How to Minimize Legal Risks in the Event of a Security Incident?
Download resourcesAbout this session
Laure Bonnave, a lawyer at Clyde & Co in Montreal who leads breach-coach engagements for organizations hit by cyberattacks, walks through Canada's legal landscape for security incidents entirely in French. She contrasts federal PIPEDA with Quebec's Law 25, whose newest provisions bring administrative fines up to ten million dollars or two percent of global revenue and punitive damages for gross negligence, and previews the similar federal Bill C-27. She defines the three types of data breach (confidentiality, availability, integrity), explains Quebec's serious-harm test for mandatory notification, and gives concrete preparation advice: inventory and minimize personal data, encrypt and test backups, train staff, buy cyber insurance, and pre-select a breach coach. She details the critical first 48 hours (notify the insurer promptly, preserve digital evidence, centralize communications) and the coach's coordinating role. A long audience question and answer session covers reporting to police, the legality and sanctions risk of paying ransoms, who decides on ransom payment under an insurance policy, credit-monitoring duration, dark-web monitoring obligations, and whether missing backups could support a negligence claim.
Key takeaways
- Pre-select a breach coach lawyer before an incident happens so privileged, confidential communications and expert coordination start on day one, not once the crisis is already underway.
- Notify your cyber insurer within days, not weeks, of discovering an incident; a delayed notice can let the insurer deny coverage for costs incurred before you told them.
- Assess breach severity using Quebec's serious-harm test (sensitivity of the data, likelihood of misuse, anticipated consequences) to decide whether notification to the regulator and affected individuals is mandatory.
- Before paying a ransom, check the attacking group against sanctions lists (e.g. the US Treasury's) through a ransom-negotiation specialist; paying a sanctioned group can itself be illegal.
- Inventory and minimize the personal data you hold, and encrypt and regularly test backups, since backup adequacy is likely to be scrutinized as evidence of fault in any future negligence claim.
Speakers

As a Senior Counsel at Clyde & Co Canada LLP, Laure Bonnave acts as a breach coach in cases involving cybersecurity incidents, including data or privacy breaches. As part of her practice, she has advised clients on multiple cyber incidents, both… Read moreRead less
As a Senior Counsel at Clyde & Co Canada LLP, Laure Bonnave acts as a breach coach in cases involving cybersecurity incidents, including data or privacy breaches. As part of her practice, she has advised clients on multiple cyber incidents, both locally and internationally. In her role, Laure regularly offers her clients expertise in cyber incident management, which includes: Overall incident response management and coordination with service providers; Responding to ransomware attacks and data recovery; Analyzing and reporting data breaches; Managing fraud cases involving payment misappropriation, locating and recovering funds; Development of a communications strategy and stakeholder management; Preparing reports to regulatory authorities; Managing risks relating to class actions following a confidentiality incident.
