About this session
A five-person panel on cyber insurance, moderated by Northbridge Insurance's Patrick Cruikshank, traces what happens once a technical incident becomes a claim. FBI veteran turned breach coach Herbert Stapleton stresses preparation: clear decision-making roles, disciplined adherence to the incident response plan, and realistic tabletop exercises. Torys partner Julie Himo explains why lawyers get involved from day one, given Canada's short notification deadlines, ransom-payment liability and the need to protect privilege. Equifax's Pasha Ebrahimi describes the human side of a breach, tracking anxious victims' calls and credit-monitoring uptake, and cites a synthetic identity created and used within days of a breach. Lawyer Dany Guimond-Valcourt cites a large rise in reported Quebec privacy incidents, a pending Quebec class action over AI-enabled car key resets, and a deepfake video used to authorize a fraudulent wire transfer. The panel also debates who belongs at the table during a live incident, including communications staff and the potential conflict of interest of a breached organization's own IT vendor, and closes with practical advice: clean up unneeded data, retain vendors before an incident happens, and actually read your policy's sub-limits.
When the incident becomes a claim. Insurers, lawyers, and cyber experts share their perspectives on the evolving landscape of risks, coverage, and incident response. How can we better prepare, collaborate, and avoid unpleasant surprises when a cyberattack occurs?
Key takeaways
- Name a decision-maker and a technical lead in the incident response plan before an incident happens, and rehearse it; plans left in a drawer fail once the people in those roles have changed.
- Decide in advance who authorizes a ransom payment and at what dollar threshold, since boards and executives can disagree mid-incident and cross-border sanctions checks still apply.
- Notify the cyber insurer as soon as a ransomware attack is discovered, even before all the facts are known, so panel vendors and coverage terms are engaged from the start.
- Delete data you no longer need before an incident happens; unneeded personal information sitting on servers is one of the biggest sources of unpleasant surprises during a breach investigation.
- Read the sub-limits in your cyber policy against your actual risk, not just the headline coverage amount, and revisit it after any merger or corporate restructuring.
Speakers

Herbert Stapleton is a partner at Dinsmore & Shohl, LLP in Cincinnati, Ohio, who focuses his practice on cybersecurity, data privacy, and complex investigations. Herb is a nationally recognized cybersecurity executive and former senior leader with… Read moreRead less
Herbert Stapleton is a partner at Dinsmore & Shohl, LLP in Cincinnati, Ohio, who focuses his practice on cybersecurity, data privacy, and complex investigations. Herb is a nationally recognized cybersecurity executive and former senior leader with the Federal Bureau of Investigation (FBI), who brings over 20 years of federal law enforcement and cyber operations experience to his legal practice. As a seasoned investigator and executive, Herb offers clients unparalleled insight into the rapidly changing landscape of cybersecurity, data privacy, and complex government investigations.
Prior to joining Dinsmore, Herb served as Special Agent in Charge of the FBI’s Indianapolis Field Office, where he led high-impact investigations that spanned cybercrime, national security, and public corruption and previously served in senior executive roles at FBI headquarters in Washington, D.C., overseeing global cyber investigations.

Julie Himo advises national and international clients on privacy and cyber security related matters. She acts as breach coach and has been appointed on numerous insurers panels. She has handled a large number of data and security breaches of all… Read moreRead less
Julie Himo advises national and international clients on privacy and cyber security related matters. She acts as breach coach and has been appointed on numerous insurers panels. She has handled a large number of data and security breaches of all types, many with international impacts and has coordinated notification and regulatory filing efforts in multiple countries. She also conducts strategic risk and privacy impact assessments and advises on a wide variety of Canadian privacy issues, including in the context of class actions. Ms Himo is also a seasoned commercial litigator, having handled over the past 25 years numerous commercial disputes in a wide variety of fields, including bankruptcy and insolvency and corporate and securities matters, commercial fraud, asset tracing and shareholder disputes. She also has considerable experience in extraordinary remedies such as seizures and injunctions.

As Managing Director of Breach Services Canada at Equifax, Pasha Ebrahimi leads the development and execution of breach response strategies. He assists organizations in safeguarding their reputation and maintaining customer trust by ensuring… Read moreRead less
As Managing Director of Breach Services Canada at Equifax, Pasha Ebrahimi leads the development and execution of breach response strategies. He assists organizations in safeguarding their reputation and maintaining customer trust by ensuring business continuity after a cyber incident. By collaborating with insurers, legal counsel, and incident response partners, Pasha facilitates essential services such as customer notification, call centre support, and identity protection. His expertise helps clients navigate the complexities of data breaches from preparation to recovery, while prioritizing the well-being of affected individuals.

Dany Guimond-Valcourt is a technology, cybersecurity and privacy lawyer at LCM Avocats in Montréal, known for translating legal frameworks into clear, practical operational guidance. She advises organizations ranging from SMEs to critical… Read moreRead less
Dany Guimond-Valcourt is a technology, cybersecurity and privacy lawyer at LCM Avocats in Montréal, known for translating legal frameworks into clear, practical operational guidance.
She advises organizations ranging from SMEs to critical infrastructure operators across the financial services, healthcare, energy, technology and professional services sectors. As breach counsel, she leads crisis management efforts following privacy and cybersecurity incidents, coordinating forensic experts, insurers, regulators and law enforcement across jurisdictions, structuring communications, and driving post-incident improvements to practices and controls.
Her practice includes technology due diligence in M&A transactions, federal and provincial privacy compliance, cross-border data transfers, AI and biometrics governance, and cyber insurance.
Before joining LCM, she held cybersecurity, data protection and risk governance roles at Desjardins Group, CDPQ and Wolters Kluwer—operational experience that distinguishes her legal practice.
She teaches in graduate programs in computer engineering and in business law and enterprise risk management at Polytechnique Montréal and Université de Sherbrooke. She chairs the Barreau de Montréal's Technology Integration Committee, serves on the executive committee of the Canadian Bar Association's Information Technology, Telecommunications and Intellectual Property Law Section (Québec Branch), and is a member of The Advocates' Society's National AI Task Force.

Patrick Cruikshank is the Director of Executive & Professional Solutions at Northbridge Insurance, where he oversees the national strategy for professional liability, management liability, and cyber insurance products. With more than 23 years of… Read moreRead less
Patrick Cruikshank is the Director of Executive & Professional Solutions at Northbridge Insurance, where he oversees the national strategy for professional liability, management liability, and cyber insurance products. With more than 23 years of experience in commercial and specialty insurance, he has extensive expertise in underwriting, broker engagement, product development, and emerging risk management. Patrick works closely with organizations across Canada to develop solutions for complex and evolving exposures, with a particular focus on cyber and executive risk.
In addition to his role at Northbridge, Patrick has been an active participant in the Insurance Bureau of Canada's Cyber Working Group for many years, contributing to industry initiatives focused on cyber market development, cyber resilience, public policy, and regulatory harmonization. He is a recognized industry leader who brings a practical, collaborative perspective to discussions on risk, resilience, and the evolving cyber threat landscape.





