Home M12600 Digest
AI-generated summary · Application · 07/08/2026

Consumer Advocate filed four Information Requests to Board Counsel Consultant INQ Law/Consulting probing Nova Scotia Power's cybersecurity incident response, personal information governance, and remedial adequacy

M12600 · Nova Scotia Power - Cybersecurity Accountability IN THE MATTER OF AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED’s collection and retention of customer information, customer service and communications, billing processes and regulatory matters
AI summary
  • The Consumer Advocate (David J. Roberts, Pink Larkin) filed IR-1 through IR-4 on July 8, 2026 to INQ Law/Consulting (William Mahody, KC, Washington & Mahody) in NSEB Matter M12600, an inquiry into the impact of a cyber incident on Nova Scotia Power Incorporated customer data, billing, and regulatory matters, with responses due July 29, 2026.
  • IR-1 targets the adequacy of Nova Scotia Power's Personal Information Inventory (Report para. 13, p. 6), including industry standards, how a well-structured inventory would have identified exposed data points, and conclusions drawn from NSPI's admission that it "does not know and will never know" which specific data points were compromised for each affected customer.
  • IR-2 asks INQ Law/Consulting to explain the governance rationale for periodic audits of internal access to personal information (Report para. 31, p. 9), framing it as a commonly expected Cybersecurity privacy-management practice.
  • IR-3 probes the basis for INQ Law/Consulting's opinion (Report para. 89, p. 21) that two years of credit monitoring was insufficient but five years was reasonable given the indefinite, non-changeable nature of Social Insurance Numbers; the CA requests all best practices, precedents, legal or regulatory standards, and references relied upon to assess the five-year offer.
  • IR-4 asks INQ Law/Consulting to rank, by significance, which of the 8 actions (out of 18 reviewed) identified in Report para. 106, p. 26 as failing best practices were most consequential both from the perspective of reasonable customer expectations and in terms of failing to limit the impact of the Cybersecurity attack on customers.

Disclaimer: This summary was generated by AI from the filings it describes. We take care to make it accurate, but errors are possible - and it isn't advice. Only the filings themselves are the record: if you're relying on something here, confirm it against the source documents or the Nova Scotia Energy Board's own record. Full disclaimer →

What was filed

Documents filed on this day

  • 102676 CA (INQ Law/Consulting) IR-1 to IR-4 other_documents