About this session
Anne-Marie Faber steps in as last-minute moderator for a panel of four breach-coach lawyers (Laure Bonnave, Julie Himo, Dany Guimond-Valcourt and Roxane Caron) on incident response and cyber insurance. They describe the breach coach as an orchestrator who assembles the response team (forensics, ransom negotiator, PR, call centres), builds trust with panicked clients in the first 72 hours, and structures the investigation under attorney-client privilege, while stressing that the privilege is not automatic just because a lawyer is in the room. They frame ransom payment as a risk-management decision, not a principled yes or no, constrained in Canada by anti-terrorism-financing and anti-money-laundering law, and note ransom negotiators can often cut a demand by 20 to 60 percent. Insurers are described as strategic partners who must be notified early, sometimes from a pre-approved vendor panel, though the breach coach represents the organization, not the insurer, even when introduced by one. They close with practical advice: test incident response plans and data retention policies before a crisis, revisit under-sized cyber insurance limits, and maintain offline, diversified backups, which the panel credits for the sharp drop in ransom payments over the past decade.
Key takeaways
- Notify your cyber insurer as early as possible; late notice can limit or void coverage, and many policies require choosing responders from a pre-approved vendor panel.
- Do not treat lawyer presence on a call as automatic privilege protection; route forensic firm engagement and reports through counsel and be prepared for the privilege claim to be contested.
- Decide on ransom payment as a case-by-case risk assessment (recovery viability, business continuity, sanctioned-group screening), not a blanket policy set in the moment of crisis.
- Test your incident response plan and data retention/flow mapping before an incident; unstructured copies of encrypted data elsewhere in the network can complicate both investigation and notification.
- Maintain offline, diversified backups (tape, disconnected cloud copies); the panel credits improved backup maturity for the drop in ransom payments from roughly 70-75 percent of cases a decade ago to far fewer today.
Speakers

As the Chief Marketing Officer at GoSecure, a leading provider of cybersecurity solutions, I leverage my 15+ years of experience in the IT industry and my MBA degree to drive the company's growth and differentiation in the market. I have a proven… Read moreRead less
As the Chief Marketing Officer at GoSecure, a leading provider of cybersecurity solutions, I leverage my 15+ years of experience in the IT industry and my MBA degree to drive the company's growth and differentiation in the market. I have a proven track record of helping various companies evolve into market leaders with double digit revenue growth, thanks to my strategic planning and business strategy skills.
I believe in the importance of a close partnership with all sales channels, direct and indirect, and the ability to think creatively and differently than competitors. I also lead a talented and diverse team of marketing professionals who share my passion and vision for security innovation and customer success.

As a Senior Counsel at Clyde & Co Canada LLP, Laure Bonnave acts as a breach coach in cases involving cybersecurity incidents, including data or privacy breaches. As part of her practice, she has advised clients on multiple cyber incidents, both… Read moreRead less
As a Senior Counsel at Clyde & Co Canada LLP, Laure Bonnave acts as a breach coach in cases involving cybersecurity incidents, including data or privacy breaches. As part of her practice, she has advised clients on multiple cyber incidents, both locally and internationally. In her role, Laure regularly offers her clients expertise in cyber incident management, which includes: Overall incident response management and coordination with service providers; Responding to ransomware attacks and data recovery; Analyzing and reporting data breaches; Managing fraud cases involving payment misappropriation, locating and recovering funds; Development of a communications strategy and stakeholder management; Preparing reports to regulatory authorities; Managing risks relating to class actions following a confidentiality incident.

Julie Himo advises national and international clients on privacy and cyber security related matters. She acts as breach coach and has been appointed on numerous insurers panels. She has handled a large number of data and security breaches of all… Read moreRead less
Julie Himo advises national and international clients on privacy and cyber security related matters. She acts as breach coach and has been appointed on numerous insurers panels. She has handled a large number of data and security breaches of all types, many with international impacts and has coordinated notification and regulatory filing efforts in multiple countries. She also conducts strategic risk and privacy impact assessments and advises on a wide variety of Canadian privacy issues, including in the context of class actions. Ms Himo is also a seasoned commercial litigator, having handled over the past 25 years numerous commercial disputes in a wide variety of fields, including bankruptcy and insolvency and corporate and securities matters, commercial fraud, asset tracing and shareholder disputes. She also has considerable experience in extraordinary remedies such as seizures and injunctions.




