About this session
This panel, moderated by GoSecure's Frédéric, brings together a broker, an insurer and a breach-coach lawyer to unpack what happens to an organization after a cyberattack. Laure Bonnave (Clyde & Co) walks through the legal, regulatory and reputational fallout under Quebec and federal privacy law, the class-action landscape including the Desjardins settlement, and the breach coach's role as the response team's quarterback, coordinating forensics, PR and legal privilege. Maxime Audet (HUB International) explains the difficulty of pricing cyber coverage given thin historical loss data, the many wordings a broker must track, and how to prepare a business for a faster claim by pre-vetting panel vendors and documenting everything. Miki Ho (Resilience) covers underwriting, why early and frequent incident reporting helps rather than hurts renewal, the shift toward ransomware and third-party or vendor exposure such as CrowdStrike-style outages, and the value of engaging law enforcement quickly in social-engineering fraud cases. Audience questions cover coverage priorities and how claim dollars break down.
Panelists will explore the effects of cyber-attacks after the breach, including the risks of lawsuits and challenges in renewing insurance, from an insider’s perspective.
Key takeaways
- Report suspected incidents to your insurer early and often; notification, not the incident date, often starts the coverage clock, and early reporting is viewed favourably at renewal rather than penalized.
- Do not spend money on forensics or incident response before notifying your insurer; costs run up with an unapproved vendor may not be reimbursed.
- Build a relationship with your policy's approved breach-coach, forensics and PR panel before an incident happens so the claim moves faster when one does.
- Keep your broker involved even in large or sensitive claims; their existing relationships and knowledge of policy wording speed up resolution.
- Focus legal review of a proposed policy on the exclusions and endorsements, such as war, neglected-software or non-IT-supplier clauses, rather than the general wording, since that is where coverage gaps hide.
Speakers

As a Senior Counsel at Clyde & Co Canada LLP, Laure Bonnave acts as a breach coach in cases involving cybersecurity incidents, including data or privacy breaches. As part of her practice, she has advised clients on multiple cyber incidents, both… Read moreRead less
As a Senior Counsel at Clyde & Co Canada LLP, Laure Bonnave acts as a breach coach in cases involving cybersecurity incidents, including data or privacy breaches. As part of her practice, she has advised clients on multiple cyber incidents, both locally and internationally. In her role, Laure regularly offers her clients expertise in cyber incident management, which includes: Overall incident response management and coordination with service providers; Responding to ransomware attacks and data recovery; Analyzing and reporting data breaches; Managing fraud cases involving payment misappropriation, locating and recovering funds; Development of a communications strategy and stakeholder management; Preparing reports to regulatory authorities; Managing risks relating to class actions following a confidentiality incident.

Maxime Audet, directeur de comptes spécialisé en risques cybernétiques, incarne l'expertise et la passion dans ce domaine en constante évolution. Diplômé en finance, il a entamé sa carrière il y a cinq ans dans le secteur de l'assurance. Depuis ses… Read moreRead less
Maxime Audet, directeur de comptes spécialisé en risques cybernétiques, incarne l'expertise et la passion dans ce domaine en constante évolution. Diplômé en finance, il a entamé sa carrière il y a cinq ans dans le secteur de l'assurance. Depuis ses débuts, il a arpenté avec détermination les échelons pour atteindre le poste de directeur de comptes spécialisés, se consacrant exclusivement à la protection contre les menaces cybernétiques. Sa fascination pour la cybersécurité ne se limite pas à une simple curiosité ; elle est la boussole qui guide chacune de ses actions professionnelles. Animé par cette passion, Maxime s'attèle à une recherche constante de solutions innovantes pour anticiper les menaces numériques émergentes. En tant que défenseur résolu de la sécurité informatique, Maxime s'engage fermement à protéger les entreprises contre les ravages des cyberattaques. Son travail acharné et son dévouement contribuent à façonner un paysage numérique plus sûr et plus résilient, où les entreprises peuvent prospérer en toute confiance.

As a recognized leader in the Canadian Cyber Insurance market, Miki joined Resilience in 2023 to launch the company’s Canadian operations. In his current role as Head of Underwriting, Canada, Miki leads the Canadian Underwriting team and works… Read moreRead less
As a recognized leader in the Canadian Cyber Insurance market, Miki joined Resilience in 2023 to launch the company’s Canadian operations. In his current role as Head of Underwriting, Canada, Miki leads the Canadian Underwriting team and works closely with capacity partners to establish regional strategies. Miki also collaborates with Resilience’s broker partners to support the Resilience Solution and make Canadian companies more Cyber resilient. Prior to joining Resilience, Miki held senior roles at other leading insurance providers where he helped launch local Canadian products and support the risk transfer needs of large and complex organizations.


