Last reviewed: September 1, 2026
Cyber warranty financial protection can be one part of a broader cybersecurity and recovery strategy. Cork Protect may provide an additional financial recovery layer for qualifying EasyITGuys Plan 1 and Plan 2 clients when applicable enrollment, activation, eligibility, and warranty requirements are satisfied. EasyITGuys works with Cork as an independent third-party provider. EasyITGuys does not issue, insure, approve, or guarantee Cork financial protection. Cork Protect is designed to work alongside managed cybersecurity, incident response, backup and recovery, business continuity, and cyber insurance. It does not replace cyber insurance.
| EasyITGuys Plan | Current Cork Reference | Current Maximum Aggregate |
|---|---|---|
| Plan 1 | Protect100 | Up to $100,000 |
| Plan 2 | Protect25 | Up to $25,000 |
These are current program references. They are not proof that a specific organization has active financial protection.
Important: Educational Reference Only
This Client University article provides general educational information. It is not a warranty agreement, insurance policy, legal or insurance advice, coverage determination, service-level commitment, or guarantee of payment. Nothing in this article creates, expands, modifies, waives, or replaces any contractual obligation, service scope, warranty term, insurance requirement, remedy, or responsibility of EasyITGuys, Cork, the client, an insurance carrier, or any other party. EasyITGuys services are governed by the applicable MSA or Terms of Service, Service Guide, Quote, Order, Statement or Scope of Work, and other client-specific written agreements. Cork financial protection is governed by the client’s current Cork Customer Limited Warranty Agreement, Schedule A, Cork portal status, Warranty Notice, and current Cork documentation. Cyber insurance is governed by the client’s actual insurance policy and carrier. Where documents conflict, the applicable contractual order of precedence and controlling source documents apply.
What Is Cork Protect? #
Cork Protect is a limited cybersecurity warranty and financial protection program provided and administered by Cork. EasyITGuys works with Cork as part of a layered cybersecurity and recovery strategy. The purpose of Cork Protect is to add another potential financial recovery resource when a qualifying event occurs and Cork’s applicable requirements are satisfied.
What Types of Incidents Can Cork Protect Address? #
Cork’s current warranty focuses on specific types of qualifying cybersecurity incidents. These currently include certain ransomware events, certain email-based ACH or wire transfer fraud events, and certain SMS phishing events. Each category has specific definitions, requirements, limits, and exclusions.
Cork Protect Is Not Cyber Insurance #
Cork Protect and cyber insurance are different forms of financial protection. They can complement one another.
| Cork Protect | Cyber Insurance |
|---|---|
| Limited cybersecurity warranty and financial protection | Insurance policy issued by an insurance carrier |
| Focused on specific qualifying incidents and expenses | Coverage depends on the individual insurance policy |
| Has its own limits, requirements, and exclusions | Has its own limits, deductibles, requirements, and exclusions |
| Does not replace cyber insurance | Remains an important part of business risk management |
Clients should maintain appropriate cyber insurance based on their business risks, contracts, regulatory requirements, and guidance from qualified insurance professionals.
Current Plan 1 and Plan 2 Financial Protection #
The amounts below reflect the Cork Schedule A as of the review date of this article. They are provided for educational reference only and can change. Always use the current client-specific Cork portal and Warranty Agreement before relying on any amount.
| Schedule A Reference | Plan 1 / Protect100 | Plan 2 / Protect25 |
|---|---|---|
| Maximum aggregate during warranty period | $100,000 | $25,000 |
| Maximum for one Warranty Incident | $100,000 | $25,000 |
| Instant fund access | $5,000 | $1,000 |
| SMS phishing loss | $500, maximum 1 event | $500, maximum 1 event |
| ACH / wire transfer loss | $50,000 | $10,000 |
| Cyber insurance deductible / retention loss | $100,000 | $10,000 |
| Incident response expenses | $20,000 | $5,000 |
| Data recovery expenses | $0 | $0 |
| Business interruption / extra expense | $0 | $0 |
| Ransom payment | $0 | $0 |
The maximum amount is not a blank check.
The overall maximum, per-incident maximum, individual sublimits, event definitions, eligibility requirements, exclusions, and circumstances all matter. Individual category limits are part of the overall maximum. They are not additional amounts added on top of it.
A $0 sublimit does not automatically explain every related recovery expense.
Cork defines different expense categories separately. Some technical remediation work may be treated differently under another category. Cork’s current Warranty Agreement determines how an actual expense is classified and whether it qualifies.
What About the Cyber Insurance Deductible? #
The current Protect100 Schedule A lists up to $100,000 for eligible Cyber Insurance Deductible/Retention Loss. Protect25 currently lists up to $10,000. This does not mean Cork automatically pays a client’s cyber insurance deductible after every incident. Cork’s current warranty includes additional requirements. These can include submitting the underlying loss to applicable cyber insurance and obtaining documentation from the insurer concerning the deductible or retention and the insurer’s coverage of the underlying claim.
Not every deductible or retention necessarily qualifies. The insurance policy, insurance carrier, Cork Warranty Agreement, and facts of the incident all matter. Always review the current legal documents instead of assuming that a listed sublimit guarantees reimbursement.
Eligibility Is About Cybersecurity Hygiene and Responsible Risk Management #
Technology environments change constantly. Devices are added and removed. Employees change. Software updates. Integrations change. New vulnerabilities are discovered. Security tools generate findings. The goal is not to maintain a dashboard that permanently displays zero alerts. The goal is to maintain a responsible and modern cybersecurity program.
Perfection is not the goal. Responsible cybersecurity hygiene is. Strong protection depends on consistent effort, modern security controls, reasonable remediation, good employee practices, accurate information, and cooperation between the client and the IT department.
This principle does not extend, waive, or replace a Cork risk deadline, warranty requirement, security requirement, or obligation contained in an applicable EasyITGuys agreement. When a specific requirement or deadline applies, the controlling documentation governs.
A Security Finding Is Not Automatically a Loss of Financial Protection #
This distinction is important. Cork can display several types of security posture information. Compliance events, risk signals, software vulnerability findings, mapping conditions, and other platform information can have different meanings. A dashboard item should be evaluated according to its actual type and current Cork documentation. It should not automatically be treated as either harmless or a loss of financial protection.
A single compliance event does not automatically mean company-wide protection is lost. Cork’s current Financial Protection Eligibility documentation states that failure to resolve a compliance event by its risk deadline may affect financial protection payout for the associated endpoint or user. Cork also states that a single asset’s compliance event that has passed its risk deadline does not void or pause financial protection for the entire client. The effect of any event on an actual claim remains subject to Cork’s current Warranty Agreement and claim determination.
Cork currently provides risk-management options for certain technical limitations or compensating controls. Additional evidence may be required if a related claim later occurs. Use of a risk-management option does not guarantee future claim approval.
Does Every Alert Need Separate Client Notification? #
Not every platform signal, alert, risk observation, or compliance event requires the same operational response or separate client communication. EasyITGuys handles monitoring, investigation, remediation, escalation, and client communication according to the applicable service scope, severity, technology involved, current operating processes, and governing agreements. Some conditions can be handled through routine technical operations. Other conditions require client information, approval, training, purchasing, policy decisions, access, or remediation cooperation.
Client University does not create a separate notification SLA. Nothing in this article creates a notification requirement, response commitment, or service-level obligation beyond the applicable MSA/TOS, Service Guide, Quote/SOW, or other governing written agreement.
Visibility Is a Shared Responsibility #
Automated tools and integrations are valuable, but no technology inventory should be treated as infallible. Where reports, inventories, documentation, or portal access are provided, client participation can help identify changes or discrepancies that automated systems may not detect immediately. Clients are encouraged to promptly report known inaccuracies, missing systems, unknown devices, personnel changes, or other material discrepancies. EasyITGuys can then investigate and work with the client to improve the accuracy of the documented environment. Any formal review or notification obligations remain governed by the applicable agreements and current Cork terms.
Shared Responsibility Matters #
Cybersecurity and recovery involve several parties. Each party controls different parts of the process.
| EasyITGuys | Client | Cork and Other Parties |
|---|---|---|
| Manage applicable cybersecurity technology within the agreed service scope | Complete onboarding and cooperate with required protections | Cork defines its current warranty requirements and terms |
| Work applicable security issues through normal operations | Respond when information, approval, training, or remediation cooperation is needed | Cork evaluates warranty claims under its current terms |
| Maintain applicable monitoring, security, support, and maintenance processes | Maintain appropriate employee practices and report material environment changes | Insurance, legal, incident response, and regulatory parties perform their own roles |
| Assist with technical response and coordination within the agreed service scope | Manage required insurance, Cork, legal, contractual, and regulatory engagement | Each party makes decisions within its own authority |
No single party controls every part of cybersecurity risk. Shared effort improves prevention, visibility, response, and recovery.
What Helps Support Financial Protection Eligibility? #
This is not a complete warranty eligibility checklist. The examples below describe common cybersecurity practices and current Cork requirements at a high level. Meeting every item listed here does not guarantee Cork eligibility or payment. An item not listed here may still matter under the current warranty.
- Complete applicable managed IT and cybersecurity onboarding.
- Keep required security tools active and properly deployed.
- Maintain appropriate endpoint monitoring and protection.
- Use multi-factor authentication where applicable.
- Maintain appropriate backup protection for critical systems.
- Maintain applicable email security.
- Keep systems and applications reasonably current and supported.
- Apply appropriate security updates and preventative maintenance.
- Maintain required employee security awareness training.
- Address applicable compliance events within current requirements.
- Keep the documented user, device, and system environment reasonably accurate.
- Cooperate when remediation or additional information is required.
- Maintain applicable legal and regulatory obligations.
Cybersecurity is an ongoing process. It is not completed once during onboarding and then ignored.
Why Onboarding and Activation Matter #
Selecting Plan 1 or Plan 2 by itself is not proof of active Cork financial protection. Applicable onboarding, security deployment, integrations, Cork enrollment, qualification requirements, and documentation must be completed as appropriate. The current client-specific Cork portal, Warranty Notice, and Warranty Agreement provide the best confirmation of current status.
Client decisions matter. Delaying or declining important security controls, remediation, updates, training, onboarding tasks, or other required protections can increase cybersecurity risk. Those decisions may also affect financial protection eligibility under Cork’s current terms.
How Do I Confirm My Current Cork Protect Status? #
Active clients should use their current Cork information rather than relying on this article. Current information can include the Cork portal, Cork Warranty Notice, Customer Limited Warranty Agreement, applicable Schedule A, and current financial protection status. Contact your EasyITGuys account manager if you need help locating or reviewing current documents. Cork currently offers Delegated Access, which can provide an authorized client user with read-only access to their organization’s information in the Cork portal. According to Cork, delegated users can view their assigned client’s information but cannot change settings, apply financial protection, modify integrations, or take action on the information they are viewing. For current details, see Cork’s Delegated Access documentation. Portal features and permissions are controlled by Cork and can change. Contact your EasyITGuys account manager if you would like delegated access reviewed for your organization.
What About New or Prospective Clients? #
Prospective or interested clients may request sample Cork documentation for educational review. Sample documents are not proof of active financial protection. They may also differ from the documents or terms that apply when financial protection is activated.
Reference copies can become outdated. If sample or reference Cork documents are attached to this article, they reflect the versions available when the article was reviewed. They should not be assumed to remain the governing versions. For an actual incident, claim, eligibility question, or coverage determination, use the current client-specific Cork portal and controlling Cork documentation.
What EasyITGuys Does and Does Not Control #
| EasyITGuys Can Help With | EasyITGuys Does Not Guarantee |
|---|---|
| Managing applicable cybersecurity technology within the agreed service scope | That a cyberattack will never occur |
| Helping maintain cybersecurity processes and hygiene | That every tool, integration, or dashboard will always be error-free |
| Responding to security issues within the applicable service scope | That an incident qualifies under Cork’s warranty |
| Providing technical information and coordination when appropriate | Cork claim approval or reimbursement |
| Helping the client engage appropriate technical parties | Cyber insurance coverage decisions |
The Cork warranty does not replace or redefine EasyITGuys’ service obligations. EasyITGuys’ responsibilities remain governed by the applicable MSA/TOS, Service Guide, Quote/SOW, and other governing written agreements.
What Should I Do If I Suspect a Cyberattack? #
Urgent? Call the Support Desk immediately. If you suspect an active cybersecurity incident:
- Stop normal use of the affected system.
- If it can be done safely, isolate the affected device from wired and wireless networks.
- Do not delete files, logs, emails, or other potential evidence.
- Do not wipe, reset, reinstall, or attempt your own cleanup.
- Do not power systems off unless directed by the appropriate incident response team or emergency conditions make another containment option impractical.
- Contact EasyITGuys Support immediately so the appropriate technical response process can begin.
Broader network or Internet isolation may be appropriate during some incidents. That decision should be coordinated with the appropriate incident response professionals whenever possible. Cyber incidents can also involve insurance, Cork, legal, contractual, and regulatory requirements.
Contacting EasyITGuys is not notice to every other party. Contacting EasyITGuys does not, by itself, satisfy any notice requirement owed to Cork, a cyber insurance carrier, broker, attorney, regulator, law enforcement agency, customer, contractual counterparty, or another party. The client remains responsible for identifying and satisfying its own insurance, Cork, legal, contractual, and regulatory obligations except where a governing written agreement expressly assigns a specific responsibility to another party. EasyITGuys can assist with technical information and coordination within the applicable service scope.
The client is responsible for ensuring required Cork notices or claims are submitted within Cork’s applicable requirements. Clients should not rely on EasyITGuys as a substitute for their own notice obligations. EasyITGuys can assist with technical information and coordination where appropriate.
Frequently Asked Questions #
Is Cork Protect cyber insurance? #
No. Cork Protect is a limited cybersecurity warranty and financial protection product. It is intended to complement cyber insurance, not replace it.
Who provides the Cork warranty? #
Cork provides and administers its warranty program. EasyITGuys works with Cork as an independent third-party provider.
Does EasyITGuys decide whether Cork pays a claim? #
No. Cork administers warranty claims and determines eligibility under its current terms.
Does EasyITGuys guarantee Cork Protect? #
No. EasyITGuys does not guarantee Cork eligibility, coverage interpretation, claim approval, or reimbursement.
Does this article prove that my company has active Cork Protect? #
No. This article is general education. Use your current client-specific Cork portal, Warranty Notice, and Warranty Agreement for confirmation.
What does Plan 1 currently use? #
Eligible Plan 1 clients are currently associated with Protect100 after applicable activation and qualification requirements are satisfied. Current active status should still be confirmed through Cork.
What does Plan 2 currently use? #
Eligible Plan 2 clients are currently associated with Protect25 after applicable activation and qualification requirements are satisfied. Current active status should still be confirmed through Cork.
Does $100,000 mean every cyber loss is covered for $100,000? #
No. The $100,000 amount is the current Protect100 maximum aggregate. Individual categories can have smaller sublimits or no separate amount under the current Schedule A.
Does Plan 1 include protection for a cyber insurance deductible? #
The current Protect100 Schedule A lists up to $100,000 for eligible Cyber Insurance Deductible/Retention Loss. This does not mean every cyber insurance deductible qualifies. The insurance policy, insurance carrier, Cork Warranty Agreement, and incident facts all matter.
Do we still need cyber insurance? #
Yes. Cork Protect should be considered an additional financial recovery layer. It is not a replacement for appropriate cyber insurance.
Can our insurance agent review Cork Protect? #
Yes. Clients are encouraged to share their current Cork documentation with their insurance professional. The insurance professional should review the actual current Cork documents rather than relying only on this educational article.
Does Cork Protect cover every cybersecurity event or data breach? #
No. The current warranty defines specific Warranty Incidents and Covered Expenses. Not every malware detection, data breach, security alert, outage, fraudulent payment, or cybersecurity event automatically qualifies.
Does one Cork alert mean our company lost all financial protection? #
No automatic assumption should be made. Cork currently states that a compliance event that passes its risk deadline may affect financial protection payout for the associated endpoint or user. Cork also states that a single asset’s lapsed compliance event does not automatically void or pause financial protection for the entire client.
Does every security finding affect Cork financial protection? #
Not necessarily. Cork displays different types of security and risk information. Those findings can have different meanings under Cork’s current program. Use current Cork documentation to understand a specific event.
Should our security dashboard always have zero alerts? #
No. Technology environments change continuously. The goal is to identify risk, maintain applicable controls, remediate meaningful issues, and continue improving cybersecurity hygiene. Specific Cork requirements and deadlines still apply when applicable.
What if a technical limitation prevents an issue from being completely resolved? #
Cork currently provides risk-management options for certain technical limitations or compensating controls. Documentation or additional evidence may be required. Use of such an option does not guarantee a future claim.
Will EasyITGuys send us a separate notice for every Cork event? #
Not every Cork signal requires the same response or separate client communication. EasyITGuys follows the applicable service scope, operating processes, severity, and governing agreements. This educational article does not create a separate notification obligation.
Can we review Cork information ourselves? #
Yes. Cork currently offers Delegated Access that can provide an authorized client user with read-only access to their organization’s information. Contact your EasyITGuys account manager if you would like access reviewed for your organization.
See Cork’s Delegated Access documentation for current feature details.
What if we see a missing computer, user, or inaccurate item? #
Tell EasyITGuys. Client feedback can help identify inventory, integration, licensing, onboarding, or documentation issues. We can investigate the discrepancy together.
What happens if we decline an important security recommendation? #
Clients remain responsible for business decisions within their control. Declining applicable controls, updates, remediation, training, or other protections can increase cybersecurity risk. Those decisions may also affect eligibility under Cork’s current warranty.
Why does security awareness training matter? #
Many cyberattacks target people. Current Cork requirements can also make security awareness training relevant to certain financial protection categories.
Why do patching and supported systems matter? #
Known vulnerabilities are frequently used in attacks. Preventative maintenance and supported systems are important parts of cybersecurity hygiene. Current Cork warranty terms can also contain related qualification requirements.
What happens if we do not complete onboarding? #
Incomplete onboarding can leave required tools, integrations, users, systems, or documentation incomplete. This can prevent activation or affect financial protection eligibility. Actual status should be confirmed through Cork.
Are unmanaged devices automatically protected? #
No assumption should be made that an unknown, unmanaged, or unprotected device is covered. Clients should report technology changes so the documented environment can be reviewed.
Does Cork guarantee reimbursement after an attack? #
No reimbursement should be assumed in advance. Claims are evaluated under Cork’s current Warranty Agreement, definitions, limits, requirements, and exclusions.
Does a $0 Data Recovery sublimit mean no technical recovery work could ever qualify? #
Not necessarily. Cork defines several expense categories separately. Some technical remediation activities may be classified under another category depending on Cork’s current terms and the circumstances.
Are incidents that existed before the warranty automatically covered? #
No. Cork’s current Warranty Agreement contains provisions addressing pre-existing and related incidents. Review the current client-specific agreement for the controlling terms.
Does Cork Protect cover liability to our customers or other third parties? #
Do not assume that it does. Cork’s current Warranty Agreement contains limitations involving third parties and third-party liability. Appropriate cyber insurance and other business insurance remain important.
Does meeting Cork’s eligibility requirements mean our business is fully prepared to recover? #
No. Financial protection eligibility and operational recovery readiness are different questions. An organization can potentially satisfy a financial protection requirement while still having backup, recovery-time, business continuity, hardware, software, staffing, or process risks. Cork eligibility should not replace disaster recovery, business continuity planning, cybersecurity strategy, or cyber insurance.
Is Cork Protect permanent as long as we remain on Plan 1 or Plan 2? #
No such assumption should be made. Cork financial protection has its own activation status, warranty period, renewal, termination, and current program terms. EasyITGuys plan participation alone is not proof that Cork financial protection is currently active.
What should we do first after a suspected cybersecurity incident? #
Call the EasyITGuys Support Desk immediately. Stop normal use of affected systems. Isolate affected devices from the network when it can be done safely. Preserve evidence and follow the direction of the incident response team.
Does calling EasyITGuys notify our cyber insurance company? #
No. The client remains responsible for following its cyber insurance policy and applicable notification requirements. Do not assume that notifying EasyITGuys satisfies an insurance notice requirement.
Who is responsible for Cork claim and notice deadlines? #
The client is responsible for ensuring its required Cork notices and claims are submitted within the applicable requirements. Clients should review their current Warranty Notice and Warranty Agreement. EasyITGuys can assist with technical information and coordination where appropriate.
Who is responsible for legal or regulatory notifications? #
The client remains responsible for its legal, contractual, insurance, and regulatory obligations unless a governing written agreement specifically provides otherwise. Qualified legal counsel, insurance professionals, compliance professionals, and incident response teams should be involved when appropriate.
Can we contact Cork directly? #
Yes, where permitted by the current Cork documentation. Nothing in this article limits a client’s rights or responsibilities under its current Cork Warranty Notice or Warranty Agreement. During a suspected incident, also contact EasyITGuys Support so the technical response process can begin.
How do we obtain our current Cork documents? #
Review the current Cork portal or contact your EasyITGuys account manager. Current client-specific documents are more reliable than old email copies, sample documents, or this educational article.
Where should we look for the most current information? #
Use the current Cork portal, Customer Limited Warranty Agreement, Schedule A, Warranty Notice, eligibility documentation, and client-specific financial protection status. The applicable EasyITGuys MSA/TOS, Service Guide, Quote/SOW, and other governing agreements control EasyITGuys services. Your actual cyber insurance policy controls your cyber insurance coverage.
Educational Use Only
Client University is designed to make complex IT and cybersecurity topics easier to understand. It does not replace governing contracts, Cork warranty terms, insurance policies, vendor documentation, legal advice, insurance advice, or a case-specific coverage determination. Always use the most current controlling documents when making business, legal, insurance, cybersecurity, or recovery decisions.