering (SIG) questionnaire published by Shared Assessments. Larger organizations send it to vendors to assess security posture before or during a business relationship. It asks program-level questions across roughly twenty risk domains — access control, endpoint security, incident response, resilience, and others — rather than the deep control-by-control detail of the full SIG Core.
A customer's or prospect's third-party risk team sends it, usually because your business will touch their data, their network, or a process they depend on. Receiving SIG Lite rather than SIG Core generally means they classified you as a lower-risk or smaller vendor. Answering it is usually a condition of winning or keeping the contract.
Same publisher, same risk domains, different depth. SIG Core runs to several hundred questions for high-risk vendor relationships; SIG Lite condenses that to a program-level assessment on the order of 125 to 130 questions in recent releases. Exact counts change with each annual release, so verify against the version you were actually sent.
Yes. Risk teams read a small vendor's honest no with a compensating control or a dated remediation plan far more favorably than a yes that falls apart during verification or an incident. What kills deals is the answer that cannot survive an audit — the same way a misrepresented control can void a cyber insurance policy.
The same artifacts a cyber insurance underwriter asks for: MFA configuration exports, EDR agent coverage and who monitors it, backup and restore-test records, the dated incident response plan, and training completion records. Screenshots and exports beat policy prose — reviewers can verify the first and can only trust the second.
Related reading
A hands-on deep-dive on cyber-insurance control #15 — link rewriting, time-of-click URL analysis, and attachment sandboxing.
Read articleIf you make anything for the defense supply chain — even as a sub-tier subcontractor — CMMC may now gate your contracts.
Read articleMost dealerships that arrange financing are 'financial institutions' under the FTC Safeguards Rule — which means a specific.
Read article