À propos de cette session
Un panel de cinq personnes sur la cyberassurance, animé par Patrick Cruikshank de Northbridge Insurance, retrace ce qui se passe lorsqu'un incident technique devient une réclamation. Herbert Stapleton, ancien cadre du FBI devenu coach en gestion de sinistres, insiste sur la préparation : rôles décisionnels clairs, discipline dans l'application du plan de réponse et exercices de simulation réalistes. Julie Himo, associée chez Torys, explique pourquoi les avocats interviennent dès le premier jour, vu les courts délais de déclaration au Canada, la responsabilité liée au paiement d'une rançon et la nécessité de préserver le privilège. Pasha Ebrahimi, d'Equifax, décrit le volet humain d'une atteinte, le suivi de l'anxiété des victimes et du recours à la surveillance de crédit, et donne un exemple de vol d'identité synthétique réalisé en quelques jours. L'avocate Dany Guimond-Valcourt cite une forte hausse des incidents de confidentialité déclarés au Québec, un recours collectif en cours sur la réinitialisation de clés de voiture par IA, et une vidéo hypertruquée utilisée pour autoriser un virement frauduleux. Le panel débat aussi de qui doit être à la table pendant un incident, y compris les communications et le conflit d'intérêts potentiel du fournisseur TI touché, et conclut avec des conseils pratiques : nettoyer les données inutiles, retenir ses fournisseurs avant l'incident, et lire les sous-limites de sa police.
When the incident becomes a claim. Insurers, lawyers, and cyber experts share their perspectives on the evolving landscape of risks, coverage, and incident response. How can we better prepare, collaborate, and avoid unpleasant surprises when a cyberattack occurs?
À retenir
- Désigner à l'avance, dans le plan de réponse, un décideur et un responsable technique, et le répéter en exercice; un plan rangé dans un tiroir échoue quand les titulaires de ces rôles ont changé.
- Décider d'avance qui autorise le paiement d'une rançon et à partir de quel seuil, car conseils d'administration et direction peuvent diverger en plein incident, et les vérifications de sanctions transfrontalières s'appliquent toujours.
- Aviser l'assureur cyber dès la découverte d'une attaque par rançongiciel, même avant de tout savoir, pour mobiliser dès le départ les fournisseurs du panel et les conditions de couverture.
- Supprimer les données devenues inutiles avant qu'un incident survienne; des renseignements personnels qui dorment sur les serveurs sont l'une des plus grandes sources de mauvaises surprises lors d'une enquête.
- Comparer les sous-limites de sa police cyber à son risque réel, pas seulement le montant de couverture affiché, et la revoir après toute fusion ou restructuration.
Conférenciers

Herbert Stapleton is a partner at Dinsmore & Shohl, LLP in Cincinnati, Ohio, who focuses his practice on cybersecurity, data privacy, and complex investigations. Herb is a nationally recognized cybersecurity executive and former senior leader with… Lire la suiteRéduire
Herbert Stapleton is a partner at Dinsmore & Shohl, LLP in Cincinnati, Ohio, who focuses his practice on cybersecurity, data privacy, and complex investigations. Herb is a nationally recognized cybersecurity executive and former senior leader with the Federal Bureau of Investigation (FBI), who brings over 20 years of federal law enforcement and cyber operations experience to his legal practice. As a seasoned investigator and executive, Herb offers clients unparalleled insight into the rapidly changing landscape of cybersecurity, data privacy, and complex government investigations.
Prior to joining Dinsmore, Herb served as Special Agent in Charge of the FBI’s Indianapolis Field Office, where he led high-impact investigations that spanned cybercrime, national security, and public corruption and previously served in senior executive roles at FBI headquarters in Washington, D.C., overseeing global cyber investigations.

Julie Himo advises national and international clients on privacy and cyber security related matters. She acts as breach coach and has been appointed on numerous insurers panels. She has handled a large number of data and security breaches of all… Lire la suiteRéduire
Julie Himo advises national and international clients on privacy and cyber security related matters. She acts as breach coach and has been appointed on numerous insurers panels. She has handled a large number of data and security breaches of all types, many with international impacts and has coordinated notification and regulatory filing efforts in multiple countries. She also conducts strategic risk and privacy impact assessments and advises on a wide variety of Canadian privacy issues, including in the context of class actions. Ms Himo is also a seasoned commercial litigator, having handled over the past 25 years numerous commercial disputes in a wide variety of fields, including bankruptcy and insolvency and corporate and securities matters, commercial fraud, asset tracing and shareholder disputes. She also has considerable experience in extraordinary remedies such as seizures and injunctions.

As Managing Director of Breach Services Canada at Equifax, Pasha Ebrahimi leads the development and execution of breach response strategies. He assists organizations in safeguarding their reputation and maintaining customer trust by ensuring… Lire la suiteRéduire
As Managing Director of Breach Services Canada at Equifax, Pasha Ebrahimi leads the development and execution of breach response strategies. He assists organizations in safeguarding their reputation and maintaining customer trust by ensuring business continuity after a cyber incident. By collaborating with insurers, legal counsel, and incident response partners, Pasha facilitates essential services such as customer notification, call centre support, and identity protection. His expertise helps clients navigate the complexities of data breaches from preparation to recovery, while prioritizing the well-being of affected individuals.

Dany Guimond-Valcourt is a technology, cybersecurity and privacy lawyer at LCM Avocats in Montréal, known for translating legal frameworks into clear, practical operational guidance. She advises organizations ranging from SMEs to critical… Lire la suiteRéduire
Dany Guimond-Valcourt is a technology, cybersecurity and privacy lawyer at LCM Avocats in Montréal, known for translating legal frameworks into clear, practical operational guidance.
She advises organizations ranging from SMEs to critical infrastructure operators across the financial services, healthcare, energy, technology and professional services sectors. As breach counsel, she leads crisis management efforts following privacy and cybersecurity incidents, coordinating forensic experts, insurers, regulators and law enforcement across jurisdictions, structuring communications, and driving post-incident improvements to practices and controls.
Her practice includes technology due diligence in M&A transactions, federal and provincial privacy compliance, cross-border data transfers, AI and biometrics governance, and cyber insurance.
Before joining LCM, she held cybersecurity, data protection and risk governance roles at Desjardins Group, CDPQ and Wolters Kluwer—operational experience that distinguishes her legal practice.
She teaches in graduate programs in computer engineering and in business law and enterprise risk management at Polytechnique Montréal and Université de Sherbrooke. She chairs the Barreau de Montréal's Technology Integration Committee, serves on the executive committee of the Canadian Bar Association's Information Technology, Telecommunications and Intellectual Property Law Section (Québec Branch), and is a member of The Advocates' Society's National AI Task Force.

Patrick Cruikshank is the Director of Executive & Professional Solutions at Northbridge Insurance, where he oversees the national strategy for professional liability, management liability, and cyber insurance products. With more than 23 years of… Lire la suiteRéduire
Patrick Cruikshank is the Director of Executive & Professional Solutions at Northbridge Insurance, where he oversees the national strategy for professional liability, management liability, and cyber insurance products. With more than 23 years of experience in commercial and specialty insurance, he has extensive expertise in underwriting, broker engagement, product development, and emerging risk management. Patrick works closely with organizations across Canada to develop solutions for complex and evolving exposures, with a particular focus on cyber and executive risk.
In addition to his role at Northbridge, Patrick has been an active participant in the Insurance Bureau of Canada's Cyber Working Group for many years, contributing to industry initiatives focused on cyber market development, cyber resilience, public policy, and regulatory harmonization. He is a recognized industry leader who brings a practical, collaborative perspective to discussions on risk, resilience, and the evolving cyber threat landscape.





