N-1Letters of Comment - Redacted
42 passages
llace acting as Chief Clerk of the Nova Scotia Energy and Regulatory Boards Tribunal Kim Adair acting as Auditor General for the Office of the Auditor General of Nova Scotia Enclosed Documentation 1. NSERBT Decision – Matter M11099 (Augus...
AI summary A data breach at Nova Scotia Power (NSP) has raised concerns about customer data security and fairness, with NSP's lack of infrastructure upgrades and privatization-related price increases exacerbating public dissatisfaction. The breach notification offers a monitoring service, but customers question accountability and cost distribution.
aspects as a cost will be downloaded to the voters who are also customers. Where is the fairness? NSP has not maintained upgrades to the grid in an acceptable manner, nor to its data infrastructure. I am very angry about this as I have no...
AI summary Katie Campbell criticizes NSP for poor grid/data infrastructure maintenance and lack of alternatives, demanding government intervention. A DRO decision on May 13, 2025, addresses a complaint about mishandled data breaches, delayed notifications, and unresolved privacy issues.
…/2 -2 - 3) Provide comprehensive identity protection through a credible provider; 4) Provide in writing, a clear acknowledgement that NS Power was the care holder of my Personal and Private information, as they had requested it from me, b...
AI summary The complainant alleges NS Power failed to protect personal data during a cyberattack, leading to the theft of 280,000 Nova Scotians' information. They demand identity protection, written acknowledgment of NS Power's data stewardship, and an explanation for restoring public trust, citing delayed breach disclosure and ongoing access barriers.
ainting-MacLean, Kimberly To: Painting-MacLean, Kimberly Subject: FW: NOVA SCOTIA POWER - FURTHER COSTLY OUTCOMES TO ALL CANADIANS Date: May 26, 2025 9:24:14 AM From: Susan Simons Sent: May 25, 2025 5:27 PM To: Premier ; [email protected]...
AI summary The email highlights the risks of Nova Scotia Power's security breach, exposing 280,000 Nova Scotians' personal data on the dark web. It warns of potential large-scale fraud and theft, drawing parallels to pandemic-era tax fraud. The breach is argued to empower criminals and terrorists to exploit data for financial gain.
repeated, given the NS Power security breach? A reply is requested and sincerely would be appreciated, by both levels of government to both questions. Thank you. Type of complaint: Other
AI summary The text raises concerns about a repeated security breach by NS Power and requests a response from both levels of government. The complaint is categorized as 'Other,' indicating it does not fall under standard regulatory or program topics.
Additional details: Cyber Security management negligence: I have contacted the NS Energy Board regarding the NS Power cyber security breach on 23 May 25. I noted that on 10 Mar 25 CBC (Blair Rhodes) issued a story that NS Power had request...
AI summary The text highlights NS Power's cybersecurity vulnerabilities, citing a $6.8M upgrade request and 12 critical sites exposed in a 2025 breach. The author argues that core cybersecurity services should be baseline-funded by NS Power, not requiring regulatory approval, due to federal obligations and current threat levels.
Page 2 of 3 How do they want the I expect PROMPT action from the NS Energy Board on this complaint resolved? ongoing cyber threat. The fact that the NS Energy Board continued to pursue a standard 90 day review period without triaging and e...
AI summary A complainant criticizes the NS Energy Board for delaying action on a cybersecurity threat, urging expedited review and self-funding by NS Power. They argue the board's standard 90-day process is inadequate, NS Power's negligence exposed 280,000 Nova Scotians to data theft, and a special board could have accelerated approval for cybersecurity measures.
making cyber security vulnerabilities a priority has resulted in mine and 280,000 other Nova Scotians vital credit information to be stolen and sold on the Dark Web. My financial vulnerability was wholly avoidable if NS Power had acted muc...
AI summary A data breach involving NS Power exposed 280,000 Nova Scotians' credit information due to cybersecurity vulnerabilities. The complainant criticizes NS Power for delayed action and demands the NS Energy Board improve consumer protection and regulatory oversight. Supporting documents include security risk analyses and privacy complaints.
C.pdf Raw Headers Missing Policies.pdf Obfuscated JS Snippet.pdf Missing Headers Summary.pdf Footer 2019 Timestamp.pdf From: Jame Y Sent: May 26, 2025 7:06 AM To: [email protected]; [email protected]; [email protected]; chie...
AI summary A privacy complaint is submitted regarding a Nova Scotia Power data breach and the use of an insecure remedial platform (mytrueidentity.ca). The complainant, YungYu Yeh, argues the platform exposes affected individuals to further cyber risks, citing technical analysis and evidence from IT student Meng Cheng Yeh.
ce of the Information and Privacy Commissioner for Nova Scotia Subject: Formal Privacy Complaint Regarding NS Power Data Breach and Insecure Remedial Platform (mytrueidentity.ca) Dear Commissioner, My name is YungYu Yeh, A victim of NS pow...
AI summary A privacy complaint is filed against NS Power regarding a data breach and the insecure remedial platform mytrueidentity.ca. The complainant highlights significant security flaws in the site, including unsafe headers, broken code, lack of HTTPS enforcement, and reliance on third-party scripts, which could expose sensitive data to attacks.
tive Summary: Security Risks of Entering Credit Card Information on mytrueidentity.ca 2025年5⽉24⽇ 晚上8:37 收件者: Grace C Based on a thorough technical analysis of the mytrueidentity.ca website due to the recent cyber incident impacting Nova Sc...
AI summary A technical analysis of mytrueidentity.ca reveals significant security risks, including missing security headers, broken JavaScript, lack of HTTPS redirection, and outdated practices. These vulnerabilities expose users to data breaches and cyber threats, particularly concerning Nova Scotia Power's recent cyber incident.
19, suggesting a lack of ongoing maintenance or security review. Use of deprecated practices like X-XSS-Protection and reliance on legacy JavaScript libraries further confirms this. Conclusion: mytrueidentity.ca does not meet modern web se...
AI summary The document highlights significant web security vulnerabilities on mytrueidentity.ca, including outdated practices and missing security headers, which expose users to cyber risks when handling financial data. It advises Nova Scotians against submitting personal information on the platform. The analysis was conducted by Meng Cheng Yeh, an IT student, with attached evidence of security flaws.
TransUnion credit monitoring services. When I called the number, I was connected with TransUnion. This limited response is not enough support for victims of a data breach of this size. In closing, I request that Nova Scotia Power immediate...
AI summary Melissa Marsh alleges a data breach by Nova Scotia Power (NSP) compromised her personal information, requesting detailed breach specifics, explanations for delayed notification, enhanced identity protection, and improved cybersecurity protocols. She criticizes NSP's current response as inadequate for protecting customer data and ensuring transparency.
Page 3 of 4 Supporting documents • 1000004479.jpg uploaded: Page 4 of 4 Type of complaint: Other Additional details: The recent cyber attack at NS Power has left me feeling vulnerable. The 2 yr credit monitoring with Transunion offered is...
AI summary A customer is concerned about the vulnerability caused by a recent cyber attack at NS Power and the inadequate credit monitoring solution provided. The customer finds the process of managing credit monitoring with Transunion cumbersome and believes NS Power should not require customers to provide their SIN. They also call for better data protection measures.
of the Privacy Commissioner of Canada Crystal Henwood, Clerk of the Board, Nova Scotia Energy and Regulatory Boards Tribunal Rod Wilson, MLA Halifax Armdale Lena Metlege Diab, MP Halifax West From: Painting-MacLean, Kimberly To: Painting-M...
AI summary This email discusses a potential source of a cyber breach on the NS Power corporate network and includes various attachments related to the incident, including articles and job postings. The email was sent to Rebecca Brown and includes a warning about external emails and caution regarding attachments and links.
ng, As discussed today, please consider this synopsis of a potential source of the cyber breach on the NS Power corporate (non-operational) network. For your further review and further investigation. On or about 20 May 2025, I received a l...
AI summary The letter discusses a cyber breach on NS Power's corporate network, referencing a 2019 project (M09301) that implemented a Security Information Event Monitoring (SIEM) tool and Security Operations Centre (SOC) service. The author requests disclosure of costs associated with the SOC service provided by Service Now.
vendor have not been reflected anywhere in this capital project. I suggest that NS Power be asked to disclose what they have spent for this SOC service from the inception of this project to its close. The SOC “is designed to identify in re...
AI summary The text raises concerns about the lack of transparency in NS Power's spending on the SOC service and questions whether necessary software updates have been performed, given the hybrid lower-cost option chosen, which places the onus on internal IT staff.
ption appears to have left the onus with internal NS Power IT employees to setup new server hardware and software and to perform routinely and timely software updates on this new software as required. As I understand it, NS Power is oblige...
AI summary The document highlights concerns about NS Power's delayed implementation of cybersecurity measures for its corporate network, noting that the project was put on hold from 2017 to 2018 due to dependencies with other IT work. Despite known threats, the corporate network lacks adequate safeguards, raising questions about regulatory oversight and resource allocation.
2 that “this capability does not exist today”. With well know threats and vulnerabilities, it appears that NS Power carried on operating the corporate network for years without suitable safeguarding. It is not clear how long NS Power has c...
AI summary The document highlights concerns about NS Power's cybersecurity practices, specifically the lack of adequate safeguards for the corporate network and the unclear timeline for establishing SOC vendor services from Service Now. It questions the effectiveness of the hybrid approach used to connect to Service Now's SOC services.
demands. Further, regarding IR-6, it is not clear how the ‘hybrid’ approach allowed NS Power to safely and securely establish a network connection to Service Now while using Service Now SOC services. IR-20 discusses the in-house and hybrid...
AI summary The text raises concerns about NS Power's implementation of a hybrid approach for network security with Service Now, questions whether the hybrid model is still in use, and highlights potential vulnerabilities due to unpatched software. It also connects a data breach to a known security vulnerability exploited by hackers.
From: Painting-MacLean, Kimberly To: Painting-MacLean, Kimberly Subject: FW: DRO 31 May re Sean Kelly re Data Breech Date: June 4, 2025 9:50:04 AM From: Sean Kelly Sent: June 3, 2025 10:27 PM To: [email protected] Cc: customer...
AI summary Sean Kelly criticizes the poor quality of regulations, arguing they favor the company and neglect customer privacy and data security. He questions the board's role in protecting Nova Scotians and highlights the lack of clarity on who is responsible for creating the regulations. He also references CMMC data security requirements and requests a meeting with the board.
Disput e Resolution Officer From: Sean Kelly Sent: May 26, 2025 7:19 PM To: [email protected] Subject: Data Breech I am writing on behalf of myself and my wife Michelle Kelly. We live at Nova Scotia. We have received a letter...
AI summary Sean Kelly and Michelle Kelly are reporting a data breach involving their personal information, which was published without their knowledge. They express dissatisfaction with the lack of notification, inadequate security measures, and the 2-year credit coverage offered as compensation, which they consider insufficient. They seek fair compensation based on previous data breach settlements.
Page 2 of 4 We are left unsure of what steps to take or what risks we truly face. 3. Inadequate Support NS Power offered 2 years of free credit monitoring via TransUnion of Canada Inc. While somewhat helpful, this offer falls short. Expert...
AI summary The customer expresses concerns about inadequate support following a data breach, questioning NS Power's data retention practices and requesting a meter inspection and billing review. They demand a full investigation into data security practices, compliance with privacy laws, and expanded protection for affected customers.
nd other relevant bodies. I hope NS Power will do the right thing and take this matter seriously. Sincerely, Elizabeth Hartling Type of complaint: Other Additional details: I am writing to formally complain about Nova Scotia Power's handli...
AI summary A customer is complaining about Nova Scotia Power's delayed and inadequate response to a data breach that occurred in March 2025, which was only disclosed in May 2025. The customer is concerned about the lack of specific information provided regarding the stolen data and the delayed notification.
ormation of mine was compromised in this breach. Explain the delay between discovering the breach (April 25) and notifying me (May 13). Offer comprehensive identity protection services beyond basic credit monitoring, and for an adequate le...
AI summary The letter from Lesley Hartman addresses a data breach involving the compromise of personal information, expressing concerns over the delay in notification and the adequacy of the response. The letter requests comprehensive identity protection services, improved cybersecurity protocols, and a more transparent and detailed response to the breach.
How do they want the I request that you urge Nova Scotia Power to: Provide me with complaint resolved? a detailed, specific account of exactly what personal information of mine was compromised in this breach. Explain the delay between disc...
AI summary The complainant requests Nova Scotia Power to provide detailed information about the data breach, explain the delay in notification, offer comprehensive identity protection, and improve cybersecurity protocols to prevent future incidents and ensure transparency and support for affected customers.
lamed for things I didn’t do. I can’t afford any costs incurred, I can barely afford food. I got a call back from the same rep, not his supervisor and was told that I wasn’t one of the people hacked. I don’t think allowing the same people...
AI summary The text includes a customer's complaint about a cyber incident involving Nova Scotia Power, expressing concerns about accountability, transparency, and potential harm from negligence. A follow-up email from Kimberly Painting-MacLean references the incident to the NSUARB.
chments or clicking on links / Faites preuve de prudence si vous ouvrez une pièce jointe ou cliquez sur un lien Good Day, I am writing this morning about the recent Nova Scotia Power cyber incident. After this issue came to light, NSP sent...
AI summary Clarence Whynot criticizes Nova Scotia Power (NSP) for its inadequate response to a cybersecurity incident that exposed customer personal information. He argues that NSP should provide detailed disclosure of affected data and explain why SINs were stored. He also expresses frustration over the lack of accountability and transparency.
unacceptable. Customers should not be on the hook for any losses accrued as a result of this outage. Did they contact the utility? No How did the utility respond? How do they want the NS Power should not be permitted to increase rates to c...
AI summary A customer is expressing concern over a data breach at Nova Scotia Power, highlighting the lack of long-term protection for personal information and dissatisfaction with the two-year credit monitoring offer. The customer feels abandoned after this period and fears ongoing risks to their credit and identity.
m really asking and if you are correct point of contact that it be disscussed within your group. The situation with NSP may not change I understand. Jim Charumski Type of complaint: Other Additional details: corporate responsibility: 1) wh...
AI summary The complaint discusses NSP's handling of a cyber attack and billing practices, including why NSP informed the complainant of a cyber attack but did not provide email coverage for 5 years, and how NSP covers penalties for double billing without informing customers. The complainant also references a CBC News article about NSP's billing practices following a ransomware attack.
loaded: Page 2 of 2 Yours truly, Timothy Leary ++++++++++++++++++++++++++++++++++++++++++ On 2025-07-15 3:01 p.m., Privacy Officer wrote: Dear Mr. Leary, We are writing in response to your request for a detailed account of what personal in...
AI summary Nova Scotia Power's Privacy Officer informed Timothy Leary that it is not possible to determine precisely what personal information, if any, was compromised in a recent cyber attack on their systems. The investigation is ongoing with cybersecurity experts, and further updates will be provided if more specific information is identified.
dividual basis. However, if we are able to determine more specific information in the future, we remain committed to keeping our customers informed and will communicate any material updates directly. From our investigation, we do know that...
AI summary Nova Scotia Power has experienced a data breach involving personal customer information. The company is offering free credit monitoring to all customers and encourages them to sign up using a provided verification form. The breach included sensitive data such as names, contact details, account history, and financial information.
.ca Cc: Board, NSUARB ; Premier ; Subject: Complaint Some people who received this message don't often get email from . Learn why this is important EXTERNAL EMAIL / COURRIEL EXTERNE Exercise caution when opening attachments or clicking on...
AI summary The complainant expressed frustration with NS Power's process for handling a cyber incident, particularly the difficulties encountered when trying to set up an account with TransUnion and the ineffective callback system provided by the representative.
Alternate phone number: Complaint Information Page 1 of 2 Type of complaint: Other Additional details: The NSP cyber breach occurred on 19 March 2025, but NSP only became aware on 25 April 2025, 37 days later. My notification was received...
AI summary The complainant alleges that Nova Scotia Power (NSP) delayed notification of a cyber breach that occurred on 19 March 2025, with NSP becoming aware on 25 April 2025 and the complainant being notified 63 days later. The complainant criticizes NSP's response as ineffective and requests a complete answer regarding the information liability and exposure related to the breach.
ire a complete answer concerning my information liability complaint resolved? and exposure. In other words, what information of mine did the cyber criminals take? Supporting documents • NSP Privacy Officer.pdf uploaded: • 2025-07-18 Peter...
AI summary The document is a complaint regarding a data breach at Nova Scotia Power (NSP), highlighting concerns about delayed notification, inadequate cybersecurity measures, and the potential exposure of customer information. The complainant seeks answers on whether the breach is ongoing, the cause of the delay, how security was bypassed, and whether the breach was deliberate or due to human error.
April?) How were your security procedures bypassed? (For example, social engineering, malware, tech failure etc.) Was this a deliberate attack or was this human error? I request that NSP provide: Detailed list of my information that was ac...
AI summary A complaint regarding a data breach involving Nova Scotia Power (NSP) is raised, with concerns about how security procedures were bypassed and whether personal and spouse’s information was compromised. The complainant requests detailed information about the breach and emphasizes the need for critical infrastructure corporations to protect personal data.
Page 2 of 5 Additional details: Primary Complaint is attempted Secrecy. On July 18, 2025, I wrote to Peter Gregg and asked a simple, sincere question: “Why should I pay my power bill?” Months after Nova Scotia Power’s (NSP) cyber incident,...
AI summary The text discusses a complaint regarding Nova Scotia Power's (NSP) cybersecurity incident and its attempts to maintain secrecy. The complainant is demanding an apology, full explanation, and a moratorium on rate increases for two years. The text highlights the risks posed by supply chain vulnerabilities and the persistent targeting of the electricity sector by state-sponsored cybercriminals.
ss network defences. If NSP uses components with these vulnerabilities, the problem is not only mismanagement but a systemic exposure that demands more than an apology. The purpose of targeting utility telecommunications is clear: harvest...
AI summary The text highlights concerns about NSP's cybersecurity vulnerabilities, emphasizing that systemic exposure from unaddressed network weaknesses could lead to serious consequences, including disruptions to critical infrastructure and operations at strategic sites like CFB Halifax. It criticizes NSP's lack of effective cyber defense measures, such as real-time threat detection and zero trust architecture.
d a zero trust architecture— measures that detect and limit the damage of targeted campaigns. I am informed these measures are not fully in place at NSP.
AI summary The text mentions the need for a zero trust architecture to detect and limit damage from targeted campaigns, noting that these measures are not fully implemented at NSP.
ny rate increases is a reasonable and necessary measure while trust is being rebuilt. Finally, regulators should require a third party audit of NSP’s supply chain and cyber defences. Longer term, this incident should prompt legislative and...
AI summary The text argues that rate increases are necessary while trust is rebuilt, calls for third-party audits of NSP’s supply chain and cyber defences, and advocates for legislative changes to improve breach notification and cyber security standards. It questions the justification for paying higher bills and emphasizes the need for competence and accountability from NSP.
? How do they want the The Board inquiry into the cyber security breach must be public complaint resolved? in it's entirety. Supporting documents • image.png uploaded: Page 5 of 5 From: Board, NSUARB To: Painting-MacLean, Kimberly Cc: Henw...
AI summary A concerned individual, Weldon Young, is inquiring about the transparency of NS Power's handling of a cyber security breach that occurred in Spring 2025, emphasizing the need for NS Power to inform customers about the personal information that was accessed and retained.
Hello, to whom it may concern, I pre-apologize for my grammar. this is an email i'm sending to be brought forward to the top levels of nova scotia power to understand and let people know that your recent cyber attack that you mentioned was...
AI summary The email discusses a customer's experience with Nova Scotia Power following a cyber attack, expressing concerns about ongoing security issues and an unusual account verification process involving excessive personal information questions.
N-2NSPI (NSEB) RIR 1 to 12 - Redacted
101 passages
REDACTED (CONFIDENTIAL INFORMATION REMOVED) Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary The document outlines a Board Inquiry into Nova Scotia Power's cybersecurity incident, referenced as NSEB M12273, with responses from Nova Scotia Power to information requests.
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED 1 Request IR-1: 2 3 Please provide a timeline of this cybersecurity incident, including: 4 5 (a) the date of the bre...
AI summary Nova Scotia Power's cybersecurity incident (NSEB M12273) was discovered on April 25, 2025, with an ongoing investigation. NS Power engaged Osler and Mandiant for response, but details remain under investigation.
er activated its established 29 incident response and business continuity protocols, and engaged Osler, and through Osler, 30 Mandiant’s cybersecurity and incident response team. Date Filed: September 5, 2025 NSPI (NSEB) IR-1 Page 1 of 18...
AI summary Nova Scotia Power (NSPI) activated incident response protocols and engaged Osler and Mandiant's cybersecurity team following a cybersecurity incident. The Board Inquiry (NSEB M12273) is examining the incident, with NSPI providing responses to information requests.
d Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary The document outlines an inquiry into Nova Scotia Power's (NSPI) cybersecurity incident, referencing responses provided to Nova Scotia Energy Board (NSEB) information requests. The matter is designated as NSEB M12273, with content redacted beyond the heading and entity mentions.
1 Under the direction of Osler, Mandiant assisted the Company and other cybersecurity 2 experts with containment, investigation, and remediation efforts, and took immediate 3 actions to contain and remediate the unauthorized activity, 4 5...
AI summary NS Power reported a cybersecurity incident involving unauthorized access and data exfiltration, notifying law enforcement agencies (RCMP, FBI, CSIS) and the OPC. The company asserts no operational systems were breached and is cooperating with investigations. The Nova Scotia Energy Board was also informed.
ively and fully cooperating with the OPC to support the OPC’s investigative efforts. 26 The Company has also provided updates to the Nova Scotia Energy Board, as well as other 27 relevant government officials throughout the Incident and in...
AI summary Nova Scotia Power (NSPI) is cooperating with the Office of the Privacy Commissioner of Canada (OPC) during a cybersecurity incident investigation and has provided updates to the Nova Scotia Energy Board (NSEB) and government officials. The context is a regulatory inquiry into the incident, referenced as NSEB M12273.
rd Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary The Nova Scotia Energy Board (NSEB) is conducting an inquiry into a cybersecurity incident involving Nova Scotia Power (NSPI), with NSPI providing responses to NSEB information requests. The matter is designated as NSEB M12273, though details are redacted.
s the top search result when customers 26 used search engines (i.e. Google) to find information about the Incident. Social media 27 accounts have been regularly monitored, and where appropriate, the Company has provided 28 answers to relat...
AI summary Nova Scotia Power (NSPI) managed a cybersecurity incident by monitoring social media, addressing customer inquiries online, and maintaining operational Customer Care Centre services. The NSEB initiated a Board Inquiry (M12273) into the incident, with NSPI providing responses to information requests.
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary The document outlines an inquiry into Nova Scotia Power's cybersecurity incident (NSEB M12273), focusing on NSPI's responses to information requests by the Nova Scotia Energy Board. The content is redacted, limiting detailed analysis.
1 Customer Notification Timeline 2 3 As noted above, the Company became aware of the Incident on Friday, April 25. The next 4 business day, on Monday, April 28, 2025, NS Power informed customers that it was 5 actively responding to a cyber...
AI summary NS Power notified customers of a cybersecurity incident starting April 28, 2025, with detailed updates on May 1, 2025, and formal notices to 277,000 customers on May 13, 2025. The company engaged third-party providers for notifications and issued press releases, with senior personnel participating in media interviews to inform the public.
identify what data was impacted has been extremely complex and remains 28 ongoing. As set out in the notices sent to impacted customers, the impacted data would 29 have varied by customer, and depended, in part, on the information a custom...
AI summary The document outlines a cybersecurity incident involving Nova Scotia Power (NSPI), with the Nova Scotia Energy Board (NSEB) conducting an inquiry. Identifying impacted data remains complex and ongoing, varying by customer based on the information they provided.
d Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary The document outlines an inquiry into Nova Scotia Power's (NSPI) cybersecurity incident, referencing responses provided to Nova Scotia Energy Board (NSEB) information requests. The matter is designated as NSEB M12273, with content redacted beyond the heading and entity mentions.
tary credit 22 monitoring to five years on June 25, 2025. 23 24 The credit monitoring service offered to customers is provided by TransUnion and has been 25 specifically designed to protect individuals in the case of a data breach, and off...
AI summary Nova Scotia Power (NSPI) offers credit monitoring services via TransUnion, extending protection for five years. The service includes daily credit report access to detect identity theft. The document also references a regulatory inquiry into NSPI's cybersecurity incident (NSEB M12273) and NSPI's responses to information requests.
d Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED 1 • Unlimited online access to their credit score, updated daily. 2 3 • Credit monitoring, which provides individu...
AI summary Nova Scotia Power (NSPI) provided customers with cybersecurity incident response measures, including credit monitoring, identity theft protection, and reimbursement insurance, following a data breach. NSPI kept customers informed through updates and addressed the incident's impact via dark web monitoring and identity restoration services.
ter discovering that the threat actor had published data on the dark 26 web, NS Power promptly provided an update to customers through the same channels as 27 previous updates. 28 Date Filed: September 5, 2025 NSPI (NSEB) IR-1 Page 6 of 18...
AI summary NS Power informed customers of a cybersecurity incident where threat actors published data on the dark web, with updates provided through existing channels. The NSEB is conducting an inquiry (M12273) into the incident, with NSPI responding to information requests.
d Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary The document outlines an inquiry into Nova Scotia Power's (NSPI) cybersecurity incident, referencing responses provided to Nova Scotia Energy Board (NSEB) information requests. The matter is designated as NSEB M12273, with content redacted beyond the heading and entity mentions.
ure that the call centre had sufficient 27 capacity to handle the volume of calls and allow NS Power’s customer service team to 28 focus on a subset of escalated queries, this call centre was staffed by TransUnion 29 employees who had been...
AI summary The document outlines NSPI's response to NSEB's inquiry regarding a cybersecurity incident, including arrangements for a call centre managed by TransUnion to handle customer inquiries, with escalated issues directed to NS Power. The proceeding is referenced as NSEB M12273.
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary The document outlines an inquiry into Nova Scotia Power's cybersecurity incident (NSEB M12273), focusing on NSPI's responses to information requests by the Nova Scotia Energy Board. The content is redacted, limiting detailed analysis.
s also actively encouraged customers and its employees to reach out to their family and 25 neighbours to encourage them to sign up. Please refer to Attachment 3. 26 27 In addition, the Company deployed dozens of employees to communities ac...
AI summary Nova Scotia Power (NSPI) actively engaged customers and employees to promote program participation, including in-person support. The text references a regulatory inquiry into NSPI's cybersecurity incident (NSEB M12273) and NSPI's responses to NSEB information requests, with redacted details.
d Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary The document outlines an inquiry into Nova Scotia Power's (NSPI) cybersecurity incident, referencing responses provided to Nova Scotia Energy Board (NSEB) information requests. The matter is designated as NSEB M12273, with content redacted beyond the heading and entity mentions.
1 these community sessions have been held to date, and have assisted hundreds of customers 2 in signing up for the service. The NS Power website also has been updated with additional 3 tips and tools to help customers navigate support serv...
AI summary NS Power has conducted community sessions to support customer engagement, updated its website with tools, and implemented cybersecurity measures aligned with NIST and NERC standards. The company conducts regular training, audits, and compliance reviews to ensure robust cybersecurity practices.
onducts 26 mandatory quarterly cyber training and monthly phishing simulation testing exercises with 27 all employees to educate employees about NS Power’s information security policies and 28 common risks, and to help them understand thei...
AI summary Nova Scotia Power (NSPI) disclosed a cybersecurity incident, detailing immediate response actions including containment, engagement with third-party experts, and ongoing remediation efforts. The company also implements mandatory quarterly cyber training and monthly phishing simulations for employees. The NSEB is conducting an inquiry into the incident (NSEB M12273).
nquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED 1 2 3 4 5 6 7 8 9 10 11 12 13 14 NS Power is also advancing efforts to restore and, where necessary, rebuild core bus...
AI summary Nova Scotia Power (NSPI) is responding to the NSEB's inquiry regarding a cybersecurity incident, detailing efforts to restore business systems, establish a restoration office, and notify customers. Recovery focuses on system continuity and security protocols, with ongoing communication updates.
notifications and updates to customers throughout 26 the next several weeks of response efforts. 27 28 These communications and releases to media occurred on the following dates: Date Filed: September 5, 2025 NSPI (NSEB) IR-1 Page 12 of 18...
AI summary The document references a regulatory inquiry into Nova Scotia Power's cybersecurity incident (NSEB M12273) and NSPI's responses to information requests from the Nova Scotia Energy Board. The text highlights ongoing communications and media releases related to the incident.
rd Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary The Nova Scotia Energy Board (NSEB) is conducting an inquiry into a cybersecurity incident involving Nova Scotia Power (NSPI), with NSPI providing responses to NSEB information requests. The matter is designated as NSEB M12273, though details are redacted.
to share 27 information about upcoming customer support sessions in local communities to help 28 customers sign up for the free credit monitoring being offered by the company. 29 Date Filed: September 5, 2025 NSPI (NSEB) IR-1 Page 13 of 18...
AI summary The Nova Scotia Energy Board (NSEB) is conducting an inquiry into Nova Scotia Power's (NSPI) cybersecurity incident (NSEB M12273), with NSPI providing responses to NSEB information requests. NSPI also plans to share details about customer support sessions promoting free credit monitoring.
d Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED 1 Cape Breton – Monday, June 30, 2025 2 • The Coast 89.7FM Radio - Sydney - [email protected] 3 • MBS Radio – S...
AI summary The document outlines Nova Scotia Power's (NSPI) media responses to inquiries about customer bills and meter readers, alongside an ongoing NSEB inquiry into a cybersecurity incident (NSEB M12273). NSPI's Director of Customer Care, Chris Lanteigne, participated in interviews with media outlets and CBC programs.
Mainland (noted in chart below), as well as information being shared with 28 AllNovaScotia.com, Global Halifax, MBS Radio, Halifax Examiner and the Chronicle 29 Herald. 30 Date Filed: September 5, 2025 NSPI (NSEB) IR-1 Page 14 of 18 REDACT...
AI summary The document outlines a regulatory inquiry by the Nova Scotia Energy Board (NSEB) into a cybersecurity incident involving Nova Scotia Power (NSPI), including NSPI's responses to information requests. The proceeding is referenced as NSEB M12273, with redacted confidential details.
d Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary The document outlines an inquiry into Nova Scotia Power's (NSPI) cybersecurity incident, referencing responses provided to Nova Scotia Energy Board (NSEB) information requests. The matter is designated as NSEB M12273, with content redacted beyond the heading and entity mentions.
1 (f) Please see the following table for details on public interviews provided: 2 Member of NSP senior Date Media Outlet Format Reporter Topic leadership team Amy Smith, Peter Gregg, Anchor Cyber incident May 23, 2025 CBC TV President and...
AI summary Nova Scotia Power (NSP) provided updates on a cyber incident through public interviews on May 23, 2025, with media outlets including CBC and allnovascotia.ca. NSP leadership, including President and CEO Peter Gregg, participated in televised, radio, and print interviews.
Cyber incident May 23, 2025 allnovascotia.ca Print/Online President and Cormier update CEO Peter Gregg, Mike Cyber incident May 29, 2025 Canadian Press Print/Online President and Tutton update CEO Peter Gregg, Cyber incident May 29, 2025 C...
AI summary Nova Scotia Power (NSP) is responding to a cyber incident, with updates provided by President and CEO Peter Gregg and other officials through multiple media outlets including Canadian Press, CTV, and CBC, dated May 23-30, 2025.
Chris Customer Ryan Lanteigne, June 17, 2025 CTV TV support MacDonald Director sessions in Customer Care communities across NS CBC Chris Billing/custom Information Lanteigne, er support June 17, Morning Radio Director sessions for 2025 Mai...
AI summary The document references a cybersecurity incident involving Nova Scotia Power (NSPI) under investigation by the Nova Scotia Energy Board (NSEB) (M12273). NSPI has submitted responses to NSEB's information requests, with the document being part of the inquiry process.
rd Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED Cyber incident update Billing Chris concerns CBC Nova Elizabeth Lanteigne, July 9, 2025 Radio Customer Scotia McM...
AI summary Inquiry into Nova Scotia Power's cybersecurity incident (NSEB M12273) and responses to NSEB information requests. Media engagements include CBC Nova Scotia Radio interviews discussing the cyber incident, billing concerns, and customer support initiatives. Community sessions and meter reader interactions were also highlighted.
Mainland Customer Care asked about (to air Monday, cyber incident) July 13) 1 Date Filed: September 5, 2025 NSPI (NSEB) IR-1 Page 18 of 18 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Cybersecurity Incident NSEB IR-01 Attachment 1 Page 1 of...
AI summary Nova Scotia Power (NSPI) notified customers of a cybersecurity incident, urging vigilance against unsolicited communications. The company apologized and committed to enhancing system security through additional safeguards. Peter Gregg, President & CEO, emphasized the importance of protecting customer data.
Cybersecurity Incident NSEB IR-01 Attachment 1 Page 3 of 4 Services Description We have retained the assistance of Trans Union of Canada, Inc. (“TransUnion Canada”), one of Canada’s leading consumer reporting agencies and arranged a 24-mon...
AI summary The Nova Scotia Energy Board (NSEB) offers a 24-month subscription to TransUnion Canada's myTrueIdentity® service for credit monitoring and identity restoration, following a cybersecurity incident. Customers are encouraged to activate the service using a provided code before 9/30/2025.
hat the creditor contact you prior to establishing any accounts in your name. To place a fraud alert on your credit report, contact TransUnion Canada and Equifax Canada using the information above. 4/4 REDACTED (CONFIDENTIAL INFORMATION RE...
AI summary Nova Scotia Power has experienced a cybersecurity incident and is urging customers to be cautious of unsolicited communications requesting personal information. The company has established a dedicated customer hotline and is taking steps to strengthen system security to prevent future incidents.
Cybersecurity Incident NSEB IR-01 Attachment 2 Page 3 of 4 Services Description We have retained the assistance of Trans Union of Canada, Inc. (“TransUnion Canada”), one of Canada’s leading consumer reporting agencies and arranged a 24-mon...
AI summary The document describes a cybersecurity incident involving the Nova Scotia Energy Board (NSEB) and outlines a service provided to affected individuals, including a 24-month subscription to myTrueIdentity® for credit monitoring and identity restoration.
hat the creditor contact you prior to establishing any accounts in your name. To place a fraud alert on your credit report, contact TransUnion Canada and Equifax Canada using the information above. 4/4 REDACTED (CONFIDENTIAL INFORMATION RE...
AI summary The document provides guidance to customers of Nova Scotia Power affected by a cybersecurity incident, advising them to sign up for TransUnion’s credit monitoring service using a unique activation code provided in their letter.
cess cannot be paused or resumed after periods of inactivity. If you aren’t able to complete the enrolment process in one session, you will have to call TransUnion to complete the process. Dark Web Monitoring: Once you’ve signed up, What i...
AI summary The text provides guidance on enrolling in TransUnion's Dark Web Monitoring service and steps to take following a cybersecurity incident. It emphasizes the importance of monitoring personal information and contacting relevant authorities if suspicious activity is detected.
ments. If you notice any suspicious activity related to your Social Insurance Number, report it to the police and contact the Canadian Anti-Fraud Centre at 1-888-495-8501. 2 Sign up for Equifax’s fraud alerts and security freezes through t...
AI summary The text discusses steps for customers to take in response to a cybersecurity incident, including reporting suspicious activity, signing up for fraud alerts, and contacting financial institutions. Nova Scotia Power is offering in-person support and guidance on credit monitoring and estimated bills.
REMOVED) Cybersecurity Incident NSEB IR-01 Attachment 4 Page 1 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) CYBER INCIDENT UPDATES NEWS July 8, 2025 Since the cyber incident discovered on April 25, power m...
AI summary Following a cyber incident discovered on April 25, NS Power has been unable to communicate data from power meters to their systems, leading to paused and estimated billing. Meter readers are now being deployed to collect actual energy usage data to resume accurate billing.
REMOVED) Cybersecurity Incident NSEB IR-01 Attachment 4 Page 2 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) Wednesday, June 25, 2025 Update A dedicated team within Nova Scotia Power, along with third-party...
AI summary Nova Scotia Power is updating customers about the ongoing investigation into a ransomware attack that affected personal data of both current and former customers. The company is offering five years of free credit monitoring to all customers and has confirmed that personal information was accessed on or around March 19, 2025.
and customer correspondence), and driver’s license number. For some of our former customers, bank account numbers (for pre-authorized payment) and Social Insurance Numbers may also have been impacted. We intend to do everything we can to s...
AI summary Nova Scotia Power has experienced a cybersecurity incident impacting customer data, including personal and financial information. The company is offering expanded credit monitoring services and is advising customers to be cautious of unsolicited communications to prevent identity theft.
to be from Nova Scotia Power asking you to provide your personal information. Please avoid clicking on suspicious links or downloading attachments without confirming they are from a legitimate source. We have heard concerns about SINs, whi...
AI summary Nova Scotia Power is addressing a cybersecurity incident involving the collection of SINs and is cooperating with the Office of the Privacy Commissioner of Canada and the Nova Scotia Energy Board. The company is committed to transparency and is working to regain customer confidence.
on and response efforts remain ongoing, we have committed to be as open and transparent as possible. This meeting today is a part of that transparency. Opening remarks by Peter Gregg, President & CEO On behalf of our entire team at Nova Sc...
AI summary Nova Scotia Power's President and CEO, Peter Gregg, discusses a cybersecurity incident affecting the company and its customers. He emphasizes the company's commitment to transparency and ongoing efforts to address the breach and strengthen systems. The incident is described as a sophisticated attack by a criminal, with data stolen from the company's systems.
N REMOVED) Cybersecurity Incident NSEB IR-01 Attachment 4 Page 5 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) The privacy commissioner of Canada stated last week that: “Data breaches have surged over the p...
AI summary Nova Scotia Power discusses a recent cybersecurity incident, emphasizing their commitment to cybersecurity and alignment with NIST and NERC standards. They mention no payments to criminals and describe their response protocols, including engaging third-party experts and isolating affected systems.
ng swift actions to contain and isolate the affected systems to prevent further intrusion. Our cybersecurity program ensured that our operations systems and electric grid continue to perform as usual. As you know, the criminals stole data,...
AI summary Nova Scotia Power has taken steps to contain a cybersecurity incident, ensuring grid operations continue normally. The breach involved the theft of customer data, and affected individuals have been notified with offers of free credit monitoring. Investigations are underway by the Nova Scotia Energy Board and the Office of the Privacy Commissioner of Canada.
ns of the incident have been initiated by both the Nova Scotia Energy Board and the Office of the Privacy Commissioner of Canada. Nova Scotia Power will fully cooperate with both of these proceedings. You have my commitment that our team i...
AI summary Nova Scotia Power has confirmed a ransomware attack and is working with cybersecurity experts to restore systems and investigate. No payment has been made to the threat actor, and data has been published by the threat actor. The incident is being investigated by the Nova Scotia Energy Board and the Office of the Privacy Commissioner of Canada.
the threat actor has published data that was stolen from our systems. We are actively working with cybersecurity experts to assess the nature and scope of the information that may have been impacted. Notifications have been mailed to impac...
AI summary Nova Scotia Power is investigating a cybersecurity incident that has impacted certain IT systems. They are working with external experts to determine the scope of the impact and restore systems. Affected customers have been notified and provided with free credit monitoring services.
as impacted certain IT systems in our network. We are working with external cybersecurity experts to determine the scope of the impact and safely and securely restore and rebuild our impacted systems. While the investigation remains ongoin...
AI summary Nova Scotia Power experienced a cybersecurity incident where customer information was accessed and taken by an unauthorized third party on or around March 19, 2025. Affected customers are being notified and offered free credit monitoring. The company is working with cybersecurity experts to restore systems and is advising customers to be cautious of unsolicited communications.
be from Nova Scotia Power asking you to provide your personal information. Please avoid clicking on suspicious links or downloading attachments without confirming they are from a legitimate source. 8 REDACTED (CONFIDENTIAL INFORMATION REMO...
AI summary Nova Scotia Power detected a cyber incident on April 25, 2025, and has initiated an investigation with external cybersecurity experts. The incident involved unauthorized access to customer personal information, and law enforcement has been notified. Customers are being informed and provided with credit monitoring services.
very seriously. The security of your information is our top priority. We are working urgently to determine the full nature and scope of the data that may have been affected, and individuals impacted. If we determine that your data was affe...
AI summary Nova Scotia Power and Emera Inc. have discovered a cybersecurity incident involving unauthorized access to parts of their Canadian network and servers. The incident has not disrupted operations, but the company is investigating and advising customers to be cautious of unsolicited communications.
iscovered and are actively responding to a cybersecurity incident involving unauthorized access into certain parts of its Canadian network and servers supporting portions of its business applications. Immediately following detection of the...
AI summary Nova Scotia Power is responding to a cybersecurity incident involving unauthorized access to parts of its Canadian network and servers. The company has activated incident response protocols, engaged cybersecurity experts, and contained the affected systems. No disruption to physical operations or customer service has been reported, and no material financial impact is expected.
curity Incident NSEB IR-01 Attachment 4 Page 12 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) LATEST UPDATES July 8, 2025 • Power meters have continued to function and gather accurate energy usage data from...
AI summary Nova Scotia Power is updating customers about the ongoing cyber incident affecting their power meters. Meters are functioning but cannot communicate data, leading to estimated billing. Meter readers are now visiting homes to collect accurate data, and customers are being informed about the process and what to expect.
• We are focused on supporting our customers. We are here for regular business from 8 AM–6 PM, Monday through Friday. Please contact us at 1-800-428-6230. Wednesday, June 5, 2025 • Nova Scotia Power leadership appeared before the Nova Scot...
AI summary Nova Scotia Power experienced a ransomware attack, leading to stolen customer data. The company did not make a ransom payment, complied with sanctions laws, and is working with cybersecurity experts and law enforcement to restore systems and support affected customers.
been impacted. • Since the incident began several weeks ago, we have been actively working with the assistance of third-party cyber security experts to restore our systems safely 13 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Cybersecurity...
AI summary Nova Scotia Power has experienced a cybersecurity incident and is working with third-party experts to restore systems and investigate the breach. Affected customers have been notified and provided with free credit monitoring services. The company expressed regret over the incident and emphasized its commitment to protecting customer data.
ely sorry that this issue has occurred. Protecting the privacy and security of information held by Nova Scotia Power is something we take very seriously. Wednesday, May 14, 2025 • Nova Scotia Power continues to investigate a cyber incident...
AI summary Nova Scotia Power is investigating a cyber incident that compromised customer information stored on impacted servers. The breach occurred around March 19, 2025, and affected personal information varies by customer. Notifications are being sent to impacted account holders, and a two-year credit monitoring service is being provided at no cost.
systems in our network. • While our investigation is ongoing, we have identified that certain customer personal information was accessed and taken by an unauthorized third party. 14 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Cybersecurity...
AI summary Nova Scotia Power is informing customers of a cybersecurity incident where personal information was accessed by an unauthorized third party. The investigation is ongoing, and customers will be notified if their data was affected, with resources and support provided.
ou to provide your personal information. Please avoid clicking on suspicious links or downloading attachments without confirming they are from a legitimate source. Monday, April 28, 2025 • Emera and Nova Scotia Power discovered and are act...
AI summary Emera and Nova Scotia Power discovered a cybersecurity incident involving unauthorized access to parts of their network and servers. They have activated incident response protocols and engaged third-party experts to contain the breach, with no disruption to physical operations or customer service.
4 Page 16 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) FAQS What happened? Last updated: Tuesday, June 24, 2025 On April 25, we discovered and began actively responding to a cybersecurity incident involvin...
AI summary Nova Scotia Power experienced a ransomware attack on April 25, 2025, leading to unauthorized access to customer personal information. No ransom was paid due to legal restrictions. The company is working with cybersecurity experts and law enforcement to investigate and remediate the incident.
ION REMOVED) Cybersecurity Incident NSEB IR-01 Attachment 4 Page 17 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) • Informed impacted customers via mail and provided a free subscription to TransUnion’s cred...
AI summary Nova Scotia Power informed impacted customers about a cybersecurity incident where personal information was accessed and published on the dark web. The company is offering free credit monitoring to all customers and has resumed billing through estimated methods. The investigation is ongoing, and the ransomware attack has complicated the restoration process.
s of Nova Scotia Power—past and present—regardless of whether you received a letter from us about the incident. I’m a current customer, but I did not get a letter. Does that mean I was not affected? 17 REDACTED (CONFIDENTIAL INFORMATION RE...
AI summary Nova Scotia Power is offering five years of free credit monitoring to all current and past customers following a cybersecurity incident, regardless of whether they received a letter about the incident. Customers who already signed up for two years will be automatically extended to five years. The company is expanding the offer to ensure customer protection and reassurance.
a code and already signed up for two years of monitoring, you will be automatically extended to five years. Why didn’t you offer credit monitoring to everyone right away when this happened? Why now? Last updated: Wednesday, June 25, 2025 O...
AI summary Nova Scotia Power is expanding free credit monitoring to all customers, including former ones, following a data breach. They initially targeted confirmed affected customers but now aim to ensure broader protection. Efforts are underway to reach former customers without contact information through media and advertising.
as broadly as possible. We are actively sharing this information with media, on social media, with stakeholders, and through paid advertising to reach as many current and former customers as possible. We strongly encourage anyone who is co...
AI summary Nova Scotia Power (NSPI) is informing customers about a cybersecurity incident affecting IT systems and customer care, leading to disruptions in billing and online portal access. NSPI is offering free credit monitoring and encourages sharing information with former customers. The NSEB is conducting an inquiry into the incident.
nquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL 1 Request IR-2: 2 3 NS Power’s Thursday, May 1, 2025, cybersecurity update letter stated: 4 While our investi...
AI summary Nova Scotia Power is responding to an inquiry regarding a cybersecurity incident that may have affected customer personal information. The company is still investigating and has not yet confirmed the number of affected customers or whether former customers were impacted.
been complex given the severe nature of Date Filed: September 5, 2025 NSPI (NSEB) IR-2 Page 1 of 2 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NS...
AI summary Nova Scotia Power (NSPI) is responding to the NSEB's inquiry regarding a cybersecurity incident that may have impacted all of its customers. The company has offered free credit monitoring for five years and has notified approximately 277,000 active customers about the incident.
d Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED 1 Request IR-3: 2 3 NS Power, in its Thursday, May 14, 2025, cybersecurity update letter stated: 4 5 Beginning tod...
AI summary The NSEB is inquiring about Nova Scotia Power's cybersecurity incident, focusing on how the utility determined no misuse of personal information, communication with customers, and the selection of credit monitoring services. Specific questions address notice letters, service components, and costs.
lease list the components of this service and provide comment of their 30 appropriateness. 31 (ii) What is the cost of two-year and five-year service to the utility? 32 Date Filed: September 5, 2025 NSPI (NSEB) IR-3 Page 1 of 7 REDACTED (C...
AI summary The document outlines a series of inquiries related to Nova Scotia Power's response to a cybersecurity incident, focusing on credit monitoring periods, customer protection, and communication efforts. It includes questions about the appropriateness of service components and the cost of two-year and five-year monitoring services.
CTED (CONFIDENTIAL INFORMATION REMOVED) Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary The document outlines the Nova Scotia Energy Board's inquiry into a cybersecurity incident involving Nova Scotia Power, along with NSPI's responses to information requests. The content is redacted and contains confidential information.
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary The document outlines an inquiry into Nova Scotia Power's cybersecurity incident (NSEB M12273), focusing on NSPI's responses to information requests by the Nova Scotia Energy Board. The content is redacted, limiting detailed analysis.
direct notifications, the Company sent two versions of letters to impacted 25 current customers, samples of which are attached as Attachments 1 and 2 to IR-1. The 26 notices are identical, except that one of the notices indicates that base...
AI summary Nova Scotia Power (NSPI) provided two versions of letters to impacted customers regarding a cybersecurity incident, with one letter indicating potential impact on customers' social insurance numbers. TransUnion’s myTrueIdentity® service is highlighted as a credit monitoring and identity protection service.
d Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary The document outlines an inquiry into Nova Scotia Power's (NSPI) cybersecurity incident, referencing responses provided to Nova Scotia Energy Board (NSEB) information requests. The matter is designated as NSEB M12273, with content redacted beyond the heading and entity mentions.
1 notification and call centre services to companies which have been the victim of security 2 incidents The credit monitoring service offered to customers is provided by TransUnion 3 and has been specifically designed to protect individual...
AI summary The text outlines a credit monitoring service provided by TransUnion to individuals affected by data breaches, offering features such as credit reports, credit scores, credit monitoring, educational resources, identity restoration assistance, expense reimbursement insurance, and dark web monitoring.
ring, which monitors surface, social, deep, and dark websites for 28 potentially exposed personal, identity and financial information and helps protect 29 individuals against identity theft. 30 Date Filed: September 5, 2025 NSPI (NSEB) IR-...
AI summary The document outlines a regulatory inquiry into a cybersecurity incident at Nova Scotia Power, with responses provided by NSPI to information requests from the Nova Scotia Energy Board. The inquiry involves confidential information that has been redacted.
rd Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED 1 Nova Scotia Power anticipates that a portion of the cost for credit monitoring will be 2 covered by insurance,...
AI summary Nova Scotia Power (NSPI) is offering complimentary credit monitoring services to affected customers following a cybersecurity incident. The company extended the service to five years, citing customer feedback and concerns, and stated that insurance will cover part of the cost, ensuring customers do not bear any financial burden.
ast 30 NS Power customers. Date Filed: September 5, 2025 NSPI (NSEB) IR-3 Page 5 of 7 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Informatio...
AI summary The document outlines NSPI's responses to information requests from the NSEB regarding a cybersecurity incident involving NS Power customers. The inquiry was filed on September 5, 2025, and includes redacted confidential information.
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary The document outlines an inquiry into Nova Scotia Power's cybersecurity incident (NSEB M12273), focusing on NSPI's responses to information requests by the Nova Scotia Energy Board. The content is redacted, limiting detailed analysis.
,000 of expense reimbursement insurance related to identity theft. 27 28 • Dark Web Monitoring, which monitors surface, social, deep, and dark websites for 29 potentially exposed personal, identity and financial information and helps prote...
AI summary The document outlines Nova Scotia Power's responses to the NSEB's information requests regarding a cybersecurity incident. It includes details on expense reimbursement insurance related to identity theft and Dark Web Monitoring services aimed at protecting individuals from identity theft.
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL
AI summary The document outlines an inquiry into a cybersecurity incident involving Nova Scotia Power, with responses provided to information requests by the Nova Scotia Energy Board. The text is marked as non-confidential.
nd 28 comprehensive solution. Date Filed: September 5, 2025 NSPI (NSEB) IR-4 Page 1 of 1 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Informa...
AI summary Nova Scotia Power (NSPI) responded to a request regarding credit monitoring services, clarifying that the service was not intended as a financial reimbursement and that customers would not be charged for the service regardless of participation.
nquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL
AI summary The document outlines an inquiry into Nova Scotia Power's cybersecurity incident, referencing NSEB M12273 and NSPI's responses to NSEB information requests. It is marked as non-confidential.
1 Request IR-6: 2 3 NS Power, in its Thursday, May 14, 2025, cybersecurity update letter stated: 4 5 The types of impacted personal information varied by individual customer and 6 depended, in part, on the information provided by each cust...
AI summary The document discusses a cybersecurity incident involving Nova Scotia Power, outlining the types of personal information potentially compromised. It also raises questions about the process for customers to obtain details about their compromised information, the reasons for not sending personalized letters, and the availability of customer support.
eived by the Board and filed as Letters of Comment have noted that 31 the dedicated number (1-844-818-0376) connects users to TransUnion instead of NS 32 Power representatives: 33 Date Filed: September 5, 2025 NSPI (NSEB) IR-6 Page 1 of 3...
AI summary The document discusses a cybersecurity incident involving Nova Scotia Power (NSPI) and the Nova Scotia Energy Board (NSEB) inquiry into the incident. It mentions a dedicated phone number that incorrectly connects to TransUnion instead of NS Power representatives.
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL
AI summary This document outlines an inquiry into a cybersecurity incident involving Nova Scotia Power, with responses provided by NSPI to information requests from the Nova Scotia Energy Board (NSEB).
scalated queries, this call centre was staffed by TransUnion, which 29 had been provided with prepared responses from NS Power, and instructed to escalate any 30 queries that could not be addressed to the Company so that customers could re...
AI summary Nova Scotia Power (NSPI) used TransUnion to manage a call centre for customer inquiries related to a cybersecurity incident. TransUnion was provided with prepared responses from NS Power and instructed to escalate unresolved queries to the company. This arrangement allowed for flexible staffing and direct customer support for credit monitoring services.
iry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL 1 Request IR-7: 2 3 NS Power’s Thursday, May 23, 2025, cybersecurity update letter stated: 4 5 Notifications hav...
AI summary Nova Scotia Power (NSPI) has responded to information requests regarding resources and support provided to impacted account holders following a cybersecurity incident. The response includes customer support measures, guidance on credit monitoring registration, and outreach through various channels.
locations throughout the province. This Date Filed: September 5, 2025 NSPI (NSEB) IR-7 Page 1 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NS...
AI summary Nova Scotia Power (NSPI) has taken multiple steps to assist customers in signing up for a credit monitoring service following a cybersecurity incident. These include distributing fact sheets, providing in-person support, and updating the website with additional resources.
signing up for the service. The NS Power website also has been updated with additional 17 tips and tools to help customers navigate support services. 18 19 Credit Monitoring 20 NS Power’s notice to impacted customers included guidance for...
AI summary NS Power has taken steps to support impacted customers following a cybersecurity incident, including offering complimentary credit monitoring services for five years. The NSPI has responded to information requests from the NSEB regarding the incident.
nquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL
AI summary The document outlines an inquiry into a cybersecurity incident at Nova Scotia Power, referencing NSEB M12273 and NSPI's responses to information requests from the Nova Scotia Energy Board.
ntinued to keep customers updated regarding the ongoing incident 28 and investigation. See response to IR-1 for additional details on NS Power’s customer 29 communication efforts. Date Filed: September 5, 2025 NSPI (NSEB) IR-7 Page 3 of 4...
AI summary Nova Scotia Power (NSPI) has been communicating with customers about a cybersecurity incident and provided guidance to protect against identity theft or fraud. Information was shared via mailed letters and made available on the NSPI website.
nquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL
AI summary The document outlines an inquiry into a cybersecurity incident involving Nova Scotia Power, with responses provided by NSPI to information requests from the Nova Scotia Energy Board (NSEB).
monitoring service. The community partners or stakeholders who have reached 29 out to the Company worked to share that information with the people and groups they heard 30 from. Date Filed: September 5, 2025 NSPI (NSEB) IR-8 Page 1 of 2 RE...
AI summary The document discusses NSPI's responses to the NSEB's inquiry regarding a cybersecurity incident, including the existence of a communication policy for such incidents. NSPI provides a 'Cyber Incident Communication Playbook' as part of its response.
as Board Confidential 14 Attachment 1. Date Filed: September 5, 2025 NSPI (NSEB) IR-9 Page 1 of 1 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Cybersecurity Incident NSEB IR-9 Attachment 1 has been removed due to confidentiality. REDACTED (...
AI summary The document outlines a Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) and includes NSPI's responses to NSEB Information Requests. The content is labeled as non-confidential and includes an attachment that was redacted due to confidentiality.
uiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL
AI summary The document pertains to an inquiry into a cybersecurity incident involving Nova Scotia Power, with responses provided by NSPI to information requests from the Nova Scotia Energy Board (NSEB). The matter is referenced as NSEB M12273.
1 Request IR-10: 2 3 (a) Please list the customer services, such as pole relocation and new connection service 4 requests, that have been impacted by this breach due to the shifting of resources away 5 from these activities to support NS P...
AI summary NS Power responded to a request about customer service impacts due to a cybersecurity breach, stating there was no disruption to generation, transmission, or distribution. They acknowledged challenges in customer communication initially but resolved the issue by May 5, 2025, and implemented workarounds for service requests.
mpany during a limited timeframe. The team worked quickly to 29 address this and implemented a workaround for customers requiring service hook-ups, 30 service closures, or moves. Date Filed: September 5, 2025 NSPI (NSEB) IR-10 Page 1 of 2...
AI summary The document refers to a cybersecurity incident at Nova Scotia Power and the subsequent Board Inquiry (NSEB M12273), along with NSPI's responses to information requests from the NSEB. A team implemented a workaround for customers needing service hook-ups, closures, or moves during a limited timeframe.
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL 1 This was communicated via the NS Power website on April 30th, and the Company 2 continued to provide servi...
AI summary Nova Scotia Power (NSPI) responded to the NSEB's inquiry regarding a cybersecurity incident by expanding customer care services, providing online workarounds, and establishing an incident response line. The company continued to provide essential services and manage customer inquiries throughout the incident.
nquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL 1 Request IR-12: 2 3 Board staff understands the billing of many customers was affected by the breach, and th...
AI summary The inquiry addresses a cybersecurity incident affecting Nova Scotia Power's billing systems, leading to delayed and inflated bills for customers. NSPI confirms that billing issues are being resolved, estimated bills were issued to prevent large unexpected bills, and customers were not charged penalties or faced credit impacts.
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL
AI summary The document outlines an inquiry into Nova Scotia Power's cybersecurity incident, with NSPI providing responses to information requests from the NSEB. The inquiry is referenced as NSEB M12273.
ly to ensure that the meters are 24 safely reconnected with the system. The Company continues to work diligently to resolve 25 this as soon as possible. The use of manual meter reading is a temporary measure that was 26 implemented to prod...
AI summary Nova Scotia Power (NSPI) is addressing a cybersecurity incident and is working to restore automated meter reading processes, currently using manual readings as a temporary measure. The NSEB has initiated a Board Inquiry into the incident, and NSPI has provided responses to information requests.
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL
AI summary The document outlines an inquiry into a cybersecurity incident involving Nova Scotia Power, with NSPI providing responses to information requests from the Nova Scotia Energy Board (NSEB).
N-3Incident Report - Redacted
90 passages
REDACTED (CONFIDENTIAL INFORMATION REMOVED) Nova Scotia Energy Board IN THE MATTER OF The Public Utilities Act, R.S.N.S. 1989, c.380, as amended M12273 Board Inquiry into Nova Scotia Power’s Cybersecurity Incident Nova Scotia Power Inciden...
AI summary This document outlines Nova Scotia Power's cybersecurity incident report, submitted under the Public Utilities Act. The inquiry investigates the incident, including affected systems, data breaches, response actions, and customer communications. Key details are redacted due to confidentiality.
..................................................... 14 10 4.2 Communications to Customers ......................................................................................... 18 11 4.3 Other Stakeholders ...............................
AI summary The document outlines a regulatory proceeding structure, including sections on stakeholder communication, personal information handling, impact analysis, and recommendations for enhancing cybersecurity, policy updates, and customer engagement. It references a specific direction (M12457) and emphasizes data privacy, security measures, and procedural improvements.
.............................................................. 38 23 8.5 Collection and Retention of Personal Information ........................................................... 40 24 9.0 CONCLUSION .......................................
AI summary The document references a redacted 2025 cybersecurity incident report by Nova Scotia Power, filed on December 22, 2025. The report's content is confidential, with no details provided about the incident or its implications.
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 1.0 INTRODUCTION 2 3 In its July 14, 2025 letter regarding the cybersecurity incident (Incident) experienced by Nova 4 Scotia Pow...
AI summary The Nova Scotia Energy Board (NSEB) requires Nova Scotia Power Inc. (NS Power) to submit a cybersecurity incident report detailing the 2025 incident, including affected systems, root causes, and recovery actions. The NSEB also directed NS Power to settle vendor dues and engage MNP to investigate financial technology data compromise and data handling practices.
va Scotia Power’s Cybersecurity Incident, NSEB Letter, July 14, 2025, page 1. 2 M12273, NSEB Letter, July 14, 2025, pp. 2-3. 3 M12273, NSEB Letter, November 7, 2025, pp. 1-2. DATE FILED: December 22, 2025 Page 3 of 43 REDACTED (CONFIDENTIA...
AI summary Nova Scotia Power (NS Power) is required to submit a cybersecurity incident report, including a Gantt chart detailing recovery tasks, timelines, and progress. The Nova Scotia Energy Board (NSEB) has issued letters (M12273) requesting this information, emphasizing transparency and accountability in incident management.
M12273, NSEB Letter, November 7, 2025, p. 2. 5 M12600, Minister of Energy – Accountability for Nova Scotia Power Inc., Minister of Energy Letter, December 3, 2025. DATE FILED: December 22, 2025 Page 4 of 43 REDACTED (CONFIDENTIAL INFORMATI...
AI summary A redacted cybersecurity incident report from Nova Scotia Power Inc. (NSP) is referenced in regulatory filings (M12273, M12600). The report, dated December 2025, was submitted to the Nova Scotia Energy Board (NSEB) and the Minister of Energy. Key details remain confidential, with no explicit claims or arguments presented in the provided text.
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power (NSP) is referenced, though specific details are confidential. The document pertains to cybersecurity measures and incidents within the organization.
1 The NSEB replied to the Premier by letter on December 10, 2025, providing, in part, the following: 2 Upon receipt of your letter, the Board opened a new matter (M12600). Given the 3 connection between these issues and the Board’s ongoing...
AI summary The NSEB opened a new matter (M12600) related to issues raised by the Premier, linking it to an ongoing cybersecurity inquiry (M12273). NS Power argues that many issues, including customer billing and communications, were addressed in prior reports and that M12273 is the appropriate proceeding. The NSEB also provided additional direction due to a customer complaint (M12457).
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 2.0 THE INCIDENT 2 3 In its letter of July 14, 2025, the NSEB directed the following be included in the Report regarding 4 the In...
AI summary NS Power's 2025 cybersecurity incident report details a sophisticated breach discovered on April 25, 2025, following system outages. The NSEB directed inclusion of breach discovery, attack vectors, timeline, evidence, vulnerabilities, and breach causation. The incident involved unauthorized access to IT systems supporting business applications.
etter, July 14, 2025, p. 2. DATE FILED: December 22, 2025 Page 7 of 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSP) was filed on December 22, 2025, as part of a regulatory proceeding. The document details a cybersecurity incident, though specific information has been confidentially removed.
f 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSP) is referenced, indicating confidential information related to a cybersecurity event involving NSP. The document's content is not disclosed due to confidentiality.
1 Immediately following detection of the Incident, NS Power activated its established incident 2 response and business continuity protocols, engaging Osler, and through Osler, Mandiant’s 3 cybersecurity and incident response team. 4 5 Unde...
AI summary NS Power responded to a cybersecurity incident by activating protocols and engaging Osler and Mandiant for containment and remediation. The breach, believed to have occurred in March-April 2025, involved data exfiltration, including customer information. NS Power notified law enforcement, cybersecurity agencies, and the Office of the Privacy Commissioner of Canada.
ny also notified the Federal Bureau 25 of Investigation (FBI). 26 27 NS Power also reported the Incident to the Office of the Privacy Commissioner of Canada (OPC) 28 on May 1, 2025, with an update on May 14, 2025. The OPC initiated an inve...
AI summary NS Power reported a cybersecurity incident to the FBI and OPC, with the OPC initiating an investigation. The incident began on March 19, 2025, and NS Power isolated affected systems on April 25, 2025. No operational disruptions were caused, and the company is cooperating with the OPC.
customers in Nova Scotia. DATE FILED: December 22, 2025 Page 10 of 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 3.0 AFFECTED SYSTEMS AND DATA 2 3 In its letter of July 14,...
AI summary NS Power's 2025 cybersecurity incident report details compromised systems including ERP platforms (PeopleSoft, PowerPlan, Oracle E-Business Suite) and customer billing systems (MyAccount, Advanced Metering Infrastructure Head End System). The report follows NSEB directives to disclose affected systems and data, referencing a July 2025 NSEB letter (M12273).
3 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 • Additional systems: 2 o Aligne Fuels/Plant Information (PI) 3 o Geospatial Information System 4 o Adept Restoration 5 o Certa...
AI summary The document is a 2025 cybersecurity incident report by Nova Scotia Power, listing affected systems and tools, including additional systems, cybersecurity technologies, and data center infrastructure. It references Appendix A for detailed restoration timelines.
3 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 3.2 Data & Personal Information 2 3 The process to 4 identify the customers who were directly impacted has been extremely compl...
AI summary NS Power's 2025 cybersecurity incident report details the complexity of identifying impacted customers and the types of personal data accessed, including names, contact information, account history, and sensitive identifiers like SIN. The company issued notifications to affected customers, clarifying the scope of data exposure.
cted by the Incident. DATE FILED: December 22, 2025 Page 13 of 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 4.0 RESPONSE AND RECOVERY ACTIONS 2 3 In its letter of July 14,...
AI summary NS Power outlines its response to a 2025 cybersecurity incident, including containment measures, engagement with third-party experts, stakeholder communication, and analysis of response effectiveness. The NSEB directed inclusion of these actions in the report.
g a thorough analysis to 25 understand the full scope and nature of the Incident. 26 27 Immediate remediation actions were taken: 28 12 M12273, NSEB Letter, July 14, 2025, p. 2. DATE FILED: December 22, 2025 Page 14 of 43 REDACTED (CONFIDE...
AI summary NS Power is addressing a 2025 cybersecurity incident through immediate remediation, system restoration, and enhanced security protocols. A Recovery Process Office (RPO) was established to coordinate efforts, focusing on restoring core business systems and strengthening cybersecurity infrastructure.
21 22 23 24 25 26 27 28 29 30 DATE FILED: December 22, 2025 Page 16 of 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A redacted cybersecurity incident report by Nova Scotia Power (NSP) was filed on December 22, 2025. The document is marked as confidential, with sensitive information removed. The proceeding appears to involve NSP's disclosure of a cybersecurity incident to regulatory authorities.
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power (NSP) is referenced, though specific details are confidential. The document pertains to cybersecurity measures and incidents within the organization.
1 Existing Safeguards 2 3 At the time of the Incident, NS Power had implemented a common set of cybersecurity standards 4 and policies that are informed, in part, by the National Institute of Standards and Technology’s 5 (NIST) Cybersecuri...
AI summary NS Power implemented cybersecurity standards aligned with NIST and NERC, including five core functions: Identify, Protect, Detect, Respond, and Recover. The company updated its practices over two years to comply with evolving guidelines and industry-specific rules.
and IT 28 including, but not limited to, those mandated by the North American Electric Reliability 29 Corporation (NERC). NERC conducts extensive periodic audits (including security) of the 30 Company’s Energy Operations to ensure effectiv...
AI summary The text references North American Electric Reliability Corporation (NERC) audits of Nova Scotia Power's Energy Operations for compliance, including cybersecurity. A redacted 2025 cybersecurity incident report is mentioned, though details are confidential.
f 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSP) is referenced, indicating confidential information related to a cybersecurity event involving NSP. The document's content is not disclosed due to confidentiality.
1 NS Power maintains a cybersecurity training and awareness program and conducts mandatory 2 quarterly cyber training and monthly phishing simulation testing exercises with all employees to 3 educate employees about NS Power’s information...
AI summary NS Power implements mandatory cybersecurity training and phishing simulations for employees. It also employs multi-channel communication strategies to inform customers about data breaches, emphasizing transparency and customer-centric support through various media platforms.
rch strategy throughout the Incident to 28 ensure that the NS Power website and information appeared as the top search result when 29 customers used search engines (i.e. Google) to find information about the Incident. This paid 30 search s...
AI summary NS Power implemented a paid search strategy to ensure its website was the top search result for customers querying the Incident, aiming to mitigate fraud risks. The approach focused on maintaining visibility and controlling information dissemination during the cybersecurity incident.
3 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 official Nova Scotia Power website. Social media accounts have been regularly updated and 2 monitored, and where appropriate, t...
AI summary Nova Scotia Power (NSP) reported a 2025 cybersecurity incident, notifying customers via multi-channel communication starting April 28, 2025. On May 13, 2025, NSP directly informed ~277,000 affected customers, detailing impacted personal information and initiating third-party assistance for notifications.
28 29 On May 13, 2025, NS Power sent direct notices to approximately 277,000 current customers whose 30 personal information the Company was able to determine had been impacted in this incident. DATE FILED: December 22, 2025 Page 19 of 43...
AI summary NS Power notified 277,000 customers on May 13, 2025, about a cybersecurity incident impacting their personal information. The report was filed confidentially on December 22, 2025, as part of a regulatory proceeding.
43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 Nova Scotia Power cybersecurity incident report is redacted, with confidential information removed. The document outlines a cybersecurity incident but provides no further details due to redaction.
1 The following morning (May 14, 2025), the Company also issued a press release, provided a 2 detailed update on its website, and updated its various social media accounts, which received 3 widespread coverage in the local and national med...
AI summary NS Power informed customers about an incident through media and provided credit monitoring services via TransUnion to mitigate risks like fraud. They offered two years of complimentary services, including credit reports and alerts.
d provide them with additional reassurance. 26 27 • Access to online educational resources concerning credit management, fraud victim 28 assistance and identity theft prevention. 29 DATE FILED: December 22, 2025 Page 20 of 43 REDACTED (CON...
AI summary The document references a 2025 cybersecurity incident report by Nova Scotia Power, though the content is redacted. It includes a date filed (December 22, 2025) and mentions access to online resources for credit management and fraud prevention, though these details are not elaborated.
43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 Nova Scotia Power cybersecurity incident report is redacted, with confidential information removed. The document outlines a cybersecurity incident but provides no further details due to redaction.
1 • Access to Identity Restoration agents who are available to assist individuals with questions 2 about identity theft. In the unlikely event that an individual becomes a victim of fraud, a 3 personal restoration specialist will help to r...
AI summary NS Power provided identity theft assistance, $1M expense reimbursement insurance, and dark web monitoring to customers affected by a 2025 cyber incident. Updates were shared via website and media, and credit monitoring was extended to former customers. The company proactively mitigated risks through these measures.
dit monitoring offer to five years 28 for all current and former customers. Customers who had already registered for credit monitoring 29 had their monitoring timeframe automatically extended. 30 DATE FILED: December 22, 2025 Page 21 of 43...
AI summary Nova Scotia Power extended credit monitoring for five years for all current and former customers, with existing registrants automatically extended. A 2025 cybersecurity incident report is mentioned but redacted.
43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 Nova Scotia Power cybersecurity incident report is redacted, with confidential information removed. The document outlines a cybersecurity incident but provides no further details due to redaction.
is standard in incidents of this nature, to ensure that the call centre had sufficient capacity to 30 handle the volume of calls and allow NS Power’s customer service team to focus on a subset of DATE FILED: December 22, 2025 Page 22 of 43...
AI summary The document references a 2025 Nova Scotia Power cybersecurity incident report, noting redacted details. It highlights efforts to ensure call center capacity to manage call volumes, allowing NS Power's customer service team to focus on specific tasks.
43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 Nova Scotia Power cybersecurity incident report is redacted, with confidential information removed. The document outlines a cybersecurity incident but provides no further details due to redaction.
age with customers on reliability 23 and other customer topics of interest. 24 25 In addition, the NS Power website was updated with additional tips and tools to help customers 26 navigate support services and a fact sheet was created with...
AI summary NS Power has implemented customer outreach initiatives to improve reliability and provide guidance on identity theft protection. A cybersecurity incident report was filed in December 2025, though the details are redacted.
43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 Nova Scotia Power cybersecurity incident report is redacted, with confidential information removed. The document outlines a cybersecurity incident but provides no further details due to redaction.
omepage of the company’s website. In December 2025, 25 sessions have been held in Yarmouth, Port Hawkesbury and Truro, helping dozens of customers 26 with their bills. Additional sessions, originally scheduled for December but postponed du...
AI summary Nova Scotia Power Inc. has held customer billing sessions in multiple locations, with additional sessions planned for January 2026. A cybersecurity incident report for 2025 has been filed, though its contents are redacted.
f 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSP) is referenced, indicating confidential information related to a cybersecurity event involving NSP. The document's content is not disclosed due to confidentiality.
o this incident will 23 include a review of lessons learned, including a review of communications with customers. 24 25 4.3 Other Stakeholders 26 27 NS Power employees have been a key stakeholder audience throughout the Incident, as they w...
AI summary The incident review includes examining lessons learned and customer communications. NS Power employees, as both employees and customers, received ongoing updates via emails and in-person briefings from leadership and supervisors during the response and restoration efforts.
f 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSP) is referenced, indicating confidential information related to a cybersecurity event involving NSP. The document's content is not disclosed due to confidentiality.
1 investigation, employees were made aware of the latest information and what to expect in terms 2 of public information, increased media coverage, and senior officials appearing before various 3 provincial government committees. Where app...
AI summary NS Power communicated with employees and stakeholders during a cyber incident, providing updates on the response, payroll restoration, and establishing a new SharePoint site for information. Key stakeholders, including Efficiency Nova Scotia and NERC, were also informed.
unities. 22 NS Power also notified NERC, the Electricity Information Sharing and Analysis Center (E-ISAC), 23 and the Northeast Power Coordinating Council, and provided them with information about the 24 Incident. 25 26 As noted above, NS...
AI summary NS Power reported a cybersecurity incident to multiple organizations, including NERC, E-ISAC, and law enforcement agencies such as RCMP and CSIS, highlighting the severity and critical nature of the attack.
43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 Nova Scotia Power cybersecurity incident report is redacted, with confidential information removed. The document outlines a cybersecurity incident but provides no further details due to redaction.
1 infrastructure nature of the company and the North American electric utility industry, the Company 2 also notified the Federal Bureau of Investigation (FBI). 3 4 NS Power also reported the Incident to the Office of the Privacy Commission...
AI summary NS Power reported a cybersecurity incident to the FBI and OPC, and described its response as effective due to prior preparedness, including third-party expertise, updated incident-response plans, and simulation exercises.
-makers were 29 engaged from the outset. This facilitated timely escalation, prioritization of actions, and 30 coordinated decision-making. Internal communication and coordination among executive DATE FILED: December 22, 2025 Page 27 of 43...
AI summary Nova Scotia Power (NSP) acknowledges the effectiveness of its incident response during a cybersecurity incident, while recognizing the need for continuous improvement. The company plans to refine its incident-response plans, incorporate real-world lessons, and enhance documentation to improve future preparedness and resilience.
institutional knowledge for future responses. 19 20 The Company considers this continuous improvement approach to be an essential component of 21 responsible cybersecurity governance. DATE FILED: December 22, 2025 Page 28 of 43 REDACTED (C...
AI summary Nova Scotia Power Inc. emphasizes a continuous improvement approach as essential to responsible cybersecurity governance. The document is a redacted 2025 cybersecurity incident report filed by the company.
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 5.0 COLLECTION AND RETENTION OF PERSONAL INFORMATION 2 3 In its letter of July 14, 2025, the NSEB directed the following be inclu...
AI summary The document outlines NS Power's policies and practices for collecting and retaining personal information following a cybersecurity incident. It mentions that NS Power had established privacy policies and procedures, and it is now enhancing its privacy governance framework in response to the incident.
s are encouraged to escalate and report privacy issues and there are clear 23 reporting processes in place. 24 25 13 M12273, NSEB Letter, July 14, 2025, p. 2. DATE FILED: December 22, 2025 Page 29 of 43 REDACTED (CONFIDENTIAL INFORMATION R...
AI summary The document references a 2025 Nova Scotia Power cybersecurity incident report, which has been redacted. It also mentions a letter from the Nova Scotia Energy Board dated July 14, 2025, and outlines processes for reporting privacy issues.
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 6.0 IMPACT ANALYSIS 2 3 In its letter of July 14, 2025, the NSEB directed the following be included in the Report regarding 4 the...
AI summary The 2025 Nova Scotia Power Cybersecurity Incident Report discusses the impact analysis of a cybersecurity breach, including financial, operational, and reputational effects. The report notes no evidence of grid or energy delivery system compromise, and NS Power is committed to restoring customer trust. A reference is made to a letter from the NSEB dated July 14, 2025.
ssed this in his opening statement to the 27 Standing Committee on Natural Resources and Economic Development on November 25, 2025: 28 14 M12273, NSEB Letter, July 14, 2025, p. 2. DATE FILED: December 22, 2025 Page 30 of 43 REDACTED (CONFI...
AI summary This document references a cybersecurity incident report submitted by Nova Scotia Power in 2025, as noted in a letter from the Nova Scotia Energy Board dated July 14, 2025. The report was presented to the Standing Committee on Natural Resources and Economic Development on November 25, 2025.
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power (NSP) is referenced, though specific details are confidential. The document pertains to cybersecurity measures and incidents within the organization.
1 At Nova Scotia Power, our commitment to providing reliable power to Nova 2 Scotians has been unwavering for over 100 years. We recognize that the recent 3 cyber event has affected the trust we have built with our customers, and I want to...
AI summary Nova Scotia Power acknowledges the impact of a recent cyber event on customer trust and service, including billing disruptions. The company is taking steps to resolve issues such as overestimated bills, payment delays, and longer wait times, while also removing social insurance numbers from systems and working to reconnect customer meters by the end of March.
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power (NSP) is referenced, though specific details are confidential. The document pertains to cybersecurity measures and incidents within the organization.
1 6.2 Assessment of Potential Harm 2 3 As outlined above, NS Power determined through its investigation that certain customer 4 information stored on the impacted servers was accessed and taken by an unauthorized third party. 5 However, wh...
AI summary NS Power acknowledges a data breach impacting customer information but has no evidence of misuse or financial harm. The company emphasizes transparency and customer support, and confirms no disruption to service or billing operations. Concerns about billing processes are being addressed seriously.
concern and disruption it has caused customers. NS Power has never 25 intentionally overbilled its customers and has been steadfast and consistent in its commitment to 26 customers that it is actively trying to address the issues and, wher...
AI summary NS Power acknowledges concerns and disruptions caused by cybersecurity incidents and emphasizes its commitment to addressing issues and fixing mistakes. The company offers flexible billing options to affected customers. The NSEB directed NS Power to address outcomes from M12457, as outlined in Appendix C.
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 8.0 RECOMMENDATIONS 2 3 In its letter of July 14, 2025, the NSEB directed the following be included in the Report regarding 4 the...
AI summary The NSEB directed the inclusion of recommendations in Nova Scotia Power’s 2025 Cybersecurity Incident Report, focusing on enhancing security measures, conducting audits, policy updates, employee training, improving customer communication, and addressing gaps in personal information management.
14 15 16 17 18 19 20 21 22 23 24 25 26 27 DATE FILED: December 22, 2025 Page 36 of 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary The document is a redacted cybersecurity incident report filed by Nova Scotia Power Inc. on December 22, 2025, and is part of a regulatory proceeding. It contains confidential information that has been removed.
f 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSP) is referenced, indicating confidential information related to a cybersecurity event involving NSP. The document's content is not disclosed due to confidentiality.
1 8.2 Additional Security Audits, Policy Updates, and Employee Training 2 Section 4.1 addressed additional security audits, policy updates, and employee training as 3 summarized below. 4 5 Regarding security audits, NERC conducts extensive...
AI summary The document discusses NS Power's efforts to enhance cybersecurity through additional security audits, policy updates, and employee training. It mentions NERC audits, the OPC's ongoing investigation, and NS Power's alignment with the NIST Cybersecurity Framework. Employee training includes quarterly sessions and phishing simulations.
their information security responsibilities. 23 24 8.3 New Strategies and Proactive Measures 25 26 With respect to new strategies and proactive measures, please refer to section 8.1 above. 27 DATE FILED: December 22, 2025 Page 37 of 43 RED...
AI summary The document discusses NS Power's approach to customer communications following a cybersecurity incident, emphasizing transparency, timely communication, and a customer-centric focus. Actions included multi-channel public communications, paid media strategies, and social media engagement.
gle) to find information about the Incident. 18 • Updated and monitored social media accounts and, where appropriate, provided answers 19 to related customer questions online. 20 • Provided customers the ability to speak directly with NS P...
AI summary The document outlines the measures taken by NS Power following a cybersecurity incident, including customer communication through social media, direct contact options, notification of affected individuals, and provision of complimentary credit monitoring services for up to five years.
could receive more information about 5 the Incident, and support for credit monitoring sign-ups, whose number was included in 6 the notice letters and made available to customers. 7 • Staffed this call centre with TransUnion employees who...
AI summary Nova Scotia Power has taken several measures to assist customers affected by a cybersecurity incident, including providing credit monitoring sign-ups, staffing a call centre with TransUnion employees, distributing fact sheets, and deploying employees to communities for hands-on support. Approximately 375,000 customers were directly notified.
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power (NSP) is referenced, though specific details are confidential. The document pertains to cybersecurity measures and incidents within the organization.
26 In limited circumstances, NS Power continued to collect SINs from customers where there was a 27 legal requirement to do so. SINs continued to be collected for tax reporting purposes where NS 17 Peter Gregg, President & CEO, Nova Scotia...
AI summary NS Power collected SINs for tax reporting in limited circumstances due to legal requirements. A cybersecurity incident report was filed in 2025, though the details are redacted. Peter Gregg, President & CEO of Nova Scotia Power, gave an opening statement to the Standing Committee on Natural Resources and Economic Development in November 2025.
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 Power was required to issue a T5 in connection with interest over $50 earned in a year on a 2 customer deposit. 3 4 In 2021, Nova...
AI summary Nova Scotia Power reported a cybersecurity incident in 2021 involving the potential exfiltration of SINs from customer data exported for the MyEnergy Insights program. The company has since taken steps to lock down affected systems and permanently delete SINs from its records, with completion expected by March 2026.
required for tax reporting purposes, any such information identified will be securely deleted. NS 21 Power anticipates obtaining confirmation of its completion of this process by March 31, 2026. DATE FILED: December 22, 2025 Page 41 of 43...
AI summary Nova Scotia Power is expected to complete a process related to tax reporting by March 31, 2026. A redacted cybersecurity incident report was filed on December 22, 2025.
f 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSP) is referenced, indicating confidential information related to a cybersecurity event involving NSP. The document's content is not disclosed due to confidentiality.
1 9.0 CONCLUSION 2 3 NS Power trusts that the foregoing addresses the NSEB’s direction with respect to the information 4 requested in its letters of July 14, 2025 and November 7, 2025. 5 6 NS Power experienced a sophisticated cyberattack d...
AI summary NS Power responded to the NSEB's information requests regarding a cyberattack in 2025. The attack led to data exfiltration and system disruption, but no operational systems were affected. NS Power activated response protocols, engaged Mandiant, and notified multiple agencies. Customer notifications, credit monitoring, and recovery efforts are ongoing.
rking to reconnect customer meters to 27 billing systems; ongoing progress, system restoration timelines, and Board‑related matters are 28 tracked in the appended charts and monthly updates. 29 DATE FILED: December 22, 2025 Page 42 of 43 R...
AI summary NS Power discusses ongoing efforts to restore customer billing systems and business capabilities following a cybersecurity incident. They note that many of the Premier's requests have been or will be addressed through materials provided in the proceeding.
terprise resource planning systems—PeopleSoft Payroll, Resource PowerPlan, and Oracle Fusion—to ensure continuity of payroll, financial, and asset Planning (ERP) management operations. Customer Recovery and restoration of advanced metering...
AI summary The document outlines a restoration roadmap for critical systems following a cyber incident at NS Power, including enterprise resource planning systems, customer-facing platforms, and cybersecurity controls, with specific project timelines and completion percentages.
31-Oct-25 N/A PowerPlan 31-Jul-26 55% Oracle Fusion 31-Jul-26 25% CUSTOMER MyAccount 25-Sep-26 25% AMI HES 31-Mar-26 50% ADMS Resiliency 17-Apr-26 50% MV90 07-Jul-26 40% ADDITIONAL CAPABILITIES Aligne Fuels/PI 31-Dec-25 90% Adept Restorati...
AI summary The text presents a Gantt chart outlining the planned schedule for the Restoration Program Office (RPO) initiatives, including various projects with their completion percentages and dates. It notes that these timelines are subject to change due to evolving priorities and unforeseen dependencies. The chart includes sections such as PowerPlan, AMI HES, and Cybersecurity initiatives.
NS Power Cyber Incident Report Appendix B Page 1 of 7 Report 2 - Report 3 - Report 4 - Forecast Restoration of Affected Regulatory Matters Latest update October 1 November 3 December 1 Normal Activities Rates-Related Matters
AI summary This document outlines a cyber incident report for NS Power, including affected regulatory matters related to rates. It lists several reports with dates and a forecast for the restoration of normal activities, though details are limited.
NS Power Cyber Incident Report Appendix B Page 2 of 7 Report 2 - Report 3 - Report 4 - Forecast Restoration of Affected Regulatory Matters Latest update October 1 November 3 December 1 Normal Activities Customer Billing
AI summary The document provides an overview of affected regulatory matters related to a cyber incident at NS Power, with a focus on customer billing and the forecast for the restoration of normal activities.
ction to the website content. NS Power will continue to revise this content to reflect the current customer experience. In addition to the foregoing, in a recent bill insert, NS Power also informed customers of the improvements made to the...
AI summary The text discusses NS Power's ongoing efforts to update website content to reflect the current customer experience, including improvements to the online customer portal (My Account) such as new features and updated login screens for better security and user experience. It also references a redacted cyber incident report and mentions affected regulatory matters, including the Capital and Ace Plan.
As noted in the October October 1 (abridged): "As noted by the NSEB in its letter of September 17, 2025, the CIS replacement capital project has been delayed by the Incident. NS monthly update, an application Power said its investigation i...
AI summary The CIS replacement capital project has been delayed due to a cybersecurity incident, according to NS Power. The company mentioned that its investigation into the incident could impact the project's direction and timeline. An updated timeline was provided in a compliance filing (M11884) submitted to the NSEB on September 23, 2025.
be submitted to the NSEB in as shown below: ... Please refer to NS Power’s compliance filing in M11884 for further information." 2026. October 1: "In the NS-NB Reliability Intertie capital project proceeding (M12217), NS Power, on behalf o...
AI summary The document references compliance filings and a capital project proceeding related to the NS-NB Reliability Intertie. It mentions NS Power's submission of sensitivity analyses and cybersecurity implications discussed by Midgard, a consultant for Board counsel.
ltant for Board counsel, commented on this and the cybersecurity implications in its evidence of July 18, 2025:
AI summary Board counsel provided evidence on July 18, 2025, regarding cybersecurity implications in the proceeding.
"Due to an ongoing cyber incident affecting portions of NS Power’s Information Technology (“IT”) systems, WTI regenerated the sensitivity analyses using the same assumptions and modeling approach. While the outputs differ slightly from tho...
AI summary Due to a cyber incident affecting NS Power’s IT systems, WTI regenerated sensitivity analyses using the same assumptions and modeling approach. The results are similar to the original but not identical, with variances attributed to rerunning the Plexos optimization engine for a complex, multivariable, 22-year problem. The NS – NB Reliability Intertie Project has been approved by the NSEB.
been transferred to the IESO- NS. Despite these differences, WTI emphasized that “the cost variance in each case is <0.5% of the System NPVRR,” which it cited as confirming that the Reliability Intertie “enables the lowest cost long-term s...
AI summary The document discusses the impact of a cybersecurity incident on financial reporting and statements, noting that automated systems were affected. It also mentions that cost variances in the NS electricity system are considered negligible and do not indicate flaws in the modeling approach.
ements Update: Automated financial reporting and statements have been affected by the cybersecurity incident. Similar to the issue noted above under Capital Budgeting/Finance Data, certain financial systems and data are unavailable as a re...
AI summary NS Power's automated financial reporting and statements have been affected by a cybersecurity incident, leading to the use of forecast figures for unregulated adjustments in the Q1 2026 Regulated Financial Statements. Actual figures are expected to be available for the Q4 2025 Regulated Financial Statements.
December 1: "As identified in the Second Monthly Update Report, Fuel Adjustment Mechanism (FAM) related matters have been affected by the Incident. The Company has commenced preparations for the 2024/2025 FAM Audit. Significant progress wa...
AI summary The document discusses the impact of an incident on Fuel Adjustment Mechanism (FAM) related matters and the progress made in preparing for the 2024/2025 FAM Audit. The Company has made progress in recovering systems and data, including enabling cloud installation of PortOps dispatch optimization software and restoring some historical network drive information.
2025 report including the period from April 25, 2025. Once all systems are back online, any discrepancies will be trued up in future reports. Dispatch Study Action Plan Quarterly Update: "In its Dispatch Study Action Plan Quarterly Update...
AI summary The text mentions a 2025 report covering April 25, 2025, and a Dispatch Study Action Plan Quarterly Update dated December 15, 2025, which includes progress updates on the ECC Optimization Tools Project with final implementation expected by the end of March 2026. A redacted section of a cyber incident report is also referenced.
NS Power Cyber Incident Report Appendix B Page 5 of 7 Report 2 - Report 3 - Report 4 - Forecast Restoration of Affected Regulatory Matters Latest update October 1 November 3 December 1 Normal Activities Performance Standards
AI summary This document text refers to a cyber incident report by NS Power and mentions 'Performance Standards' in the context of affected regulatory matters. It includes dates and a forecast for the restoration of normal activities.
October 1: "As noted by the NSEB in its letter of September 17, 2025, the hosting capacity map and analysis has been affected by the cybersecurity incident. In Dependent on the GIS its report on the Hosting Capacity Analysis Stakeholder Wo...
AI summary The hosting capacity map and analysis for the Commercial Net Metering Program have been affected by a cybersecurity incident, causing delays in updating the map and planned 2026 enhancements. The incident impacted GIS applications, preventing updates to online maps and integration with CYME.
minimize impact, and recreating work made unavailable due to the Incident. To date, NS Power Return to normal processes for has maintained its obligations under the SGIP and DGIP with respect to timelines and processing of Interconnection...
AI summary The text discusses NS Power's efforts to maintain obligations under the SGIP and DGIP despite a cyber incident, highlighting the dependency of DGIP modelling on PI data and GIS, with an estimated ETA of March 2026.
The Residential Behaviour October 1: "As noted by the NSEB in its letter of September 17, 2025, the ability to provide relevant customer data to EfficiencyOne (E1) has been affected by program will require a the cybersecurity incident. Cus...
AI summary The NSEB noted that a cybersecurity incident has disrupted data flows from NS Power to EfficiencyOne (E1), affecting the Residential Behaviour Program. This has limited E1's access to customer consumption data from AMI meters and the My Energy Insights platform. NS Power is working to restore data flows and is meeting with E1 to discuss interim solutions.
Reliability Intertie model." to the IESO-NS Relatedly, as referenced above under NS-NB Reliability Intertie, historical PLEXOS models were unretrievable as a result of the Incident. However, as noted above, NS Power was able to recreate th...
AI summary The document discusses the impact of a cyber incident on NS Power's ability to retrieve historical PLEXOS models related to the NS-NB Reliability Intertie. NS Power was able to recreate the models temporarily, allowing continued system planning activities, with no expected impact on customers.
NS Power Cyber Incident Report Appendix B Page 7 of 7 Report 2 - Report 3 - Report 4 - Forecast Restoration of Affected Regulatory Matters Latest update October 1 November 3 December 1 Normal Activities Miscellaneous
AI summary This document is a page from a cyber incident report by NS Power, specifically Appendix B, which lists affected regulatory matters and includes reports dated October 1, November 3, and December 1. It mentions the forecast for the restoration of normal activities but provides no further details.
N-5Refiled Incident Report - NSPI - Redacted
163 passages
REDACTED (CONFIDENTIAL INFORMATION REMOVED) Nova Scotia Energy Board IN THE MATTER OF The Public Utilities Act, R.S.N.S. 1989, c.380, as amended M12273 Board Inquiry into Nova Scotia Power’s Cybersecurity Incident Nova Scotia Power Inciden...
AI summary Nova Scotia Power's cybersecurity incident report, part of a regulatory inquiry under the Public Utilities Act, details the incident, affected systems, and response actions. The report is submitted as part of a regulatory proceeding (M12273) to address the incident's implications.
Preventing Future Breaches ....................................... 38 20 8.2 Additional Security Audits, Policy Updates, and Employee Training.............................. 40 21 8.3 New Strategies and Proactive Measures .....................
AI summary The document outlines Nova Scotia Power's cybersecurity incident report, detailing measures to prevent future breaches through audits, policy updates, employee training, customer communication, and data retention policies.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 1.0 INTRODUCTION 2 3 In its July 14, 2025 letter regarding the cybersecurity incident (Incident) experienced by Nova 4 Scotia Powe...
AI summary Nova Scotia Power Inc. (NSP) is required by the Nova Scotia Energy Board (NSEB) to submit a cybersecurity incident report detailing the 2025 incident, including affected systems, root causes, and response actions. The NSEB also directed NSP to settle vendor dues and engage MNP to investigate data handling practices following a financial technology data compromise.
Board will also refer this matter to MNP to further 25 investigate causes of the NS Power’s financial technology data compromise and 26 assess its data handling practices. 1 M12273, Board Inquiry into Nova Scotia Power’s Cybersecurity Inci...
AI summary The Board will refer the matter to MNP to investigate the causes of Nova Scotia Power’s financial technology data compromise and assess its data handling practices. The incident report must include a Gantt chart detailing recovery tasks, timelines, and progress.
M12273, NSEB Letter, November 7, 2025, p. 2. 5 M12600, Minister of Energy – Accountability for Nova Scotia Power Inc., Minister of Energy Letter, December 3, 2025. DATE FILED: December 22, 2025 Page 4 of 46 20260427 REFILE 20251222 NSPI to...
AI summary A redacted cybersecurity incident report from Nova Scotia Power Inc. (NSPI) to the Nova Scotia Energy Board (NSEB) is referenced in regulatory proceeding M12273, alongside a December 2025 letter from the Minister of Energy regarding NSPI accountability. The document's confidentiality and lack of details limit further analysis.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.
1 The NSEB replied to the Premier by letter on December 10, 2025, providing, in part, the following: 2 3 Upon receipt of your letter, the Board opened a new matter (M12600). Given the 4 connection between these issues and the Board’s ongoi...
AI summary The NSEB opened a new matter (M12600) related to issues raised by the Premier, considering whether they should be addressed in the ongoing cybersecurity inquiry (M12273). NS Power argues that many issues were already addressed in prior reports and that the second set of Information Requests (IRs) under M12273 specifically handle customer billing concerns, making M12273 the appropriate proceeding.
ceeding in which to address the issues raised by the Premier without the need for a 24 new matter. 25 26 On December 10, 2025, the NSEB provided additional direction by letter stemming from a 27 customer complaint (M12457). In its letter,...
AI summary The document references a cybersecurity incident report by Nova Scotia Power Inc. (NSPI) and a board inquiry (M12273) into the incident. It also mentions a customer complaint (M12457) leading to a directive for NSPI to report on a broader regulatory review, with updates to be included in a separate process from the initial complaint.
Page 6 of 46 20260427 REFILE 20251222 NSPI to NSEB Cyber Incident Report PCON.docx REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 2.0 THE INCIDENT 2 3 In its letter of July 14,...
AI summary Nova Scotia Power Inc. (NSPI) reported a sophisticated cyberattack discovered on April 25, 2025, when employees noticed non-functional applications. Investigation revealed unauthorized access to IT systems by a threat actor, with the NSEB requiring detailed incident reporting including discovery, attack vector, timeline, and vulnerabilities exploited.
became evident that a threat actor had gained unauthorized access into certain parts of NS Power’s 26 information technology network and servers which support portions of its business applications. 8 M12273, NSEB Letter, July 14, 2025, p....
AI summary A threat actor gained unauthorized access to parts of Nova Scotia Power’s IT network and servers supporting business applications. The document references a July 2025 NSEB letter and a December 2025 cyber incident report submitted by NSPI to NSEB.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.
1 Immediately following detection of the Incident, NS Power activated its established incident 2 response and business continuity protocols, engaging Osler, and through Osler, Mandiant’s 3 cybersecurity and incident response team. 4 5 Unde...
AI summary NS Power responded to a cybersecurity incident by engaging Osler and Mandiant, containing the breach, and notifying law enforcement and regulatory bodies. The incident, detected in March 2025, involved data exfiltration starting in April 2025. No operational systems were accessed, and notifications were sent to RCMP, CSIS, FBI, and OPC.
ny also notified the Federal Bureau 25 of Investigation (FBI). 26 27 NS Power also reported the Incident to the Office of the Privacy Commissioner of Canada (OPC) 28 on May 1, 2025, with an update on May 14, 2025. The OPC initiated an inve...
AI summary Nova Scotia Power Inc. (NSPI) notified the Federal Bureau of Investigation (FBI) and the Office of the Privacy Commissioner of Canada (OPC) about a cybersecurity incident. The OPC initiated an investigation into the matter following reports on May 1, 2025, and an update on May 14, 2025.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 Incident, on May 28, 2025 and the Company is actively and fully cooperating with the OPC to 2 support the OPC’s investigative effo...
AI summary Nova Scotia Power Inc. (NSP) experienced a cybersecurity incident starting March 19, 2025, via a phishing attack leading to malware installation. The attack evolved into ransomware deployment on April 25, 2025. NSP is cooperating with the OPC investigation.
25, the threat actor began to move laterally to systems in the environment using 28 accounts with elevated privileges. The threat actor then deployed additional malware in additional 29 systems. DATE FILED: December 22, 2025 Page 9 of 46 2...
AI summary A cybersecurity incident involving lateral movement and malware deployment by a threat actor is reported by Nova Scotia Power Inc. to the Nova Scotia Energy Board, with details redacted. The incident is part of a regulatory proceeding.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 Between April 8 and April 22, 2025, the threat actor leveraged this malware to access systems in 2 the environment and to perform...
AI summary In April 2025, NS Power experienced a cybersecurity incident involving malware deployment, data exfiltration, and ransomware. The threat actor used sophisticated methods to evade detection. NS Power contained the incident by April 29, 2025, and no further activity was detected. Mandiant confirmed containment, and NS Power provided details to the Board’s consultant.
Page 10 of 46 20260427 REFILE 20251222 NSPI to NSEB Cyber Incident Report PCON.docx REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 The Incident has not caused any disruption to...
AI summary Nova Scotia Power Inc. (NSPI) reported a 2025 cybersecurity incident to the Nova Scotia Energy Board (NSEB), confirming no disruption to physical operations or electricity reliability in Nova Scotia. The incident did not affect NSPI's ability to provide safe, reliable service to customers.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 3.0 AFFECTED SYSTEMS AND DATA 2 3 In its letter of July 14, 2025, the NSEB directed the following be included in the Report regard...
AI summary NSPI's 2025 cybersecurity incident report details compromised systems including ERP platforms (PeopleSoft, PowerPlan) and customer billing systems (MyAccount, AMI Head End System) as directed by the NSEB. The report references a July 14, 2025 NSEB letter (M12273) requiring specific disclosure of affected systems and data exposure.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 • Additional systems: 2 • Aligne Fuels/Plant Information (PI) 3 • Geospatial Information System 4 • Adept Restoration 5 • Certain...
AI summary Nova Scotia Power Inc. (NSPI) submitted a 2025 cybersecurity incident report to the Nova Scotia Energy Board (NSEB), detailing affected systems including Aligne Fuels/Plant Information, Geospatial Information Systems, and cybersecurity tools like Active Directory and Data Loss Prevention Tools. Appendix A provides technical details and restoration timelines.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 3.2 Data & Personal Information 2 3 . The process to 4 identify the customers who were directly impacted has been extremely comple...
AI summary Nova Scotia Power (NSP) reported a 2025 cybersecurity incident where unauthorized access exposed customer data, including names, contact details, SINs, and account history. Identifying impacted customers was complex, and two notification letters were issued, with one highlighting potential SIN exposure. The breach included bank account numbers for some customers.
etters were substantively identical, except that one version 19 advised the customer that based on the investigation, their social insurance number may have been 20 affected by the Incident. 21 DATE FILED: December 22, 2025 Page 14 of 46 2...
AI summary Nova Scotia Power Inc. (NSPI) submitted a cybersecurity incident report to the Nova Scotia Energy Board (NSEB), disclosing customer notifications regarding potential social insurance number breaches. The report, filed December 22, 2025, details substantively identical letters sent to affected customers.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 4.0 RESPONSE AND RECOVERY ACTIONS 2 3 In its letter of July 14, 2025, the NSEB directed the following be included in the Report re...
AI summary Nova Scotia Power Inc. (NSP) reported on its response to a 2025 cybersecurity incident, including containment, threat eradication, stakeholder communication, and lessons learned. The NSEB directed the inclusion of these actions in the report, referencing Board Order M12273.
ion and remediation of the threat, and conducting a thorough analysis to 25 understand the full scope and nature of the Incident. 26 12 M12273, NSEB Letter, July 14, 2025, p. 2. DATE FILED: December 22, 2025 Page 15 of 46 20260427 REFILE 2...
AI summary Nova Scotia Power Inc. (NSPI) submitted a cybersecurity incident report to the Nova Scotia Energy Board (NSEB), outlining immediate, intermediate, and ongoing remediation actions. The document references a prior NSEB letter (M12273) and emphasizes incident analysis and threat remediation, though specific details are redacted.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 2 3 4 5 6 NS Power is also advancing efforts to restore and, where necessary, rebuild core business 7 applications and infrastruct...
AI summary NS Power is restoring core business applications and infrastructure following a cybersecurity incident, leveraging secure backups and reestablishing security protocols. A Business Restoration Process Office (RPO) has been established, with a strategic partner assisting in recovery efforts focused on business continuity and customer stability.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 2 3 4 5 6 Existing Safeguards 7 8 At the time of the Incident, NS Power had implemented a common set of cybersecurity standards 9...
AI summary Nova Scotia Power (NSP) outlines its cybersecurity safeguards aligned with NIST's framework, including Identify, Protect, Detect, Respond, and Recover functions. The company completed a two-year update to ensure compliance with evolving standards and maintains continuous improvement in cybersecurity programs.
Recover – Establishes the appropriate activities to maintain plans for resilience and to 29 restore any capabilities or services that were impaired due to a cybersecurity event. DATE FILED: December 22, 2025 Page 18 of 46 20260427 REFILE 2...
AI summary Nova Scotia Power Inc. (NSPI) submitted a cybersecurity incident report to the Nova Scotia Energy Board (NSEB), detailing measures to restore capabilities impaired by a cyber event and establish resilience planning activities.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.
1 In relation to NS Power’s operational program, NS Power’s core energy operations are designed 2 to comply with other industry-specific rules and standards relating to cybersecurity and IT 3 including, but not limited to, those mandated b...
AI summary NS Power outlines its cybersecurity compliance with NERC standards, including audits and employee training. It emphasizes transparency and multi-channel communication strategies for customer notifications following an incident, focusing on accountability and trust-building.
website and 27 social media channels, notice to all local media, and communications directly to key 28 account/business customers, government and other stakeholders in addition to employees. 29 DATE FILED: December 22, 2025 Page 19 of 46 2...
AI summary Nova Scotia Power Inc. (NSPI) submitted a confidential cybersecurity incident report to the Nova Scotia Energy Board (NSEB) on December 22, 2025, detailing a cyber incident. The report includes redacted information and was filed as part of a regulatory proceeding.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.
1 To ensure customers were kept informed, the Company also employed a multi-platform paid media 2 strategy that includes online, as well as TV, print and radio to reach a wide variety of customer 3 demographics. In addition, NS Power activ...
AI summary NS Power informed customers about a cybersecurity incident through multi-platform communication strategies, including paid media, social media, and direct customer service. Notifications began on April 28, 2025, with updates on May 1, 2025, detailing impacted customer data and scam prevention measures.
ere working 24 urgently to determine the full nature and scope of the data that may have been affected. The 25 Company also initiated the process of notifying affected individuals, including retaining third- 26 party service providers to a...
AI summary Nova Scotia Power Inc. (NSPI) is investigating the scope of a cybersecurity incident and notifying affected individuals, with third-party assistance. The report, filed on December 22, 2025, details NSPI's response to the incident and efforts to mitigate impacts.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 2 3 4 5 6 On May 13, 2025, NS Power sent direct notices to approximately 277,000 current customers whose 7 personal information th...
AI summary NS Power notified 277,000 customers of a cybersecurity incident in 2025, offering two years of free credit monitoring via TransUnion. The company issued press releases, engaged with media, and provided guidance to mitigate fraud risks. The response included daily credit report access and identity theft protections.
d is one of the primary tools 25 leveraged for determining credit-related identity theft or fraud. 26 27 • Unlimited online access to their credit score, updated daily. 28 DATE FILED: December 22, 2025 Page 21 of 46 20260427 REFILE 2025122...
AI summary A redacted cybersecurity incident report by Nova Scotia Power Inc. (NSPI) to the Nova Scotia Energy Board (NSEB) was filed on December 22, 2025. The document details a cyber incident but contains confidential information removed for redaction.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 • Credit monitoring, which provides individuals with email notifications to key changes on 2 an individual’s TransUnion Canada cre...
AI summary Nova Scotia Power Inc. (NSP) implemented measures to assist customers affected by a 2025 cybersecurity incident, including credit monitoring, identity theft protection, educational resources, and dark web monitoring. NSP also provided updates through its website and media channels after threat actors published data on the dark web.
to customers through the same channels as previous 24 updates, including updating the company’s website and social media channels, notifying local 25 media, and conducting media interviews. 26 DATE FILED: December 22, 2025 Page 22 of 46 20...
AI summary Nova Scotia Power Inc. (NSPI) submitted a redacted cybersecurity incident report to the Nova Scotia Energy Board (NSEB), detailing a 2025 incident. The report outlines communication channels used to inform customers, including website updates, social media, local media, and interviews.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.
1 Former Customers 2 3 As the Company continued its investigation of the impacted data, NS Power determined that 4 personal information relating to former customers had also been impacted by the Incident. 5 6 On June 25, 2025, NS Power not...
AI summary NS Power identified former customers affected by a data incident, extended credit monitoring to five years, and notified them through media and advertising due to lack of contact info. Additional 97,000 customers were later identified, with direct notices sent on October 31, 2025, offering credit monitoring.
Power sent direct notices to these 28 individuals on October 31, 2025, and offered them an additional opportunity to sign up for credit 29 monitoring, to the extent they have not already done so. DATE FILED: December 22, 2025 Page 23 of 46...
AI summary Nova Scotia Power has sent direct notifications to approximately 375,000 customers impacted by a cybersecurity incident, and also sent direct notices to 28 individuals offering credit monitoring.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.
pany deployed dozens 26 of employees to communities across the province to provide hands-on support for customers who 27 prefer assistance in person, recognizing that not all customers may be comfortable registering 28 online, and to ensur...
AI summary Nova Scotia Power Inc. (NSP) deployed employees across the province to assist customers in person, ensuring access to services for those uncomfortable with online registration. Over 30 community sessions were held, assisting more than 700 customers. A cybersecurity incident report was filed with the Nova Scotia Energy Board (NSEB) on December 22, 2025.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.
Page 27 of 46 20260427 REFILE 20251222 NSPI to NSEB Cyber Incident Report PCON.docx REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary This document is a redacted cybersecurity incident report submitted by Nova Scotia Power Inc. (NSPI) to the Nova Scotia Energy Board (NSEB) in 2025, detailing a cyber incident. The content has been redacted due to confidentiality.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.
o this incident will 23 include a review of lessons learned, including a review of communications with customers. 24 25 4.3 Other Stakeholders 26 27 NS Power employees have been a key stakeholder audience throughout the Incident, as they w...
AI summary The document outlines a review of a cybersecurity incident involving Nova Scotia Power, including lessons learned and communication with stakeholders, particularly employees who were impacted both as employees and customers. The report was filed on December 22, 2025.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.
1 throughout the response and restoration to date. Ahead of each public update related to the cyber 2 investigation, employees were made aware of the latest information and what to expect in terms 3 of public information, increased media c...
AI summary NS Power kept employees and stakeholders informed throughout the cyber incident response, providing regular updates, FAQs, and a new SharePoint site for information. Key stakeholders, including Efficiency Nova Scotia and the Independent Energy System Operator, were also kept informed of progress.
esentatives of the 22 Affordable Energy Coalition, and key contacts within Nova Scotia’s Mi’kmaw communities. 23 NS Power also notified NERC, the Electricity Information Sharing and Analysis Center (E-ISAC), 24 and the Northeast Power Coor...
AI summary Nova Scotia Power (NSP) reported a cybersecurity incident to multiple entities, including NERC, E-ISAC, the Northeast Power Coordinating Council, and law enforcement agencies such as CCCS, RCMP, and CSIS. This incident was also reported to Nova Scotia’s Mi’kmaw communities and the Affordable Energy Coalition.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.
1 them with information about the Incident. Given the nature of the cyber attack and the critical 2 infrastructure nature of the company and the North American electric utility industry, the Company 3 also notified the Federal Bureau of In...
AI summary Nova Scotia Power Inc. (NSP) reported a cyber attack to the FBI and OPC, and considers its response effective due to prior preparedness measures, including third-party expertise, updated plans, and simulation exercises.
. 27 28 During the Incident response, governance structures and workstreams were clearly established, 29 and appropriately experienced and skilled subject-matter experts and decision-makers were DATE FILED: December 22, 2025 Page 30 of 46...
AI summary The document outlines the response to a cybersecurity incident by Nova Scotia Power, highlighting the establishment of governance structures and the involvement of experienced experts during the incident response.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 engaged from the outset. This facilitated timely escalation, prioritization of actions, and 2 coordinated decision-making. Interna...
AI summary NSP acknowledges the effectiveness of its incident response during the 2025 cybersecurity incident but emphasizes the need for continuous improvement, including updating response plans and enhancing documentation to improve future preparedness and resilience.
institutional knowledge for future responses. 21 22 The Company considers this continuous improvement approach to be an essential component of 23 responsible cybersecurity governance. 24 DATE FILED: December 22, 2025 Page 31 of 46 20260427...
AI summary The document outlines Nova Scotia Power's cybersecurity incident report, highlighting the company's commitment to continuous improvement in cybersecurity governance as a key component of responsible management.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 5.0 COLLECTION AND RETENTION OF PERSONAL INFORMATION 2 3 In its letter of July 14, 2025, the NSEB directed the following be includ...
AI summary The NSEB directed NS Power to review its policies and practices for collecting, using, and retaining personal information following a cybersecurity incident. NS Power has since taken steps to enhance its privacy governance framework and improve its privacy program, including enhancing employee training and promoting a culture of privacy.
are encouraged to escalate and report privacy issues and there are clear 26 reporting processes in place. 27 13 M12273, NSEB Letter, July 14, 2025, p. 2. DATE FILED: December 22, 2025 Page 32 of 46 20260427 REFILE 20251222 NSPI to NSEB Cyb...
AI summary The document references a cybersecurity incident report submitted by Nova Scotia Power Inc. (NSPI) to the Nova Scotia Energy Board (NSEB), highlighting the importance of privacy reporting processes. A specific reference to a letter (M12273) dated July 14, 2025, is included.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 6.0 IMPACT ANALYSIS 2 3 In its letter of July 14, 2025, the NSEB directed the following be included in the Report regarding 4 the...
AI summary This section of the 2025 Nova Scotia Power Cybersecurity Incident Report discusses the impact analysis of a breach, including financial, operational, and reputational effects. It confirms that no operational technology or energy delivery systems were accessed, and the grid remained uninterrupted. NS Power is committed to restoring customer trust, as noted by Peter Gregg in a public statement.
ddressed this in his opening statement to the 28 Standing Committee on Natural Resources and Economic Development on November 25, 2025: 14 M12273, NSEB Letter, July 14, 2025, p. 2. DATE FILED: December 22, 2025 Page 33 of 46 20260427 REFIL...
AI summary This document is a redacted version of Nova Scotia Power’s 2025 cybersecurity incident report, filed with the Nova Scotia Energy Board on December 22, 2025. It references a prior letter from the NSEB dated July 14, 2025, and was addressed by a representative to the Standing Committee on Natural Resources and Economic Development on November 25, 2025.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.
1 At Nova Scotia Power, our commitment to providing reliable power to Nova 2 Scotians has been unwavering for over 100 years. We recognize that the recent 3 cyber event has affected the trust we have built with our customers, and I want to...
AI summary Nova Scotia Power acknowledges the impact of a recent cyber event on customer trust and service, including billing disruptions. The company is working to restore systems, address overestimated bills, and implement flexible billing options. They are also removing social insurance numbers from systems and plan to reconnect customer meters by the end of March.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.
1 6.2 Assessment of Potential Harm 2 3 As outlined above, NS Power determined through its investigation that certain customer 4 information stored on the impacted servers was accessed and taken by an unauthorized third party. 5 However, wh...
AI summary NS Power acknowledges a data breach where customer information was accessed by an unauthorized third party but has no evidence of misuse or financial harm. The company committed to transparency, timely communication, and customer support. The incident did not disrupt physical operations but affected billing systems, prompting concerns about billing processes and late fees.
the concern and disruption it has caused customers. NS Power has never 25 intentionally overbilled its customers and has been steadfast and consistent in its commitment to 26 customers that it is actively trying to address the issues and,...
AI summary NS Power is addressing a cybersecurity incident that has caused customer concerns and disruptions. The company has committed to fixing any billing errors and is offering flexible payment options to affected customers. The NSEB has directed NS Power to address broader review outcomes from M12457, with responses provided in Appendix C.
N 2 3 As noted in the introduction, the NSEB directed NS Power to address the broader review outcomes 4 arising from M12457. Each of the Board’s questions are addressed in turn in Appendix C. 5 DATE FILED: December 22, 2025 Page 37 of 46 2...
AI summary The NSEB directed NS Power to address outcomes from M12457, with recommendations including enhancing security measures, conducting audits, updating policies, and improving customer communication following a cybersecurity incident.
taken the following steps to enhance its cybersecurity environment to facilitate the 22 prevention of future breaches: 23 24 25 26 27 16 M12273, NSEB Letter, July 14, 2025, p. 2. DATE FILED: December 22, 2025 Page 38 of 46 20260427 REFILE...
AI summary The document outlines ongoing steps taken by Nova Scotia Power to enhance its cybersecurity environment following a cyber incident, though specific details are redacted. It references a report filed with the Nova Scotia Energy Board.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.
1 8.2 Additional Security Audits, Policy Updates, and Employee Training 2 3 Section 4.1 addressed additional security audits, policy updates, and employee training as 4 summarized below. 5 6 Regarding security audits, NERC conducts extensi...
AI summary The text discusses NS Power's efforts in cybersecurity, including security audits conducted by NERC, an ongoing investigation by the OPC, updates to cybersecurity policies informed by NIST, and mandatory employee training programs to ensure compliance and awareness.
r information security responsibilities. 24 25 8.3 New Strategies and Proactive Measures 26 27 With respect to new strategies and proactive measures, please refer to section 8.1 above. 28 DATE FILED: December 22, 2025 Page 40 of 46 2026042...
AI summary The document outlines NS Power's approach to customer communications following a cybersecurity incident, emphasizing transparency, timely communication, and a customer-centric strategy. Actions include multi-channel public communications, paid media strategies, and social media engagement.
e) to find information about the Incident. 18 • Updated and monitored social media accounts and, where appropriate, provided answers 19 to related customer questions online. 20 • Provided customers the ability to speak directly with NS Pow...
AI summary The document outlines Nova Scotia Power's response to a cybersecurity incident, including customer communication, provision of credit monitoring services, and establishment of a dedicated call centre to support affected individuals.
Page 42 of 46 20260427 REFILE 20251222 NSPI to NSEB Cyber Incident Report PCON.docx REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary This document is a confidential cybersecurity incident report submitted by Nova Scotia Power Inc. to the Nova Scotia Energy Board, related to a cyber incident that occurred in 2025. The content has been redacted, and key details are not disclosed.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.
26 In limited circumstances, NS Power continued to collect SINs from customers where there was a 27 legal requirement to do so. SINs continued to be collected for tax reporting purposes where NS 17 Peter Gregg, President & CEO, Nova Scotia...
AI summary The document references a 2025 cybersecurity incident report submitted by Nova Scotia Power to the Nova Scotia Energy Board, which includes redacted confidential information. It also mentions the collection of Social Insurance Numbers (SINs) by NS Power in limited circumstances for tax reporting purposes.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.
quired for tax reporting purposes, any such information identified will be securely deleted. NS 21 Power anticipates obtaining confirmation of its completion of this process by March 31, 2026. 22 DATE FILED: December 22, 2025 Page 44 of 46...
AI summary This document is a redacted cybersecurity incident report submitted by Nova Scotia Power to the Nova Scotia Energy Board, filed on December 22, 2025. It outlines a cybersecurity incident and includes sensitive information that has been removed for confidentiality.
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED
AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.
1 9.0 CONCLUSION 2 3 NS Power trusts that the foregoing addresses the NSEB’s direction with respect to the information 4 requested in its letters of July 14, 2025 and November 7, 2025. 5 6 NS Power experienced a sophisticated cyberattack d...
AI summary NS Power responded to a cyberattack in 2025, addressing the NSEB's information requests. The attack affected customer data and internal systems, but not operational systems. NS Power activated incident response protocols, notified multiple agencies, and implemented customer support and recovery measures.
orking to reconnect customer meters to 27 billing systems; ongoing progress, system restoration timelines, and Board‑related matters are 28 tracked in the appended charts and monthly updates. 29 DATE FILED: December 22, 2025 Page 45 of 46...
AI summary NS Power indicates that many of the Premier’s requests to the NSEB have been addressed through materials provided in the proceeding or will be addressed in future deliverables. Billing concerns related to the cybersecurity incident are being considered as part of the process.
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED 1 Request IR-1: 2 3 Please provide a timeline of this cybersecurity incident, including: 4 5 (a) the date of the breach; 6 7 (b) the date suspicious...
AI summary NSPI is responding to NSEB's information request regarding a cybersecurity incident. The incident was discovered on April 25, 2025, and involves a sophisticated cyberattack on NSPI's IT systems. The investigation is ongoing, and the timeline of the incident is being provided as part of the response.
NSPI (NSEB) IR-1 Page 1 of 21 20260427 REFILE M12273 Cybersecurity Incident NSEB IR-01 PCONF.docx REDACTED (CONFIDENTIAL INFORMATION REMOVED) Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSE...
AI summary This document outlines NSPI's responses to the NSEB's information requests regarding a cybersecurity incident. The inquiry is part of a regulatory proceeding, and the responses include redacted confidential information.
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary This document outlines NSPI's responses to NSEB information requests related to a cybersecurity incident, with details redacted.
1 certain parts of NS Power’s information technology network and servers which support 2 portions of its business applications. 3 4 Immediately following detection of the Incident, NS Power activated its established 5 incident response and...
AI summary NS Power detected a cyber incident involving unauthorized access to its IT network and servers, leading to data exfiltration. The company activated incident response protocols, engaged cybersecurity experts, and notified law enforcement agencies including CCCS, RCMP, and CSIS. No operational technology systems were compromised.
an Security Intelligence Service (CSIS) on April 27, 2025 and 24 provided them with information about the Incident. Given the nature of the cyber attack 25 and the critical infrastructure nature of the company and the North American electr...
AI summary Nova Scotia Power Inc. (NSP) reported a cybersecurity incident to multiple federal and international agencies, including CSIS, FBI, and OPC, due to the critical infrastructure nature of the company and the North American electric utility industry. The incident was reported on April 27, 2025, and May 1, 2025, with an update on May 14, 2025.
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary This document relates to a cybersecurity incident and NSPI's responses to information requests from the NSEB. The content has been redacted and does not include specific details about the incident or the responses.
ns directly to key account/business customers, government and 25 other stakeholders in addition to employees. 26 27 The Company also employed a multi-platform advertising strategy that includes online 28 media, as well as TV, print and rad...
AI summary NS Power implemented a multi-platform advertising strategy, including online media, TV, print, and radio, to communicate directly with key customers, government stakeholders, and employees during a cybersecurity incident. A paid search strategy was also activated to ensure broad reach.
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary This document outlines NSPI's responses to information requests from the NSEB regarding a cybersecurity incident, with the content redacted.
1 the NS Power website and information appeared as the top search result when customers 2 used search engines (i.e. Google) to find information about the Incident. Social media 3 accounts have been regularly monitored, and where appropriat...
AI summary NS Power informed customers about a cybersecurity incident, providing updates on the impact of the incident and encouraging vigilance against scams. Notifications were sent to affected customers, and third-party service providers were engaged to assist with the process.
ders to assist with this effort. 23 24 On May 13, 2025, NS Power sent notices to approximately 277,000 current customers 25 whose personal information the Company was able to determine had been impacted in this 26 incident. 27 28 The follo...
AI summary NS Power notified approximately 277,000 customers on May 13, 2025, about a cybersecurity incident affecting their personal information. The company also issued a press release and detailed updates on its website and social media the following day.
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary This document pertains to a cybersecurity incident and includes NSPI's responses to NSEB information requests. The content has been redacted, limiting the availability of specific details.
indicates that based on the investigation, the 22 customer’s social insurance number may have been impacted in the Incident. 23 24 NS Power’s notice to impacted customers also included guidance for steps they could take 25 to reduce any ri...
AI summary The text discusses a cybersecurity incident that may have impacted customers' social insurance numbers. NS Power informed affected customers and offered complimentary credit monitoring services, later extended to five years. The document is part of a regulatory inquiry into the incident.
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary This document outlines NSPI's responses to information requests related to a cybersecurity incident, as part of the NSEB M12273 proceeding. The content is redacted and does not provide specific details about the incident or responses.
identity theft. 25 26 • Dark Web Monitoring, which monitors surface, social, deep, and dark websites for 27 potentially exposed personal, identity and financial information and helps protect 28 individuals against identity theft. 29 Date F...
AI summary The document outlines NSPI's response to the NSEB's inquiry regarding a cybersecurity incident involving the exposure of customer data on the dark web. NSPI provided updates to customers through established communication channels following the discovery of the breach.
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary The document outlines NSPI's responses to information requests from the NSEB regarding a cybersecurity incident, with details redacted.
available to customers. 26 27 As is standard in incidents of this nature, to ensure that the call centre had sufficient 28 capacity to handle the volume of calls and allow NS Power’s customer service team to 29 focus on a subset of escalat...
AI summary The document outlines NSPI's responses to the NSEB's information requests regarding a cybersecurity incident. It mentions that a call centre was staffed by TransUnion to manage the high volume of calls during the incident, allowing NS Power's customer service team to focus on escalated queries.
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary The document outlines NSPI's responses to information requests from the NSEB related to a cybersecurity incident, with the content of the responses redacted.
of paper copies were distributed and available to customers across the province 24 through customer support sessions at community locations. In addition, the fact sheet was 25 available at NS Power local depots and provided to MLAs and loc...
AI summary NS Power distributed paper copies of a fact sheet across the province, made it available at local depots, and encouraged customers and employees to spread awareness. The document relates to a cybersecurity incident inquiry by the NSEB and NSPI's responses to information requests.
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary The document outlines NSPI's responses to NSEB information requests related to a cybersecurity incident, with portions redacted.
1 In addition, the Company deployed dozens of employees to communities across the 2 province to provide hands-on support for customers who prefer assistance in person, 3 recognizing that not all customers may be comfortable registering onl...
AI summary NS Power has deployed employees to assist customers in person and updated its website to improve service access. The company has implemented cybersecurity standards based on NIST guidelines and completed a two-year update to its cybersecurity practices.
ations are 24 designed to comply with other industry-specific rules and standards relating to 25 cybersecurity and IT including, but not limited to, those mandated by the North American 26 Electric Reliability Corporation (NERC). NERC cond...
AI summary The document discusses Nova Scotia Power's (NSPI) cybersecurity measures, including mandatory training and phishing simulations, in response to a cybersecurity incident inquiry by the Nova Scotia Energy Board (NSEB). It mentions compliance with NERC standards and audits.
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED 1 Incident Response and Remediation: 2 3 Immediately following detection of unauthorized access, NS Power activated its incident 4 response and busin...
AI summary NSPI responded to the NSEB's information requests regarding a cybersecurity incident, activating incident response protocols, engaging third-party experts, and taking immediate remediation actions to contain and isolate affected servers.
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED 1 2 3 4 Ongoing remediation steps include: 5 6 7 8 9 10 11 12 13 14 NS Power is also advancing efforts to restore and, where necessary, rebuild core...
AI summary NSPI is responding to NSEB information requests regarding a cybersecurity incident. Ongoing remediation includes restoring core business systems and strengthening cybersecurity protocols. A business restoration process office has been established, and a strategic partner has been retained to assist in the recovery.
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 (e) NS Power initially notified customers of the Incident on Monday, April 28, 2025 as noted...
AI summary This document outlines NSPI's responses to the NSEB's information requests regarding a cybersecurity incident. NSPI notified customers on April 28, 2025, and provided ongoing updates during the response period. The matter is under inquiry by the NSEB as part of proceeding M12273.
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary The document outlines NSPI's responses to NSEB information requests regarding a cybersecurity incident, with sensitive details redacted.
streamed session. Following this two-hour session with elected officials, Peter Gregg made 26 himself available and spoke to media gathered outside the legislative chamber. 27 Date Filed: September 5, 2025 NSPI (NSEB) IR-1 Page 15 of 21 20...
AI summary This document outlines NSPI's responses to the NSEB's information requests regarding a cybersecurity incident. It includes actions taken, such as proactive notifications to media and customer support sessions for credit monitoring.
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary This document pertains to a cybersecurity incident and includes NSPI's responses to information requests from the NSEB. The content has been redacted.
ainland (noted in chart below), as well as information being shared with 28 AllNovaScotia.com, Global Halifax, MBS Radio, Halifax Examiner and the Chronicle 29 Herald. 30 Date Filed: September 5, 2025 NSPI (NSEB) IR-1 Page 17 of 21 2026042...
AI summary Nova Scotia Power Inc. (NSPI) has been involved in a cybersecurity incident, leading to an inquiry by the Nova Scotia Energy Board (NSEB). NSPI has taken proactive steps to inform customers through outreach to local radio stations.
Ken Kingston, News Director [email protected] Port Hawkesbury: 101.5FM Sydney: The Coast 89.7FM Radio [email protected] - (CKOA) [email protected] MBS Radio [email protected] New Country 103.5FM NORTHEAST Amherst: CFTA Tantram...
AI summary The document outlines a Board Inquiry into a cybersecurity incident involving Nova Scotia Power, with responses provided by NSPI to NSEB information requests. The filing date is September 5, 2025, and the matter number is M12273. The document is marked as confidential with redacted information.
REDACTED Station Contact & CKTO EZ Rock (MBS Radio) New Glasgow: [email protected] CKEZ 97.9FM Pictou County: [email protected] CKEC 94.1FM The Breeze METRO Halifax: Surge 105FM (CKHY) & Hot [email protected] (both newsroo...
AI summary The document outlines Nova Scotia Power Inc.'s (NSPI) responses to information requests from the Nova Scotia Energy Board (NSEB) regarding a cybersecurity incident. Advertisements were placed in local and provincial newspapers to reach a broader audience, though specific details are redacted.
's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED
AI summary The document discusses a cybersecurity incident involving Nova Scotia Power Inc. (NSPI) and its responses to information requests from the Nova Scotia Energy Board (NSEB). The incident is referenced by the matter number M12273.
1 (f) Please see the following table for details on public interviews provided: 2 Member of NSP senior Date Media Outlet Format Reporter Topic leadership team Amy Smith, Peter Gregg, Anchor Cyber incident May 23, 2025 CBC TV President and...
AI summary The text lists public interviews conducted by NSP senior leadership regarding a cyber incident update. The interviews were conducted on May 23, 2025, with CBC TV and CBC Mainstreet Radio, featuring Peter Gregg, President and CEO, and Jeff Douglas as the reporter.
Radio Douglas President and Mainstreet update (live/on air) CEO Peter Gregg, Gillian Cyber incident May 23, 2025 allnovascotia.ca Print/Online President and Cormier update CEO Peter Gregg, Mike Cyber incident May 29, 2025 Canadian Press Pr...
AI summary This text lists media coverage and updates related to a cyber incident involving Nova Scotia Power Inc. (NSPI), with updates provided by Peter Gregg, President and CEO, and other officials.
update CEO Peter Gregg, CBC Info Portia Cyber incident May 30, 2025 Radio President and Morning Clarke update CEO Cyber incident update Chris Customer Ryan Lanteigne, June 17, 2025 CTV TV support MacDonald Director sessions in Customer Car...
AI summary The text provides updates on cyber incidents from Nova Scotia Power Inc. (NSPI), with statements from Peter Gregg, CEO, and Portia Clarke, President and CEO. It also mentions a customer support initiative led by Ryan Lanteigne, Director of Customer Care, involving community sessions across Nova Scotia.
communities across NS CBC Chris Billing/custom Information Lanteigne, er support June 17, Morning Radio Director sessions for 2025 Mainland Customer Care credit (recorded to air monitoring June 18) Date Filed: September 5, 2025 NSPI (NSEB)...
AI summary This document outlines a board inquiry into a cybersecurity incident involving Nova Scotia Power, with responses provided by NSPI to the Nova Scotia Energy Board. The incident is referenced as NSEB M12273, and the filing date is September 5, 2025.
s Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED Cyber incident update Billing Chris concerns CBC Nova Elizabeth Lanteigne, July 9, 2025 Radio Customer Scotia McMillan Director support Customer Ca...
AI summary The document discusses a cybersecurity incident related to Nova Scotia Power Inc. (NSPI) and their responses to information requests from the Nova Scotia Energy Board (NSEB). It also mentions customer concerns and outreach efforts by NSPI.
communities across NS CBC Nova Scotia – Chris Meter Readers Information Lanteigne, & Community Taryn July 11, 2025 Morning Radio Director Sessions (also Grant Mainland Customer Care asked about (to air Monday, cyber incident) July 13) 1 Da...
AI summary This document is a confidential report related to a cybersecurity incident filed by Nova Scotia Power Inc. (NSPI) with the Nova Scotia Energy Board (NSEB), referencing matter number M12273. The report includes attachments and is part of a regulatory proceeding.
ttachment 1 Page 1 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Cybersecurity Incident NSEB IR-01 Attachment 1 Page 2 of 4 We encourage you to remain vigilant and cautious about any unsolicited communications (such as emails, text mess...
AI summary Nova Scotia Power Inc. (NSPI) has experienced a cybersecurity incident and is advising customers to be cautious of unsolicited communications. They have partnered with TransUnion Canada to provide a 24-month subscription to myTrueIdentity® for credit monitoring and identity restoration at no cost to affected customers.
hat the creditor contact you prior to establishing any accounts in your name. To place a fraud alert on your credit report, contact TransUnion Canada and Equifax Canada using the information above. 4/4 REDACTED (CONFIDENTIAL INFORMATION RE...
AI summary Nova Scotia Power has experienced a cybersecurity incident and is advising customers to be cautious of unsolicited communications requesting personal information. The company has established a dedicated contact number for customer inquiries and is taking steps to enhance system security.
Cybersecurity Incident NSEB IR-01 Attachment 2 Page 3 of 4 Services Description We have retained the assistance of Trans Union of Canada, Inc. (“TransUnion Canada”), one of Canada’s leading consumer reporting agencies and arranged a 24-mon...
AI summary The document outlines a cybersecurity incident and describes a service provided to affected individuals, including a 24-month subscription to myTrueIdentity® for credit monitoring and identity restoration, with instructions on how to activate the service using an activation code.
hat the creditor contact you prior to establishing any accounts in your name. To place a fraud alert on your credit report, contact TransUnion Canada and Equifax Canada using the information above. 4/4 REDACTED (CONFIDENTIAL INFORMATION RE...
AI summary This text discusses steps customers affected by a cybersecurity incident involving Nova Scotia Power should take, including signing up for credit monitoring services and using an activation code provided in a letter.
cess cannot be paused or resumed after periods of inactivity. If you aren’t able to complete the enrolment process in one session, you will have to call TransUnion to complete the process. Dark Web Monitoring: Once you’ve signed up, What i...
AI summary The text outlines steps for individuals to take following a cybersecurity incident, including enrolling in dark web monitoring, contacting TransUnion for technical support, and taking further protective measures such as contacting credit reporting agencies and reviewing financial statements.
ments. If you notice any suspicious activity related to your Social Insurance Number, report it to the police and contact the Canadian Anti-Fraud Centre at 1-888-495-8501. 2 Sign up for Equifax’s fraud alerts and security freezes through t...
AI summary The document provides guidance to customers affected by a cybersecurity incident involving Nova Scotia Power, advising them to report suspicious activity, sign up for fraud alerts, and contact their financial institutions. It also outlines support measures being taken by Nova Scotia Power, including in-person assistance and customer care resources.
REMOVED) Cybersecurity Incident NSEB IR-01 Attachment 4 Page 1 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) CYBER INCIDENT UPDATES NEWS July 8, 2025 Since the cyber incident discovered on April 25, power m...
AI summary Following a cyber incident discovered on April 25, NS Power has paused and resumed customer billing due to communication issues with power meters. Meter readers are now visiting homes to collect accurate energy usage data to provide actual bills until systems are restored.
REMOVED) Cybersecurity Incident NSEB IR-01 Attachment 4 Page 2 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) Wednesday, June 25, 2025 Update A dedicated team within Nova Scotia Power, along with third-party...
AI summary Nova Scotia Power is updating customers about a ransomware attack that impacted personal data, including that of former customers. The company is offering five years of free credit monitoring to all customers and is investigating the full scope of data affected.
and customer correspondence), and driver’s license number. For some of our former customers, bank account numbers (for pre-authorized payment) and Social Insurance Numbers may also have been impacted. We intend to do everything we can to s...
AI summary Nova Scotia Power Inc. (NSPI) is informing customers of a cybersecurity incident that may have exposed personal information, including bank account numbers and Social Insurance Numbers. The company is offering expanded credit monitoring and providing resources to help customers protect themselves from identity theft.
to be from Nova Scotia Power asking you to provide your personal information. Please avoid clicking on suspicious links or downloading attachments without confirming they are from a legitimate source. We have heard concerns about SINs, whi...
AI summary Nova Scotia Power is addressing a cybersecurity incident involving the collection of SINs and is cooperating with the Office of the Privacy Commissioner of Canada and the Nova Scotia Energy Board. They are committed to transparency and have been invited to speak with the Nova Scotia Public Accounts Committee.
on and response efforts remain ongoing, we have committed to be as open and transparent as possible. This meeting today is a part of that transparency. Opening remarks by Peter Gregg, President & CEO On behalf of our entire team at Nova Sc...
AI summary Nova Scotia Power Inc. (NSPI) is addressing a cybersecurity incident affecting its systems and customers. The company has apologized for the impact and is working to resolve the issue while maintaining transparency. Cybersecurity experts and law enforcement are involved in the ongoing investigation.
N REMOVED) Cybersecurity Incident NSEB IR-01 Attachment 4 Page 5 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) The privacy commissioner of Canada stated last week that: “Data breaches have surged over the p...
AI summary Nova Scotia Power Inc. (NSPI) discusses a recent cybersecurity incident, emphasizing its commitment to cybersecurity and compliance with standards set by NIST and NERC. The company assured that no payments were made to the attackers and highlighted its response protocols, including engaging third-party experts and isolating affected systems.
ng swift actions to contain and isolate the affected systems to prevent further intrusion. Our cybersecurity program ensured that our operations systems and electric grid continue to perform as usual. As you know, the criminals stole data,...
AI summary Nova Scotia Power Inc. (NSPI) has taken steps to isolate affected systems following a cybersecurity incident and is providing credit monitoring services to impacted customers. Investigations are ongoing, with cooperation from the Nova Scotia Energy Board (NSEB) and the Office of the Privacy Commissioner of Canada.
ns of the incident have been initiated by both the Nova Scotia Energy Board and the Office of the Privacy Commissioner of Canada. Nova Scotia Power will fully cooperate with both of these proceedings. You have my commitment that our team i...
AI summary Nova Scotia Power has been the victim of a ransomware attack and is working with cybersecurity experts to restore systems and investigate the incident. No ransom has been paid, and the threat actor has published stolen data. The company is committed to transparency and cooperation with the Nova Scotia Energy Board and the Office of the Privacy Commissioner of Canada.
the threat actor has published data that was stolen from our systems. We are actively working with cybersecurity experts to assess the nature and scope of the information that may have been impacted. Notifications have been mailed to impac...
AI summary Nova Scotia Power is addressing a cybersecurity incident that affected IT systems, working with experts to assess the impact and restore systems. Affected customers have been notified and provided with free credit monitoring services. The company emphasizes the importance of vigilance against phishing and unsolicited communications.
as impacted certain IT systems in our network. We are working with external cybersecurity experts to determine the scope of the impact and safely and securely restore and rebuild our impacted systems. While the investigation remains ongoin...
AI summary Nova Scotia Power Inc. experienced a cybersecurity incident where customer information was accessed by an unauthorized third party around March 19, 2025. Customers are being notified, and a free credit monitoring service is being provided. The affected information includes personal and account details, and customers are advised to be cautious of unsolicited communications.
be from Nova Scotia Power asking you to provide your personal information. Please avoid clicking on suspicious links or downloading attachments without confirming they are from a legitimate source. 8 REDACTED (CONFIDENTIAL INFORMATION REMO...
AI summary Nova Scotia Power detected unusual network activity on April 25, 2025, and initiated an incident response plan. The company confirmed that personal customer information was accessed by an unauthorized third party. They are working with external cybersecurity experts and law enforcement to investigate and restore affected systems.
very seriously. The security of your information is our top priority. We are working urgently to determine the full nature and scope of the data that may have been affected, and individuals impacted. If we determine that your data was affe...
AI summary Nova Scotia Power and Emera Inc. discovered a cybersecurity incident involving unauthorized access into parts of their Canadian network and servers. The incident does not impact generation, transmission, or distribution facilities, nor does it affect customer service. The company is working to determine the full scope of the breach and will notify affected individuals.
iscovered and are actively responding to a cybersecurity incident involving unauthorized access into certain parts of its Canadian network and servers supporting portions of its business applications. Immediately following detection of the...
AI summary Nova Scotia Power Inc. is responding to a cybersecurity incident involving unauthorized access to its Canadian network and servers. The incident has not disrupted physical operations or impacted customer service in Nova Scotia. The company is working with cybersecurity experts to restore affected systems.
curity Incident NSEB IR-01 Attachment 4 Page 12 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) LATEST UPDATES July 8, 2025 • Power meters have continued to function and gather accurate energy usage data from...
AI summary Nova Scotia Power Inc. (NSPI) is experiencing a cyber incident that has disrupted communication between power meters and their systems. While meters continue to collect data, billing has been paused and later resumed with estimated bills. Meter readers are now being deployed to gather actual usage data to provide more accurate bills.
etation, pets, fencing, etc., you will receive an estimated bill based on an average of the previous energy used at your property during a similar time of year. Wednesday, June 25, 2025 • Beginning today, we will be offering five years of...
AI summary Nova Scotia Power is offering free credit monitoring to current and former customers following a cybersecurity incident where personal information was accessed by an unauthorized third party. The company is providing expanded support and covering all costs related to the credit monitoring service.
• We are focused on supporting our customers. We are here for regular business from 8 AM–6 PM, Monday through Friday. Please contact us at 1-800-428-6230. Wednesday, June 5, 2025 • Nova Scotia Power leadership appeared before the Nova Scot...
AI summary Nova Scotia Power Inc. confirmed a ransomware attack that led to stolen customer data. The company did not make a ransom payment and is working with cybersecurity experts and law enforcement to restore systems and support affected customers with credit monitoring and identity protection.
been impacted. • Since the incident began several weeks ago, we have been actively working with the assistance of third-party cyber security experts to restore our systems safely 13 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Cybersecurity...
AI summary Nova Scotia Power has been dealing with a cybersecurity incident, working with third-party experts to restore systems and strengthen security. Affected customers have been notified and offered free credit monitoring. The company expresses regret over the incident and emphasizes the importance of data security.
ely sorry that this issue has occurred. Protecting the privacy and security of information held by Nova Scotia Power is something we take very seriously. Wednesday, May 14, 2025 • Nova Scotia Power continues to investigate a cyber incident...
AI summary Nova Scotia Power is investigating a cyber incident that led to unauthorized access and exfiltration of customer information. Affected customers are being notified and offered free credit monitoring services. The company emphasizes the seriousness of protecting customer privacy and security.
systems in our network. • While our investigation is ongoing, we have identified that certain customer personal information was accessed and taken by an unauthorized third party. 14 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Cybersecurity...
AI summary Nova Scotia Power Inc. (NSPI) has identified a cybersecurity incident where customer personal information was accessed by an unauthorized third party. NSPI is investigating and will notify affected customers with further details and resources. Customers are advised to be cautious of unsolicited communications requesting personal information.
ou to provide your personal information. Please avoid clicking on suspicious links or downloading attachments without confirming they are from a legitimate source. Monday, April 28, 2025 • Emera and Nova Scotia Power discovered and are act...
AI summary Emera and Nova Scotia Power have discovered a cybersecurity incident involving unauthorized access to parts of their network and servers. They have activated response protocols, engaged cybersecurity experts, and isolated affected systems. Operations remain unaffected, and customers are advised to remain vigilant against suspicious communications.
4 Page 16 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) FAQS What happened? Last updated: Tuesday, June 24, 2025 On April 25, we discovered and began actively responding to a cybersecurity incident involvin...
AI summary Nova Scotia Power Inc. (NSPI) experienced a ransomware attack on April 25, 2025, leading to unauthorized access to customer personal information. No ransom was paid due to legal restrictions. NSPI is working with cybersecurity experts and law enforcement to investigate and remediate the breach.
ION REMOVED) Cybersecurity Incident NSEB IR-01 Attachment 4 Page 17 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) • Informed impacted customers via mail and provided a free subscription to TransUnion’s cred...
AI summary Nova Scotia Power informed impacted customers about a cybersecurity incident where personal information was accessed and published on the dark web. The company provided credit monitoring services and organized in-person support. They are expanding free credit monitoring to all customers, regardless of whether they received a letter.
s of Nova Scotia Power—past and present—regardless of whether you received a letter from us about the incident. I’m a current customer, but I did not get a letter. Does that mean I was not affected? 17 REDACTED (CONFIDENTIAL INFORMATION RE...
AI summary Nova Scotia Power is offering free credit monitoring to all current and past customers, regardless of whether they received a letter about a cybersecurity incident. The offer was expanded from two years to five years. Customers who already signed up will be automatically extended to five years. The expansion is part of ongoing efforts to protect customers.
a code and already signed up for two years of monitoring, you will be automatically extended to five years. Why didn’t you offer credit monitoring to everyone right away when this happened? Why now? Last updated: Wednesday, June 25, 2025 O...
AI summary Nova Scotia Power Inc. (NSPI) is expanding free credit monitoring to all past and present customers following a cybersecurity incident. Initially, it was offered only to those confirmed to have been impacted. The company is now reaching out to former customers through various channels to ensure they are informed.
as broadly as possible. We are actively sharing this information with media, on social media, with stakeholders, and through paid advertising to reach as many current and former customers as possible. We strongly encourage anyone who is co...
AI summary Nova Scotia Power Inc. (NSPI) is informing customers of a cybersecurity incident that disrupted internal IT systems, billing processes, and access to the MyAccount portal. The company is offering free credit monitoring and encourages customers to share information with former customers. NSPI is working to restore systems and provide estimated bills.
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL 1 Request IR-3: 2 3 NS Power, in its Thursday, May 14, 2025, cybersecurity update letter stated: 4 5 Beginni...
AI summary The Nova Scotia Energy Board (NSEB) is inquiring into Nova Scotia Power's (NSPI) cybersecurity incident, focusing on the determination of no misuse of customer data, notice procedures, communication strategies, and the selection of credit monitoring services. NSPI has committed to providing five years of free credit monitoring to affected customers.
TransUnion myTrueIdentity® services? 31 Date Filed: September 5, 2025 NSPI (NSEB) IR-3 Page 1 of 7 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NS...
AI summary The document outlines NSPI's responses to the NSEB's information requests regarding a cybersecurity incident. The inquiry is part of a regulatory proceeding, and the responses are non-confidential.
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL 1 (i) Please list the components of this service and provide comment of their 2 appropriateness. 3 4 (ii) Wh...
AI summary Nova Scotia Power Inc. (NSPI) responded to inquiries regarding a cybersecurity incident, detailing their investigation and credit monitoring measures. They mentioned enhanced dark web monitoring and indicated no misuse of data. NSPI also began notifying affected customers.
’s personal information 26 has been misused in a manner that is directly connected to this Incident. 27 28 (b) NS Power began mailing letters to impacted customers on May 13, 2025. 29 Date Filed: September 5, 2025 NSPI (NSEB) IR-3 Page 2 o...
AI summary Nova Scotia Power Inc. (NSPI) is responding to an inquiry by the Nova Scotia Energy Board (NSEB) regarding a cybersecurity incident. Personal information of customers was misused, and NSPI began mailing letters to impacted customers on May 13, 2025.
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL
AI summary This document outlines Nova Scotia Power's responses to information requests from the Nova Scotia Energy Board regarding a cybersecurity incident. The inquiry focuses on NSPI's handling of the incident and its implications.
set out above, the Company’s approach to transparent communications about the impact 26 of the Incident on NS Power customers principally consisted of direct notifications to active 27 impacted customers, and public postings to the Company...
AI summary The Company communicated the impact of a cybersecurity incident to NS Power customers through direct notifications and public postings on the Company website, supported by media outreach and social media engagement. Samples of notification letters are attached as Attachments 1 and 2 to IR-1.
nquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL
AI summary This document relates to an inquiry into a cybersecurity incident at Nova Scotia Power and includes their responses to information requests from the Nova Scotia Energy Board. It is marked as non-confidential.
ailable to assist individuals with 26 questions about identity theft. In the unlikely event that an individual becomes a 27 victim of fraud, a personal restoration specialist will help to resolve any identity 28 theft. 29 30 • Up to $1,000...
AI summary The document outlines identity theft protection services offered by Nova Scotia Power Inc., including assistance with fraud resolution and up to $1,000,000 in expense reimbursement insurance. It is part of NSPI's responses to the NSEB regarding a cybersecurity incident inquiry.
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL
AI summary This document outlines Nova Scotia Power's responses to the Nova Scotia Energy Board's information requests regarding a cybersecurity incident. The inquiry is part of a regulatory proceeding to assess the incident and its implications.
ubscription to TransUnion’s myTrueIdentity® service, as a two-year time period for a 25 credit monitoring service has become a well-established, common practice for 26 organizations across industries (financial services, healthcare, retail...
AI summary The document discusses Nova Scotia Power's cybersecurity incident and their responses to information requests from the Nova Scotia Energy Board (NSEB). It references a subscription to TransUnion’s myTrueIdentity® service for credit monitoring following a data breach.
nquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL
AI summary This document outlines Nova Scotia Power's responses to information requests from the Nova Scotia Energy Board regarding a cybersecurity incident. The inquiry is referenced as NSEB M12273, and the responses are marked as non-confidential.
dit management, fraud victim 26 assistance and identity theft prevention. 27 28 • Access to Identity Restoration agents who are available to assist individuals with 29 questions about identity theft. In the unlikely event that an individua...
AI summary The document outlines measures for identity theft prevention and restoration assistance, including access to Identity Restoration agents and personal restoration specialists. It is related to a cybersecurity incident inquiry by the Nova Scotia Energy Board (NSEB) into Nova Scotia Power Inc. (NSPI).
nquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL 1 • Up to $1,000,000 of expense reimbursement insurance related to identity theft. 2 3 • Dark Web Monitoring,...
AI summary The document outlines NSPI's responses to the NSEB's information requests regarding a cybersecurity incident, including measures such as expense reimbursement insurance, dark web monitoring, and communication strategies with impacted individuals.
IR-3 Page 7 of 7 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Osler, Hoskin & Harcourt LLP Box 50, 1 First Canadian Place Toronto, Ontario, Canada M5X 1B8 416.362.2111 MAIN 416.862.6666 FACSIMILE August 8, 2025 Adam Kardash Direct Dial: 416...
AI summary NS Power has been the victim of a sophisticated ransomware attack that did not impact customer power infrastructure but affected internal IT and customer care systems. The threat actor exfiltrated customer data and posted it on the dark web. NS Power seeks a procedural order to keep its confidential submissions restricted to the Inquiry panel, the Clerk of the Board, and the Board's counsel.
o exfiltrated certain data, including customer information. Consistent with the aggressive tactics of ransomware attackers, the threat actors have already posted certain NS Power data on the dark web. 3. In line with recognized best practi...
AI summary NS Power has experienced a ransomware attack leading to data exfiltration and public posting of data on the dark web. NS Power is collaborating with cybersecurity experts and intends to provide sensitive information to the Board regarding the incident, emphasizing the need for confidentiality due to the unique nature of the cybersecurity inquiry.
ive nature of privacy or cybersecurity investigations. REDACTED (CONFIDENTIAL INFORMATION REMOVED) Page 3 9. Should the Board require further information regarding these special circumstances (including the detailed basis for the credible...
AI summary The letter requests the Board to convene an in-camera meeting with NS Power to discuss special circumstances and credible risks related to privacy or cybersecurity investigations. The request is made by Adam Kardash and his team, representing NS Power.
tia B3J 3P6 Attention: Crystal Henwood, Clerk of the Board Dear Ms. Henwood: M12273 – Inquiry of the Nova Scotia Energy Board (the Board) into Cybersecurity Incident of Nova Scotia Power (NS Power) Thank you for your correspondence dated A...
AI summary NS Power is responding to the Nova Scotia Energy Board's inquiry into a cybersecurity incident. They emphasize their commitment to cooperation while requesting strict confidentiality for sensitive information. They reference privacy regulatory authorities' procedures as a model for handling such investigations.
en privacy regulatory authorities’ extensive experience investigating cybersecurity incidents, we view their investigative procedures as being helpful and informative to the Board as it determines the 1 Sherman Estate v. Donovan, 2021 SCC...
AI summary The document discusses NS Power's expectations regarding the Board's handling of confidentiality claims during the Inquiry, emphasizing the need for scrutiny and the opportunity to explain the necessity of keeping certain information confidential, potentially through an oral hearing with cybersecurity experts.
us peine des sanctions prévues à l’article 413-10 du code pénal et, sous réserve de ce qui est nécessaire à l’établissement du rapport annuel, à l’article 226- 13 du même code. Unofficial Translation Art II The commission’s agents are boun...
AI summary NS Power has faced a sophisticated ransomware attack, leading to the theft and potential dark web posting of customer personal information. Despite extortion tactics, NS Power has decided not to pay the ransom, aligning with law enforcement guidance and applicable sanctions laws.