Topic/Matter Intersection

Topic:"Compliance Legislation" in M12600

Matter: Nova Scotia Power - Cybersecurity Accountability IN THE MATTER OF AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED’s collection and retention of customer information, customer service and communications, billing processes and regulatory matters
59 passages 28 documents

Compliance Legislation across all matters →

N-1LOCs Redacted (N-1 from M12273) 2 passages
\ \ EXTERNAL EMAIL / COURRIEL EXTERNE \ \ p. p. 6
\ \ EXTERNAL EMAIL / COURRIEL EXTERNE \ \ Exercise caution when opening attachments or clicking on links / Faites preuve de prudence si vous ouvrez une pièce jointe ou cliquez sur un lien To: Michael Savage acting as Chief Executive Office...

AI summary This email requests formal review and structural accountability from Nova Scotia's executive leadership regarding governance failures by the Nova Scotia Energy and Regulatory Boards Tribunal (NSERBT) and Nova Scotia Power's (NS Power) use of unconscionable contracting mechanisms. It highlights concerns about unlawful contract formation and identity breach issues.

Contact Information p. pp. 51-89
Contact Information Name on account: Lisa Winch Account number: \ \ \ \ \ \ \ \ Business contact: Account address: Address 1: \ \ \ \ \ \ \ \ Address 2: \ \ \ \ \ \ \ \ City: \ \ \ \ \ \ \ Province: \ \ \ \ \ \ \ Postal code: \ \ \ \ \ \ \...

AI summary A customer of NS Power reports that their personal and financial information was compromised in a ransomware attack, leading to identity theft and financial fraud. The customer criticizes NS Power for not providing adequate legal protection or compensation, and calls for stronger transparency, policy changes, and consumer support measures.

N-2NSPI (NSEB) RIR 1 to 12 - Redacted (N-2 from M12273) 1 passage
Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests p. pp. 10-27
Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests 1 Request IR-1: 1 these community sessions have been held to date, and have assisted hundreds of customers 2 in signing...

AI summary The text discusses Nova Scotia Power's (NSP) cybersecurity measures, including its adherence to the NIST Cybersecurity Framework and recent updates to its cybersecurity practices. It outlines the company's existing safeguards and alignment with industry standards.

N-3Incident Report - Redacted (N-3 from M12273) 2 passages
2025 Nova Scotia Power's Cybersecurity Incident Report REDACTED p. pp. 35-36
2025 Nova Scotia Power's Cybersecurity Incident Report REDACTED 1 8.2 Additional Security Audits, Policy Updates, and Employee Training 2 Section 4.1 addressed additional security audits, policy updates, and employee training as 3 summariz...

AI summary Nova Scotia Power (NSP) has implemented additional security audits, policy updates, and employee training to enhance cybersecurity. These measures include compliance with NERC audits, updates informed by the NIST Cybersecurity Framework, and mandatory training for employees. The Office of the Privacy Commissioner of Canada (OPC) is investigating the incident and NSP is cooperating fully.

NS Power Cyber Incident Report Appendix B Page 1 of 7 p. p. 44
NS Power Cyber Incident Report Appendix B Page 1 of 7 Affected Regulatory Matters Report 2 - October 1 Report 3 - November 3 Report 4 - December 1 Latest update Forecast Restoration of Normal Activities CIS Replacement Project Introduced N...

AI summary The CIS Replacement Project, affected by a cybersecurity incident, has been delayed. NS Power reported this delay in its compliance filing M11884, and an application for the project is expected to be submitted to the NSEB in 2026.

N-6NSPI (CA) RIR 1-11 - Redacted 1 passage
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to Consumer Advocate Information Requests
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to Consumer Advocate Information Requests 1 (b) Based on the above quote, NSPI was aware in 2018 the Company had collected 2 customer SIN without a vali...

AI summary NSPI was asked to explain why customer SIN data collected without a valid business reason under PIPEDA had not been expunged by 2018. NSPI responded that it initiated a process to identify and remove SINs from its systems, with a third-party expert certifying the deletion on March 27, 2026.

N-9NSPI (INQ Law) RIRs 1-7 2 passages
Section 2
below). For 2025, approximately 79% of assigned training was completed, though the schedule for completion of these processes was disrupted due to the Incident. As noted above, since the Incident, NS Power has taken steps to enhance its ex...

AI summary NS Power has completed 79% of assigned privacy training for 2025, though the schedule was disrupted by an incident. Since the incident, NS Power has increased training frequency to quarterly and achieved 100% completion for the first quarter of 2026. Procedures for reporting and responding to privacy breaches and cyber incidents have been established and provided as confidential attachments.

30
30 1 (g) NS Power did not conduct a formal audit of access to personal data of customers in the 2 2 years leading up to the incident. NS Power prohibits employees from accessing personal 3 information of customers without a legitimate busi...

AI summary The document discusses NS Power's lack of a formal audit of customer data access in the two years prior to an incident. It outlines NS Power's policies on employee access to personal information and procedures for reporting unauthorized access. The request also includes inquiries about NS Power's awareness date of a cybersecurity incident.

N-10NSPI (NSEB) RIRs 1-25 - Redacted 1 passage
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to NSEB Information Requests p. p. 16
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to NSEB Information Requests 1 Request IR-10: 2 3 Please provide specific and detailed information addressing whether all or any part of the 4 informati...

AI summary The document outlines information requests related to Nova Scotia Power's (NSPI) data collection and retention policies following a cyber attack. The requests focus on whether data was improperly collected, retained, or destroyed, and whether NSPI was compliant with applicable laws and internal policies. Responses refer to another information request (NSEB IR-9) for detailed information.

N-11NSPI (SBA) RIRs 1-20 - Redacted 2 passages
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to Small Business Advocate Information Requests
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to Small Business Advocate Information Requests 1 Request IR-01: 30 regulatory authorities. 31 1 (c) Yes. The Company's established incident response pr...

AI summary The document outlines Nova Scotia Power's (NS Power) incident response protocols, including notification to the Office of the Privacy Commissioner of Canada (OPC) and other regulatory bodies such as NERC, E-ISAC, and NEPCC following an incident. Questions are raised regarding the timing of notifications and whether advice was provided.

REDACTED
REDACTED 1 Request IR-20: 2 3 Refer to Compliance Letter to the Office of the Privacy Commissioner of Canada ("OPC") 4 dated March 18, 2026 (https://www.priv.gc.ca/en/opc-actions-and 5 decisions/investigations/investigations-into-businesse...

AI summary Nova Scotia Power (NSP) received communications from a threat actor claiming to have obtained sensitive customer information, but no evidence of public disclosure or sale has emerged. NSP did not pay a ransom. The incident was first identified on April 25, 2025, and an investigation confirmed likely impact to customer information by May 1, 2025.

N-14Evidence & Appendix A Resume - Tricia Ralph INQ Law/Consulting - BCC 7 passages
D. Methodology p. p. 3
D. Methodology 5. In order to come to my opinions, I reviewed the 2025 Nova Scotia Power's Cybersecurity Incident Report (the "Incident Report") and responses to my Information Request ("IR") to NSPI, as well as relevant information in oth...

AI summary The methodology section outlines the review of NSPI's 2025 Cybersecurity Incident Report and responses to an information request, using PIPEDA principles as a benchmark for evaluating the reasonableness of NSPI's actions without interpreting PIPEDA itself.

Privacy Training p. p. 4
Privacy Training - 20. Privacy training ensures that employees who handle PI understand their obligations and the risks associated with mishandling it. Without it, even well-designed policies are ineffective, as human error remains one of...

AI summary The document outlines NSPI's privacy training initiatives, including quarterly cybersecurity training and monthly phishing simulations. While NSPI achieved a 96% completion rate in 2024, the rate dropped to 79% in 2025, which is considered low. After the Incident, 100% of required training was completed in the first quarter of 2026.

Issue 3 – Reporting and Notification p. pp. 4-8
Issue 3 – Reporting and Notification - 32. Board counsel has asked that I provide an opinion on the reasonableness of NSPI's actions in relation to the Incident in delivering services to its customers concerning reporting to regulators, an...

AI summary The document addresses Issue 3 – Reporting and Notification, focusing on NSPI's actions regarding a data breach incident. NSPI believes an unauthorized third-party accessed its systems around March 19, 2025, and exfiltrated customer data, including personal information, which was discovered on April 25, 2025. The Board is evaluating the reasonableness of NSPI's reporting and notification practices.

Notification to the Regulator p. p. 8
Notification to the Regulator - 34. As set out in Section 2.0 of the Incident Report, NSPI reported the Incident to the Office of the Privacy Commissioner of Canada (OPC) on May 1, 2025, with an update on May 14, 2025. - 35. Expeditious no...

AI summary NSPI reported a privacy breach to the Office of the Privacy Commissioner of Canada (OPC) on May 1, 2025, with an update on May 14, 2025. Notification within several days is considered best practice, and NSPI's five-day response is deemed reasonable.

Contents of Direct Customer Notification p. pp. 8-13
letters. In the frequently asked questions and answers that were provided to staff responding to customer calls that were provided in nonconfidential response to NSEB's IR-14, the following was used: Does this mean that someone has my pers...

AI summary The document discusses concerns raised by customers regarding the lack of specificity in notices about a data breach by Nova Scotia Power, leading to confusion and uncertainty. It also highlights the need for better system structures to determine the exact nature of impacted data and criticizes the insufficient and unclear customer notices as unreasonable.

Issue 5 - Measures Implemented to Mitigate Risk from Identity Theft and Fraud p. pp. 17-19
Issue 5 - Measures Implemented to Mitigate Risk from Identity Theft and Fraud - 81. Board counsel has asked that I provide an opinion on the reasonableness of NSPI's actions in delivering its services to customers concerning measures imple...

AI summary The document discusses NSPI's measures to mitigate risks from identity theft and fraud following a cybersecurity incident, including offering complimentary credit monitoring services to affected customers and extending the offer to former customers.

Issue 6 – Third-party Service Providers p. pp. 19-21
Issue 6 – Third-party Service Providers - 90. Board counsel has asked that I provide an opinion on the reasonableness of NSPI's actions in relation to the Incident concerning security measures implemented with third -party service provider...

AI summary The Board counsel seeks an opinion on the reasonableness of NSPI's actions regarding third-party service providers in relation to a security incident. NSPI asserts the incident was caused by malware installed by an employee, not due to third-party service providers. Active oversight of third-party providers is emphasized, but since they were not involved in the incident, further opinion on this issue is not required.

N-15INQ Law/Consulting (CA) RIRs 1-4 2 passages
14 The relevant components of ID.IM-P are:
14 The relevant components of ID.IM-P are: Subcategory Function ID.IM-P1: Systems/products/services that process data are inventoried. Gives the closed set of systems to check against the incident's affected asset list. ID.IM-P2: Owners or...

AI summary This section outlines the components of ID.IM-P, focusing on inventorying systems, data processing, and data actions to manage data breaches and incidents. It details how to identify affected systems, individuals, data elements, and the environments where data is processed.

Request IR-3:
Request IR-3: 7 With regard to paragraph 89, page 21 of the Report, which states: 9 "…..In my opinion, the initial offer of two years of credit monitoring was insufficient to address 10 the risks arising from the unauthorized access to SIN...

AI summary The response to Request IR-3 discusses the rationale for extending credit monitoring from two to five years following a data breach, citing recommendations from the Saskatchewan Information and Privacy Commissioner and other reports. It notes that while some standards historically supported two years, recent recommendations suggest longer periods, such as five to ten years, may be more appropriate.

N-16NSPI Refiled Formal Incident Report - Redacted (filed in M12273 as N-5 on April 27, 2026) 2 passages
Re: Important Notice About Your Personal Information
Re: Important Notice About Your Personal Information Dear Valued Customer: We are writing to provide you with information about the recent cyber incident impacting Nova Scotia Power. On April 25, 2025, Nova Scotia Power discovered that an...

AI summary Nova Scotia Power informed customers of a cyber incident on April 25, 2025, where unauthorized access occurred to parts of its Canadian network. Personal information, including names, contact details, and account history, may have been accessed. The company has activated incident response protocols and provided free credit monitoring through TransUnion. Customers are advised to remain cautious of unsolicited communications.

NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025)
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) The privacy commissioner of Canada stated last week that: "Data breaches have surged over the past decade, and this incident highlights the growing risks of cyberatta...

AI summary NS Power discusses a recent cyber incident, emphasizing their commitment to cybersecurity and compliance with standards like NIST and NERC. They confirmed no payment was made to attackers and detailed their response, including engaging third-party experts and notifying affected customers.

N-17NS Power Rebuttal Evidence - Redacted 9 passages
4.0 EVIDENCE OF INTERGROUP CONSULTANTS p. pp. 9-20
4.0 EVIDENCE OF INTERGROUP CONSULTANTS The InterGroup Evidence makes 13 recommendations focused on areas where NS Power's cybersecurity, privacy, communications, customer notification, billing contingency, and governance practices could be...

AI summary The InterGroup Evidence provides 13 recommendations to NS Power to improve cybersecurity, privacy, communication, and governance practices. NS Power agrees with the need for continuous improvement and highlights existing initiatives, noting that some recommendations align with OPC guidance. Specific emphasis is placed on updating staff training policies and addressing system access restrictions for non-compliance.

Cybersecurity Accountability REDACTED p. pp. 25-57
Cybersecurity Accountability REDACTED of an audit regime considering the OPC compliance process audit and to ensure any regime is consistent with the outcome of that process. Recommendation 4: InterGroup recommends the Board direct NS Powe...

AI summary The document discusses a recommendation for NS Power to update its Communications Policy to notify all customers in the event of a privacy breach, which NS Power opposes, arguing that such notifications are not required by law and could lead to notification fatigue. NS Power emphasizes that privacy laws like PIPEDA require notifications only to those affected by a breach.

The reasonableness of NS Power 's actions regarding use of a PI inventory. p. p. 41
The reasonableness of NS Power 's actions regarding use of a PI inventory. INQ notes: An adequate PI inventory as a privacy program control is a critically important building block. In their guidance, the regulators explain that organizati...

AI summary The document discusses concerns regarding the adequacy of NS Power's PI inventory practices, noting that NSPI did not provide a copy of the inventory and claimed it could not determine what data points were exposed during an incident, raising questions about the completeness of their privacy program controls.

Preamble p. pp. 43-46
While I agree that it is important to take steps to identify whether sensitive personal data was affected in an incident and act quickly to notify as soon as feasible, a finding of unreasonableness is not sustained by the evidentiary recor...

AI summary The text discusses the reasonableness of NS Power's response to a cybersecurity incident, emphasizing the need to balance timely notification with operational challenges. It highlights that NS Power prioritized service continuity and took steps such as restoring systems, extracting documents, and engaging third parties for credit monitoring and customer communication.

8.0 CONCLUSION p. pp. 59-64
8.0 CONCLUSION Over the past 16 months, the team at NS Power has worked around the clock to restore and strengthen all systems and to support its customers. NS Power acknowledges the significant impact the Attack and consequent privacy bre...

AI summary NS Power acknowledges the impact of a cyberattack and subsequent privacy breach on its customers and emphasizes its commitment to transparency, customer support, and continuous improvement. The company asserts that its response was reasonable and customer-centered, and requests that the Board's findings align with the evidence provided, preserving normal regulatory processes while recognizing its commitments.

8 Summary of Ms. Ralph's Finding p. p. 72
8 Summary of Ms. Ralph's Finding 9 At paragraph 46 of the Ralph Report, Ms. Ralph concludes that the approximately two-month 10 delay between the discovery of the Incident on April 25, 2025, and the public notification to former customers...

AI summary Ms. Ralph found that NS Power's two-month delay in notifying former customers about a data incident was unreasonable. She noted that NS Power should have been aware of former customer data in its systems and should have assessed if it was impacted. Best practices require notification within days unless extenuating circumstances exist, which were not identified.

17 Expert Opinion p. p. 72
17 Expert Opinion 18 I disagree with this finding. While I agree that it is important to take steps to identify whether 19 sensitive personal data was affected in an incident and act quickly to notify as soon as feasible, a 20 finding of u...

AI summary The expert disagrees with the finding of unreasonableness regarding NS Power's handling of a data incident, emphasizing the contextual nature of reasonableness and the operational challenges of notifying former customers without reliable contact information.

3 Rationale p. p. 79
3 Rationale - 4 Individualized Data Element Identification Was Not Reasonably Feasible on the Notification - 5 Timeline - 6 The record establishes clearly that the absence of customer-specific data element information in - 7 the notices wa...

AI summary The text discusses the rationale for not providing individualized data element identification in breach notifications, citing forensic impossibility and the need for speed. It notes that NS Power provided clarity regarding SIN exposure through two letter versions, which was deemed appropriate.

11 RECOMMENDATIONS p. p. 86
11 RECOMMENDATIONS - 12 Recommendation 4: That the Board Direct NS Power to Update Its Communications Policy - 13 to Require a Minimum of Two to Three Direct Notifications to All Customers and Not - 14 Only Those Potentially Affected in th...

AI summary The recommendation suggests that the Board direct NS Power to update its communications policy to ensure a minimum of two to three direct notifications are sent to all customers, not just those potentially affected, in the event of future privacy breaches.

100191Letter from Minister of Energy re: accountability for Nova Scotia Power 1 passage
Energy Board: p. p. 0
Energy Board: I am extremely concerned about the number of Nova Scotians who are experiencing inaccurate billing and lack of responsiveness from Nova Scotia Power. Since the cyberattack over eight months ago, NSP has continually relied on...

AI summary The Premier expresses concern over inaccurate billing and lack of responsiveness by Nova Scotia Power (NSP) following a cyberattack. Thousands of households continue to face estimated billing with full restoration not expected until 2026, leading to financial strain and eroded trust. The Premier calls for an investigation into NSP's billing practices, consumer protections, and potential financial penalties.

100855NS Power's Monthly Update #4 (M12273) 1 passage
Opening statement p. p. 7
Thanks to our robust systems, ongoing investments, and the dedication of our people, we ensured that core operations and the electric grid continued uninterrupted – no power was lost to Nova Scotians. There is still much work ahead, and as...

AI summary Nova Scotia Power ensured uninterrupted operations during a recent incident, implementing recovery measures such as IT security upgrades and customer support options. They are addressing billing and payment challenges, removing social insurance numbers from systems, and working to reconnect meters with billing systems by the end of March.

101377Board Letter re: Final Issues List 1 passage
Section 3 p. pp. 0-1
supervisory power includes the ability to investigate and the authority to consider the reasonableness of any "practice or act whatsoever affecting or relating to the operation of any public utility". The Privacy Commissioner of Canada is...

AI summary The document outlines the Board's decision to address certain issues in the proceeding while removing others, citing their relevance to separate matters. Issue #3 is removed as it pertains to a different proceeding, while Issue #7 remains as it includes non-technical aspects related to customer information sharing policies.

101524David MacLeod (NSPI) IR A-1 to G-5 1 passage
IR F-3 — Third-Party Cybersecurity Assessments
IR F-3 — Third-Party Cybersecurity Assessments - (a) Identify all third-party cybersecurity assessments, audits, penetration tests, vulnerability - assessments, or red team exercises conducted for NSP in the five years prior to the Attack,...

AI summary The document requests information on third-party cybersecurity assessments conducted for Nova Scotia Power (NSP) in the five years prior to a cyberattack, including details on the firms involved, assessment scope, findings, and NSP's responses. It also asks for unaddressed findings at the time of the attack and explanations for their non-remediation.

101618INQ Law Consulting (NSPI) IR-1 to IR-7 1 passage
NOVA SCOTIA ENERGY BOARD
NOVA SCOTIA ENERGY BOARD IN THE MATTER OF: THE PUBLIC UTILITIES ACT - and - IN THE MATTER OF: AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer information, customer...

AI summary The Nova Scotia Energy Board is conducting an inquiry under the Public Utilities Act regarding the impact of a cyber incident on Nova Scotia Power Incorporated's data collection, customer service, billing processes, and regulatory compliance.

101623NSPI Monthly Update Report #7 (M12273) 1 passage
Customer SIN Deletion p. p. 0
Customer SIN Deletion In the Compliance Letter, NS Power committed to the OPC that by March 31, 2026, NS Power would initiate a process to identify and remove instances of customer social insurance numbers (SINs) contained within its syste...

AI summary NS Power committed to the OPC to delete customer SINs by March 31, 2026, except for those required by law. The process was completed on March 27, 2026, with Legally Required SINs segregated and protected for lawful use only.

101692CA (NSPI) IR-1 to IR-11 1 passage
42 43
42 43 1 Request IR-4: Data Retention Policy Compliance with Legislation 2 3 4 Reference: Exhibit N-3 - 2025 Nova Scotia Power's Cybersecurity Incident Report, Page 40, ll 3-5 5 6 7 8 9 Quote: At the time of the Incident, NS Power had forma...

AI summary The document contains a series of requests related to data retention policies and customer account collections by NSPI. It references a cybersecurity incident and asks about NSPI's compliance with privacy and security policies, as well as actions taken in response to the incident and its impact on customer billing.

101693DOE (NSPI) IR-1 to IR-10 1 passage
Business and Regulatory Impacts
Business and Regulatory Impacts IR-5. Please provide a table listing every regulatory filing or milestone from April 2025 to the present that required an extension or was filed with "data limitations," including the specific date the utili...

AI summary The text requests a table of regulatory filings with data limitations and asks for quantification of extra labor hours and costs related to breach-related billing tasks, including their coverage in specific budgets.

101694NSEB (NSPI) IR-1 to IR-25 2 passages
Request IR-11:
Request IR-11: - Please confirm that, at all material times relating to the cyber attack, NS Power was fully compliant with all applicable statutes and regulations relating to the collection and retention of personal information of custome...

AI summary The document requests confirmation of NS Power's compliance with statutes and regulations related to the collection and retention of customer personal information during a cyber attack. If non-compliance is identified, the request asks for details on each statute, the reasons for non-compliance, and corrective actions taken or planned.

Request IR-15:
Request IR-15: - In its response to NSEB IR-1 (Exhibit N-2), NS Power said it "adopted a best-practices approach - to mitigating potential harm to customers whose personal information was impacted by the - Incident." Please explain why NS...

AI summary The document requests NS Power to explain why its approach to mitigating harm to customers affected by an incident is considered a 'best-practice' and to identify the benchmarks or metrics used to assess this approach, as outlined in its response to NSEB IR-1.

101697SBA (NSPI) IR-1 to IR-20 2 passages
Request IR-4:
Request IR-4: Please refer to the Report Page 8, Lines 27 - 28: NS Power also reported the Incident to the Office of the Privacy Commissioner of Canada (OPC) on May 1, 2025, with an update on May 14, 2025. - a) Why was there a gap from Apr...

AI summary NS Power reported an incident to the Office of the Privacy Commissioner of Canada (OPC) on May 1, 2025, but there was a gap between when they first became aware of the issue on April 25, 2025, and the OPC notification. The questions raised pertain to the delay, whether law enforcement recommended OPC notification, and if NS Power received advice on timing.

Request IR-17:
Request IR-17: Refer to M12600, Exhibit N-1, NSEB IR 12, Page 2-3, Lines 8-9: …Also, the Company has not applied late charges, or penalties on any outstanding balances since the incident. NS Power will communicate directly with customers b...

AI summary The document references NS Power's handling of late fees and a cybersecurity incident. It asks about the reinstatement of late fees, their financial impact, and cybersecurity measures in place during a breach. It also cites a compliance letter to the OPC regarding a data breach in 2025.

101749Letter NSPI re: Information requests not within scope of M21600 (refiled on May 8 to correct typo) 1 passage
Section 3 p. p. 0
ng and transition to IESO Nova Scotia Conversely, the issues to be addressed in M12273 are set out in the Board's February 6, 2026 correspondence in relation to that matter and include the following: - a. NS Power's cybersecurity assets an...

AI summary The document discusses the scope of M12600 and M12273, focusing on NS Power's cybersecurity measures before and after a cyberattack. It identifies which issues fall under M12600 and which are better addressed in M12273, where MNP Digital is assisting the Board. Only specific IRs are deemed relevant to M12600.

101835Letter NSPI re: Reply comments for out of scope IRs 1 passage
Section 2 p. p. 0
be part of the record in M12273, not M12600. Including the subject matter of the Out of Scope IRs in M12600 would lead to a scenario where issues are before the Board without a full or proper record. In its comments, the CA states that the...

AI summary The Consumer Advocate (CA) argues that the Out of Scope IRs in M12600 could provide insights into Nova Scotia Power's governance and risk management. However, the scope of M12600 is limited to the impact of a cyber incident on data collection, billing, and regulatory matters. The CA and SBA reference the Board's March 25, 2026 letter regarding overlap between matters.

101927Letter NSPI re: IR Scope Letter - Refile 1 passage
Section 3 p. p. 0
ng and transition to IESO Nova Scotia Conversely, the issues to be addressed in M12273 are set out in the Board's February 6, 2026 correspondence in relation to that matter and include the following: - a. NS Power's cybersecurity assets an...

AI summary This document discusses the scope of M12600 and the relevance of Mr. MacLeod's IRs to the proceeding. NS Power argues that most of the IRs are not relevant to M12600 and should instead be addressed in M12273, which is currently under review by MNP Digital. Only specific IRs are considered relevant to M12600.

102138Board Decision Letter - Scope of IRs 1 passage
Section 3 p. p. 0
Business Advocate submitted that there were non-technical aspects of the questions it asked that would "add value and insight into the regulatory oversight that is clearly within the scope of M12600." The Consumer Advocate also submitted t...

AI summary The Business Advocate and Consumer Advocate argue that non-technical aspects of questions should be included in the regulatory proceeding, emphasizing their value in understanding NS Power's governance and risk management. The Board notes that while there may be overlap between matters, certain technical and non-technical components should be considered separately.

102711NSPI Monthly Update Report #10 (M12273) 1 passage
Recovery Timeline p. p. 0
Recovery Timeline The program has now delivered the majority of its recovery objectives, with key business and technology capabilities fully operational and supporting organizational needs. Service continuity remained stable throughout the...

AI summary The program has largely met its recovery objectives, with key systems operational and service continuity stable. NS Power is addressing commitments from the OPC regarding a cyberattack investigation, which will be resolved upon completion of these commitments.

20260819-1Hearing Transcript — 08/19/2026 (Chris Lanteigne, Lia MacDonald, Glen MacLeod, Blake Williams) 10 passages
Section 55
- on anything sort of specific or from his point of view in terms of what we mean by those words. - A. (Williams) I certainly agree with what Ms. MacDonald has said, sir. There's no one aspect to this that I can point to that's demonstrati...

AI summary The discussion emphasizes the importance of accountability and transparency in regulatory processes, highlighting the need for a comprehensive approach in interactions with regulatory bodies such as the OPC. It stresses the significance of how processes are conducted, including evidence provision and responsiveness.

NOVA SCOTIA POWER PANEL 441 Questions, (Deveau)
NOVA SCOTIA POWER PANEL 441 Questions, (Deveau) 1 actions that we'll take forward. 10 the company recognized that you shouldn't be retaining 11 SIN numbers, so I'm just I'm just wondering you were 12 able to do in 2025 within nine months....

AI summary The Nova Scotia Power Panel discusses the company's actions taken to enhance its governance program, including the revised role of the Privacy Officer and changes in reporting structure. The discussion centers on the urgency of implementing these changes and the technical risks involved in the CIS system.

Section 68
INTERNATIONAL REPORTING INC. CERTIFIED COURT REPORTERS 1 the Board of Directors on the cycle? 2 A. (Williams) Just referring with 3 Ms. MacDonald, and neither of us are aware of that, that 4 what you're describing there, but I think it's t...

AI summary The discussion revolves around a compliance program within Nova Scotia Power, referred to as Optro, which is used to track compliance with legal and internal obligations. The witness clarifies that the program is new but not a new compliance tool, with references to page 61 and line 23 of the document.

Section 70
1 the business area. So again, this is not just as 2 you'll see here, it's not just in relation to something 3 like privacy. It's any and all compliance obligations 4 that the company may have. 5 Q. CRA deductions and that sort of 6 thing?...

AI summary The discussion focuses on compliance obligations within a business area, including CRA deductions and the transition from the former name AuditBoard to Optro as an interim measure. The process is described as automated and managed by the internal compliance team.

NOVA SCOTIA POWER PANEL 465 Questions, (Deveau)
NOVA SCOTIA POWER PANEL 465 Questions, (Deveau) 1 there's not necessarily a 2 So there's a screen that says Q. 3 A. (Williams) That's right. 4 And the privacy policies are part Q. 5 of that screen? They're part of that? 6 (Williams) It wou...

AI summary The text contains a portion of a regulatory proceeding involving Nova Scotia Power, discussing privacy policies and their compliance with development regulations. The discussion includes references to audits and interim measures related to policy updates. The session was interrupted and reconvened later.

NOVA SCOTIA POWER PANEL 491 Questions, (Deveau)
NOVA SCOTIA POWER PANEL 491 Questions, (Deveau) INTERNATIONAL REPORTING INC. CERTIFIED COURT REPORTERS 1 2020, that the date on their last reviewer. They would 2 not have been reviewed in the interim between 2020 and 3 now, just because th...

AI summary The discussion revolves around the review of privacy policies by Nova Scotia Power, referencing the existing legislation in 2020 and the impact of new federal legislation and AI technology on the need for policy updates. The speaker affirms that the policies at the time of the incident complied with applicable privacy legislation.

NOVA SCOTIA POWER PANEL 503 Questions, (Deveau)
NOVA SCOTIA POWER PANEL 503 Questions, (Deveau) 1 it's an audit of access to information that is made 2 no formalized review of compliance or the policies 3 themselves on a regular basis, on a regular cycle; it 4 depends on what the intern...

AI summary The discussion focuses on Nova Scotia Power's audit practices and customer privacy policy, highlighting gaps in compliance reviews and the handling of customer information retention and destruction following a data breach.

VALDETERO 633
VALDETERO 633 1 Q. Okay. Thank you. 2 AKCAKIRYAN: Those are all my MS. 3 questions. 4 THE CHAIR: Thank you. 5 Industrial Group? 6 MS. RUDDERHAM: No questions, 7 Mr. Chair. Thanks. 8 THE CHAIR: Department of Energy? 9 KAYTER: No questions,...

AI summary This excerpt from a regulatory proceeding includes cross-examination of Ms. Valdetero by Mr. Mahody, focusing on her experience with data privacy and security in regulated utilities, including telecommunications providers and utilities in the United States. She discusses her role as external counsel for multiple companies.

Section 169
INTERNATIONAL REPORTING INC. CERTIFIED COURT REPORTERS different area. THE CHAIR: Yeah. Well, why don't we move on to that one then? BY MR. MAHODY: Q. All right. Ms. Valdetero, could I take you in your evidence to your critique of Ms. Ralp...

AI summary The discussion centers on the reasonableness of the timeframe for notifying former customers of a data breach by Nova Scotia Power. The witness, Ms. Valdetero, indicates that a period from May 1st to June 25th, 2025, was considered reasonable, taking into account the resources required to address the breach.

Section 171
been reasonable, but given all that needed to happen in that timeframe, from when they first identified and I wasn't sure when they first identified former customers, but I was still basing it off INTERNATIONAL REPORTING INC. CERTIFIED COU...

AI summary The testimony discusses the timeline and approach taken by Nova Scotia Power regarding customer notification following a data breach. The witness acknowledges the May 1st public announcement and subsequent October 31st direct mailing as a more individualized outreach step.

20260820-1Hearing Transcript — 08/20/2026 (Jena Valdetero, Ed Mollard, Tricia Ralph) 1 passage
1 that well. Can you say your question again? 5 tying it back to the consumer as opposed to, like best 6 practice was sort of the benchmark for me assessing what 7 the consumer would have reasonably expected. Do you mean 8 for the whole re...

AI summary The discussion revolves around the concept of 'best practice' in the context of privacy and data management, with emphasis on evolving customer and regulatory expectations. The speaker suggests regular audits and independent reviews to ensure compliance with best practices.

Disclaimer: These summaries were generated by AI from the filings they describe. We take care to make them accurate, but errors are possible - and they aren't advice. Only the filings themselves are the record: if you're relying on something here, confirm it against the source documents or the Nova Scotia Energy Board's own record. Full disclaimer →