
- Event
- Coalition Canada Broker Summit (the first in Canada)
- Venue
- Hockey Hall of Fame, Toronto
- When
- Tuesday, September 15, 2026, afternoon
- Host
- Coalition, Inc., with sponsors Allianz, HDI, Arch and DWF
Key takeaways
- Coalition says cyber risk changes too fast for a once-a-year look, so it pairs insurance with year-round scanning, alerts and response. It calls this “active insurance.”
- Its Active Cyber Policy is shorter and easier to read. It names AI-driven attacks and deepfake scams in the wording, so brokers do not have to argue about whether they are covered.
- Speed decides outcomes. Clients who report a misdirected payment within 72 hours have the best chance of getting the money back, and the policy rewards fast reporting.
- The claims team said email-driven fraud, not ransomware, is where the growth is, and AI is making small scams bigger and faster.
- The simplest security step is also the most powerful: log in to the security platform, invite the right people, and answer the alerts.
How did Coalition build its Canadian business?
George Bozanin, Coalition’s head of Canada, opened the afternoon with a hockey line that fit the room. When Coalition launched in Canada in May 2020, he said, the business was “a blank sheet of ice.” There were no broker contracts, no premium and very little brand recognition. Today Coalition works with brokers in every province and territory, from national firms to small independent shops.
He also wanted brokers to understand how the company is built. Coalition operates as a managing general agent with delegated authority, but it also has its own admitted carrier, Coalition Insurance Company, so it has its own capital at risk. One of its mottos, he said, is that it is only one percent of the way there.
What is active cyber insurance?
Michael Phillips, head of global cyber portfolio underwriting, explained the thinking. Most insurance is priced at one point in time and pays out after the loss. Cyber risk does not sit still. Technology changes, criminals change their tactics, and privacy rules keep moving. A policy checked once a year can leave gaps nobody sees.
He compared it to crashing a new car. With most insurance, you call the tow truck, find the mechanic and sort it out yourself, then send the bill and hope. Active insurance means someone is on your side from the first minute, helping you respond and get back to work. He also pointed out that risk managers, IT heads and security chiefs often think about cyber risk in very different ways, and that bringing them together is part of the job.
What changed in Coalition’s Active Cyber Policy?
Thomas Orofino, Coalition’s director of cyber product counsel, walked brokers through the policy. He started his career as an underwriter before becoming a lawyer, and it showed in how practical his points were.
Easier to read
The document is shorter, has links to each section, and folds many old endorsements into the base form. Brokers should not have to flip back and forth to see if the right endorsement is attached.
AI named in the wording
The policy explicitly covers AI-driven security failures and deepfake-enabled social engineering. If a criminal uses a deepfake of an executive to trick staff into wiring money, the wording says it is covered.
Rewards for speed
When a client reports a funds transfer fraud within 72 hours, the retention is reduced. The first calls to the hotline, legal help and incident response come with no retention and no erosion of the limit.
He also described a deepfake response cover built into the policy. It pays for a forensic expert to confirm a deepfake, legal work to get it taken down, and crisis communications support to protect the client’s reputation.
Why do so many small businesses still go without cyber insurance?
Sarah Woods, a product leader at Coalition, told the story of Bob, the owner of a coffee shop in her small town. Bob was sure he did not need cyber insurance. He was in a people business, not tech. He only used outside software. Nobody would bother hacking a small shop like his. After six months of friendly pressure, he finally agreed to call his broker, mostly so she would stop talking about it.
The point was serious. Coalition’s research found that only about one in five small businesses carries cyber insurance. Brokers told her they hear the same excuses Bob gave, but unlike her, they have minutes, not months, to make the case. Cyber specialists know the product deeply, while frontline brokers juggle many lines and may not feel confident. So her team builds tools to close that gap: very short applications for smaller clients, peer benchmarks, a suggested limit, and a client-ready presentation made for every quote. Their research found that the best way to get a client to say yes is to present one recommended quote, not a long menu.
She ended with a second story. On her way to Toronto, a panicked local business owner called her after being hacked. Three hours later the same woman sounded calm. She had cyber insurance and a team of experts in her corner. That change in her voice, Woods said, is what every business owner deserves.
What do cyber claims look like in Canada right now?
Raffaella Rullo, counsel at DWF, one of Coalition’s panel law firms, introduced the claims team. A cyber incident, she said, is often one of the worst days of a client’s life, and what makes the difference is having the right team, people who pick up the phone late on a Friday or on Christmas Eve.
Anne Juntunen, senior claims manager, said Coalition has built its Canadian claims team so that Canadian claims are handled in Canada, by people who understand the client’s world, with licences across every province and territory and French-language service. Her headline was that ransomware gets the attention, but the growth is in email-driven fraud: funds transfer fraud and business email compromise. In some cases criminals are not just sending fake invoices. They get into the client’s online banking and move money out in many small amounts, which makes it harder to trace.
If you tell us within 72 hours, we have a pretty good shot at getting that money back.
Anne Juntunen, Coalition, on funds transfer fraud (as told to the room)
She shared one Canadian case where a policyholder lost nine million dollars after a criminal got into its banking portal. Working through the night with breach counsel at DWF, the team went to court, froze the funds and traced what had moved through a crypto exchange. All nine million dollars was recovered within 13 days, at a cost of under twenty thousand dollars.
Jodi Buck, claims manager, and Eric Griffi, Canada claims lead, then showed how AI is supercharging scams. In one case, criminals got hold of a client’s contact list and used an automated script to message the whole list in a staff member’s name. In another, a criminal used an AI-generated video call and an AI-written legal document to impersonate a senior executive and trigger a payment overseas. The lesson for brokers was clear: these attacks look routine until it is too late, so clients should call the moment something feels wrong.
What is the simplest way for clients to reduce cyber risk?
Jake Reynolds, head of engineering and product for Coalition Security, spent his early career breaking into large systems to test them, and now defends businesses of every size. He said the cyber security industry loves complex dashboards, but complexity is where things go wrong. His team built the simplest product it could, focused on the few signals that actually lead to claims, with alerts written in one plain sentence.
He told brokers that policyholders who log in to Coalition Control and act on it are four times less likely to have a claim. He also shared a painful example: a client ignored an alert about an exposed system a month before it was breached, because the only person who had ever logged in was the executive who signed the policy. His advice for every client came down to three steps:
Log in
Open the security platform that comes with the policy.
Invite the right people
Add the IT and security team, not just the person who signed.
Answer the alerts
When an email arrives, act on it. That is where claims are prevented.
Why it matters for brokers
The summit’s message was that cyber insurance works best when it is simple to explain and fast to act on. Plain wording helps brokers sell it. Quick reporting helps claims teams recover money. A few simple habits help clients avoid the claim in the first place. People do not just buy a policy. They buy trust, and plain words are how it is earned.
The AI wording in the Active Cyber Policy also connects to an argument in ZERO LEGACY, from Zero Legacy Press. Its glossary, on page 162, describes “silent AI” as unpriced AI exposure hiding inside older policies, “the direct successor to the silent-cyber problem of the 2010s.” The book’s answer is the same move Coalition has made: “Naming the peril and moving it to affirmative, standalone cover is itself an act of governance.”
Who spoke at the summit
- George Bozanin, Head of Canada, Coalition
- Joel Lauzon, Business Development, Coalition (host)
- Michael Phillips, Head of Global Cyber Portfolio Underwriting, Coalition
- Thomas R. Orofino, Director, Cyber Product Counsel, Coalition
- Sarah Woods, Product Management Leader, Coalition
- Raffaella Rullo, Counsel, DWF
- Anne Juntunen, Senior Manager, Claims, Coalition
- Eric Griffi, Canada Claims Lead, Coalition
- Jodi Buck, Claims Manager, Coalition
- Jake Reynolds, Head of Engineering and Product, Coalition Security
