N-14Evidence & Appendix A Resume - Tricia Ralph INQ Law/Consulting - BCC
7 passages
D. Methodology 5. In order to come to my opinions, I reviewed the 2025 Nova Scotia Power's Cybersecurity Incident Report (the "Incident Report") and responses to my Information Request ("IR") to NSPI, as well as relevant information in oth...
AI summary The methodology section outlines the review of NSPI's 2025 Cybersecurity Incident Report and responses to an information request, using PIPEDA principles as a benchmark for evaluating the reasonableness of NSPI's actions without interpreting PIPEDA itself.
Privacy Training - 20. Privacy training ensures that employees who handle PI understand their obligations and the risks associated with mishandling it. Without it, even well-designed policies are ineffective, as human error remains one of...
AI summary The document outlines NSPI's privacy training initiatives, including quarterly cybersecurity training and monthly phishing simulations. While NSPI achieved a 96% completion rate in 2024, the rate dropped to 79% in 2025, which is considered low. After the Incident, 100% of required training was completed in the first quarter of 2026.
Issue 3 – Reporting and Notification - 32. Board counsel has asked that I provide an opinion on the reasonableness of NSPI's actions in relation to the Incident in delivering services to its customers concerning reporting to regulators, an...
AI summary The document addresses Issue 3 – Reporting and Notification, focusing on NSPI's actions regarding a data breach incident. NSPI believes an unauthorized third-party accessed its systems around March 19, 2025, and exfiltrated customer data, including personal information, which was discovered on April 25, 2025. The Board is evaluating the reasonableness of NSPI's reporting and notification practices.
Notification to the Regulator - 34. As set out in Section 2.0 of the Incident Report, NSPI reported the Incident to the Office of the Privacy Commissioner of Canada (OPC) on May 1, 2025, with an update on May 14, 2025. - 35. Expeditious no...
AI summary NSPI reported a privacy breach to the Office of the Privacy Commissioner of Canada (OPC) on May 1, 2025, with an update on May 14, 2025. Notification within several days is considered best practice, and NSPI's five-day response is deemed reasonable.
letters. In the frequently asked questions and answers that were provided to staff responding to customer calls that were provided in nonconfidential response to NSEB's IR-14, the following was used: Does this mean that someone has my pers...
AI summary The document discusses concerns raised by customers regarding the lack of specificity in notices about a data breach by Nova Scotia Power, leading to confusion and uncertainty. It also highlights the need for better system structures to determine the exact nature of impacted data and criticizes the insufficient and unclear customer notices as unreasonable.
Issue 5 - Measures Implemented to Mitigate Risk from Identity Theft and Fraud - 81. Board counsel has asked that I provide an opinion on the reasonableness of NSPI's actions in delivering its services to customers concerning measures imple...
AI summary The document discusses NSPI's measures to mitigate risks from identity theft and fraud following a cybersecurity incident, including offering complimentary credit monitoring services to affected customers and extending the offer to former customers.
Issue 6 – Third-party Service Providers - 90. Board counsel has asked that I provide an opinion on the reasonableness of NSPI's actions in relation to the Incident concerning security measures implemented with third -party service provider...
AI summary The Board counsel seeks an opinion on the reasonableness of NSPI's actions regarding third-party service providers in relation to a security incident. NSPI asserts the incident was caused by malware installed by an employee, not due to third-party service providers. Active oversight of third-party providers is emphasized, but since they were not involved in the incident, further opinion on this issue is not required.
N-17NS Power Rebuttal Evidence - Redacted
9 passages
4.0 EVIDENCE OF INTERGROUP CONSULTANTS The InterGroup Evidence makes 13 recommendations focused on areas where NS Power's cybersecurity, privacy, communications, customer notification, billing contingency, and governance practices could be...
AI summary The InterGroup Evidence provides 13 recommendations to NS Power to improve cybersecurity, privacy, communication, and governance practices. NS Power agrees with the need for continuous improvement and highlights existing initiatives, noting that some recommendations align with OPC guidance. Specific emphasis is placed on updating staff training policies and addressing system access restrictions for non-compliance.
Cybersecurity Accountability REDACTED of an audit regime considering the OPC compliance process audit and to ensure any regime is consistent with the outcome of that process. Recommendation 4: InterGroup recommends the Board direct NS Powe...
AI summary The document discusses a recommendation for NS Power to update its Communications Policy to notify all customers in the event of a privacy breach, which NS Power opposes, arguing that such notifications are not required by law and could lead to notification fatigue. NS Power emphasizes that privacy laws like PIPEDA require notifications only to those affected by a breach.
The reasonableness of NS Power 's actions regarding use of a PI inventory. INQ notes: An adequate PI inventory as a privacy program control is a critically important building block. In their guidance, the regulators explain that organizati...
AI summary The document discusses concerns regarding the adequacy of NS Power's PI inventory practices, noting that NSPI did not provide a copy of the inventory and claimed it could not determine what data points were exposed during an incident, raising questions about the completeness of their privacy program controls.
While I agree that it is important to take steps to identify whether sensitive personal data was affected in an incident and act quickly to notify as soon as feasible, a finding of unreasonableness is not sustained by the evidentiary recor...
AI summary The text discusses the reasonableness of NS Power's response to a cybersecurity incident, emphasizing the need to balance timely notification with operational challenges. It highlights that NS Power prioritized service continuity and took steps such as restoring systems, extracting documents, and engaging third parties for credit monitoring and customer communication.
8.0 CONCLUSION Over the past 16 months, the team at NS Power has worked around the clock to restore and strengthen all systems and to support its customers. NS Power acknowledges the significant impact the Attack and consequent privacy bre...
AI summary NS Power acknowledges the impact of a cyberattack and subsequent privacy breach on its customers and emphasizes its commitment to transparency, customer support, and continuous improvement. The company asserts that its response was reasonable and customer-centered, and requests that the Board's findings align with the evidence provided, preserving normal regulatory processes while recognizing its commitments.
8 Summary of Ms. Ralph's Finding 9 At paragraph 46 of the Ralph Report, Ms. Ralph concludes that the approximately two-month 10 delay between the discovery of the Incident on April 25, 2025, and the public notification to former customers...
AI summary Ms. Ralph found that NS Power's two-month delay in notifying former customers about a data incident was unreasonable. She noted that NS Power should have been aware of former customer data in its systems and should have assessed if it was impacted. Best practices require notification within days unless extenuating circumstances exist, which were not identified.
17 Expert Opinion 18 I disagree with this finding. While I agree that it is important to take steps to identify whether 19 sensitive personal data was affected in an incident and act quickly to notify as soon as feasible, a 20 finding of u...
AI summary The expert disagrees with the finding of unreasonableness regarding NS Power's handling of a data incident, emphasizing the contextual nature of reasonableness and the operational challenges of notifying former customers without reliable contact information.
3 Rationale - 4 Individualized Data Element Identification Was Not Reasonably Feasible on the Notification - 5 Timeline - 6 The record establishes clearly that the absence of customer-specific data element information in - 7 the notices wa...
AI summary The text discusses the rationale for not providing individualized data element identification in breach notifications, citing forensic impossibility and the need for speed. It notes that NS Power provided clarity regarding SIN exposure through two letter versions, which was deemed appropriate.
11 RECOMMENDATIONS - 12 Recommendation 4: That the Board Direct NS Power to Update Its Communications Policy - 13 to Require a Minimum of Two to Three Direct Notifications to All Customers and Not - 14 Only Those Potentially Affected in th...
AI summary The recommendation suggests that the Board direct NS Power to update its communications policy to ensure a minimum of two to three direct notifications are sent to all customers, not just those potentially affected, in the event of future privacy breaches.
20260819-1Hearing Transcript — 08/19/2026 (Chris Lanteigne, Lia MacDonald, Glen MacLeod, Blake Williams)
10 passages
- on anything sort of specific or from his point of view in terms of what we mean by those words. - A. (Williams) I certainly agree with what Ms. MacDonald has said, sir. There's no one aspect to this that I can point to that's demonstrati...
AI summary The discussion emphasizes the importance of accountability and transparency in regulatory processes, highlighting the need for a comprehensive approach in interactions with regulatory bodies such as the OPC. It stresses the significance of how processes are conducted, including evidence provision and responsiveness.
NOVA SCOTIA POWER PANEL 441 Questions, (Deveau) 1 actions that we'll take forward. 10 the company recognized that you shouldn't be retaining 11 SIN numbers, so I'm just I'm just wondering you were 12 able to do in 2025 within nine months....
AI summary The Nova Scotia Power Panel discusses the company's actions taken to enhance its governance program, including the revised role of the Privacy Officer and changes in reporting structure. The discussion centers on the urgency of implementing these changes and the technical risks involved in the CIS system.
INTERNATIONAL REPORTING INC. CERTIFIED COURT REPORTERS 1 the Board of Directors on the cycle? 2 A. (Williams) Just referring with 3 Ms. MacDonald, and neither of us are aware of that, that 4 what you're describing there, but I think it's t...
AI summary The discussion revolves around a compliance program within Nova Scotia Power, referred to as Optro, which is used to track compliance with legal and internal obligations. The witness clarifies that the program is new but not a new compliance tool, with references to page 61 and line 23 of the document.
1 the business area. So again, this is not just as 2 you'll see here, it's not just in relation to something 3 like privacy. It's any and all compliance obligations 4 that the company may have. 5 Q. CRA deductions and that sort of 6 thing?...
AI summary The discussion focuses on compliance obligations within a business area, including CRA deductions and the transition from the former name AuditBoard to Optro as an interim measure. The process is described as automated and managed by the internal compliance team.
NOVA SCOTIA POWER PANEL 465 Questions, (Deveau) 1 there's not necessarily a 2 So there's a screen that says Q. 3 A. (Williams) That's right. 4 And the privacy policies are part Q. 5 of that screen? They're part of that? 6 (Williams) It wou...
AI summary The text contains a portion of a regulatory proceeding involving Nova Scotia Power, discussing privacy policies and their compliance with development regulations. The discussion includes references to audits and interim measures related to policy updates. The session was interrupted and reconvened later.
NOVA SCOTIA POWER PANEL 491 Questions, (Deveau) INTERNATIONAL REPORTING INC. CERTIFIED COURT REPORTERS 1 2020, that the date on their last reviewer. They would 2 not have been reviewed in the interim between 2020 and 3 now, just because th...
AI summary The discussion revolves around the review of privacy policies by Nova Scotia Power, referencing the existing legislation in 2020 and the impact of new federal legislation and AI technology on the need for policy updates. The speaker affirms that the policies at the time of the incident complied with applicable privacy legislation.
NOVA SCOTIA POWER PANEL 503 Questions, (Deveau) 1 it's an audit of access to information that is made 2 no formalized review of compliance or the policies 3 themselves on a regular basis, on a regular cycle; it 4 depends on what the intern...
AI summary The discussion focuses on Nova Scotia Power's audit practices and customer privacy policy, highlighting gaps in compliance reviews and the handling of customer information retention and destruction following a data breach.
VALDETERO 633 1 Q. Okay. Thank you. 2 AKCAKIRYAN: Those are all my MS. 3 questions. 4 THE CHAIR: Thank you. 5 Industrial Group? 6 MS. RUDDERHAM: No questions, 7 Mr. Chair. Thanks. 8 THE CHAIR: Department of Energy? 9 KAYTER: No questions,...
AI summary This excerpt from a regulatory proceeding includes cross-examination of Ms. Valdetero by Mr. Mahody, focusing on her experience with data privacy and security in regulated utilities, including telecommunications providers and utilities in the United States. She discusses her role as external counsel for multiple companies.
INTERNATIONAL REPORTING INC. CERTIFIED COURT REPORTERS different area. THE CHAIR: Yeah. Well, why don't we move on to that one then? BY MR. MAHODY: Q. All right. Ms. Valdetero, could I take you in your evidence to your critique of Ms. Ralp...
AI summary The discussion centers on the reasonableness of the timeframe for notifying former customers of a data breach by Nova Scotia Power. The witness, Ms. Valdetero, indicates that a period from May 1st to June 25th, 2025, was considered reasonable, taking into account the resources required to address the breach.
been reasonable, but given all that needed to happen in that timeframe, from when they first identified and I wasn't sure when they first identified former customers, but I was still basing it off INTERNATIONAL REPORTING INC. CERTIFIED COU...
AI summary The testimony discusses the timeline and approach taken by Nova Scotia Power regarding customer notification following a data breach. The witness acknowledges the May 1st public announcement and subsequent October 31st direct mailing as a more individualized outreach step.