Panel : Who Do You Know – Getting to know key partners in cybersecurity breach response
About this session
Patrick Bourk, an insurance broker at Navacord, moderates a panel with breach-coach lawyer Julie Himo of Torys and RCMP cybercrime officer Lina Dabit on who to call during a breach. They trace ransom trends: average Q1 2024 payments around 390,000 dollars, smaller organizations, eleven to 1,000 employees, taking the majority of hits, and a shift toward stealing data without encrypting it, since exfiltration alone avoids tripping alarms while data itself has become a tradeable commodity. Himo describes the breach coach's quarterback role, retaining IT forensics, ransomware negotiators and PR firms under legal privilege, and now routinely recommends contacting police early despite past frustration with slow response. Dabit corrects misconceptions about law enforcement seizing equipment, describes a jurisdiction-dependent reporting path through municipal police, provincial units and a national coordination centre, and warns that paying a ransom does not guarantee data stays private, citing a United States health-sector double-extortion case. Both stress cyber insurance's low uptake despite falling premiums after a punishing 2020-2021 loss ratio, and close on AI-enabled deepfake social-engineering risk and the roughly 60 percent one-year failure rate for small businesses hit by an attack.
When cybersecurity incidents happen, time is of the essence for companies that have been compromised. Knowing who to call and how to pay for the fallout can be critical. Welcome to how insurance, breach coach lawyers and law enforcement can play a vital part in cybersecurity breach response. From financial backing to legal advice to law enforcement support, these key constituents can become a breached company's life line. In this session you will learn how the cyber insurance community supports cybersecurity breach response and how some of the critical partners play a vital role in this response, including breach coach lawyers and law enforcement.
Key takeaways
- Build the incident response roster before a crisis, not during one: know which lawyer, IT forensics vendor, negotiator and local police jurisdiction you will call in advance.
- Route breach investigation and reporting through outside counsel so as much of it as possible falls under solicitor-client privilege before it can be used against you in later litigation.
- Report incidents to law enforcement even without a payment decision pending; attempted intrusions are still crimes and feed intelligence that helps other targets in your sector.
- Do not assume paying a ransom keeps data private: known double-extortion cases show attackers who received payment still leaked the data afterward.
- Do not treat small size as safety: businesses with 11 to 1,000 employees take the majority of ransomware hits, and about 60% of small businesses that are attacked fail within a year.
Speakers

Patrick is a lawyer and specialty commercial insurance expert with a passion for helping companies and professionals with their specialty insurance and risk management needs. As a specialty insurance expert, he collaborates with clients to build and… Read moreRead less
Patrick is a lawyer and specialty commercial insurance expert with a passion for helping companies and professionals with their specialty insurance and risk management needs. As a specialty insurance expert, he collaborates with clients to build and support the strategic direction of their cyber liability insurance needs. Patrick helps shape business development and client experience while also providing technical expertise in the analysis, negotiation, and placement of these coverages. Patrick’s cyber liability insurance practice also includes advising clients on how best to align breach response planning with insurance and risk mitigation solutions. He also provides claims expertise and assists clients by managing and advocating on their behalf. Patrick is currently the Cyber & Professional Lines Practice Leader for Navacord, Canada's fastest growing insurance brokering organization that owns and partners with over 65 insurance brokerage firms. Patrick also serves as a Strategic Advisor to NetDiligence, a consulting firm specializing in cyber risk readiness and response services to the insurance industry. NetDiligence publishes an annual Cyber Claims Study and hosts annual Cyber Risk Insurance Summits in Philadelphia, California, Toronto and Florida.

Julie Himo advises national and international clients on privacy and cyber security related matters. She acts as breach coach and has been appointed on numerous insurers panels. She has handled a large number of data and security breaches of all… Read moreRead less
Julie Himo advises national and international clients on privacy and cyber security related matters. She acts as breach coach and has been appointed on numerous insurers panels. She has handled a large number of data and security breaches of all types, many with international impacts and has coordinated notification and regulatory filing efforts in multiple countries. She also conducts strategic risk and privacy impact assessments and advises on a wide variety of Canadian privacy issues, including in the context of class actions. Ms Himo is also a seasoned commercial litigator, having handled over the past 25 years numerous commercial disputes in a wide variety of fields, including bankruptcy and insolvency and corporate and securities matters, commercial fraud, asset tracing and shareholder disputes. She also has considerable experience in extraordinary remedies such as seizures and injunctions.

Lina Dabit joined the RCMP in 1994 and started her career in BC working a variety of duties ranging from uniform patrol, drug section, major crime, intelligence, and border integrity. After transferring to Ontario in 2008, she focused on organized… Read moreRead less
Lina Dabit joined the RCMP in 1994 and started her career in BC working a variety of duties ranging from uniform patrol, drug section, major crime, intelligence, and border integrity. After transferring to Ontario in 2008, she focused on organized crime, national security and established the RCMP interview team in Ontario. She was commissioned in 2017 as commander of the Toronto Air Marshal Unit. Since 2021, she has led the Cybercrime Investigative Team and is building an innovative operational Cyber hub focused on collaboration between federal, international and private sector partnerships.


