ESET PROTECT – Table of Contents

Cyber warranty

The cyber warranty, provided by Cysurance, offers specified benefits for eligible security incidents under the ESET PROTECT MDR or ESET PROTECT MDR Ultimate plans and is available exclusively in the United States and Canada. Enrollment is complete when the participant receives a confirmation email from Cysurance. The service will start no later than the 10th day of the month following the purchase date of the plan, subject to fulfillment of the requirements described in the Cysurance terms.

Warranty program coverage

A claim is a request for reimbursement or benefits following a covered cybersecurity incident. Within a 12-month period, you are eligible for one incident reimbursement.

Warranty program provides coverage should any and/or all of the following security events occur:

Compliance events

Compliance event means a BEC (business email compromise) event or ransomware event directly resulting in a personal data breach, triggering HIPAA, GDPR, UK GDPR, PCI, OSHA, SEC, FTC, and/or any international, federal, state or other legally required notice and/or reporting requirements, where the sole recover benefit is for immediate legal assessment and emergency response of the compliance event. Continuing legal services beyond initial breach assessment, including dealing with the nature of the data breach and any extent of the same, are beyond the scope of any recovery benefit for this event.

Ransomware or business email compromise (BEC) events

Ransomware event means the unauthorized access to at least one participant endpoint in the form of ransomware, which has caused material harm to a participant, whereby “material harm” must include at least one of the following:

I.the unauthorized acquisition of unencrypted digital data from a participant's environment that compromises the security, confidentiality, or integrity of personal data or confidential information from the participant's environment;

II. public disclosure of personal data or confidential information maintained by the participant;

III.the compromise of at least one endpoint in the participant's environment, resulting in the blocking of access to such endpoint.

BEC event means a business email compromise in which a full, unauthorized threat actor takes over a participant's account within the participant's environment. The warranty program does not apply to BEC events where social engineering results in a funds transfer or fraud.

Cyber legal liability events

Cyber legal liability event means litigation arising directly out of a breach of data privacy and/or data security as a result of a BEC event or ransomware event, arising out of binding statements made regarding data privacy or security on the participant´s website, where legal defense expenses and settlement costs are incurred.

Business income events

Business income event means a security breach of the participant's environment that materially affects business operations, resulting in an actual, documentable loss or business income (net profit or loss before taxes) that would have been earned had no security breach occurred.

Participants enrolled in the $500,000 USD indemnification level*

Per event

Per participant

Compliance event

A maximum of $100,000 USD

$100,000 USD

Ransomware event, BEC event

A maximum of $100,000 USD

$100,000 USD

Cyber legal liability event**

A maximum of $250,000 USD

$250,000 USD

Business income event

A maximum of $50,000 USD

$50,000 USD

Participants enrolled in the $1,000,000 USD indemnification level*

Per event

Per participant

Compliance event

A maximum of $200,000 USD

$200,000 USD

Ransomware event, BEC event

A maximum of $200,000 USD

$200,000 USD

Cyber legal liability event**

A maximum of $500,000 USD

$500,000 USD

Business income event

A maximum of $100,000 USD

$100,000 USD

*Participants must first exhaust any other service warranty that would apply to these expenses.

**Participants must exhaust all other financial benefits before triggering the indemnification level.

For more information about warranty program benefits, including required cybersecurity controls, claim eligibility requirements and more, visit Cysurance.

Required cybersecurity controls

For the claim to be successful, the following controls must be implemented:

Warranty control requirements

Control description

Antivirus

ESET Endpoint Security and ESET Server Security (if applicable) must be deployed and kept up to date, including major, minor and bugfix updates on all endpoints in operation.

MDR/SIEM

ESET MDR must be active and monitoring on all endpoint devices in operation. Monitoring-only arrangements on specific assets are generally acceptable. However, customers must act on security notifications, remediation recommendations, and incident response guidance within a reasonable timeframe. Failure to do so may impact coverage eligibility if the incident can be tied to an identified issue that was not addressed.

MFA

Multi-factor authentication (MFA) must be enabled and enforced for all accounts (user, administrative and privileged) that can access or administer the organization´s email environment. MFA must not be optional and should not rely solely on password-based authentication. Including, but not limited to, ESET Secure Authentication. Specific attention should be given to administrator and privileged accounts, as they are among the most commonly exploited accounts observed in cyber incidents and claims.

Backups

Immutable backups (securely stored copies of data for recovery) must be in place, including Ransomware Remediation or an equivalent functionality.

Encryption

AES-256-bit encryption algorithms are employed, and all data is protected by AES-256-bit encryption. PHI/PII encryption in place (if regulatory requirements apply, such as HIPAA), including, but not limited to, ESET Full Disk Encryption.

Compliance

National, state and federal regulatory, privacy and security policies, such as PCI, HIPAA, GDPR, SEC, or other standards, must be followed by the participant (if regulatory conditions apply).

Maintenance

Available patches as well as fixes for known vulnerabilities (CVEs) alongside the available application updates must be applied within 60 days of the software manufacturer’s release cycle, including, but not limited to, ESET Vulnerability and Patch Management.

Security Awareness

Continuous security awareness training is delivered to employees. Such training must be implemented, and its completion must be documented for both employees and contractors.

Business Controls

Out-of-cycle wire transfers and invoice routing changes must be verified and documented prior to action taken. Any kind of wire fund transfers out of the norm may be verified if the event that caused the breach is tied back to this scenario.

Locate enrollment confirmation from Cysurance

Check your inbox for an email from orders@cysurance.com with subject line: Service Assurance Activation Confirmation - important information.

arrow_down_businessSee example:

Submit an incident claim

Incidents must be reported via the designated form within 48 hours of discovery. Requests to verify security controls or provide supporting information for claim processing must be addressed promptly. Failure to submit the required claim supporting the warranty within 15 days may result in the claim being deemed invalid and canceled.

Cysurance contact information

For questions regarding your cyber warranty program, contact Cysurance at:

Email: claims@cysurance.com

Phone: +1.917.503.8031

For more information see Cyber warranty FAQ.