TO FILE A CLAIM: EMAIL CLAIMS@CYSURANCE.COM OR CALL +1.917.503.8031

Request An Appointment

SUBSCRIBER PARTICIPANT AGREEMENT FOR CYSURANCE 360 PROTECTION PROGRAM

Terms and Conditions

This Subscriber Participant Agreement and the terms and conditions herein (the Agreement), is a legal agreement entered into by and between Cysurance, LLC (Cysurance, or Provider) and the Participant enrolling in the 360 Protect Program (the 360 Program, or Warranty) pursuant to the terms herein. This Agreement governs Participant’s access to benefits available only through this 360 Program. This Agreement is effective on the date the Participant fully enrolls to receive benefits under the Program and agrees to the terms and conditions set forth in the Provider Terms included in Cysurance’s enrollment portal (the Effective Date). BY ENROLLING IN THE 360 PROGRAM AND CLICKING A “SUBMIT”, “CONTINUE” OR OTHER SIMILAR BUTTON ASSOCIATED WITH THIS AGREEMENT, PARTICIPANT OR ITS AUTHORIZED AGENT EXPRESSLY AND EXPLICITLY ACKNOWLEDGES AND AGREES (I) IT IS A BUSINESS ENTITY DULY ORGANIZED, VALIDLY EXISTING AND IN GOOD STANDING UNDER THE LAWS OF THE STATE OR COUNTRY IN WHICH IT IS INCORPORATED; (II) THIS IS A BINDING AGREEMENT; (III) PARTICIPANT HAS FULLY IMPLEMENTED THE SOLUTIONS FOR ITS ENVIRONMENT; AND (IV) IT ACCEPTS THE OFFER TO ENROLL IN THE 360 PROGRAM PURSUANT TO SEPARATE PROVIDER TERMS HERE AS WELL AS TO THE TERMS HEREIN. PARTICIPANT’S ENROLLMENT IS CONSIDERED ACCEPTED WHEN PARTICIPANT RECEIVES A CONFIRMATION EMAIL FROM CYSURANCE EVIDENCING ITS SUCCESSFUL ENROLLMENT. AS A REPRESENTATIVE ENTERING INTO THIS AGREEMENT ON BEHALF OF A PARTICIPANT, YOU HEREBY REPRESENT AND WARRANT TO CYSURANCE YOU ARE: (A) AUTHORIZED TO ENTER INTO THIS AGREEMENT ON BEHALF OF PARTICIPANT; AND (B) OVER 18 YEARS OLD. IF PARTICIPANT DOES NOT ACCEPT ALL TERMS AND CONDITIONS IN THIS AGREEMENT OR IS NOT AUTHORIZED TO ENTER INTO THIS AGREEMENT, DO NOT ACCEPT THE TERMS OF THIS AGREEMENT. PARTICIPANT MUST IMMEDIATELY REPORT AN EVENT TO CYSURANCE. FAILURE TO REPORT AN EVENT WITHIN FORTY-EIGHT (48) HOURS OF DISCOVERY WILL EXCLUDE THE EVENT FROM CONSIDERATION FOR A RECOVERY BENEFIT. WITHIN FIFTEEN (15) DAYS OF DISCOVERY OF AN ACTUAL OR REASONABLY SUSPECTED EVENT, PARTICIPANT MUST SUPPLY CYSURANCE WITH REQUESTED INFORMATION TO VALIDATE ALLEGED LOSS OF BUSINESS INCOME AND EVALUATE AN ASSERTED EVENT, OR A REQUEST FOR RECOVERY BENEFITS WILL BE CLOSED. IF PARTICIPANT FAILS TO DELIVER REQUESTED INFORMATION TO CYSURANCE AS SET FORTH HEREIN OR FAILS TO RESPOND FOR MORE THAN THIRTY (30) DAYS AFTER INITIAL PROVISION OF INFORMATION TO CYSURANCE, PARTICIPANT’S PROFFERED EVENT WILL BE TREATED AS AN INVALID EVENT INELIGIBLE FOR A RECOVERY BENEFIT. DETERMINATIONS REGARDING A QUALIFYING EVENT OR GRANT OF A RECOVERY BENEFIT ARE MADE IN CYSURANCE’S SOLE DISCRETION. In consideration of the mutual covenants and agreements contained herein, and other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the parties agree as follows:

1. Definitions. Any capitalized terms not otherwise defined herein shall have the meaning set forth in the

Solutions Agreement, or any similarly intended agreement which governs the delivery of the managed detection and response, managed risk, and/or managed security awareness solutions (Solutions Agreement) for the delivery of the Solutions.

a. BEC Event means a business email compromise (BEC) where a full, unauthorized threat-actor takeover

of a Participant account occurs within Participant’s Environment. The 360 Program does not apply to BEC Events where social engineering results in funds transfer or fraud. To be a Qualifying Event, a BEC Event must result from the compromise of credential or other unauthorized access in and of a Participant's own Environment.

b. Benefit End Date means the last day of Participant’s qualifying Enrollment Term pursuant to the

Enrollment Confirmation or other confirmation from Cysurance.

c. Benefit Start Date means the first day of Participant’s qualifying Enrollment Term pursuant to the

Enrollment Confirmation or other confirmation from Cysurance.

d. Business Income Event means a Security Breach of Participant’s Environment materially affecting

business operations resulting in actual, documentable loss of business income (net profit or loss before taxes) that would have been earned had no Security Breach occurred.

e. Compliance Event means a BEC Event or Ransomware Event directly resulting in a personal data

breach, triggering HIPAA, GDPR, UK GDPR, PCI, OSHA, SEC, FTC, and/or any international, federal, state or other legally required notice and/or reporting requirements, where the sole Recovery Benefit is for immediate legal assessment and emergency response of the Compliance Event. Continuing legal services beyond initial breach assessment, including dealing with the nature of the data breach and any extent of the same, are beyond scope of any Recovery Benefit for this Event.

f. Cyber Legal Liability Event means litigation arising directly out of a breach of data privacy and/or data

security as a result of a BEC Event or Ransomware Event, arising out of binding statements made regarding data privacy or security on Participant’s website where legal defense expenses and settlement costs are incurred.

g. Enrollment Confirmation means an email issued by Cysurance confirming Participant’s enrollment in

the 360 Program setting forth the Benefit Start Date. The Enrollment Confirmation is incorporated into and becomes part of this Agreement.

h. Enrollment Term means the period within which Participant may receive Recovery Benefits and which

begins on the Benefit Start Date as defined in Section 1(c) and ends upon termination in accordance with Sections 2(b) and 10. Dependent on the Benefit Start Date, generally the Enrollment Term is equivalent to the annual subscription term for pursuant to the Solutions Agreement.

i. Environment means computer systems or networks identified by Participant and for which Solutions are

active and fully deployed. The 360 Program applies solely to Environments such Solutions are purchased to secure.

j. Event means a Ransomware Event or BEC Event occurring in a Participant's Environment, which may

then result in a Business Income Event, Compliance Event or Cyber Legal Liability Event.

k. Qualifying Event means a Business Income Event, Compliance Event, Cyber Legal Liability Event

resulting from a Ransomware Event or BEC Event occurring in Participant's Environment, which qualifies for a Recovery Benefit. For avoidance of doubt, a Ransomware Event and BEC Event cannot be combined in the same request for a Recovery Benefit.

l. Ransomware Event means the unauthorized access to at least one Participant endpoint in the form of

ransomware which has caused material harm to Participant, whereby “material harm” must include at least one of the following: (i) the unauthorized acquisition of unencrypted digital data from Participant's Environment that compromises the security, confidentiality, or integrity of personal data or confidential information from Participant's Environment; (ii) public disclosure of personal data or confidential information maintained by Participant; or (iii) the compromise of at least one endpoint in Participant's Environment resulting the blocking of access to such endpoint.

m. Recovery Benefit is the funding conferred to the Participant by Cysurance upon a Qualifying Event. A

Recovery Benefit is limited to supporting repair, remediation, and/or replacement of those parts of Participant’s Environment damaged by the Qualifying Event, including, but not limited to, removing and remediating elements that caused such Event. Recovery Benefits apply to immediate recovery services such as initial investigation to determine required services and restoration of Participant's current business systems covered by the Solutions. Continuing investigation concerning the extent of an actual or suspected Event, ongoing negotiations with a threat actor, procurement of new solutions or recovery beyond Participant's Environment, legal evaluation of certain reporting obligations, or other ongoing breach services, are not eligible for a Recovery Benefit.

n. Security Breach means the loss of business income (net profit or loss before income taxes) which would

have been earned had no loss occurred as a result of (i) an unauthorized access or use of Participant's Environment resulting from theft of a password from an agent of the Participant; (ii) a denial of service attack affecting Participant's Environment; or (iii) an infection of a part of Participant's Environment by malicious code or the unauthorized transmission of malicious code from the Participant's Environment.

o. Solutions means the services for which Participant has entered into a Solutions Agreement for the

provision of protection for Participant's Environment for delivery of managed detection and response, managed risk, and/or managed security awareness solutions.

2. 360 Protect Program

a. Benefit Start Date. Participant’s Enrollment Term will begin on the Benefit Start Date.

b. Benefit End Date. Unless otherwise terminated earlier pursuant to Section 10 below, Participant’s

Enrollment Term will automatically terminate on the Benefit End Date.

3. 360 Protect Program Benefits.

a. During the Enrollment Term, Participant may submit a request for a Recovery Benefit by notifying

Cysurance at claims@CYSURANCE.COM that one of the following Events may have occurred during the Enrollment Term:

i. Ransomware Event;

ii. BEC Event;

iii. Compliance Event;

iv. Cyber Legal Liability Event; and/or

v. Business Income Event.

b. Should an Event be determined a Qualifying Event, and provided an exclusion set forth in Section 4 does

not apply, Cysurance will provide Participant a Recovery Benefit, subject to the following:

i. Participant may seek indemnification for one (1) Qualifying Event during the Enrollment Term;

ii. Participant must have a commercially reasonable belief damages resulting from the Event will

exceed $5,000 USD or equivalent in applicable foreign currency;

iii. The Recovery Benefit will not exceed Participant’s maximum 360 Program Indemnification Level

as specified within Participant’s Enrollment Confirmation;

iv. Payment of any applicable deductible; and

v. The Recovery Benefit is provided in accordance with any additional terms and conditions applicable

as specified in the 360 Program Confirmation Summary attached hereto as Schedule 1.

4. Recovery Benefit Exclusions. A Recovery Benefit may be restricted to the country in which Participant

subscribed to the Solutions. A Recovery Benefit will not be provided if one or more of the following conditions occur:

a. Participant fails to take commercially reasonable measures to (i) undertake preventative maintenance,

including patching that is up to date within sixty (60) days of the software manufacturer’s release cycle; and (ii) implement cloud or other back up measures of Participant’s data, including offline data backup for critical data, to allow for recovery from a Ransomware Event;

b. If Participant has not implemented and documented completion of security awareness training for

employees and contractors;

c. Participant fails to deploy multifactor authentication (MFA) on all email, servers housing proprietary

and privacy data, and operating systems essential business operations;

d. Participant fails to deploy industry standard and up-to-date anti-virus or comparable prevention tools on

its endpoints;

e. Participant does not have the Solutions actively deployed in the Participant’s Environment where the

Event occurred, such that security relevant telemetry from such environment is produced and available for review and assessment (i.e., infrastructure or endpoint);

f. Participant is in breach of this Agreement and/or the Solutions Agreement, or this Agreement or

Solutions Agreement has terminated or expired;

g. Participant is unable to provide sufficient proof of the Event or cannot verify the Event through log or

Event data;

h. If there is a systemic failure of the Solution, service, vendor’s infrastructure, or a systemic incident that

results in an Event where there is a systemic attack inflicting global widespread harm from commonly used tools and/or a global, systemic zero-day exploit caused by a flaw in software, hardware or firmware occurring in the Participant’s Environment;

i. After notification or an alert of a possible Event to Participant from the Solutions vendor, Participant

fails to take reasonable measures or actions to investigate and adequately address the issues prompting the alert in an effort to circumvent or prevent an Event from occurring in Participant's Environment;

j. If a Participant is regulated by HIPAA, PCI, SEC, FTC, GDPR and/or any other international, federal,

state or other law, regulation or rule:

i. Participant has not completed an annual security and data risk assessment or other necessary risk

assessments, and documented risks associated therewith;

ii. Protected health information (PHI) or other protected information data inventory has not been fully

completed and accounted for prior to an incident and request for a Recovery Benefit;

iii. Subject to Participant’s standard historical employment practices related to HIPAA, GLBA, CCPA,

GDPR, UK GDPR or other data protection required training for employees, all of Participant’s employees have not completed such necessary training within twelve (12) months prior to any Event;

iv. Participant has not adopted and adhered to all privacy and security policies, public facing, internal

or otherwise, related to any international, federal, state or other legal or related regulatory requirements to which Participant is subject prior to any Event; or

v. Participant is named as a defendant, respondent, co-defendant or other defending party in a class-

action lawsuit resulting from violation of any international, federal, state or other law, regulation or rule arising from or relating to an Event.

k. The Event did not occur during the Enrollment Term;

l. Participant fails to verify Wire Transfers and Routing Number Changes with the requestor including

documenting such verification(s) with name and date;

m. Participant does not timely submit the request for a Recovery Benefit for the Event during the Enrollment

Term; or

n. Participant has not, with regard to all applicable privacy, data protection or security laws, regulations

and rules governing the processing of personal information, (i) conducted an assessment or analysis regarding, (ii) taken steps to assess its risks under, and also (iii) adopted and adhered to privacy, data protection or security laws, prior to any Event.

5. Recovery Benefit Request Requirements.

a. PARTICIPANT MUST IMMEDIATELY REPORT AN EVENT TO CYSURANCE. FAILURE TO

REPORT AN EVENT WITHIN FORTY-EIGHT (48) HOURS OF DISCOVERY WILL EXCLUDE THE EVENT FROM CONSIDERATION FOR A RECOVERY BENEFIT. WITHIN FIFTEEN (15) DAYS OF DISCOVERY OF AN ACTUAL OR REASONABLY SUSPECTED EVENT, PARTICIPANT MUST SUPPLY CYSURANCE WITH THE REQUESTED INFORMATION TO VALIDATE ANY ALLEGED LOSS OF BUSINESS INCOME AND EVALUATE ANY ASSERTED EVENT OR THE REQUEST FOR RECOVERY BENEFITS WILL BE CLOSED. IF PARTICIPANT FAILS TO DELIVER ANY REQUESTED INFORMATION TO CYSURANCE AS SET FORTH HEREIN OR FAILS TO RESPOND FOR MORE THAN THIRTY (30) DAYS AFTER INITIAL PROVISION OF INFORMATION TO CYSURANCE, PARTICIPANT’S PROFFERED EVENT WILL BE TREATED AS AN INVALID EVENT INELIGIBLE FOR A RECOVERY BENEFIT. DETERMINATIONS REGARDING A QUALIFYING EVENT OR THE GRANT OF A RECOVERY BENEFIT, ARE MADE IN CYSURANCE’S SOLE DISCRETION.

b. Participant understands this Agreement is separate and apart from, not affiliated with, and not issued by

or part of any insurance product it has purchased, engaged or otherwise obtained. Participant understands it is responsible for reporting Events to its insurance carrier regardless of whether Participant elects to make a request for a Recovery Benefit with Cysurance for an Event under this 360 Program.

c. By submitting a request for a Recovery Benefit and information to Provider, Participant understands and

acknowledges Cysurance has separate terms and conditions related to privacy and data protection as set forth in Provider’s Terms of Service, Privacy Policy, or other agreements made by and between Participant and Cysurance which will govern the use and protection of the information. Participant understands and agrees it should review any terms prior to submission of information. In the event Participant requests that the Solutions vendor or other third-party provide information directly to Cysurance on Participant’s behalf, Participant authorizes and consents to that third-party sharing the information with Provider, subject to the terms set forth in Section 5(b) and 5(c) of this Agreement.

d. Qualification of a Recovery Benefit made under the 360 Program is subject to Cysurance’s standards of

review. If Provider denies indemnification to Participant, notwithstanding anything to the contrary in this Agreement, Cysurance shall have no liability to Participant.

e. To qualify for a Recovery Benefit under the 360 Program, Participant agrees to:

i. Provide documentation evidencing the Participant’s date of enrollment in the 360 Program;

ii. Preserve and provide log files and information about the symptoms and causes of a network

compromise and all other information, documents or things requested by Cysurance pertaining to the request for Recovery Benefit, and all other information, documents or things requested by Provider to assess the Event; and

iii. Verify the Event via log files and/or other documentation of malicious code that resulted in loss of

data and/or records that triggered a violation of state and/or federal regulatory enforcement to which Participant is subject;

iv. Submit all requests for a Recovery Benefit in good faith and shall only submit information that is

true and accurate.

6. Additional Services. Following Participant’s enrollment in the 360 Program, and included with such,

Provider will perform regular scans of Participant’s Environment. Results will be provided to Participant to augment the external monitoring and risk rating analyses Cysurance will deliver to Participant. Such results may identify vulnerabilities related to:

a. Network Security

b. DNS Health

c. Patching Cadence

d. IP Reputation

e. Application Security

f. Threat Intelligence

g. Social Intel & Industry Intel

h. Information Leak including Dark Web scanning for credentials

i. Cloud Score

An initial scan will be conducted upon Participant’s enrollment in the 360 Program and monthly thereafter during the Participant’s Enrollment Term. By enrolling in the 360 Program, Participant consents to the receipt of such additional services by Cysurance.

7. 360 Program Disclaimer. EXCEPT AS SPECIFICALLY SET FORTH HEREIN, CYSURANCE MAKES

NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY TO PARTICIPANT, REGARDING OR RELATING TO THE 360 PROGRAM OR ITS SOLUTIONS PROVIDED TO PARTICIPANT UNDER THIS AGREEMENT, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THE 360 PROGRAM WILL MEET PARTICIPANT’S REQUIREMENTS OR THAT THE OPERATION THEREOF OR ACCESS THERETO WILL BE ERROR FREE, CURRENT OR UNINTERRUPTED. FOR THE AVOIDANCE OF DOUBT, THIS 360 PROGRAM DOES NOT EXPAND OR INFER ANY WARRANTIES RELATED TO THE SOLUTIONS. TO THE GREATEST EXTENT ALLOWED BY LAW, CYSURANCE SPECIFICALLY DISCLAIMS ALL IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND WARRANTIES ARISING FROM COURSE OF DEALING, USAGE OR TRADE PRACTICE, EXCEPT TO THE EXTENT THAT ANY WARRANTIES IMPLIED BY LAW CANNOT BE VALIDLY WAIVED.

8. Limitation of Liability. TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, FOR ANY

CAUSE RELATED TO OR ARISING OUT OF THIS AGREEMENT, WHETHER IN AN ACTION BASED ON A CONTRACT, TORT (INCLUDING NEGLIGENCE AND STRICT LIABILITY) OR OTHER LEGAL THEORY, HOWEVER ARISING, CYSURANCE WILL IN NO EVENT BE LIABLE TO CUSTOMER OR ANY THIRD PARTY FOR LOST REVENUES, PROFITS, BUSINESS OR GOODWILL, BREACHES BY CYSURANCE, OR ANY INDIRECT, SPECIAL, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES. IN NO EVENT WILL CYSURANCE’S LIABILITY EXCEED $100. THESE LIMITATIONS SHALL APPLY WHETHER OR NOT PARTICIPANT HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES AND NOTWITHSTANDING ANY FAILURE OF ESSENTIAL PURPOSE OF ANY LIMITED REMEDY.

9. Updates. Cysurance reserves the right to modify this Agreement and any terms related to the 360 Program

in Cysurance’s sole discretion. Should Cysurance make modifications to the Agreement or the 360 Program, Cysurance will post the amended terms or use at https://www.cysurance.com/terms-of-use/ and will update the “Last Updated Date” within such document or provide notification by such other reasonable notification method implemented by Cysurance.

10. Termination.

10.1. Should Participant’s Solution Agreement change such that it impacts the 360 Program Indemnification Level

for which Participant qualifies, the existing Enrollment Term will terminate, and, if applicable, Participant must re- enroll to qualify for a different or new 360 Program Indemnification Level. In the event Participant’s Solution ceases to qualify for the 360 Program, the Enrollment Term will immediately terminate.

10.2. This Agreement, the 360 Program, and/or Participant’s Enrollment Term may be terminated by Cysurance

for convenience and for any reason in Cysurance’s sole discretion and Cysurance will have no further liabilities to Participant under this Agreement. Cysurance will use commercially reasonable efforts to notify Participant of any such termination. For the avoidance of doubt, termination of a Solutions Agreement shall terminate this Agreement, but termination of this Agreement shall not terminate a Solutions Agreement.

11. Survival. The definitions in Section 1, along with Sections 4, 5, 7, 8, 9, 10, 11 and 12 will survive the non-

renewal or termination of this Agreement.

12. Miscellaneous.

12.1. Except as otherwise provided herein, all notices, consents, demands, waivers and other communications other

than a submission of an Event hereunder, shall be in writing and shall be deemed to have been given: (i) when delivered by hand (with written confirmation of receipt); (ii) on the next business day after the date sent, if sent for overnight delivery by a generally recognized international courier (e.g., FedEx, UPS, DHL, etc.) (receipt requested); or (iii) on the date sent by e-mail (with confirmation of transmission) if sent during normal business hours of the recipient, and on the next business day if sent after normal business hours of the recipient. Cysurance’s address for notification purposes shall be legal@cysurance.com. Participant’s address for notification purposes shall be as provided by Participant to Cysurance at the time of Enrollment or in the Solutions Agreement (which shall be the same). Either party may update its notice address upon written notice to the other party.

12.2. Cysurance is not responsible for failures or delays resulting from events outside its control.

12.3. No failure or delay by Cysurance in exercising any right, power or privilege hereunder shall operate as a waiver

thereof nor shall any single or partial exercise thereof preclude any other or further exercise thereof or the exercise of any other right, power, or privilege.

12.4. Participant shall not be entitled to assign, subcontract, delegate or otherwise transfer any of its rights and/or

duties arising out of this Agreement and/or parts thereof to third parties, voluntarily or involuntarily, including by change of control, operation of law or any other manner, without Cysurance’s express prior written consent. Any purported assignment, subcontract, delegation, or other transfer in violation of the foregoing shall be null and void.

12.5. Unless otherwise prohibited by law, (i) this Agreement shall be governed by the laws of the State of Delaware

without regard to the conflicts of law provisions thereof and (ii) any controversy or claim arising out of or relating to this Agreement, or the breach thereof, shall be settled by arbitration in Kent County, Delaware in English and in accordance with the JAMS International Arbitration Rules then in effect. Any judgment on the award rendered by the arbitrator may be entered in any court having jurisdiction thereof. Notwithstanding the foregoing, each party shall have the right to institute an action in a court of proper jurisdiction for preliminary injunctive relief pending a final decision by the arbitrator(s), provided that a permanent injunction and damages shall only be awarded by the arbitrator(s). In any action or proceeding to enforce rights under this Agreement, the prevailing party shall be entitled to recover costs and attorneys’ fees.

12.6. If any provision of this Agreement is held invalid or unenforceable by any court of competent jurisdiction,

the other provisions of this Agreement will remain in full force and effect. Any provision of this Agreement held invalid or unenforceable only in part or degree will remain in full force and effect to the extent not held invalid or unenforceable. The parties agree to replace such void or unenforceable provision of this Agreement with a valid and enforceable provision that will achieve, to the extent possible, the economic, business and other purpose of such void or unenforceable provision.

12.7. This Agreement (including the Enrollment Confirmation and exhibits hereto) constitutes the parties’ entire

agreement by and between the parties with respect to the subject matter hereof and supersedes any prior or contemporaneous agreement or understanding by and among the parties with respect to such subject matter.

12.8. Cysurance is not responsible for any failures or delays in performing under the 360 Program that are due to

events outside of Cysurance’s reasonable control. The 360 Program may not be available in all jurisdictions and is not available where prohibited by law or where not offered by Cysurance.

12.9. The parties have agreed that this Agreement as well as any notice, document or instrument relating to it be

drawn up in English only.

Schedule 1

360 Program Confirmation Summary*

Subject to all the terms and conditions in the Agreement, the 360 Program provides the following 360 Program Indemnification Levels:

Participants enrolled in the $500,000 Indemnification Level*

360. Program Indemnification Per Event Per Participant

$500,000 Level

Compliance Event A Maximum of $100,000 USD $100,000 USD
Ransomware Event & BEC Event A Maximum of $100,000 USD $100,000 USD
Cyber Legal Liability Event ** A Maximum of $250,000 USD $250,000 USD
Business Income Event A Maximum of $50,000 USD $ 50,000 USD

Participants Enrolled in the $1,000,000 Indemnification Level*

360. Program Indemnification $1,000,000 Per Event Per Participant

Level

Compliance Event A Maximum of $200,000 USD $200,000 USD
Ransomware Event & BEC Event A Maximum of $200,000 USD $200,000 USD
Cyber Legal Liability Event ** A Maximum of $500,000 USD $500,000 USD
Business Income Event A Maximum of $100,000 USD $100,000 USD

*Participant must first exhaust any other service warranty that would apply to these expenses. **Cyber Legal Liability/Media - Participant must exhaust all other financial benefits before triggering this Indemnification Level. The Indemnification Level, Per Event, and Per Participant amounts reflected in the tables above, although shown in USD, means the equivalent amount in the applicable foreign currency reflected within an Order Form.