11 questions in this section
verifiedIs inbound email security (SEG) deployed with sandbox attachment detonation?
verifiedDoes the Applicant employ a sandboxing solution for investigating suspicious emails/attachments?
verifiedDoes the Applicant have a report-phishing email add-in enabled for all email users?
verifiedDoes the Applicant employ SPF, DKIM, and DMARC?
partialAre phishing simulations conducted for all employees, with click rate tracking?
attestedHow does the Applicant handle repeat offenders/clickers in phishing simulations?
attestedAre employees with financial/accounting responsibility given social engineering and phishing training?
attestedWhich inbound email security product / Secure Email Gateway (SEG) does the Applicant use?
verifiedAre external emails tagged as originating from an external source?
verifiedIs legacy email authentication (IMAP, POP, basic authentication) disabled?
verifiedIs email filtering in place for inbound mail?
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture