AI-generated summary
· Application · 08/10/2026
NS Power files rebuttal evidence and refiled incident report in M12600 cybersecurity accountability proceeding, defending its ransomware response as meeting or exceeding industry standards
AI summary
- NS Power's rebuttal evidence (N-17), now available, responds point-by-point to 13 recommendations from Consumer Advocate consultant InterGroup and 8 unreasonableness findings from Board Counsel consultant INQ Law, arguing its response to the April 25, 2025 Cybersecurity ransomware attack — which affected approximately 915,000 current and former customers — was reasonable and in many respects exceeded industry norms
- NS Power retained U.S. data privacy expert Jena Valdetero of Greenberg Traurig, who concluded that direct notification of 277,000 current customers within 18 days of discovering the attack placed NS Power's response 'in the top three percent' of companies addressing similarly significant incidents, and that the five-year Customer Service credit monitoring offer via TransUnion went well beyond the two-year Canadian industry standard
- On Billing Procedures, NS Power argues InterGroup failed to conduct any accuracy analysis of estimated bills issued during the recovery period, noting that overbilling or overpayment scenarios represented less than 1% of bills post-recovery, while acknowledging the CIS replacement project (targeted for mid-2029) will incorporate improved estimation logic
- NS Power pushes back on several InterGroup and INQ recommendations — including blanket notification to all customers, cost reimbursement for alternative credit monitoring services, and third-party privacy audits every three years — arguing these either conflict with Regulatory Compliance under PIPEDA's risk-based framework or are duplicative of commitments already made to the Office of the Privacy Commissioner under a March 2026 Compliance Letter
- The refiled Formal Incident Report (N-16), now available in redacted form, provides the underlying factual record including the attack timeline (unauthorized access began around March 19, 2025; discovered April 25, 2025), the scope of compromised data including names, SINs, bank account numbers and billing history, and NS Power's enhanced Cybersecurity governance program including a new dedicated Privacy Officer role, elevated Privacy Committee, and deployment of Microsoft Purview and DLP monitoring tools
Disclaimer: This summary was generated by AI from the filings it describes. We take care to make it accurate, but errors are possible - and it isn't advice. Only the filings themselves are the record: if you're relying on something here, confirm it against the source documents or the Nova Scotia Energy Board's own record. Full disclaimer →
What was filed
Documents filed on this day
- N-16 NSPI Refiled Formal Incident Report - Redacted (filed in M12273 as N-5 on April 27, 2026)
- N-16(BC) NSPI Refiled Formal Incident Report - Board Confidential (filed in M12273 as N-5(BC) on April 27, 2026) Board Only
- N-17 NS Power Rebuttal Evidence - Redacted
- N-17(C) NS Power Rebuttal Evidence - Confidential
- N-17(C)-(ii) Attachment 03 - 2018 Customer Personal Information Inventory - Confidential