
Ady Sharma
Senior Vice-President & Cyber Solutions Co-Leader,
Aon Canada
With cyber threats becoming increasingly sophisticated and persistent, today’s business leaders need to understand, manage, quantify, and insure against the evolving risks.
Organizations of all shapes and sizes around the world are navigating increasingly complex cyber risks. Cyberattacks and data breaches were ranked as the number one risk for the third consecutive time in Aon’s 2025 Global Risk Management Survey, which gathered insights from nearly 3,000 leaders in over 60 countries.
“The cyber risk landscape is evolving very quickly now with the introduction of AI, deepfakes, and other technological advancements,” says Ady Sharma, Senior Vice-President and Cyber Solutions Co-Leader at Aon Canada, a leading global professional services firm focusing on risk and insurance. “We’re seeing threat actors becoming more sophisticated and more persistent.”
Cyberattacks can severely disrupt operations, lead to theft of highly sensitive information and cause significant financial and reputational damage to a business. Given this environment, Sharma says it’s important for organizations to assess their cyber risk, quantify their cyber exposure, and purchase cyber insurance protection thereafter.
Assessing and quantifying your cyber exposure
Assessing an organization’s cyber risk involves understanding what information it holds, how sensitive that information is, and what protections surround it.
“Several organizations continue to buy insurance based on a hunch or what their peers are buying. While benchmarking against your peers is a good start, it can never give you the most accurate picture,” says Sharma.
Risk quantification models help organizations assess the probability and potential financial consequences of different cyber incidents. The analysis can help business leaders make better decisions about how much to invest in cybersecurity, the type and amount of insurance coverage to purchase, and how to manage cyber risk more broadly.
“This is how we at Aon help our clients make risk transfer decisions: through a customized cyber assessment followed by risk quantification modeling to ensure that we’re equipping organizations to be adequately insured,” says Sharma.
Effective, affordable, and accessible cyber insurance
Security controls and cyber insurance should go hand in hand as part of a broader risk management strategy, with Sharma stressing that organizations shouldn’t rely exclusively on one or the other. “Adequate risk management has to be a healthy balance of risk control and risk transfer,” he says.
Cyber insurance coverage is specifically designed to not only provide financial protection from expenses that may be incurred as a result of an incident, but also the infrastructure needed to effectively respond and recover. Sharma explains how critical that support is given the rising complexity of incidents, and this includes access to a range of experts and service providers which can be extremely expensive in the absence of insurance.
Fortunately, cyber insurance in Canada has become more affordable and accessible in recent years. “The cyber insurance market is ultra-competitive, which has brought prices down despite a consistently heightening risk environment,” says Sharma.
Underwriting has also become more streamlined, and smaller businesses may be able to obtain coverage while providing only minimal information.
To learn more about Aon’s cyber risk and insurance capabilities, visit aon.com/en/capabilities/cyber-resilience or email [email protected] with any inquiries.
