Topic/Matter Intersection

Topic:"Compliance Legislation" in M12273

Matter: Board Inquiry into Nova Scotia Power's Cybersecurity Incident
36 passages 13 documents

Compliance Legislation across all matters →

N-1Letters of Comment - Redacted 9 passages
Section 2
ficer of the Province of Nova Scotia Tim Houston acting as President of the Province of Nova Scotia Becky Druhan acting as Minister of Justice and Attorney General for the Province of Nova Scotia Please find attached an Administrative Dema...

AI summary An administrative demand for structural redress is filed against Nova Scotia Power (NS Power) for using unconscionable contracting mechanisms and the Nova Scotia Energy and Regulatory Boards Tribunal (NSERBT) for governance failures. The claim cites unlawful contract formation under Regulation 2.2, NSERBT’s procedural inaction, and systemic administrative failure confirmed by an identity breach. The petitioner requests formal review and accountability from the Executive Council Office.

Section 4
I submit this demand in good faith, not as a threat or adversarial challenge, but as a necessary act of civic accountability in response to structural conditions that have proven materially unsafe. Summary of Structural Breakdown 1. Contra...

AI summary The submitter challenges NS Power's use of deemed contracts under Regulation 2.2, arguing they lack proper consent, jurisdiction, and transparency. The NSERBT upheld these contracts despite acknowledging regulatory shortcomings, citing passive access as lawful consent, which conflicts with Canadian legal standards of equity and informed consent.

Section 20
Public Utility is clearly legally obliged to action to meet Federal standards without delay. Did they contact the utility? Yes How did the utility respond?

AI summary The text indicates a legal obligation on the public utility to comply with federal standards promptly. It also notes that contact was made with the utility, though the response is unspecified.

Section 52
From: Painting-MacLean, Kimberly To: Painting-MacLean, Kimberly Subject: FW: DRO 31 May re Sean Kelly re Data Breech Date: June 4, 2025 9:50:04 AM From: Sean Kelly Sent: June 3, 2025 10:27 PM To: [email protected] Cc: customer...

AI summary Sean Kelly criticizes the poor quality of regulations, arguing they favor the company and neglect customer privacy and data security. He questions the board's role in protecting Nova Scotians and highlights the lack of clarity on who is responsible for creating the regulations. He also references CMMC data security requirements and requests a meeting with the board.

Section 53
d how he/she may do that. I assume that the board can change the regulations? If so I request a meeting with the board to discuss why these regulations have little to no protections for its customers. I wish to escalate this to a higher au...

AI summary Sean Kelly is concerned about the lack of data protection in the board's regulations and has requested a meeting with the board. He also mentions the possibility of a class action lawsuit if the issue is not resolved. Don Farmer, the Dispute Resolution Officer, provided information on the current regulations and directed Sean Kelly to contact the Nova Scotia Energy Board for further assistance.

Section 59
Page 2 of 4 We are left unsure of what steps to take or what risks we truly face. 3. Inadequate Support NS Power offered 2 years of free credit monitoring via TransUnion of Canada Inc. While somewhat helpful, this offer falls short. Expert...

AI summary The customer expresses concerns about inadequate support following a data breach, questioning NS Power's data retention practices and requesting a meter inspection and billing review. They demand a full investigation into data security practices, compliance with privacy laws, and expanded protection for affected customers.

Section 66
Page 2 of 5 As a victim of the company’s security breach, and according to the Personal Information Protection and Electronic Documents Act (PIPEDA), I have a legal right to know the full scope of my personal data exposure. Only today, whe...

AI summary The complainant, a Nova Scotia Power customer, reports a data breach involving their SIN and requests detailed information about the breach, an explanation for the delay in notification, and comprehensive identity protection services. They criticize the lack of support and guidance provided by the company.

Section 75
m stemming from your mishandling of personal information and the prolonged disruption of service access.​ I expect a written response outlining next steps and your resolution plan. Sincerely, Danielle Kristine Maillet From: Painting-MacLea...

AI summary A customer of Nova Scotia Power reports being mishandled during a data breach, including not receiving any communication about the breach and being unable to speak with a supervisor. The customer is disabled and expresses concern about potential misuse of their personal information.

Section 79
ce my information is out there forever? I feel that I am left to worry for the rest of my life about what is happening to my information while Nova Scotia Power walks away from this after two years. I am not sure of what power you have ove...

AI summary The text includes a letter from Susanne Roy expressing concerns about Nova Scotia Power's handling of customer information and the lack of long-term credit monitoring support. It also includes email correspondence related to fraud protection and accountability and transparency, with a focus on organizational responsibility and communication.

N-2NSPI (NSEB) RIR 1 to 12 - Redacted 1 passage
Section 25
1 these community sessions have been held to date, and have assisted hundreds of customers 2 in signing up for the service. The NS Power website also has been updated with additional 3 tips and tools to help customers navigate support serv...

AI summary NS Power has conducted community sessions to support customer engagement, updated its website with tools, and implemented cybersecurity measures aligned with NIST and NERC standards. The company conducts regular training, audits, and compliance reviews to ensure robust cybersecurity practices.

N-3Incident Report - Redacted 4 passages
Section 6
me, start 4 date, finish date, and percentage completion. If no progress is made from one month 5 to the next, this should also be clearly indicated along with the reasons. 6 3. A separate chart is to be provided in the Incident Report whi...

AI summary The report outlines requirements for tracking progress on matters, including timelines and completion percentages. It references a Premier's letter requesting an investigation into NSP's billing practices, consumer protections, system restoration, financial relief, and potential penalties. Appendices include charts on system restoration and impacted matters, with vendor dues information expected by early February 2026.

Section 24
and IT 28 including, but not limited to, those mandated by the North American Electric Reliability 29 Corporation (NERC). NERC conducts extensive periodic audits (including security) of the 30 Company’s Energy Operations to ensure effectiv...

AI summary The text references North American Electric Reliability Corporation (NERC) audits of Nova Scotia Power's Energy Operations for compliance, including cybersecurity. A redacted 2025 cybersecurity incident report is mentioned, though details are confidential.

Section 68
1 8.2 Additional Security Audits, Policy Updates, and Employee Training 2 Section 4.1 addressed additional security audits, policy updates, and employee training as 3 summarized below. 4 5 Regarding security audits, NERC conducts extensive...

AI summary The document discusses NS Power's efforts to enhance cybersecurity through additional security audits, policy updates, and employee training. It mentions NERC audits, the OPC's ongoing investigation, and NS Power's alignment with the NIST Cybersecurity Framework. Employee training includes quarterly sessions and phishing simulations.

Section 98
be submitted to the NSEB in as shown below: ... Please refer to NS Power’s compliance filing in M11884 for further information." 2026. October 1: "In the NS-NB Reliability Intertie capital project proceeding (M12217), NS Power, on behalf o...

AI summary The document references compliance filings and a capital project proceeding related to the NS-NB Reliability Intertie. It mentions NS Power's submission of sensitivity analyses and cybersecurity implications discussed by Midgard, a consultant for Board counsel.

N-5Refiled Incident Report - NSPI - Redacted 4 passages
Section 6
, start 4 date, finish date, and percentage completion. If no progress is made from one month 5 to the next, this should also be clearly indicated along with the reasons. 6 3. A separate chart is to be provided in the Incident Report which...

AI summary The NSEB is required to report on progress tracking, including a Gantt chart of system restoration timelines and impacted Board matters. The Premier of Nova Scotia directed the NSEB to investigate NSP’s billing practices, consumer protections, system restoration timelines, financial relief options for customers, and potential financial penalties. The Company will provide vendor dues information by early February 2026.

Section 69
the concern and disruption it has caused customers. NS Power has never 25 intentionally overbilled its customers and has been steadfast and consistent in its commitment to 26 customers that it is actively trying to address the issues and,...

AI summary NS Power is addressing a cybersecurity incident that has caused customer concerns and disruptions. The company has committed to fixing any billing errors and is offering flexible payment options to affected customers. The NSEB has directed NS Power to address broader review outcomes from M12457, with responses provided in Appendix C.

Section 73
1 8.2 Additional Security Audits, Policy Updates, and Employee Training 2 3 Section 4.1 addressed additional security audits, policy updates, and employee training as 4 summarized below. 5 6 Regarding security audits, NERC conducts extensi...

AI summary The text discusses NS Power's efforts in cybersecurity, including security audits conducted by NERC, an ongoing investigation by the OPC, updates to cybersecurity policies informed by NIST, and mandatory employee training programs to ensure compliance and awareness.

Section 96
1 the NS Power website and information appeared as the top search result when customers 2 used search engines (i.e. Google) to find information about the Incident. Social media 3 accounts have been regularly monitored, and where appropriat...

AI summary NS Power informed customers about a cybersecurity incident, providing updates on the impact of the incident and encouraging vigilance against scams. Notifications were sent to affected customers, and third-party service providers were engaged to assist with the process.

100161NSPI Monthly Update Report #4 2 passages
Section 1
December 1, 2025 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power’s Cybersecurity Incident – Monthly Update 4 Dear Ms. Henwood: On July 14, 20...

AI summary The Nova Scotia Energy Board (NSEB) directed Nova Scotia Power (NS Power) to submit monthly updates on its response to a cybersecurity incident. NS Power is on track to deliver its Incident Report by December 31, 2025. The NSEB mandated resolving vendor dues, providing a Gantt chart in the report, and engaging MNP to investigate data handling practices.

Section 14
oint-Use Agreement Proceeding (M12149), June 16, 2025. 6 SBA IR-2, Joint-Use Agreement Proceeding (M12149), June 16, 2025. Page 8 of 9 December 1, 2025 C. Henwood Update on OPC Investigation As noted in previous reports, the Office of the...

AI summary The document updates on an ongoing OPC investigation into a cyber incident, noting Nova Scotia Power's cooperation. It mentions CEO Peter Gregg and Director Chris Lanteigne's testimony before the Standing Committee on Natural Resources and Economic Development, acknowledging customer concerns and commitment to resolution.

99375Board Letter re: Response to Monthly Update #1 and confidentiality 1 passage
Section 16
ever, NS Power consented to the Board disclosing Appendix B and the Confidential Submission to the Formal Intervenors in this matter, under the Board’s normal process for confidentiality undertakings. As the Board has previously stated in...

AI summary NS Power agreed to the Board disclosing Appendix B and a Confidential Submission to formal intervenors. The Board clarified it is an economic regulator, not a privacy authority, and emphasized its 'open courts' principle. It noted it typically does not require confidentiality undertakings for external advisors like MNP Digital, though such advisors generally maintain confidentiality.

99535NSPI Monthly Update Report #2 1 passage
Section 13
f September 17, 2025, the CIS replacement capital project has been delayed by the Incident. NS Power said its investigation into the cybersecurity incident “could impact the direction and timeline” of the project. The Company provided an u...

AI summary A cybersecurity incident has delayed the CIS replacement capital project, with NS Power stating it may affect the project's timeline. NS Power provided an updated timeline in compliance filing M11884. The NS-NB Reliability Intertie project (M12217) also faced rerun sensitivity analyses due to the incident, with Midgard noting minor output variances from the original models.

100161NSPI Monthly Update Report #4 1 passage
Section 8
rim for business continuity, which allowed for the uninterrupted monthly capital filings, the development of the 2026 ACE Plan, and continued financial reporting requirements. Fuel Adjustment Mechanism As identified in the Second Monthly Upd...

AI summary The document outlines the impact of an incident on the Fuel Adjustment Mechanism (FAM), including progress in restoring systems for the 2024/2025 audit, data recovery efforts, and the company's commitment to ensuring accurate fuel cost reporting and compliance with prudence reviews.

100677Affidavit - MacGillivray Law 8 passages
Section 10
-4- STATEMENT OF CLAIM Class Proceeding Pursuant to the Class Proceedings Act, S.N.S. 2007, c.28 I. OVERVIEW 1. Utilities occupy a position of trust in Canadian society. The majority of Nova Scotia citizens and consumers have little choice...

AI summary A class proceeding alleges Nova Scotia Power Inc. (NSP) failed in statutory and common law obligations following a 2025 cyberattack, causing systemic data breaches, billing inaccuracies, and prioritizing corporate interests over consumer protection, shifting financial and logistical burdens to customers.

Section 14
limited to) bill smoothing, interest forgiveness, or temporary credits. Furthermore, NSP did not inform customers of how it changed its billing practices in the aftermath of the Data Breach. (C) MISLEADING AND INADEQUATE COMMUNICATIONS 19....

AI summary The document alleges that NSP engaged in misleading and inadequate communication following a data breach, including failing to inform customers about billing practices based on estimates and omitting material details about the breach. It further claims NSP violated PIPEDA by failing to implement adequate safeguards for customer personal information.

Section 15
s standard by permitting unauthorized actors to access customers' personal information and by maintaining inadequate administrative, physical and technical safeguards. 26. NS P's offer of free credit monitoring constitutes an acknowledgmen...

AI summary The document outlines a data breach by Nova Scotia Power (NSP) leading to unauthorized access to customer personal information. NSP's failure to implement adequate cybersecurity measures resulted in significant harm, including anxiety and financial risks for customers. The Plaintiff alleges negligence in safeguarding data and non-compliance with statutory obligations under PIPEDA.

Section 16
iling to implement policies and procedures for the protection of personal information; (c) failing to implement mechanisms to prevent unauthorized access to personal information; (d) failing to implement meaningful consent practices regard...

AI summary The plaintiff alleges NSP negligently failed to protect personal information, leading to a data breach and mental distress. NSP is also accused of billing integrity failures through inadequate operational controls, inaccurate meter data, and delayed error corrections, resulting in financial and reputational harm to the plaintiff.

Section 19
f suffered damages and loss, including (but not necessarily limited to): (a) overpayment for electricity consumed; (b) bank fees, interest charges, or credit impacts; (c) cash-flow disruption and financial hardship; (d) time and effort spe...

AI summary The plaintiff alleges NSP caused damages through billing errors, negligent/fraudulent misrepresentations, and breaches of contract and the Consumer Protection Act. Claims include financial losses, contractual obligations violations, and statutory non-compliance.

Section 20
ch recognizes the Plaintiff as a "consumer" and NSP a "supplier', thereunder. 44. NSP engaged in "unfair practices'', as defined in the CPA, including (but not necessarily limited to): (a) making misleading representations regarding billin...

AI summary The Plaintiff alleges NSP engaged in unfair practices under the CPA, including misleading billing and inadequate system security. NSP is accused of breaching statutory duties under the Public Utilities Act and PIPEDA by issuing incorrect invoices, failing to maintain billing integrity, and mishandling personal information.

Section 21
ity, implement policies and practices to give effect to privacy protections, and prevent unauthorized access, disclosure, copying, harvesting, use, or modification of personal information. 50. NSP failed to comply with these non-optional s...

AI summary NSP is accused of failing to protect customer data under PIPEDA and the Public Utilities Act, leading to a breach and claims of negligence. The Plaintiff alleges unjust enrichment from overcharging customers and unconscionable conduct due to NSP's monopoly power and exploitation of consumer vulnerabilities.

Section 22
s imbalance by shifting the burden of its system failures onto Nova Scotia consumers. 59. The Plaintiff states that NS P's conduct in this regard entitling her to damages and other relief. VI. DAMAGES AND LOSS 60. The Plaintiff states that...

AI summary The plaintiff alleges NSP, as a regulated monopoly, breached legal and statutory obligations, causing overpayment, financial hardship, emotional distress, and identity theft risks. Relief sought includes class certification, declarations of breaches, and damages (general, aggravated, punitive).

101537NSPI Monthly Update Report #7 2 passages
Section 6
n NS Power’s systems in 2025, pending NS Power’s completion of the commitments from NS Power outlined in a Compliance Letter to the OPC. Page 4 of 5 April 9, 2026 C. Henwood Customer SIN Deletion In the Compliance Letter, NS Power committe...

AI summary NS Power completed the deletion of customer SINs from its systems by March 27, 2026, as required by a Compliance Letter to the OPC, retaining only legally mandated SINs with segregated controls. This addresses privacy obligations while complying with legal data retention requirements.

Section 35
filed on October 15, 2025. On March 19, 2026, the NSEB issued its decision in the JUA Proceeding. The decision requires NS Power to file any executed Joint Use Agreement with Bell, notify the Board within 14 days if the Letter of Intent is...

AI summary The NSEB mandated NS Power to file executed Joint Use Agreements with Bell, notify the Board of termination or changes, and submit follow-up reports on implementation and cost impacts. Non-compliance by June 30, 2026, may trigger further Board action.

102001NSPI Monthly Update Report #8 1 passage
Section 5
ation available for this reporting period, no new material impacts were identified beyond those already documented. Resolution of the Investigation of the Office of the Privacy Commissioner of Canada As indicated in Monthly Update 7 the Of...

AI summary NS Power is addressing the Office of the Privacy Commissioner of Canada's (OPC) investigation into a cyberattack by fulfilling commitments outlined in a Compliance Letter. Progress on restoration efforts includes five portfolios focusing on enterprise systems and customer-facing platforms. Blake Williams, NS Power's VP, Legal and Regulatory, confirms ongoing compliance efforts.

102372NSPI Monthly Update Report #9 1 passage
Resolution of the Investigation of the Office of the Privacy Commissioner of Canada p. p. 0
Resolution of the Investigation of the Office of the Privacy Commissioner of Canada As indicated in Monthly Update 8, the Office of the Privacy Commissioner of Canada (OPC) has announced that it would discontinue its investigation of the c...

AI summary The Office of the Privacy Commissioner of Canada (OPC) has paused its investigation into NS Power's cyberattack response pending NS Power's fulfillment of commitments outlined in a Compliance Letter. NS Power reports ongoing efforts to meet these obligations and maintain OPC updates.

102710NSPI Monthly Update Report #10 1 passage
Recovery Timeline p. p. 0
Recovery Timeline The program has now delivered the majority of its recovery objectives, with key business and technology capabilities fully operational and supporting organizational needs. Service continuity remained stable throughout the...

AI summary The program has achieved most of its recovery goals, with key systems operational and service continuity maintained. NS Power is addressing commitments from the OPC regarding a cyberattack investigation, which will be resolved upon completion of these commitments.

Disclaimer: These summaries were generated by AI from the filings they describe. We take care to make them accurate, but errors are possible - and they aren't advice. Only the filings themselves are the record: if you're relying on something here, confirm it against the source documents or the Nova Scotia Energy Board's own record. Full disclaimer →