The Chronicles of Cyber Insurance: Separating Fact from Fiction in Cyber Risk
Download resourcesAbout this session
Kelly McGuinness of CFC, Canada's largest cyber insurer, sets out to debunk misconceptions about cyber insurance from the underwriting side. She admits the industry often fixates on checklist questions such as end-of-life software or MFA coverage instead of understanding real cyber hygiene, and that policy wording varies so much between carriers that comparing coverage is genuinely hard. She traces the market from early third-party-liability buyers, through the COVID-driven hard market when ransomware losses spiked, to today's broader, more competitively priced coverage. She breaks down first-party coverage (incident costs, business interruption, ransom payment and negotiation, funds-transfer fraud) and third-party coverage (privacy liability, regulatory fines, PCI DSS penalties, media liability), and shares CFC's own claims data: theft of funds is the most frequent claim type, while ransomware, though less frequent, causes the most severe losses. She describes CFC's proactive scanning service, which flagged a Commvault zero-day to affected clients before it was exploited, and closes on the gap between the 61 percent of Canadian SMEs that have faced an attack and the roughly 10 percent that carry standalone cyber coverage, taking audience questions on underwriting verification, pricing and how CFC works exclusively through brokers.
Cyber insurance is often misunderstood. Some believe it covers everything, while others view it as little more than a compliance exercise. Drawing on real-world cyber incidents and claims experience, this session will debunk common myths surrounding cyber insurance, explore how insurers assess cyber risk, and reveal what actually happens when organizations experience a cyber event. Attendees will gain practical insights into how cyber insurance and cybersecurity work together to improve organizational resilience.
Key takeaways
- Push your insurer or broker for an onboarding call and ask who your claims contact will be before you ever file a claim, not during the incident.
- Know the difference between a bolt-on cyber endorsement on a property and casualty package and a standalone cyber policy; coverage depth and exclusions differ substantially.
- Budget for both first-party costs (forensics, notification, business interruption, ransom negotiation) and third-party exposure (privacy liability, regulatory fines, PCI DSS penalties) when sizing coverage.
- Fix flagged public-facing vulnerabilities quickly if your insurer's proactive scanning team contacts you; the same scanning caught a Commvault zero-day before it was exploited against clients.
- Do not assume company size protects you: roughly 61 percent of Canadian SMEs have already faced a cyberattack, while only about 10 percent hold standalone cyber insurance.
Speakers

Kelly McGuinness is the National Development Leader for Cyber and Tech at CFC Canada, bringing more than 15 years of experience in the insurance industry. Throughout her career, Kelly has specialized in cyber and tech insurance, holding a variety of… Read moreRead less
Kelly McGuinness is the National Development Leader for Cyber and Tech at CFC Canada, bringing more than 15 years of experience in the insurance industry. Throughout her career, Kelly has specialized in cyber and tech insurance, holding a variety of underwriting and leadership roles while building and leading high-performing teams.
In her current role, Kelly is responsible for driving the growth and development of CFC's cyber and tech business across Canada. She works closely with brokers and industry partners to increase awareness, education, and understanding of cyber risk, helping organizations navigate an increasingly complex threat landscape.
Kelly holds a Bachelor of Arts in Politics and English, as well as a master’s degree in criminology from University College Cork in Ireland. Combining her academic background with deep industry expertise, she is a passionate advocate for expanding cyber insurance adoption in Canada and is committed to improving cyber resilience through education, engagement, and innovation.

