Understanding Your Cyber Warranty
Everything you need to navigate your cyber warranty, what it covers, how it protects your business, and how to submit a claim if you ever need to.
Start Your Warranty Claim
Terms and Conditions
Warranty Program Benefits
The certification warranty covers the following events:
Ransomware & Business Email Compromise (BEC) Events
Ransomware Event means the unauthorized access to at least one Participant endpoint in the form of ransomware which has caused material harm to the Participant, where “material harm” must include at least one of: (i) the unauthorized acquisition of unencrypted digital data from the Participant’s Environment that compromises the security, confidentiality, or integrity of personal data or confidential information; (ii) public disclosure of personal data or confidential information maintained by the Participant; or (iii) the compromise of at least one endpoint resulting in the blocking of access to such endpoint.
BEC Event means a business email compromise where a full unauthorized threat-actor takeover of a Participant account occurs within the Participant’s environment. The warranty program does not apply to BEC events where social engineering results in a funds transfer or fraud.
Compliance Events
A Compliance Event means a BEC event or Ransomware event directly resulting in a personal data breach, triggering HIPAA, GDPR, UK GDPR, PCI, OSHA, SEC, FTC, and/or any international, federal, state or other legally required notice and/or reporting requirements, where the sole recovery benefit is for immediate legal assessment and emergency response of the compliance event. Continuing legal services beyond initial breach assessment are beyond the scope of any recovery benefit for this event.
Cyber Legal Liability Events
Cyber Legal Liability Events means litigation arising directly out of a breach of data privacy and/or data security as a result of a BEC event or ransomware event, arising out of binding statements made regarding data privacy or security on the Participant’s website, where legal defense expenses and settlement costs are incurred.
Business Income Events
Business Income Events mean a security breach of the Participant’s environment materially affecting business operations resulting in actual, documentable loss of business income (net profit or loss before taxes) that would have been earned had no security breach occurred.
Required Cybersecurity Controls
For a claim to be successful, the following controls must be implemented:
| Warranty control requirements | Control description |
|---|---|
| Antivirus | ESET Endpoint Security and ESET Server Security (if applicable) must be deployed and kept up to date (including major, minor and bugfix updates) on all endpoints in operation. |
| MDR / SIEM | ESET MDR must be active and monitoring on all endpoint and server devices in operation. Monitoring-only arrangements on specific assets are generally acceptable; however, customers must act on security notifications, remediation recommendations, and incident response guidance within a reasonable timeframe. Failure to do so may impact coverage eligibility if the incident can be tied to an identified issue that was not addressed. |
| MFA | Multifactor authentication (MFA) must be enabled and enforced for all accounts (user, administrative, and privileged) that can access or administer the organization’s email environment. MFA must not be optional and should not rely solely on password-based authentication—ESET solution or equivalent Secure Authentication. Particular attention should be given to administrator and privileged accounts. |
| Backups | Immutable backups (securely stored copies of data for recovery) must be in place, including ESET Ransomware Remediation and an equivalent functionality. |
| Encryption | AES-256-bit encryption algorithms are employed and all data is protected by AES-256-bit encryption. PHI/PII encryption in place (if regulatory requirements apply, such as HIPAA)—ESET solution or equivalent Full Disk Encryption. |
| Compliance | National, state and federal regulatory, privacy and security policies—such as PCI, HIPAA, GDPR, SEC, or other standards—must be followed by the participant (if regulatory conditions apply). |
| Maintenance | Available patches as well as fixes for known vulnerabilities (CVEs) alongside available application updates must be applied within 60 days of the software manufacturer’s release cycle—ESET solution or equivalent Vulnerability and Patch Management. |
| Security Awareness | Continuous security awareness training is delivered to employees. Such training must be implemented, and its completion must be documented for both employees and contractors. |
| Business Controls | Out-of-cycle wire transfers and invoice routing changes must be verified and documented prior to action being taken. Any wire fund transfers out of the norm may be verified if the event that caused the breach is tied back to this scenario. |
Indemnification Limits
Recovery benefits are based on your enrolled indemnification level. The recovery benefit will not exceed the certification warranty indemnification level specified in your enrollment confirmation.
Participants Enrolled in the $500,000 Indemnification Level*
| Coverage | Per Event | Per Participant |
|---|---|---|
| Compliance Event | Max of $100,000 USD | $100,000 USD |
| Ransomware Event & BEC Event | Max of $100,000 USD | $100,000 USD |
| Cyber Legal Liability Event ** | Max of $250,000 USD | $250,000 USD |
| Business Income Event | Max of $50,000 USD | $50,000 USD |
* Participant must first exhaust any other service warranty that would apply to these expenses.
Participants Enrolled in the $1,000,000 Indemnification Level*
| Coverage | Per Event | Per Participant |
|---|---|---|
| Compliance Event | Max of $200,000 USD | $200,000 USD |
| Ransomware Event & BEC Event | Max of $200,000 USD | $200,000 USD |
| Cyber Legal Liability Event ** | Max of $500,000 USD | $500,000 USD |
| Business Income Event | Max of $100,000 USD | $100,000 USD |
** Cyber Legal Liability / Media — Participant must exhaust all other financial benefits before triggering this Indemnification Level.
Submitting an Incident Claim
Incidents must be reported within 48 hours of discovery. Any requests to confirm the security controls in place—or supporting data needed for warranty claim processing—must be responded to promptly. If you fail to provide the required evidence within 15 days, the claim may be deemed invalid and subsequently canceled.
1
Discover & Document
Identify the event and gather log files, dates, and details about the network compromise.
2
Report Within 48 Hours
Notify Cysurance within 48 hours of discovery to begin the claim process.
3
Submit Documentation
Provide enrollment documentation and validating information within 15 days of the event.
4
Coordinate & Recover
Report to your insurance carrier as well, and submit required documentation to both for your recovery benefit.
Ready to file a claim? Start your warranty claim using the official form below.
Start Your Warranty Claim
Cysurance Contact Information
For questions regarding your cyber warranty program, please contact Cysurance:
Email: claims@cysurance.com
Phone: +1.917.503.8031