

ITHACA: THE CYSURE PLATFORMÍTACA: LA PLATAFORMA DE CYSURE
We watch your operation and respondVigilamos tu operación y respondemos
Ithaca prioritizes your risks using signals from your own tools and connects them to a Cybersecurity and Artificial Intelligence insurance policy.Ítaca prioriza tus riesgos con las señales de tus propias herramientas y los conecta con un seguro de Ciberseguridad e Inteligencia Artificial.
CHAPTER I:CAPÍTULO I:THE PROBLEMEL PROBLEMA
Risk is not up for negotiationEl riesgo no se negocia
In Latin America, few mid-sized businesses have Cybersecurity tools, fewer still insurance to complement them.En Latinoamérica, pocas empresas medianas tienen herramientas de Ciberseguridad y menos aún un seguro que las complemente.
Cybersecurity coverage is already on the market; we also design Artificial Intelligence coverage.El mercado ya ofrece cobertura de Ciberseguridad; también diseñamos la de Inteligencia Artificial.
PreventPrevenirSignals from your tools to catch early what could stop your operations.Señales de tus herramientas para detectar a tiempo lo que puede detener tu operación.
RespondResponderInsurance designed to respond to events covered under your policy.Un seguro pensado para responder ante eventos cubiertos, según tu póliza.

CHAPTER II:CAPÍTULO II:OUR AGENTSNUESTROS AGENTES
Nine agents, one engineNueve agentes, un solo motor
The platform gathers signals from your tools, identifies what needs attention and helps you decide with your Resilience Lead.La plataforma reúne las señales de tus herramientas, detecta qué necesita atención y te ayuda a decidir con tu Resilience Lead.
The Harness is designed to coordinate the agents and read-only tools, with human oversight and transparent Artificial Intelligence consumption.El Harness está diseñado para coordinar a los agentes y las herramientas de solo lectura, con supervisión humana y consumo de Inteligencia Artificial transparente.
Our agentsNuestros agentesThey gather the signals from your tools and identify what needs attention.Reúnen las señales de tus herramientas y detectan qué necesita atención.
The integrationsLas integracionesThey read from the tools you already use, with read-only access within the scope you authorize.Consultan las herramientas que ya usas, con acceso de solo lectura y dentro del alcance que autorizas.
Resilience LeadA person with Cybersecurity experience helps you understand the findings and decide what to address first.Una persona con experiencia en Ciberseguridad te ayuda a entender los hallazgos y decidir qué atender primero.
The MDREl MDRIt coordinates incident handling, from detection to response, within the scope you authorize.Coordina la atención de incidentes, de la detección a la respuesta, dentro del alcance que autorizas.

MDR AgentAgente de MDR
A watch over your operation. Correlates signals from your security tools and coordinates the response with your Resilience Lead. Actions stay within your authorization.Una guardia atenta a tu operación. Correlaciona las señales de tus herramientas de seguridad y coordina la atención con tu Resilience Lead. Actúa solo dentro de lo autorizado.

Attack Surface AgentAgente de Superficie de Ataque
Even shifting shapes leave a trace. Continuous discovery of your exposed domains, services and certificates. Flags what changes and ranks what to review first.Lo que cambia de forma también deja rastro. Descubrimiento continuo de dominios, servicios y certificados expuestos. Detecta cambios y ordena qué revisar primero.

Scout AgentAgente de Exploración
Look beyond your perimeter. Finds leaked secrets, exposed API keys and lookalike domains. Every finding arrives with its source, date and a concrete next step.Mira más allá de tu perímetro. Busca secretos, llaves de API filtradas y dominios que te imitan. Cada hallazgo llega con fuente, fecha y el paso para cerrarlo.

Cloud Security AgentAgente de Seguridad en la Nube
Keep the winds under control. Reviews your cloud configuration and non-human identities with excess permissions. Recommends keeping only the access needed and checks the change.Que los vientos sigan bajo control. Revisa la configuración de tu nube y las identidades no humanas con permisos de más. Propone dejar solo el acceso necesario y verifica el cambio.

Email Security AgentAgente de Seguridad de Correo
Not every familiar voice deserves trust. Detects email fraud of the Artificial Intelligence era: impersonation and lookalike domains. Holding a message always requires your permission.No toda voz conocida merece confianza. Detecta el fraude por correo de la era de la Inteligencia Artificial: suplantaciones y dominios gemelos. Retener un mensaje requiere tu permiso.

Audit AgentAgente de Auditoría
Every action, with its original source. Continuous compliance: records who did what, when and with what outcome, with the evidence ready for your auditor, a certification or a customer.Cada acción, con su fuente original. Cumplimiento continuo: registra quién hizo qué, cuándo y con qué resultado, con la evidencia lista para tu auditor, una certificación o un cliente.

Red Team AgentAgente de Red Team
Find the way in before they do. Continuous red teaming: tests full attack paths with written authorization and an agreed scope. Shows where to break them.Encuentra la entrada antes de que la encuentren. Red teaming continuo: prueba rutas de ataque con autorización escrita y alcance acordado. Señala dónde cortarlas.

Vendor Watch AgentAgente de Proveedores
Know who your journey depends on. Watches your software and Artificial Intelligence supply chain: breaches, outages and changes across your vendors, models and integrations.Conoce a quienes sostienen tu travesía. Vigila tu cadena de suministro de software y de Inteligencia Artificial: brechas, caídas y cambios en tus proveedores, modelos e integraciones.

Artificial Intelligence Spend AgentAgente de Gasto de Inteligencia Artificial
Give every resource its place on board. Usage by team, frontier model and provider. Alerts before you hit the limit. Spend management, not insurance coverage.Que cada recurso tenga su lugar a bordo. Consumo por equipo, modelo frontera y proveedor. Alertas antes de tocar el límite. Gestión del gasto, no cobertura.

CHAPTER III:CAPÍTULO III:ENGINE AND RESILIENCE LEADEL MOTOR Y TU RESILIENCE LEAD
The engine watches. A person advises youEl motor vigila. Una persona te aconseja
Our Harness for Artificial Intelligence & Cybersecurity coordinates agents and tools with your permission, under human oversight, with every step logged. Your Resilience Lead guides you.Nuestro Harness para Inteligencia Artificial y Ciberseguridad coordina agentes y herramientas con tu permiso, bajo supervisión humana y con cada paso registrado. Tu Resilience Lead te orienta.
Every week:Cada semana:
Findings: what happened, what's next.Hallazgos: qué pasó y qué sigue.
Priorities: fixes and their Risk Score impact.Prioridades: arreglos y cómo mueven tu Risk Score.
Decisions: only yours, plainly put.Decisiones: solo las tuyas, en palabras sencillas.
No tech skills needed: you bring the judgment.No necesitas ser técnico: tú pones el criterio.

CHAPTER IV:CAPÍTULO IV:THE RISK SCOREEL RISK SCORE
The telemetry that protects you also scores youLa telemetría que te cuida también te evalúa
Your Risk Score shows what to tackle first and can change daily.Tu Risk Score marca qué atender primero y puede cambiar cada día.
Cysure Impact Engine connects Artificial Intelligence and telemetry in a model for estimating a failure’s cost, prioritizing prevention and informing risk assessment.Cysure Impact Engine conecta Inteligencia Artificial y telemetría en un modelo para estimar cuánto costaría una falla, priorizar prevención y orientar la evaluación del riesgo.
READ-ONLY, ON WHAT YOU ALREADY RUNREAD-ONLY, SOBRE LO QUE YA USAS











CHAPTER V:CAPÍTULO V:DETECTION-COVERAGE ALIGNMENTDETECTION-COVERAGE ALIGNMENT
We only insure what we detectSolo aseguramos lo que detectamos
The rule is simple: if our telemetry cannot see a risk, we do not insure it, and we tell you before you sign. No signal, no coverage.La regla es simple: si nuestra telemetría no puede ver un riesgo, no lo aseguramos, y te lo decimos antes de firmar. Sin señal, no hay cobertura.

CiberseguridadCybersecurityThe events that freeze an operation: the risk the market knows and LATAM still leaves largely uncovered.Los eventos que congelan una operación: el riesgo que el mercado conoce y que en LATAM sigue poco cubierto.
Inteligencia ArtificialArtificial IntelligenceArtificial Intelligence failures: the category just starting to show up in policies.Las fallas de Inteligencia Artificial: la categoría que apenas empieza a aparecer en las pólizas.
Cybersecurity coverage we designCoberturas de Ciberseguridad que diseñamos





Email fraud (Business Email Compromise or BEC)Fraude de correo (Business Email Compromise o BEC)Impersonation that reroutes payments from a compromised inbox.Suplantación que desvía pagos desde un correo comprometido.
USD $55Bglobal losses to BEC fraud reported to the FBI; Mexico sits on the main route of the diverted transfers.pérdidas globales por fraude BEC reportadas al FBI; México está en la ruta principal de las transferencias desviadas.FBI IC3

RansomwareEncryption that freezes systems and stops the operation.Cifrado que congela sistemas y detiene la operación.
8.13%of organizations in Latin America were hit by ransomware in 2025: the most attacked region in the world.de las organizaciones de América Latina sufrió ransomware en 2025: la región más atacada del mundo.KASPERSKY, 2025

DDoS AttacksAtaques de DDoSSaturation that takes down your internet-facing services.Saturación que tira tus servicios expuestos a internet.
1M+DDoS attacks struck Latin America in the second half of 2025 alone; Brazil took nearly half.ataques DDoS golpearon América Latina solo en el segundo semestre de 2025; Brasil concentró casi la mitad.NETSCOUT

Data BreachExposure of confidential data from your operation or your clients.Exposición de datos confidenciales de tu operación o tus clientes.
USD $4.65Maverage cost of a data breach in Latin America, with 40,300 records exposed per incident.costo promedio de una filtración de datos en América Latina, con 40,300 registros expuestos por incidente.IBM, 2026

Cloud OutageYour cloud provider down, verified via status page.Caída de tu proveedor de nube, verificada vía status page.
USD $5.4Bdirect losses for the Fortune 500 from a single day of the CrowdStrike outage; only 10 to 20% was insured.perdió el Fortune 500 en un solo día por la caída global de CrowdStrike; solo 10–20 % estaba asegurado.PARAMETRIX, 2024
Artificial Intelligence coverage we designCoberturas de Inteligencia Artificial que diseñamos 




Runaway Artificial Intelligence spendGasto de Inteligencia Artificial fuera de controlSignal: spend per key and model breaking your daily baseline.Señal: consumo por llave y modelo que rompa tu línea base diaria.
LLM10:2025OWASP lists Unbounded Consumption among the ten top risks for LLM applications: excessive, uncontrolled inference that ends in economic losses, with attackers exploiting pay-per-use cloud pricing until the bill becomes unsustainable.OWASP incluye el consumo sin límite entre los diez riesgos principales de las aplicaciones con LLM: inferencias excesivas y sin control que terminan en pérdidas económicas, con atacantes que explotan el cobro por uso de la nube hasta volver la factura insostenible.Source: OWASP, 2025Fuente: OWASP, 2025

Agent decisions gone wrongDecisiones erróneas de agentesSignal: agent actions outside its scope, or with no human review.Señal: acciones de un agente fuera de su alcance o sin revisión humana.
25%of enterprise breaches will be traced back to Artificial Intelligence agent abuse by 2028, from both external and malicious internal actors, Gartner predicts.de las brechas empresariales se rastreará hasta el abuso de agentes de Inteligencia Artificial para 2028, tanto por actores externos como por personal interno malintencionado, según prevé Gartner.Source: GARTNER, 2024Fuente: GARTNER, 2024

Data leaking through Artificial IntelligenceFuga de datos por Inteligencia ArtificialSignal: sensitive data flowing to models or vendors outside your inventory.Señal: datos sensibles viajando a modelos o proveedores fuera de tu inventario.
1 in 5organizations studied by IBM (20%) had a breach linked to unauthorized Artificial Intelligence, tools used without approval; those incidents added as much as USD 670K to the average breach cost, and 97% lacked proper access controls.empresas estudiadas por IBM (20 %) sufrió una brecha ligada a Inteligencia Artificial sin autorización, herramientas usadas sin aprobación; esos incidentes añadieron hasta USD 670K al costo promedio de la brecha y el 97 % no tenía controles de acceso adecuados.Source: IBM, 2025Fuente: IBM, 2025

Prompt injectionInyección de promptSignal: orders arriving in outside content that steer the agent off course.Señal: órdenes que llegan en contenido externo y desvían al agente.
#1OWASP ranks prompt injection as the number-one risk for LLM applications (LLM01:2025). The instruction does not have to be visible: it only has to be parsed by the model, even if no human can read it.OWASP coloca la inyección de prompt como el riesgo número uno de las aplicaciones con LLM (LLM01:2025). La orden no tiene que ser visible: basta con que el modelo la procese, aunque ninguna persona pueda leerla.Source: OWASP, 2025Fuente: OWASP, 2025
CHAPTER VI:CAPÍTULO VI:THE EXPRESS PAYOUTLA INDEMNIZACIÓN EXPRESS
The payout you do not have to ask forLa indemnización que no tienes que pedir
We design an automatic payout in local currency, subject to verification of the covered event and your policy’s terms and timing. If the evidence needs review, the process follows the policy’s agreed terms.Diseñamos una indemnización automática en moneda local, sujeta a verificar el evento cubierto y a las condiciones y el plazo que fija tu póliza. Si la evidencia requiere revisión, se sigue lo acordado en ella.
VERIFIABLE SEALSELLO VERIFICABLEThe design keeps the evidence and a fingerprint that can be checked.El diseño conserva la evidencia y una huella que permite verificarla.

Clear rulesReglas clarasThe payout is designed to trigger on a verified covered event, under your policy’s terms and within the window it sets.El pago está diseñado para activarse al verificarse un evento cubierto, conforme a las condiciones y en el plazo que fija tu póliza.
Agreed termsCondiciones acordadasThe scope and limits of each coverage are defined in the policy.El alcance y los límites de cada cobertura se definen en la póliza.
5Cybersecurity eventsEventos de Ciberseguridad
CHAPTER VII:CAPÍTULO VII:PLANSPLANES
Your next stepTu siguiente paso
Two paths: a free month toward Active, or Enterprise if you already have Cybersecurity insurance. Enrollment and coverage are subject to assessment and policy terms.Dos rutas: un mes gratis rumbo a Active, o Enterprise si ya tienes seguro de Ciberseguridad. La incorporación y las coberturas están sujetas a evaluación y a las condiciones de cada póliza.
I
First month freePrimer mes gratis
We review your signals together: what to strengthen first and how to improve your Risk Score.Revisamos contigo tus señales: qué reforzar primero y cómo mejorar tu Risk Score.
II
ActiveActive
The subscription to monitor and improve your security, with the platform and your Resilience Lead, designed to add parametric policies and other coverage.Suscripción para vigilar y mejorar tu seguridad, con la plataforma y tu Resilience Lead, diseñada para sumar pólizas paramétricas y más coberturas.
III
EnterpriseEnterprise
To broaden protection, we assess reinsurance options and Mexico-registered insurer products with you, case by case.Para ampliar tu protección, evaluamos contigo alternativas de reaseguro y productos de aseguradoras registrados en México, caso por caso.
CHAPTER VIII:CAPÍTULO VIII:CONTACTCONTACTO
Talk to the foundersHabla con los fundadores
Let’s talk about the tools you use, the risks on your mind and what would make sense to assess first. Write to us through this form and talk directly with the founders.Conversemos sobre las herramientas que usas, los riesgos que te preocupan y qué tendría sentido evaluar primero. Escríbenos desde este formulario y hablas directo con los fundadores.

WRITE TO THE FOUNDERSESCRÍBELES A LOS FUNDADORES
Listo. Muy pronto nos contactaremos contigo.Done. We will be in touch very soon.
Algo falló al enviar. Inténtalo de nuevo en unos minutos.Something went wrong. Please try again in a few minutes.






