N-1LOCs Redacted (N-1 from M12273)
24 passages
Re: Important Notice About Your Personal Information Dear Valued Customer: We are writing to provide you with information about the recent cyber incident impacting Nova Scotia Power. On April 25, 2025, Nova Scotia Power discovered that an...
AI summary This notice informs customers of a cyber incident at Nova Scotia Power, where unauthorized access occurred on March 19, 2025, potentially exposing personal information. The company has initiated response protocols, informed authorities, and provided free credit monitoring services to affected customers. A related legal matter, M12273, is referenced in an email exchange.
tolen in this security breach; - 2) A lawful explanation as to the communication delay between discovering the security breach on April 25, 2025, and the communication that I received on May 22, 2025; - 3) Provide comprehensive identity pr...
AI summary The text outlines a customer's concerns regarding a data breach by NS Power, requesting explanations for the delayed communication, identity protection measures, and a written acknowledgment of NS Power's responsibility for the breach, as well as an explanation for why Nova Scotians should trust NS Power again.
Contact Information Name on account: Account number: \ \ \ \ \ \ \ Business contact: Account address: Address 1: \ \ \ \ \ \ \ Address 2: \ \ \ \ \ \ \ \ City: \ \ \ \ \ \ \ Province: \ \ \ \ \ \ \ Postal code: \ \ \ \ \ \ \ Country: \ \ \...
AI summary The complaint details a cyber security breach at NS Power and highlights concerns over the lack of in-house expertise and the need for regulatory approval for a $6.8M cyber security upgrade. The complainant questions why such a core service is not baseline funded and why regulatory approval is needed for a legally mandated effort.
How do they want the complaint resolved? I expect PROMPT action from the NS Energy Board on this ongoing cyber threat. The fact that the NS Energy Board continued to pursue a standard 90 day review period without triaging and expediting th...
AI summary The complainant is urging the NS Energy Board to take prompt action on a cybersecurity threat, criticizing the standard 90-day review period and NS Power's failure to prioritize cybersecurity. The complainant claims that NS Power's negligence led to the theft of credit information affecting 280,000 Nova Scotians. They expect the NS Energy Board to expedite the process and for NS Power to self-fund the cybersecurity effort.
Attached, you will find: - 1. A formal complaint letter outlining the incident, technical analysis, and risks posed by the remedial platform; - 2. An email with evidence from Meng Cheng Yeh. (Meng Cheng Yeh is a formal privacy complaint co...
AI summary A formal complaint letter and supporting evidence from Meng Cheng Yeh, a student specializing in IT Systems Management and Security, are submitted regarding a data breach at Nova Scotia Power. The incident is said to pose ongoing cyber risks to affected individuals, and the complainant requests urgent review and additional documentation if needed.
Dear Commissioner, My name is YungYu Yeh, A victim of NS power's customer data breach. I am writing to formally file a privacy complaint regarding the recent cyber incident involving Nova Scotia Power, which has resulted in the confirmed l...
AI summary A customer of Nova Scotia Power, YungYu Yeh, reports a data breach and expresses concerns about the security of the identity protection service provided by NS Power, 'mytrueidentity.ca,' highlighting multiple vulnerabilities in its implementation.
5. Indications of Neglect: - Outdated copyright (2019). - Use of deprecated security practices (e.g., X-XSS-Protection). - No evidence of recent updates or audits. Given these findings, I strongly believe that this "remedial" service may f...
AI summary The document highlights cybersecurity concerns related to an outdated service used by NS Power, noting outdated copyright and deprecated security practices. It requests an investigation into due diligence and alignment with privacy laws, emphasizing potential risks to Nova Scotians.
Conclusion: mytrueidentity.ca does not meet modern web security standards for handling sensitive financial information. Until critical security policies, headers, and coding practices are addressed, entering credit card data into this site...
AI summary The document concludes that mytrueidentity.ca lacks modern web security standards for handling sensitive financial information, exposing users to cyber risks. It advises Nova Scotian residents against submitting payment or personal information on the platform.
ring CSP analysis Cool des Raw : server headers Scan history Benchmark comparison Test Score Reason Recommendation Content Security Policy (CSP) -25 🗴 Content Security Policy (CSP) header not implemented Implement one, see MDN's Content Se...
AI summary The document provides a security analysis of a website, highlighting several security headers and their implementation status. Key issues include the lack of a Content Security Policy (CSP) header, absence of Subresource Integrity (SRI), and incomplete implementation of X-Content-Type-Options and X-Frame-Options headers. Recommendations are provided to improve security settings.
tionList.longestInteractionList.longestInteractionList.longestInteractionList.longestInteractionList.longestInteractionList.longestInteractionList.l longestInteractionList.sort(function(h,d){return d.latency}),longestInteractionList.splice...
AI summary The provided text is a fragment of code or technical documentation, likely related to performance monitoring or web security headers. It includes references to performance events, timing functions, and security headers such as CSP, SRI, X-Content-Type-Options, X-Frame-Options, and HSTS. The text also includes a mention of 'Security Analysis by Meng Cheng'.
ay 23, 2025. While your letter acknowledged that my personal data had been stolen by an unauthorized third party, it didn't meet acceptable standards for breach notification in several important ways: - 1. Lack of Specific Information: The...
AI summary The letter criticizes Nova Scotia Power for inadequate breach notification following a data theft, citing lack of specific information, no guidance on next steps, and minimal support. It requests detailed disclosure, explanation of the delay, enhanced identity protection, clear guidance, and improved cybersecurity protocols.
Re: Important Notice About Your Personal Information Dear Valued Customer We are writing to provide you with information about the recent cyber incident impacting Nova Scotia Power. On April 25, 2025, Nova Scotia Power discovered that an u...
AI summary Nova Scotia Power experienced a cyber incident on April 25, 2025, where unauthorized access was gained to parts of its network and servers. Customer information, including personal and account details, may have been accessed. As a precaution, TransUnion myTrueIdentity credit monitoring service is being offered to affected customers.
Re: Important Notice About Your Personal Information Dear Valued Customer: We are writing to provide you with information about the recent cyber incident impacting Nova Scotia Power. On April 25, 2025, Nova Scotia Power discovered that an...
AI summary Nova Scotia Power has informed customers of a cyber incident where unauthorized access occurred on March 19, 2025, leading to the potential exposure of personal information. The company has engaged cybersecurity experts and notified authorities. As a precaution, customers are being offered free credit monitoring through TransUnion.
Good evening, As discussed today, please consider this synopsis of a potential source of the cyber breach on the NS Power corporate (non-operational) network. For your further review and further investigation. On or about 20 May 2025, I re...
AI summary The letter discusses a cyber breach on NS Power's corporate network and requests disclosure of costs related to a Security Operations Centre (SOC) and Security Information Event Monitoring (SIEM) project. The letter references documents M09301 and N-2 NSPI responses, highlighting concerns about unaccounted expenses for the SOC service provided by Service Now.
Nova Scotia Power Careers Home careers.emera.com I recommend that the NS Energy Board, in the service of its formal investigation of NS Power's cyber security breach of its corporate network infrastructure, seek out how NS Power was able t...
AI summary The text discusses a cybersecurity breach at Nova Scotia Power (NSP) involving vulnerabilities in Service Now software, which were identified on 10 July 2024. The author raises concerns about whether NSP addressed these vulnerabilities across its locations, highlighting that hackers exploited these vulnerabilities on 19 March 2025, leading to unauthorized access to customer information. The text calls for an investigation into NSP's network security practices.
READ MORE These two Ivanti bugs are allowing hackers to target cloud instances - so patch now
AI summary The text highlights two Ivanti bugs that are enabling hackers to target cloud instances, emphasizing the need for immediate patching to prevent potential security breaches.
Hackers are ramping up attacks using year-old ServiceNow security bugs to target unpatched systems Carly Page 9:04 AM PDT · March 20, 2025 IMAGE CREDITS: SMITH COLLECTION/GADO / GETTY IMAGES Hackers are ramping up their attempts to exploit...
AI summary Hackers are exploiting year-old ServiceNow security vulnerabilities (CVE-2024-4879, CVE-2024-5178, CVE-2024-5217) to target unpatched systems, with a notable resurgence in attacks. Security researchers warn that these flaws can be chained for full database access, and organizations using ServiceNow for sensitive employee data are at risk.
News Jul 30, 2024 • 5 mins Data Breach Vulnerabilities The vulnerabilities have exposed sensitive information from over 105 organizations including government agencies, data centers, energy providers, and software development firms. $\labe...
AI summary A data breach involving three critical vulnerabilities in the ServiceNow IT service management platform has exposed sensitive information from over 105 organizations, including government agencies and energy providers. The vulnerabilities allow unauthenticated remote attackers to execute arbitrary code, potentially leading to data theft and disruption of business operations. Cybersecurity firms have reported active exploitation and the sale of stolen data on the dark web.
Explore related questions - How do ServiceNow vulnerabilities impact specific industries? - Why do unpatched old vulnerabilities pose significant cybersecurity risks? - How do known vulnerabilities impact government organizations? - What a...
AI summary The text presents a list of cybersecurity-related questions focusing on the impact of ServiceNow vulnerabilities, unpatched old vulnerabilities, and misconfigured ServiceNow KB articles on specific industries, government organizations, and the risks associated with unencrypted services.
Danielle Kristine Maillet NSPower Account #: To: NS Power Customer Service CC: Privacy Office, Billing Department, Legal Department Re: Data Breach, Billing Disruption, and Compensation Demand Dear NS Power, I am writing to formally expres...
AI summary Danielle Kristine Maillet is writing to NS Power to express concerns about a data breach and billing disruptions, demanding a full waiver of her current bill, a credit for an unsolicited service, and a freeze on future charges until online access is restored. She threatens to escalate the matter to regulatory bodies and seek legal consultation if unresolved.
We are writing in response to your request for a detailed account of what personal information of yours may have been compromised in the cyber attack that recently affected Nova Scotia Power's systems. First, we want to assure you that pro...
AI summary Nova Scotia Power informs customers that a cyber attack may have compromised personal information, including contact details, account history, and financial data. While specific details cannot be identified, the company encourages credit monitoring and other security measures to protect affected individuals.
RE: Nova Scotia Power (NSP) Cyber Breach Nova Scotia Power (NSP) knows, or should know, that Canada is a target for cyber criminals and hostile governments such as China, Russia, Iran, and North Korea. NSP, a critical infrastructure corpor...
AI summary The document discusses a data breach by Nova Scotia Power (NSP), highlighting the delayed response and lack of transparency. The breach, which occurred on 19 March 2025, was not detected until 25 April 2025, with customer notifications delayed further. NSP is criticized for not adhering to PIPEDA standards and for insufficient security measures such as real-time threat detection and zero-trust architecture.
DRO made decision on: May Type of complaint: Other Additional details: I am writing to have it on record that the data breach has literally RUINED us and the billing is out of control for us who live in NS. During all of this while our cre...
AI summary A Nova Scotia Power ratepayer is filing a complaint regarding the impact of a data breach on their personal and financial well-being, highlighting the stress caused by fraud and medical issues. They also request specific information requests to the Board regarding where customer data is stored and its exposure to foreign legal process.
who holds the encryption keys and in what jurisdiction; (c) any contractual restriction on onward transfer or vendor use of the data. Produce the governing data-processing agreement or transfer terms. Question 6 — Foreign legal process exp...
AI summary The questions focus on data security, privacy, and compliance, asking about encryption key management, foreign legal process exposure, privacy impact assessments, vendor environments in a 2025 cyber incident, and systems handling customer personal information in specific capital projects.
N-2NSPI (NSEB) RIR 1 to 12 - Redacted (N-2 from M12273)
53 passages
Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests 1 Request IR-1: 2 3 Please provide a timeline of this cybersecurity incident, including: 4 5 (a) the date of the breach...
AI summary The document outlines a request for a timeline of a cybersecurity incident at Nova Scotia Power, including dates of the breach, discovery, confirmation, and public communication. The response indicates the investigation is ongoing, and the incident was discovered on April 25, 2025, when employees noticed system malfunctions due to unauthorized access.
Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests
AI summary The document outlines the NSEB's inquiry into Nova Scotia Power's cybersecurity incident and includes NSPI's responses to information requests. The proceeding involves cybersecurity and regulatory oversight themes.
2 Station Contact WEST Contact W 25 1 Bridgewater: CKBW Country 100.7FM [email protected]; [email protected] Yarmouth: СЛLS [email protected] Liverpool: QCCR 99.3 FM navia@gaarfm aam [email protected] Kentville/New Minas: 89.3 Rewi...
AI summary The document lists contact information for various radio stations across Nova Scotia and references a regulatory inquiry by the Nova Scotia Energy Board (NSEB) into a cybersecurity incident at Nova Scotia Power (NSP), identified as matter number M12273.
2 Advertisements were also placed in approximately 15 local and provincial newspapers across the province to ensure broader reach to demographics within the province. A sample ad is provided below. 4 5 Board Inquiry into Nova Scotia Power'...
AI summary Advertisements were placed in 15 local and provincial newspapers to reach broader demographics. A sample ad is included. The document references a Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) and NSPI responses to NSEB information requests.
REDACTED July 9, 2025 CBC Nova Scotia Radio Elizabeth McMillan Chris Lanteigne, Director Customer Care Cyber incident update Billing concerns Customer support sessions in communities across NS July 11, 2025 CBC Nova Scotia – Information Mo...
AI summary The document includes media mentions related to a cybersecurity incident and customer concerns, with references to a cybersecurity incident report from the NSEB. It also includes details about customer support sessions and meter reader community sessions.
Re: Important Notice About Your Personal Information Dear Valued Customer: We are writing to provide you with information about the recent cyber incident impacting Nova Scotia Power. On April 25, 2025, Nova Scotia Power discovered that an...
AI summary Nova Scotia Power informed customers of a cyber incident on April 25, 2025, where unauthorized access occurred to certain parts of its Canadian network and servers. Customer information, including personal and account details, may have been accessed. As a precaution, customers are being offered a two-year credit monitoring service at no cost.
Cybersecurity Incident NSEB IR-01 Attachment 1 Page 2 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED) We encourage you to remain vigilant and cautious about any unsolicited communications (such as emails, text messages, social posts or ph...
AI summary Nova Scotia Power is advising customers to be cautious of unsolicited communications, including those appearing to be from the company, and has established a dedicated hotline for inquiries. The company apologizes for a cybersecurity incident and is taking steps to improve system security.
Cybersecurity Incident NSEB IR-01 Attachment 1 Page 3 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED)
AI summary This document discusses a cybersecurity incident related to Nova Scotia Power (NSP) and involves the Canadian Centre for Cybersecurity (CCCS) and the Royal Canadian Mounted Police (RCMP). The Nova Scotia Energy Board (NSEB) is mentioned in the context of the incident.
Cybersecurity Incident NSEB IR-01 Attachment 1 Page 4 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED)
AI summary This document is a redacted attachment related to a cybersecurity incident under the Nova Scotia Energy Board (NSEB) IR-01 proceeding. It contains confidential information and is part of a regulatory proceeding involving cybersecurity concerns.
Cybersecurity Incident NSEB IR-01 Attachment 2 Page 2 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED) We encourage you to remain vigilant and cautious about any unsolicited communications (such as emails, text messages, social posts or ph...
AI summary Nova Scotia Power has experienced a cybersecurity incident and is urging customers to remain cautious of unsolicited communications. They have provided a dedicated contact number for inquiries and are working to strengthen system security to prevent future incidents. Peter Gregg, President & CEO of Nova Scotia Power, has apologized for the incident.
Cybersecurity Incident NSEB IR-01 Attachment 2 Page 3 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED)
AI summary This document is a redacted attachment related to a cybersecurity incident under the Nova Scotia Energy Board (NSEB) reference number IR-01. It contains confidential information and is part of a regulatory proceeding.
Cybersecurity Incident NSEB IR-01 Attachment 2 Page 4 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED)
AI summary This document is a redacted attachment related to a cybersecurity incident involving Nova Scotia Power and the Nova Scotia Energy Board. It contains confidential information and is part of a regulatory proceeding.
What is the dark web? These threat actors, and other cyber criminals, use a hidden part of the internet that is only accessible through special software—it is commonly referred to as the "dark web" and is known to be used by cyber criminal...
AI summary The text introduces the concept of the dark web, describing it as a hidden part of the internet used by cyber criminals to store and trade data. It also includes a note about technical support for myTrueIdentity® and a reference to a cybersecurity incident attachment.
Further Protection Here's are some additional steps you can take to further protect your personal information: Service Canada advises individuals affected by a breach to contact both TransUnion and Equifax for file monitoring and to regula...
AI summary The text provides guidance on protecting personal information following a data breach, including contacting credit agencies, monitoring financial accounts, and signing up for fraud alerts.
Cybersecurity Incident NSEB IR-01 Attachment 4 Page 1 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED) NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025)
AI summary This document provides updates from NS Power regarding a cybersecurity incident, including excerpts from their website as of September 5, 2025. The content is redacted and marked as confidential information.
CYBER INCIDENT UPDATES
AI summary The document provides updates on recent cyber incidents, highlighting the involvement of key organizations such as Nova Scotia Power and the Canadian Centre for Cybersecurity.
July 8, 2025 Since the cyber incident discovered on April 25, power meters have continued to function and gather accurate energy usage data from homes and businesses across the province. However, due to the cyber incident, the meters have...
AI summary Following a cyber incident, Nova Scotia Power has paused and resumed billing with estimated bills until systems are restored. Meter readers are now visiting homes to collect accurate energy usage data. Customers are advised to expect meter readers wearing branded clothing and identification badges.
Cybersecurity Incident NSEB IR-01 Attachment 4 Page 2 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED) NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025)
AI summary This document provides updates on a cybersecurity incident involving NS Power, with information sourced from website excerpts dated September 5, 2025. The content is redacted due to the inclusion of confidential information.
Wednesday, June 25, 2025 Update A dedicated team within Nova Scotia Power, along with third-party cybersecurity experts, are continuing the investigation into the recent ransomware attack that has impacted our customers and our company. To...
AI summary Nova Scotia Power is updating customers about a ransomware attack that impacted personal data, including that of former customers. The company is offering five years of free credit monitoring to all customers and is investigating the full scope of data affected.
Cybersecurity Incident NSEB IR-01 Attachment 4 Page 3 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED)
AI summary The document is a redacted attachment related to a cybersecurity incident under the Nova Scotia Energy Board (NSEB) proceeding. It contains confidential information and does not provide specific details about the incident or its implications.
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) We are focused on supporting our customers. We are here for regular business from 8 AM–6 PM, Monday through Friday. Please contact us at [1-800-428-6230](tel:1-800-42...
AI summary Nova Scotia Power is addressing a cyber incident by providing customer support, removing SINs from systems, and cooperating with investigations. They are also offering resources to help customers protect themselves from identity theft and are committed to restoring customer confidence.
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025)
AI summary This document provides updates on a recent cyber incident affecting NS Power, including actions taken by the Canadian Centre for Cybersecurity (CCCS) and the Royal Canadian Mounted Police (RCMP). It outlines the ongoing investigation and steps being taken to secure systems.
Wednesday, June 4, 2025 Update Following the recent ransomware attack and its effect on our customers, we've been invited to speak with members of the Nova Scotia Public Accounts Committee at their meeting today. While recognizing that the...
AI summary Nova Scotia Power (NSP) is addressing a recent ransomware attack impacting customers and is participating in a meeting with the Nova Scotia Public Accounts Committee. NSP expressed transparency and apologized for the incident, emphasizing ongoing investigations and collaboration with cybersecurity experts and law enforcement.
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) The privacy commissioner of Canada stated last week that: "Data breaches have surged over the past decade, and this incident highlights the growing risks of cyberatta...
AI summary NS Power discusses a recent cyber incident, emphasizing their commitment to cybersecurity and compliance with standards. They highlight their response measures and ongoing investigation into the breach, which affected customer data. No ransom was paid to the attackers.
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) I am also encouraging all impacted customers to sign up for complimentary credit monitoring and identity protection services. We have updated our [website](https://ww...
AI summary Nova Scotia Power (NSP) is providing credit monitoring and identity protection services to impacted customers following a cyber incident. NSP is cooperating with the Nova Scotia Energy Board and the Office of the Privacy Commissioner of Canada in the investigation. In-person support will be available for customers who need assistance. The President & CEO, Peter Gregg, assures continued transparency and efforts to restore services.
Cybersecurity Incident NSEB IR-01 Attachment 4 Page 7 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED)
AI summary This document is a redacted page from a cybersecurity incident report related to Nova Scotia Energy Board (NSEB) IR-01. It contains confidential information and is part of an attachment to the incident report.
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025)
AI summary This document provides updates on a cyber incident affecting NS Power, including actions taken by the Canadian Centre for Cybersecurity, RCMP, and Nova Scotia Energy Board.
Friday, May 23, 2025 Update We wanted to provide an update on Nova Scotia Power's ongoing cyber incident. Today, we are confirming we have been the victim of a sophisticated ransomware attack. Since the incident began several weeks ago, No...
AI summary Nova Scotia Power has been the victim of a sophisticated ransomware attack. They have not paid the threat actor and are working with cybersecurity experts to restore systems and assess the impact. Affected customers have been notified and provided with free credit monitoring services.
Wednesday, May 14, 2025 Update Nova Scotia Power continues to investigate a cyber incident that has impacted certain IT systems in our network. We are working with external cybersecurity experts to determine the scope of the impact and saf...
AI summary Nova Scotia Power is investigating a cyber incident that occurred on or around March 19, 2025, which resulted in unauthorized access to customer information stored on impacted servers. Notifications are being sent to affected customers, and a free two-year credit monitoring service is being provided through TransUnion. Customers are advised to be cautious of unsolicited communications.
Cybersecurity Incident NSEB IR-01 Attachment 4 Page 9 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED) NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) Any customer who receives a letter in the mail from Nova Scoti...
AI summary Nova Scotia Power is providing customers who receive mail letters with a phone number to contact for questions and to activate a two-year credit monitoring subscription following a cybersecurity incident.
Cybersecurity Incident NSEB IR-01 Attachment 4 Page 10 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED) NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025)
AI summary This document provides updates from NS Power regarding a cybersecurity incident, as reported on their website on September 5, 2025. The content is redacted, indicating that it contains confidential information.
Thursday, May 1, 2025 Update Nova Scotia Power is providing important information about the recent cyber incident affecting our company. On April 25, we detected unusual activity on our network and immediately initiated our incident respon...
AI summary Nova Scotia Power has experienced a cyber incident where unauthorized access occurred, potentially compromising customer personal information. The company has initiated an investigation with external cybersecurity experts and notified law enforcement. No disruption to operations has been reported, and customers are advised to remain cautious of unsolicited communications.
Cybersecurity Incident NSEB IR-01 Attachment 4 Page 11 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED) NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025)
AI summary This document provides updates on a cybersecurity incident involving NS Power, with excerpts from their website as of September 5, 2025. It highlights the ongoing efforts and responses to the incident, though specific details are redacted due to confidentiality.
Monday, April 28, 2025 Update Emera Inc. and Nova Scotia Power today announced on April 25, 2025 they discovered and are actively responding to a cybersecurity incident involving unauthorized access into certain parts of its Canadian netwo...
AI summary Emera Inc. and Nova Scotia Power disclosed a cybersecurity incident involving unauthorized access to parts of their Canadian network. They have activated response protocols, engaged cybersecurity experts, and isolated affected servers. Operations in Nova Scotia remain unaffected, and there is no expected material financial impact.
July 8, 2025 - Power meters have continued to function and gather accurate energy usage data from homes and businesses across the province. However, due to the cyber incident, the meters have not been able to communicate that data to our s...
AI summary Nova Scotia Power has experienced a cyber incident affecting communication from power meters to their systems. Billing was paused and later resumed with estimated bills. Meter readers are now visiting homes to collect accurate energy usage data, and customers may receive estimated bills if access is hindered.
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) - Those who want to sign up for the credit monitoring service can use our [Customer Verification Form](https://www.nspower.ca/home cyber/customer-verification-form) t...
AI summary NS Power is offering a credit monitoring service to affected customers following a cyber incident. Customers can access the service through a verification form and will not be charged for any related costs. NS Power remains available for regular business during standard hours.
Wednesday, June 5, 2025 - Nova Scotia Power leadership appeared before the Nova Scotia Public Accounts Committee as part of our ongoing commitment to transparency following the recent ransomware attack. - Immediately after detecting the cy...
AI summary Nova Scotia Power addressed a recent ransomware attack before the Public Accounts Committee, outlining their response, including notifying affected customers, offering credit monitoring, and cooperating with investigations. No ransom was paid, and the company is focused on rebuilding trust and enhancing cybersecurity.
Friday, May 23, 2025 - Nova Scotia Power confirms we been the victim of a sophisticated ransomware attack. - No payment has been made to the threat actor. This decision reflects our careful assessment of applicable sanctions laws and align...
AI summary Nova Scotia Power has confirmed being a victim of a ransomware attack. No payment has been made to the threat actor, and the company is working with cybersecurity experts to assess the impact and restore systems safely.
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) and investigate the incident. We have also been working to further strengthen our systems and add additional security protections. - Notifications have been mailed to...
AI summary NS Power has been working to strengthen its systems and add additional security protections following a cyber incident. Notifications have been sent to impacted account holders, and a two-year free credit monitoring service has been provided through TransUnion. NS Power expresses regret over the incident and emphasizes the importance of protecting customer information.
Wednesday, May 14, 2025 - Nova Scotia Power continues to investigate a cyber incident that has impacted certain IT systems in our network. - While the investigation remains ongoing, we have determined that on or around March 19, 2025, cert...
AI summary Nova Scotia Power is investigating a cyber incident that occurred on or around March 19, 2025, which led to unauthorized access to customer information. Affected customers are being notified and offered free credit monitoring services from TransUnion.
Thursday, May 1, 2025 - We are actively responding to a cyber incident that has impacted certain IT systems in our network. - While our investigation is ongoing, we have identified that certain customer personal information was accessed an...
AI summary Nova Scotia Power is responding to a cyber incident that has compromised certain IT systems, resulting in unauthorized access to customer personal information. The investigation is ongoing.
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) - If we determine that your data was affected, we will send you notice with further details including about the affected information, along with resources and support...
AI summary NS Power is informing customers about a potential cyber incident and advising them to be cautious of unsolicited communications requesting personal information. Customers affected will be notified with further details and resources.
Monday, April 28, 2025 - Emera and Nova Scotia Power discovered and are actively responding to a cybersecurity incident involving unauthorized access into certain parts of our network and servers supporting portions of our business applica...
AI summary Emera and Nova Scotia Power have detected a cybersecurity incident involving unauthorized access to parts of their network and servers. They have taken steps to contain the breach and ensure no disruption to physical operations or customer service.
What happened? Last updated: Tuesday, June 24, 2025 On April 25, we discovered and began actively responding to a cybersecurity incident involving unauthorized access into certain parts of our network and servers. Upon further investigatio...
AI summary A cybersecurity incident involving unauthorized access to Nova Scotia Power's network and servers was discovered on April 25. A ransomware attack led to the access and exfiltration of customer personal information. No ransom was paid in compliance with legal guidance, and the investigation is ongoing.
What is Nova Scotia Power doing to address this cyber incident? Last updated: Tuesday, June 24, 2025 While our investigation remains ongoing, we have taken the following steps: - Engaged third-party cybersecurity experts to help us investi...
AI summary Nova Scotia Power is addressing a cyber incident by engaging third-party cybersecurity experts, notifying law enforcement and regulators, and conducting a detailed review of accessed data. The investigation is ongoing, and it has been confirmed that some customer personal information was taken.
Cybersecurity Incident NSEB IR-01 Attachment 4 Page 17 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED)
AI summary This document is a redacted attachment from a cybersecurity incident report related to the Nova Scotia Energy Board. It contains confidential information and does not provide specific details about the incident or its implications.
Was customer information or confidential business information accessed? Last updated: Tuesday, June 24, 2025 While our investigation is ongoing, we have identified that certain customer personal information was accessed and taken by the th...
AI summary The investigation revealed that customer personal information was accessed and taken by a threat actor, with some data published on the dark web. Impacted customers have been notified and provided with resources and support.
Was my data impacted? Last updated: Wednesday, June 25, 2025 Anyone who received a letter from us did receive information about what personal data may have been impacted in that letter. Our investigation remains ongoing. The ransomware att...
AI summary Nova Scotia Power is investigating the impact of a ransomware attack on customer data. While letters were sent to those affected, specifics remain unclear. The company is offering free credit monitoring to all customers as a precautionary measure.
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) Last updated: Wednesday, June 25, 2025 Our investigation is ongoing, and we sent letters to customers we determined to have been impacted in the incident. Out of an a...
AI summary NS Power is expanding its offer of five years of free credit monitoring to all current and past customers as part of ongoing efforts to address a cyber incident. The investigation is ongoing, and letters have been sent to impacted customers.
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) Power—past and present—regardless of whether you received a letter from us about the incident.
AI summary NS Power provides updates regarding a cyber incident, including information for customers who may have received a letter about the incident, as well as those who have not.
Cybersecurity Incident NSEB IR-01 Attachment 4 Page 20 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED) NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025)
AI summary This document provides updates from NS Power regarding a cybersecurity incident, as reported on their website on September 5, 2025. It is part of a regulatory proceeding and includes redacted confidential information.
Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests
AI summary The document outlines the Nova Scotia Energy Board's inquiry into Nova Scotia Power's cybersecurity incident, along with NSP's responses to information requests from the NSEB.
BOARD CONFIDENTIAL (Attachment Only) 1 Request IR-9: 2 3 Does the utility currently have a communication policy in place in case of a cybersecurity 4 breach? 5 6 (a) If yes, please share the policy document. 7 (b) If not, why not. 8 9 Resp...
AI summary The utility, NS Power, confirms it has a 'Cyber Incident Communication Playbook' in place to address cybersecurity breaches. The document outlining this policy is included as a confidential attachment.
N-3Incident Report - Redacted (N-3 from M12273)
10 passages
Board Inquiry into Nova Scotia Power's Cybersecurity Incident Nova Scotia Power Incident Report December 22, 2025 REDACTED
AI summary The document outlines a Board Inquiry into a cybersecurity incident involving Nova Scotia Power, with the incident report dated December 22, 2025. The content is partially redacted, limiting the details available.
2025 Nova Scotia Power's Cybersecurity Incident Report REDACTED 1 TABLE OF CONTENTS 2 3 1.0 INTRO DDUCTION 3 4 2.0 THE IN NCIDENT 7 5 3.0 AFFEC CTED SYSTEMS AND DATA 11 6 3.1 Compromised Systems 11 7 3.2 Data & Personal Information 13 8 4....
AI summary This document outlines the 2025 Nova Scotia Power's Cybersecurity Incident Report, which was requested by the Nova Scotia Energy Board following a cybersecurity incident. The report includes sections on the incident description, affected systems, response actions, impact analysis, and recommendations for improving cybersecurity measures.
26 assess its data handling practices. DATE FILED: December 22, 2025 Page 3 of 43 1 M12273, Board Inquiry into Nova Scotia Power's Cybersecurity Incident, NSEB Letter, July 14, 2025, page 1. 2 M12273, NSEB Letter, July 14, 2025, pp. 2-3. 3...
AI summary The document references a cybersecurity incident involving Nova Scotia Power and an inquiry by the Nova Scotia Energy Board. It includes citations to letters and pages from the inquiry, indicating a regulatory process focused on data handling practices.
2025 Nova Scotia Power's Cybersecurity Incident Report REDACTED 1 2. In the incident report to be filed by the end of this year, please provide a Gantt chart 2 that includes a list of all the summary tasks/rolled-up tasks currently underta...
AI summary Nova Scotia Power (NSP) is required to submit a detailed cybersecurity incident report, including Gantt charts for system restoration and impacted Board matters. The Premier of Nova Scotia has directed the NSEB to investigate NSP's billing methodology, consumer protections, and potential financial relief for affected customers.
2025 Nova Scotia Power's Cybersecurity Incident Report REDACTED 1 Matter M12273-Board Inquiry into Nova Scotia Power's Cybersecurity Incident. This would be the most efficient way to address the matter.[7](#page-5-0) 2 3 4 Accordingly, the...
AI summary This document outlines a 2025 cybersecurity incident report by Nova Scotia Power (NSP) under a Board inquiry (M12273). It references a related complaint (M12457) regarding systemic regulatory compliance issues at Blarney Stone Restaurant and a letter from the Nova Scotia Energy Board (NSEB) dated December 10, 2025.
- 3 As discussed above, NS Power has been committed to transparency in its communications with - 4 customers and other stakeholders throughout the cyber response to date. This approach has focused - 5 on the importance of sharing known inf...
AI summary Nova Scotia Power has emphasized transparency in its communication with customers and stakeholders during the cyber incident, evolving its approach based on new information, customer feedback, and system restoration. The company has used various channels, including in-person sessions and radio ads, to reach customers and provide updates on billing and credit monitoring.
25 4.3 Other Stakeholders 26 - 27 NS Power employees have been a key stakeholder audience throughout the Incident, as they were - 28 impacted as employees and as customers. Employees have received ongoing communications in - 29 the form of...
AI summary This section discusses the involvement of NS Power employees as key stakeholders during a cyber incident, highlighting their dual role as employees and customers, and the communication efforts made to keep them informed.
NS Power Cyber Incident Report Appendix A Page 1 of 2 REDACTED (CONFIDENTIAL INFORMATION REMOVED)
AI summary The document is a redacted appendix from a cyber incident report by NS Power, indicating that confidential information has been removed. It does not provide specific details about the incident or its implications.
PROGRAM STRUCTURE The Restoration Program is structured into five (5) key portfolios of work – focusing on restoring business capabilities. Portfolio Scope Summary Enterprise Resource Planning (ERP) Recovery and restoration of core enterpr...
AI summary The Restoration Program is structured into five portfolios: Enterprise Resource Planning, Customer, Additional Capabilities, Cybersecurity, and Technology Enablement, each aimed at restoring critical business operations and systems.
NS Power Cyber Incident Report Appendix B Page 1 of 7 Affected Regulatory Matters Report 2 - October 1 Report 3 - November 3 Report 4 - December 1 Latest update Forecast Restoration of Normal Activities Rates-Rela ted Matters
AI summary The document is an appendix from a cyber incident report by NS Power, outlining affected regulatory matters. It includes a table with reports dated October 1, November 3, and December 1, along with a forecast for the restoration of normal activities.
N-13Evidence - InterGroup, on behalf of CA - Redacted
11 passages
In the Matter of EVIDENCE OF ED MOLLARD M12600 JUNE 23, 2026 Nova Scotia Power Incorporated (NSPI) AN INQUIRY ABOUT THE IMPACT OF THE CYBER INCIDENT ON NSPI'S COLLECTION AND RETENTION OF CUSTOMER INFORMATION, CUSTOMER SERVICE AND COMMUNICA...
AI summary This document is pre-filed testimony from Ed Mollard on behalf of the Consumer Advocate regarding the impact of a cyber incident on NSPI's customer information management, customer service, billing processes, and regulatory matters. The testimony was submitted to the Nova Scotia Energy Board.
This testimony has been prepared for the Consumer Advocate ("CA") by or under the direction of Ed Mollard of InterGroup Consultants Ltd. ("InterGroup"). This report reviews the Nova Scotia Power ("NSP", "NSPI", "NS Power") Cybersecurity In...
AI summary This testimony, prepared by Ed Mollard of InterGroup Consultants Ltd. for the Consumer Advocate, reviews a cybersecurity incident at Nova Scotia Power. Mollard outlines his qualifications, the scope of his review, and his commitment to providing fair and objective evidence to the Nova Scotia Energy Board.
2.0 SUMMARY OF RECOMMENDATIONS Based on the analysis summarized in this report, InterGroup makes the following recommendations to the Board: - Recommendation 1: InterGroup recommends NSPI be directed to update its staff training policies a...
AI summary InterGroup recommends several measures to NSP and NSPI, including updating staff training policies, enhancing privacy practices, conducting compliance audits, improving customer notifications, and managing credit monitoring services. These recommendations aim to improve cybersecurity, privacy, and customer communication following a data breach incident.
3.0 OVERVIEW OF INCIDENT The NSPI Incident Report 1 dated December 22, 2025, states that on or around March 19, 2025 a Nova Scotia Power employee visited a website and clicked on a pop-up link which resulted in malware being downloaded and...
AI summary A cybersecurity incident occurred at Nova Scotia Power on March 19, 2025, when an employee clicked on a malicious link, leading to malware installation. The breach was discovered on April 25, 2025, and affected ERP systems, billing systems, and customer data, including personal information. The threat actor did not access operational systems, and the company has taken steps to address the incident.
4.0 CYBERSECURITY AWARENESS TRAINING NS Power indicates at the time of the incident, its approach to privacy compliance was documented through its privacy policies and procedures.[13](#page-8-1) We understand that NSP maintains thirteen (1...
AI summary The document discusses NSP's cybersecurity awareness training program, including its mandatory quarterly training, monthly phishing simulations, and privacy policies. NSP reports high completion rates for training and outlines its phishing failure rate targets.
5.0 COLLECTION AND RETENTION OF CUSTOMER INFORMATION NS Power's cybersecurity incident investigations showed that certain personal customer information for both current and former customers was exfiltrated from the system. Depending on the...
AI summary NS Power experienced a cybersecurity incident resulting in the exfiltration of personal customer information. The document discusses NS Power's data collection and retention practices, referencing PIPEDA and noting issues revealed by the incident. InterGroup highlights the requirement for clear purposes in data collection and consent for new uses.
5.2 FORMER CUSTOMER DATA NS Power retained personal information relating to former customers within its CIS system and these were also impacted by the cybersecurity breach. NSP states approximately 540,000 former customers were affected by...
AI summary NS Power retained personal information of approximately 540,000 former customers, which were impacted by a cybersecurity breach. The company's policy on data retention and disposal is unclear, despite information requests. NSP's privacy policy mentions varying retention periods based on product/service and legal needs, but specific timelines are not provided. Emera's records management policies are referenced but lack detailed data retention timelines.
6.0 STAKEHOLDER COMMUNICATION NS Power states that its incident response and business continuity processes were activated following the detection of the Cybersecurity breach.[40](#page-15-2) NS Power notified relevant law enforcement agenc...
AI summary NS Power activated its incident response and business continuity processes after a cybersecurity breach was detected. It notified law enforcement agencies and the OPC, and implemented a multi-channel communication approach, including public postings, direct notices to impacted customers, and updates through various platforms.
6.1 TIMING OF INCIDENT DETECTION AND INITIAL CUSTOMER NOTIFICATION NS Power discovered the incident on April 25, 2025, over a month after the breach first occurred (March 19, 2025) and subsequently issued a public notice on April 28, 2025....
AI summary NS Power discovered a cybersecurity breach on April 25, 2025, over a month after it occurred on March 19, 2025, and issued a public notice 39 days later. This delay led to customer trust loss, complaints, and service disruptions. NS Power attributes the delay to limitations in its security detection systems. The NSEB is reviewing cybersecurity improvements as part of Proceeding M12273.
6.3 COMMUNICATION TO FORMER CUSTOMERS NS Power determined that personal information of former customers was also impacted by the breach and provided a public notification on June 25, 2025.[59](#page-18-1) With respect to communication to i...
AI summary NS Power notified the public about a data breach affecting former customers but did not directly contact them due to lack of updated contact information. A recommendation is made for NSP to explore ways to reach former customers who may have relocated outside the province.
9.0 INCIDENT COST TREATMENT NSP notes it activated its incident response and business continuity protocols, engaging both internal and external experts to support efforts on containment, eradication and remediation of the threat.[84](#page...
AI summary NSP has incurred costs related to a security breach and is isolating these costs through separate project codes. While some costs, such as credit monitoring, may be covered by insurance, it is unclear whether other costs will be passed on to customers. Recommendations suggest that NSP should not recover these costs from customers and isolate future insurance premium increases related to the incident.
N-14Evidence & Appendix A Resume - Tricia Ralph INQ Law/Consulting - BCC
11 passages
- 1. In my opinion, the following met best practice, and were reasonable in terms of expectations for customer service and limiting the impacts of the cybersecurity attack on customers: - Aside from issues related to the personal informati...
AI summary The text evaluates Nova Scotia Power Incorporated's (NSPI) response to a cybersecurity attack, finding some actions reasonable and others unreasonable. Key points include the reasonableness of customer notification timelines and communication efforts, while the use of a PI inventory, retention of SINs, and insufficient customer notices were deemed unreasonable.
B. Introduction - 1. I have been retained by Counsel for the Nova Scotia Energy Board ("NSEB") to carry out a review of NSPI's privacy related practices in relation to the cybersecurity incident NSPI identified on April 25, 2025 (the "Inci...
AI summary This report outlines a review of NSPI's privacy practices following a cybersecurity incident identified on April 25, 2025. The reviewer was retained by the Nova Scotia Energy Board to assess the reasonableness of NSPI's actions in delivering services to its customers.
D. Methodology 5. In order to come to my opinions, I reviewed the 2025 Nova Scotia Power's Cybersecurity Incident Report (the "Incident Report") and responses to my Information Request ("IR") to NSPI, as well as relevant information in oth...
AI summary The methodology section outlines the review of NSPI's 2025 Cybersecurity Incident Report and responses to an information request, using PIPEDA principles as a benchmark for evaluating the reasonableness of NSPI's actions without interpreting PIPEDA itself.
Privacy Training - 20. Privacy training ensures that employees who handle PI understand their obligations and the risks associated with mishandling it. Without it, even well-designed policies are ineffective, as human error remains one of...
AI summary The document outlines NSPI's privacy training initiatives, including quarterly cybersecurity training and monthly phishing simulations. While NSPI achieved a 96% completion rate in 2024, the rate dropped to 79% in 2025, which is considered low. After the Incident, 100% of required training was completed in the first quarter of 2026.
Current Customer Notification - 37. As set out in Section 4.2 of the Incident Report, on Monday April 28, 2025, three days after it discovered the Incident, NSPI informed customers that it was actively responding to a cybersecurity inciden...
AI summary NSPI informed customers of a cybersecurity incident through various channels starting on April 28, 2025, and continued updates through May 2025. Direct notifications were sent on May 13, 2025, to 277,000 affected customers. The timeline was deemed reasonable, balancing the need for accuracy with timely communication.
Former Customer Notification 45. Section 4.2 of the Incident Report states that as it continued its investigation, NSPI determined that PI relating to former customers had also been impacted by the Incident. The Incident Report does not sp...
AI summary The Incident Report indicates that NSPI identified former customer data was impacted by the Incident, but did not notify them until two months after the Incident was discovered. The delay is considered unreasonable, as best practices suggest notification should occur within days, not months, unless extenuating circumstances apply, which were not indicated here.
- 50. In its notification letters, NSPI explained that the impacted data would have varied by customer, and depended, in part, on the information a customer would have provided NSPI. The types of PI that customers were notified as having p...
AI summary NSPI informed customers of a data breach affecting personal information, including names, addresses, SINs, and account details. Customers were concerned about the lack of specific information on impacted data and the difficulty in taking protective measures. NSPI could not definitively identify the data impacted on an individual basis.
- 65. In Section 8.5 of the Incident Report, NSPI explained that in addition to the information it collects identified above, prior to the Incident, there was also a practice of collecting social insurance numbers (SINs): - Prior to 2018,...
AI summary NSPI collected SINs from customers prior to 2018 for account authentication but stopped in 2018. In 2021, during the MyEnergy Insights program, SINs were inadvertently exported to a cloud environment and may have been exfiltrated. SINs are considered highly sensitive due to the difficulty in remediation if compromised.
Issue 6 – Third-party Service Providers - 90. Board counsel has asked that I provide an opinion on the reasonableness of NSPI's actions in relation to the Incident concerning security measures implemented with third -party service provider...
AI summary The Board counsel seeks an opinion on the reasonableness of NSPI's actions regarding third-party service providers in relation to a security incident. NSPI asserts the incident was caused by malware installed by an employee, not due to third-party service providers. Active oversight of third-party providers is emphasized, but since they were not involved in the incident, further opinion on this issue is not required.
Issue 10 – Communications Related to Cybersecurity Issues - 93. Board counsel has asked that I provide an opinion on the reasonableness of NSPI's actions concerning communications with customers about the Incident. - 94. In Section 4.2 of...
AI summary The document discusses NSPI's approach to communicating with customers and stakeholders during a cybersecurity incident, including the use of a multi-channel strategy and media outreach to ensure transparency and keep customers informed.
F. Conclusion - 105. In conclusion, in my opinion, the following actions by NSPI met best practice, and were reasonable in terms of expectations for customer service and limiting the impacts of the cybersecurity attack on customers: - Asid...
AI summary The conclusion evaluates NSPI's actions following a cybersecurity attack, finding some measures reasonable and others not. While NSPI's privacy governance, notification timelines, and customer communication were deemed reasonable, the use of a PI inventory, retention of SINs, and lack of record-keeping were considered unreasonable.
N-16NSPI Refiled Formal Incident Report - Redacted (filed in M12273 as N-5 on April 27, 2026)
41 passages
DATE FILED: December 22, 2025 Page 4 of 46 20260427 REFILE 20251222 NSPI to NSEB Cyber Incident Report PCON.docx 5 M12600, Minister of Energy – Accountability for Nova Scotia Power Inc., Minister of Energy Letter, December 3, 2025.
AI summary A cyber incident report from NSPI to NSEB was filed on December 22, 2025, referencing a ministerial letter dated December 3, 2025, concerning accountability for Nova Scotia Power Inc.
2025 Nova Scotia Power's Cybersecurity Incident Report REDACTED 1 The NSEB replied to the Premier by letter on December 10, 2025, providing, in part, the following: 2 3 Upon receipt of your letter, the Board opened a new matter (M12600). G...
AI summary The NSEB opened a new matter (M12600) following a letter from the Premier, connecting it to an ongoing cybersecurity inquiry (M12273). NS Power argues that many issues raised by the Premier were already addressed in prior reports and that M12273 is the appropriate proceeding. The NSEB also requested NS Power to provide updates on a broader review related to a customer complaint (M12457).
1 Incident, on May 28, 2025 and the Company is actively and fully cooperating with the OPC to 2 support the OPC's investigative efforts. 3 4 Incident Timeline & Attack Vector 5 6 The forensic investigation of the Incident has been complex....
AI summary This text details a cybersecurity incident at NS Power, where an employee clicked on a malicious link, leading to a sophisticated attack that compromised the company's systems starting March 19, 2025. The threat actor used persistence mechanisms and elevated privileges to move laterally and deploy ransomware on April 25, 2025.
1 Between April 8 and April 22, 2025, the threat actor leveraged this malware to access systems in 2 the environment and to perform additional internal reconnaissance and credential harvesting 3 activities. 4 5 Beginning on or around April...
AI summary Between April 8 and 22, 2025, a threat actor used malware to access systems in the environment and perform reconnaissance and credential harvesting. On April 25, 2025, data was exfiltrated, ransomware was deployed, and backups were destroyed. NS Power disabled external access and isolated affected systems. The incident was contained by April 29, 2025.
2025 Nova Scotia Power's Cybersecurity Incident Report REDACTED 1 4.0 RESPONSE AND RECOVERY ACTIONS 23 24 Ongoing remediation steps include: 25 26 27 28 1 2 3 4 5 6 NS Power is also advancing efforts to restore and, where necessary, rebuil...
AI summary The document outlines Nova Scotia Power's response and recovery actions following a 2025 cybersecurity incident. It details ongoing remediation efforts, including the restoration of core business systems and the establishment of a Business Restoration Process Office (RPO) to coordinate recovery. The report also mentions the company's existing cybersecurity safeguards, which are based on the NIST Cybersecurity Framework.
1 To ensure customers were kept informed, the Company also employed a multi-platform paid media 2 strategy that includes online, as well as TV, print and radio to reach a wide variety of customer 3 demographics. In addition, NS Power activ...
AI summary NS Power implemented a multi-platform communication strategy, including paid media and social media, to keep customers informed during a cybersecurity incident. Customers were also encouraged to report suspicious activities, and support was available via customer care representatives.
day, April 28, 2025, NS Power informed customers that it was actively 16 responding to a cybersecurity incident, and encouraged customers to report any suspicious emails 17 or phone calls. 18 11 13 19 On May 1, 2025, NS Power determined th...
AI summary NS Power informed customers on April 28, 2025, about a cybersecurity incident and encouraged them to report suspicious communications. On May 1, 2025, the company confirmed that customer information had been impacted and updated customers using a multi-channel strategy, while working to determine the full scope of the incident and initiating notification processes.
1 them with information about the Incident. Given the nature of the cyber attack and the critical 2 infrastructure nature of the company and the North American electric utility industry, the Company 3 also notified the Federal Bureau of In...
AI summary NS Power experienced a cyber attack and notified the FBI and OPC. The company's response was deemed effective due to prior preparation, including third-party experts, updated incident-response plans, and simulation exercises.
REDACTED 1 In addition, the Company deployed dozens of employees to communities across the 2 province to provide hands-on support for customers who prefer assistance in person, 3 recognizing that not all customers may be comfortable regist...
AI summary NS Power deployed employees to assist customers in person and updated its website to improve access to services. The company has implemented cybersecurity standards aligned with NIST and NERC, and has completed a two-year update to its cybersecurity practices. NERC conducts periodic audits of NS Power's energy operations.
REDACTED 1 NS Power maintains a cybersecurity training and awareness program and conducts 2 mandatory quarterly cyber training and monthly phishing simulation testing exercises with 3 all employees to educate employees about NS Power's inf...
AI summary NS Power has implemented a cybersecurity training and awareness program, including mandatory quarterly training and monthly phishing simulations. Following a cybersecurity incident, NS Power activated its incident response protocols, engaged third-party experts, and initiated containment, eradication, and remediation efforts. Ongoing restoration and strengthening of cyber security systems are also being prioritized.
Station Contact WEST Bridgewater: CKBW Country 100.7FM [email protected]; [email protected] Yarmouth: CJLS [email protected] Liverpool: QCCR 99.3 FM [email protected] Kentville/New Minas: 89.3 Rewind [email protected] 94.9 Magic (M...
AI summary The document lists contact information for radio stations across Nova Scotia and references a Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273), along with NSPI Responses to NSEB Information Requests.
2 Date Media Outlet Format Reporter Member of NSP senior leadership team Topic May 23, 2025 CBC TV Amy Smith, Anchor recorded sit-down interview Peter Gregg, President and CEO Cyber incident update May 23, 2025 CBC Mainstreet Radio Jeff Do...
AI summary Nova Scotia Power (NSP) has been involved in a series of media interviews and public communications regarding a cybersecurity incident. NSP's President and CEO, Peter Gregg, and Director of Customer Care, Chris Lanteigne, have addressed the incident and related customer support efforts. The Nova Scotia Energy Board (NSEB) is conducting an inquiry into the incident under matter number M12273.
REDACTED July 9, 2025 CBC Nova Scotia Radio Elizabeth McMillan Chris Lanteigne, Director Customer Care Cyber incident\nupdate Billing concerns Customer support sessions in communities across NS July 11, 2025 CBC Nova Scotia – Information M...
AI summary The text includes a table with media coverage related to a cybersecurity incident and customer care sessions in Nova Scotia. It also references a cybersecurity incident report attached to NSEB IR-01.
Re: Important Notice About Your Personal Information Dear Valued Customer: We are writing to provide you with information about the recent cyber incident impacting Nova Scotia Power. On April 25, 2025, Nova Scotia Power discovered that an...
AI summary Nova Scotia Power informed customers of a cyber incident on April 25, 2025, where unauthorized access occurred to parts of its Canadian network. Customer information, including personal and account details, was accessed. The company is offering free credit monitoring and advising customers to be cautious of unsolicited communications.
https://www.mytrueidentity.ca You will be prompted to enter the following activation code: Please ensure that you redeem your activation code before 9/30/2025 to take advantage of the service. Upon completion of the online activation proce...
AI summary This document provides information about activating a service called my TrueIdentity® which offers credit monitoring, identity theft protection, and related features. It also includes a note about cybersecurity incident NSEB IR-01 Attachment 1 Page 4 of 4.
What is the dark web? These threat actors, and other cyber criminals, use a hidden part of the internet that is only accessible through special software—it is commonly referred to as the "dark web" and is known to be used by cyber criminal...
AI summary The text explains that the dark web is a hidden part of the internet accessible only through special software, often used by cyber criminals to store and trade data. It also provides contact information for technical support related to myTrueIdentity® and references a cybersecurity incident attachment.
We're Here to Help We know this has been a scary and frustrating time for our customers, and we are sincerely sorry that this has happened. To better assist you, we will be visiting communities in Nova Scotia to offer in-person support. Ou...
AI summary Nova Scotia Power is offering in-person support to customers affected by a cybersecurity incident. They are providing assistance with credit monitoring registration, estimated bills, and other customer-related inquiries. Customers are advised to be cautious of scams during the incident.
July 8, 2025 Since the cyber incident discovered on April 25, power meters have continued to function and gather accurate energy usage data from homes and businesses across the province. However, due to the cyber incident, the meters have...
AI summary A cyber incident on April 25 has caused power meters to function but not communicate data, leading to estimated billing. Meter readers are now visiting properties to collect actual usage data, with customers receiving estimated bills if access is not possible. Nova Scotia Power is addressing the issue and has provided information on adjusted billing processes.
Wednesday, June 25, 2025 Update A dedicated team within Nova Scotia Power, along with third-party cybersecurity experts, are continuing the investigation into the recent ransomware attack that has impacted our customers and our company. To...
AI summary Nova Scotia Power is updating customers about a ransomware attack that impacted personal data of former and current customers. The company is offering five years of free credit monitoring to all customers. Personal information potentially accessed includes names, contact details, account history, and possibly bank account numbers and Social Insurance Numbers.
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) We are focused on supporting our customers. We are here for regular business from 8 AM–6 PM, Monday through Friday. Please contact us at 1-800-428-6230 . To make it e...
AI summary Nova Scotia Power is addressing a cybersecurity incident, providing customer support, and cooperating with the Office of the Privacy Commissioner and the Nova Scotia Energy Board. They are working to delete SINs from their systems and are taking steps to prevent future incidents.
Wednesday, June 4, 2025 Update Following the recent ransomware attack and its effect on our customers, we've been invited to speak with members of the Nova Scotia Public Accounts Committee at their meeting today. While recognizing that the...
AI summary Nova Scotia Power is addressing a recent ransomware attack affecting customers and is participating in a meeting with the Nova Scotia Public Accounts Committee. The company emphasizes its commitment to transparency and collaboration with cybersecurity experts and law enforcement.
Friday, May 23, 2025 Update We wanted to provide an update on Nova Scotia Power's ongoing cyber incident. Today, we are confirming we have been the victim of a sophisticated ransomware attack. Since the incident began several weeks ago, No...
AI summary Nova Scotia Power has confirmed a ransomware attack affecting its systems. The company has been working with cybersecurity experts to restore systems and investigate the incident. No ransom has been paid, and affected customers have been notified with details on credit monitoring services. The incident is being discussed in the context of cybersecurity and regulatory oversight.
Wednesday, May 14, 2025 Update Nova Scotia Power continues to investigate a cyber incident that has impacted certain IT systems in our network. We are working with external cybersecurity experts to determine the scope of the impact and saf...
AI summary Nova Scotia Power is investigating a cybersecurity incident that occurred on or around March 19, 2025, where unauthorized access occurred to customer information stored on impacted servers. Notifications are being sent to affected customers, and a two-year credit monitoring service is being provided at no cost.
Thursday, May 1, 2025 Update Nova Scotia Power is providing important information about the recent cyber incident affecting our company. On April 25, we detected unusual activity on our network and immediately initiated our incident respon...
AI summary Nova Scotia Power is informing customers about a recent cybersecurity incident that resulted in unauthorized access to customer personal information. The company has initiated an investigation with external experts and is working to restore systems securely. Customers are advised to be cautious of unsolicited communications. No disruption to service has been reported.
Monday, April 28, 2025 Update Emera Inc. and Nova Scotia Power today announced on April 25, 2025 they discovered and are actively responding to a cybersecurity incident involving unauthorized access into certain parts of its Canadian netwo...
AI summary Emera Inc. and Nova Scotia Power disclosed a cybersecurity incident involving unauthorized access to parts of their Canadian network. The companies have activated response protocols and engaged cybersecurity experts to contain the breach. Operations in Nova Scotia remain unaffected, and there is no expected material financial impact.
Wednesday, June 25, 2025 - x Beginning today, we will be offering five years of free credit monitoring to all customers of Nova Scotia Power, past and present, regardless of whether you received a letter from us about the incident. Anyone...
AI summary Nova Scotia Power is offering free credit monitoring for five years to all current and former customers following a cybersecurity incident where personal information was accessed by an unauthorized third party on or around March 19, 2025.
Wednesday, June 5, 2025 - x Nova Scotia Power leadership appeared before the Nova Scotia Public Accounts Committee as part of our ongoing commitment to transparency following the recent ransomware attack. - x Immediately after detecting th...
AI summary Nova Scotia Power leadership appeared before the Nova Scotia Public Accounts Committee following a ransomware attack that resulted in stolen customer data. The company activated response protocols, engaged cybersecurity experts, and notified impacted customers, offering free credit monitoring and identity protection. No ransom was paid, and the company is cooperating with investigations and investing in cybersecurity.
Friday, May 23, 2025 - x Nova Scotia Power confirms we been the victim of a sophisticated ransomware attack. - x No payment has been made to the threat actor. This decision reflects our careful assessment of applicable sanctions laws and a...
AI summary Nova Scotia Power has confirmed a ransomware attack, resulting in stolen data being published by the threat actor. No ransom has been paid, and the company is working with cybersecurity experts to assess the impact and restore systems.
Wednesday, May 14, 2025 - x Nova Scotia Power continues to investigate a cyber incident that has impacted certain IT systems in our network. - x While the investigation remains ongoing, we have determined that on or around March 19, 2025,...
AI summary Nova Scotia Power is investigating a cyber incident that occurred around March 19, 2025, which resulted in unauthorized access to customer information stored on impacted servers. Notifications are being sent to affected customers, and a two-year credit monitoring service is being provided at no cost as a precaution.
Thursday, May 1, 2025 - x We are actively responding to a cyber incident that has impacted certain IT systems in our network. - x While our investigation is ongoing, we have identified that certain customer personal information was accesse...
AI summary A cybersecurity incident has occurred, impacting IT systems and leading to unauthorized access of customer personal information. The investigation is ongoing, and the incident is being actively addressed.
Monday, April 28, 2025 - x Emera and Nova Scotia Power discovered and are actively responding to a cybersecurity incident involving unauthorized access into certain parts of our network and servers supporting portions of our business appli...
AI summary Emera and Nova Scotia Power are responding to a cybersecurity incident involving unauthorized access to parts of their network and servers. Incident response protocols have been activated, and no physical operations have been disrupted. Customers are advised to remain vigilant and report suspicious activity.
What happened? Last updated: Tuesday, June 24, 2025 On April 25, we discovered and began actively responding to a cybersecurity incident involving unauthorized access into certain parts of our network and servers. Upon further investigatio...
AI summary A cybersecurity incident involving unauthorized access and a ransomware attack occurred on April 25, leading to the theft of customer personal information. No ransom was paid in compliance with sanctions laws. The investigation is ongoing, and updates are being provided through the company's website.
:KDWLV1RYD6FRWLD3RZHUGRLQJWRDGGUHVVWKLVF\EHULQFLGHQW"ௗௗ Last updated: Tuesday, June 24, 2025 While our investigation remains ongoing, we have taken the following steps: - x Engaged third-party cybersecurity experts to help us investigate,...
AI summary The NSEB has engaged cybersecurity experts to investigate and remediate a recent incident where customer personal information was accessed. The investigation is ongoing, and law enforcement and regulators have been notified.
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) - x Informed impacted customers via mail and provided a free subscription to TransUnion's credit monitoring service, my TrueIdentity®. - x Organized in-person support...
AI summary NS Power has informed impacted customers via mail and provided credit monitoring services. They have organized in-person support and resumed billing through an estimated billing approach, with customers able to access their bills through MyAccount.
Was my data impacted? Last updated: Wednesday, June 25, 2025 Anyone who received a letter from us did receive information about what personal data may have been impacted in that letter. Our investigation remains ongoing. The ransomware att...
AI summary Nova Scotia Power is investigating the impact of a ransomware attack on customer data. While they cannot confirm specifics, they are offering free credit monitoring to all customers as a precautionary measure.
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) Last updated: Wednesday, June 25, 2025 Our investigation is ongoing, and we sent letters to customers we determined to have been impacted in the incident. Out of an a...
AI summary NS Power is updating customers about a cyber incident, expanding free credit monitoring to all current and past customers for five years as a precautionary measure.
Why didn't you offer credit monitoring to everyone right away when this happened? Why now? Last updated: Wednesday, June 25, 2025 Our initial focus was on customers that were confirmed to have their personal data impacted by the breach. As...
AI summary The organization initially focused on customers confirmed to have been affected by a data breach but later expanded free credit monitoring to all customers, including former ones, due to evolving findings and a desire to provide reassurance and protection.
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) Power—past and present—regardless of whether you received a letter from us about the incident.
AI summary The document provides updates on a cyber incident affecting NS Power, with information directed to both past and present power customers, regardless of whether they received a letter regarding the incident.
What services have been affected? Last updated: Tuesday, June 24, 2025 Initially, there was disruption to our internal IT and customer care systems, which affected our billing processes and access to our online customer portal, MyAccount....
AI summary The incident disrupted internal IT and customer care systems, affecting billing processes and access to the online customer portal, MyAccount. Services such as MyEnergy Insights and Efficiency Insights are currently unavailable through MyAccount. Efforts are ongoing to restore full system functionality.
A. Background Facts - 2. NS Power has been the victim of a highly sophisticated ransomware attack. While the attack did not affect NS Power's infrastructure relating to the provision of power to its customers, the incident has caused some...
AI summary NS Power suffered a ransomware attack that did not impact customer infrastructure but disrupted internal IT and customer care systems. Customer data was exfiltrated and posted on the dark web. NS Power has collaborated with cybersecurity experts to respond to the incident.
Appendix "B" \ \ \ CONFIDENTIAL \ \ \ NS Power's Confidential Submission, particularly in respect of paragraphs 3-8, as well as the last sentence of paragraph 2, requires confidentiality protection because the information — when taken coll...
AI summary NS Power has experienced a major ransomware attack, leading to the theft and dark web posting of customer personal information. NS Power has not made any ransom payments and is seeking confidentiality protection for its submission due to the sensitive nature of the information. Cybersecurity guidelines from the Canadian Centre for Cyber Security and insights from PWC's Alison Wikoff are referenced.
N-17NS Power Rebuttal Evidence - Redacted
38 passages
Cybersecurity Accountability Nova Scotia Power Rebuttal August 10, 2026 REDACTED
AI summary The document is a redacted rebuttal from Nova Scotia Power regarding cybersecurity accountability, submitted on August 10, 2026.
1.0 INTRODUCTION - In a letter dated December 10, 2025, the Board initiated this matter (M12600) as a separate matter - from the ongoing cybersecurity inquiry (M12273). The Board confirmed it would determine a - process to consider M12600...
AI summary The document outlines the initiation and progression of regulatory matter M12600, which was separated from the ongoing cybersecurity inquiry (M12273). The Board determined that the matter would be addressed in an oral hearing after receiving NS Power's Cybersecurity Incident Report. NS Power provided responses to information requests and submitted evidence, including rebuttal evidence from Jena Valdetero of GreenbergTraurig.
Cybersecurity Accountability REDACTED Customers can still access these public/media updates on NS Power's website at nspower.ca/cyber. There are "[Cyber Incident Updates](https://www.nspower.ca/home cyber)", which directs viewers to the de...
AI summary NS Power has provided impacted customers with complimentary credit monitoring services for five years, expanding eligibility to all current and former customers. The service includes credit reports, credit scores, monitoring alerts, educational resources, and identity restoration assistance.
Cybersecurity Accountability REDACTED • Up to $1,000,000 of expense reimbursement insurance related to identity theft. • Dark Web Monitoring, which monitors surface, social, deep, and dark websites for potentially exposed personal, identit...
AI summary NS Power is addressing the cybersecurity breach by offering credit monitoring and identity theft insurance to affected customers, including former ones. The company communicated through multiple channels to inform customers about the breach and the measures being taken.
Cybersecurity Accountability REDACTED Station Contact NORTHEAST Amherst: CFTA Tantramar 107.9 FM [email protected] Truro: [email protected] CKYT Cat Country (MBS or: [email protected] Radio) & CKTO EZ Rock (MBS Radio) New Glasgow: newglas...
AI summary The document provides a list of radio stations and their contact information in Nova Scotia, including email addresses for various stations across different regions such as the Northeast, Metro, and Pictou County. The heading mentions 'Cybersecurity' and 'Accountability' but is redacted, suggesting the content may be sensitive or incomplete.
4 Date Media Outlet Format Reporter Member of NSP senior leadership team Topic May 23, 2025 CBC TV Amy Smith, Anchor recorded sit down interview Peter Gregg, President and CEO Cyber incident update May 23, 2025 CBC Mainstreet Radio Jeff Do...
AI summary The document lists media interviews and appearances by Nova Scotia Power (NSP) senior leadership regarding a cyber incident update, with the most recent interview occurring on June 17, 2025. The information was filed on August 10, 2026, as part of a regulatory proceeding.
Cybersecurity Accountability REDACTED Date Media Outlet Format Reporter Member of NSP senior leadership team Topic Customer support sessions in communities across NS June 17, 2025 CBC Information Morning Mainland (recorded to air June 18)...
AI summary The document outlines media appearances by Chris Lanteigne, Director of Customer Care at Nova Scotia Power, discussing cybersecurity incidents, billing concerns, and customer support sessions in communities across Nova Scotia.
4.0 EVIDENCE OF INTERGROUP CONSULTANTS The InterGroup Evidence makes 13 recommendations focused on areas where NS Power's cybersecurity, privacy, communications, customer notification, billing contingency, and governance practices could be...
AI summary The InterGroup Evidence provides 13 recommendations to NS Power to improve cybersecurity, privacy, communication, and governance practices. NS Power agrees with the need for continuous improvement and highlights existing initiatives, noting that some recommendations align with OPC guidance. Specific emphasis is placed on updating staff training policies and addressing system access restrictions for non-compliance.
Cybersecurity Accountability REDACTED - NS Power has had a Personal Information Inventory in place since 2018. As noted above, it has - been attached hereto as Confidential Attachment 3. - In INQ's response to CA IR-1, INQ added, when aske...
AI summary NS Power has maintained a personal information inventory since 2018. The inventory helps identify data categories but not specific records accessed during a cyber incident. Forensic evidence is needed for that. NS Power notified customers about SIN compromises and sent tailored notifications.
While I agree that it is important to take steps to identify whether sensitive personal data was affected in an incident and act quickly to notify as soon as feasible, a finding of unreasonableness is not sustained by the evidentiary recor...
AI summary The text discusses the reasonableness of NS Power's response to a cybersecurity incident, emphasizing the need to balance timely notification with operational challenges. It highlights that NS Power prioritized service continuity and took steps such as restoring systems, extracting documents, and engaging third parties for credit monitoring and customer communication.
Cybersecurity Accountability REDACTED posted on May 14, 2025. As additional information became available and evolving expectations regarding longer-term protections emerged, the Company proactively expanded the offering to five years on Ju...
AI summary NS Power initially offered two years of credit monitoring following a data breach but later expanded it to five years. The company argues that the initial decision was reasonable given no legal requirement, historical practice, and the subsequent proactive extension. The expansion provided greater protection than industry norms and was not a reimbursement opportunity.
7.0 NS POWER'S ENHANCED PRIVACY GOVERNANCE PROGRAM Beyond the circumstances of this Attack and the response to it, the Company recognizes that the privacy, cybersecurity, and related regulatory landscape is ever evolving with significant a...
AI summary NS Power is enhancing its privacy governance program in response to evolving regulatory and technological challenges, including Bill C-36 and the increasing use of AI. The company is strengthening its privacy framework, policies, and oversight mechanisms, with a dedicated Privacy Officer role being formalized and elevated in the organizational structure.
Inquiry into Nova Scotia Power Incorporated's Cybersecurity Incident Evidence of Jena Valdetero, Co-Chair US Data Privacy and Cybersecurity at Greenberg Traurig LLP Prepared for NS Power Inc. August 10, 2026 NON-CONFIDENTIAL
AI summary This document outlines the evidence provided by Jena Valdetero, Co-Chair of US Data Privacy and Cybersecurity at Greenberg Traurig LLP, prepared for Nova Scotia Power Inc. in an inquiry related to a cybersecurity incident.
1 1.0 SCOPE AND MANDATE - 2 I have been retained by Nova Scotia Power Incorporated ("NS Power" or "Company") in - 3 connection with the recent cybersecurity incident (the "Incident") impacting the Company to - 4 provide expert rebuttal opi...
AI summary The document outlines the scope and mandate of the expert opinion provided by the individual retained by Nova Scotia Power Incorporated in response to findings and recommendations from two expert reports regarding a recent cybersecurity incident.
Cybersecurity Accountability Rebuttal Attachment 1 Page 4 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL - 1 questions of legal interpretation...
AI summary Jena Valdetero, an expert in data security and privacy law, provides an opinion on whether NS Power acted reasonably in response to a cybersecurity incident. She has extensive experience managing data security incidents and advising on privacy laws, including PIPEDA and similar legislation.
11 3.0 INFORMATION CONSIDERED - 12 In preparing this Report, I have considered: - 13 The Ralph Report (M12600, Exhibit N-14, Evidence of Tricia Ralph INQ Law/Consulting, - 14 June 23, 2026); - 15 The Mollard Report (M12600, Exhibit N-13, E...
AI summary The document outlines the information considered in the inquiry into NS Power's cybersecurity incident, including reports, regulatory guidance, industry standards, and input from various stakeholders such as TransUnion, NS Power, Osler, and Emera.
12 4.0 SUMMARY OF OPINIONS - 13 In my opinion, NS Power's response to the Incident should be assessed in the context of a large- - 14 scale ransomware event involving extensive data exfiltration, severe operational disruption - 15 experien...
AI summary The text presents an opinion from a witness, Jena Valdetero, defending NS Power's response to a major ransomware incident. It highlights the company's actions, such as public notice, customer communication, and remedial measures, and argues that these were reasonable and timely compared to other incidents handled by the witness over the past 14 years. The opinion disagrees with conclusions in the Ralph Report and Mollard Report that NS Power's response was unreasonable.
1 5.0 KEY CHRONOLOGICAL FACTS IDENTIFIED IN THE RECORD - 2 Before turning to the specific findings and recommendations in the Ralph Report and Mollard - 3 Report, I set out the key chronological facts established by the evidentiary record,...
AI summary This section outlines key chronological events related to a cybersecurity incident discovered by NS Power in April 2025. The incident led to the activation of response protocols, notifications to authorities, and customer communication. NS Power informed the OPC and offered credit monitoring services to affected customers.
Cybersecurity Accountability Rebuttal Attachment 1 Page 9 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL - 1 notice; it was a recognized notifi...
AI summary This document discusses the evidence presented by Jena Valdetero regarding NS Power's cybersecurity incident, focusing on the use of a recognized notification mechanism permitted by Canadian law to inform affected individuals.
3 Rationale - 4 (a) The Incident Was a Complex, Large-Scale Ransomware Event, Not a Routine Breach - 5 The record establishes that this was not a routine data breach. This was a sophisticated and - 6 coordinated cyberattack in which a thre...
AI summary The document explains that the cybersecurity incident involving NS Power was a complex, large-scale ransomware attack, not a routine breach. It outlines the steps NS Power took, including engaging external legal counsel, forensic investigators, and third-party services, to manage the incident and notify affected individuals.
15 (b) Current Customer Notification Speed Does Not Establish What Was Feasible for 16 Former Customers 17 Based on the information in the record and information obtained from individuals directly involved 18 in the Incident response, NS P...
AI summary NS Power quickly notified current customers of a data breach by using existing customer data, but faced challenges in notifying former customers due to the lack of current contact information, which is common given the transient nature of the customer base and the presence of universities in Nova Scotia.
14 (c) Former Customer Notice Required Additional Operational Readiness - 15 Tasked with notifying former customers indirectly, NS Power sought assistance from TransUnion, - 16 who in turn connected NS Power with Sogica, an IT services com...
AI summary NS Power, in response to a cybersecurity incident, partnered with TransUnion and Sogica to notify former customers and provide credit monitoring services. Concerns about the initial two-year offer led to an upgrade to five years of service without additional action from customers. NS Power implemented a multi-channel communication strategy to ensure broad awareness of the incident.
Cybersecurity Accountability Rebuttal Attachment 1 Page 14 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL 1 Even so, NS Power continued to cond...
AI summary NS Power conducted forensic analysis with third-party vendors to identify impacted customers following a cybersecurity incident. They mailed 97,000 letters to additional affected individuals. Ms. Ralph criticized the customer notices for being insufficient and unclear, suggesting customers should have been informed that all their data elements were impacted.
Cybersecurity Accountability Rebuttal Attachment 1 Page 16 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL - 1 community outreach and the dedica...
AI summary Jena Valdetero testifies that NS Power acted reasonably and met or exceeded industry standards in its notification strategy following a cybersecurity incident, citing community outreach and a dedicated TransUnion call center as evidence.
Cybersecurity Accountability Rebuttal Attachment 1 Page 17 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL known."[7](#page-81-0) 1 Thus, even t...
AI summary This document discusses the inquiry into NS Power's cybersecurity incident, referencing evidence provided by Jena Valdetero and mentioning the governing privacy law, which allows for the possibility that certain information may not be known.
3 (b) Telling Customers to Assume All Data Was Accessed Would Have Created Its Own 4 Risks 5 Ms. Ralph suggests at paragraph 55 that a more cautious approach would have been to advise 6 customers to assume that all data points had been acc...
AI summary Ms. Ralph suggests advising customers to assume all data was accessed, but this approach could cause unnecessary alarm and costly actions. NS Power's approach of informing customers about the largest scope of potentially affected data while acknowledging variation by customer is considered accurate and defensible.
17 (c) Customer Confusion Does Not, By Itself, Establish Inadequate Notice 18 In my experience advising on numerous large scale cyber security incidents, when communicating 19 information to a large population of individuals of varying edu...
AI summary The text discusses the adequacy of notice provided to customers following a cybersecurity incident, emphasizing that customer confusion alone does not establish inadequate notice. It highlights that the standard is whether the notice adequately informed individuals of the incident and available protective steps, not whether it was perfectly clear to each individual.
Cybersecurity Accountability Rebuttal Attachment 1 Page 19 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL - 1 community support sessions of thi...
AI summary The text discusses NS Power's cybersecurity incident response, highlighting the extensive customer support measures taken, including community support sessions and multi-channel communication, which are noted as exceeding typical breach response practices.
19 Summary of Ms. Ralph's Finding - 20 At paragraph 89 of the Ralph Report, Ms. Ralph concludes that NS Power's initial offer of two - 21 years of credit monitoring was insufficient because SINs, which are static identifiers that cannot -...
AI summary Ms. Ralph's finding concludes that NS Power's initial offer of two years of credit monitoring was insufficient due to the persistent risk of misuse of SINs. She determined that extending the offer to five years was reasonable given the nature of the compromised information.
13 (b) Two Years Is Consistent with Standard Breach Response Practice - 14 In the United States, a handful of states require credit monitoring where the U.S. equivalent of - 15 SINs Social Security Numbers (SSNs) are affected in an inciden...
AI summary The text discusses the standard practice of offering credit monitoring following data breaches, noting that two years is consistent with industry norms in Canada. It references statistics from TransUnion and mentions that only a small percentage of companies offer five years of monitoring. The extension to five years was acknowledged as reasonable by Ms. Ralph.
Cybersecurity Accountability Rebuttal Attachment 1 Page 22 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL - 1 condition. of resolution. In my e...
AI summary The text discusses the challenges of implementing a reimbursement program for a data breach, emphasizing the administrative burden on NS Power during a period of concurrent recovery efforts, including containment, remediation, and regulatory cooperation.
23 (a) The Recommendation Conflicts with Risk-Based Notification Principles - 24 The foundational principle of data breach notification reflected in PIPEDA and in analogous - 25 provincial frameworks is that notification obligations are ri...
AI summary The recommendation conflicts with risk-based notification principles, as data breach notification obligations under PIPEDA and provincial frameworks are risk-proportionate and targeted, requiring notification only when individuals are or may reasonably be affected by the breach.
Cybersecurity Accountability Rebuttal Attachment 1 Page 24 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL - 1 individual's information was not...
AI summary Jena Valdetero disagrees with Recommendation 6, which directs NS Power to reach former customers who may have relocated outside the province. She argues that NS Power took meaningful steps to notify former customers through public channels and that practical limitations, such as lack of real-time national address databases, make this task unfeasible.
Cybersecurity Accountability Rebuttal Attachment 1 Page 26 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL - 1 complaints and inquiries from aff...
AI summary The testimony discusses NS Power's cybersecurity incident, focusing on the challenges of notifying relocated former customers and the infeasibility of achieving comprehensive reach. It also addresses the recommendation for cost reimbursement for credit monitoring services, arguing against it as not standard practice in Canadian regulatory proceedings.
18 Burdens - 19 A reimbursement program requires a defined claims period, a claims administration process, - 20 invoice verification, dispute resolution, and budget management. These are not trivial - 21 requirements for a utility that was...
AI summary The text discusses the complexities and administrative burdens associated with managing a reimbursement program, including claims periods, invoice verification, and dispute resolution, while also managing a major systems recovery program involving multiple business applications.
Cybersecurity Accountability Rebuttal Attachment 1 Page 29 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL - 1 offered five years to individuals...
AI summary NS Power's response to Exhibit N-2, NSEB IR-4 states that affected individuals will retain free access to their credit information through TransUnion and other providers beyond five years, which is considered in assessing the need for a longer monitoring period.
Cybersecurity Accountability Rebuttal Attachment 1 Page 30 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL 1 Appendix A 2 I serve as Co-Chair of...
AI summary Jena Valdetero, a U.S. data privacy and cybersecurity expert, provides evidence in the inquiry into NS Power's cybersecurity incident. She has extensive experience in handling data breaches, ransomware attacks, and advising on compliance with data privacy laws, including PIPEDA and GDPR.
Cybersecurity Accountability Rebuttal Attachment 1 Page 32 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL - 1 Member, Global Advisory Board, 20...
AI summary This document is a rebuttal related to a cybersecurity incident involving NS Power, filed on August 10, 2026. It includes evidence from Jena Valdetero, who has professional affiliations with various legal and privacy organizations. Attachments 2, 3, and 4 have been filed or removed due to confidentiality.
100853NS Power's Monthly Update #2 (M12273)
12 passages
October 1, 2025 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power's Cybersecurity Incident – Monthly Update 2 Dear Ms. Henwood: On July 14, 202...
AI summary This document is a monthly update from Nova Scotia Power regarding its response to a cybersecurity incident. The Nova Scotia Energy Board directed the company to submit monthly progress reports until the Incident Report is filed by December 31, 2025. This update includes information on the Recovery Program Office, incident impact, regulatory matters, and timelines.
Cybersecurity The operation of cybersecurity capabilities is a critical aspect of recovery, ensuring that business services are restored in a secure and controlled manner. As technology services are reintroduced, the cybersecurity team val...
AI summary Cybersecurity is emphasized as essential during recovery operations to ensure secure restoration of business services. The cybersecurity team validates controls as technology services are reintroduced, with additional information provided in NS Power's response to NSEB IR-01(a) (M12273).
Technology Enablement The Incident disrupted foundational technology services, which created dependencies that impacted the restoration of some business functions and required employees to rely on contingency solutions. To address these ch...
AI summary The Incident disrupted foundational technology services, leading to dependencies that impacted business functions. A secure network rebuild, device re-imaging, and backup programs are underway to restore operations and ensure continuity.
Recovery Program Office The RPO has continued to advance recovery activities across all major business and technology areas. The RPO was established following the incident response to coordinate recovery and restoration efforts across the...
AI summary The Recovery Program Office (RPO) was established to coordinate recovery and restoration efforts after an incident. It manages program delivery, regulatory and insurance obligations, resourcing, internal controls, cybersecurity, enterprise architecture, organizational change management, reporting, and data privacy across all major business and technology areas.
CIS Replacement Project As noted by the NSEB in its letter of September 17, 2025, the CIS replacement capital project has been delayed by the Incident. NS Power said its investigation into the cybersecurity incident "could impact the direc...
AI summary The CIS replacement project has been delayed due to a cybersecurity incident, as noted by the NSEB and confirmed by NS Power. NS Power provided an updated project timeline in its compliance filing for M11884.
NS-NB Reliability Intertie In the NS-NB Reliability Intertie capital project proceeding (M12217), NS Power, on behalf of Wasoqonatl Transmission Incorporated, produced various sensitivity analyses in response to IRs. Midgard, the consultan...
AI summary In the NS-NB Reliability Intertie capital project proceeding (M12217), NS Power, on behalf of Wasoqonatl Transmission Incorporated, resubmitted sensitivity analyses after a cyber incident affected their IT systems. Despite minor differences in results, the cost variance was less than 0.5% of the System NPVRR, and the reliability intertie was confirmed as the lowest cost long-term solution for the NS electricity system.
Financial Reporting and Statements Automated financial reporting and statements have been affected by the cybersecurity incident. Similar to the issue noted above under Capital Budgeting/Finance Data , certain financial systems and data ar...
AI summary Automated financial reporting and statements have been affected by a cybersecurity incident, leading to the use of forecast figures for certain unregulated adjustments. NS Power expects actual figures to be available by the end of 2025, with no expected impact on customers.
available for reporting. This was conveyed in the Q2 FAM report filed on August 18, 2025, tab Q13 footnote 2. An update to this was provided during the FAM SWG meeting on September 26, 2025, stating: The cause codes during the period were...
AI summary The Q2 FAM report highlights disruptions due to a cybersecurity event affecting dispatch processes, with Cause Code 5 and 3 being recorded. NSP Marketing resumed providing real-time dispatch schedules on August 5. The Dispatch Study Action Plan was impacted, delaying the ECC Optimization Tools project, with new implementation dates yet to be determined.
Hosting Capacity Map and Analysis As noted by the NSEB in its letter of September 17, 2025, the hosting capacity map and analysis has been affected by the cybersecurity incident. In its report on the Hosting Capacity Analysis Stakeholder W...
AI summary The hosting capacity map and analysis have been impacted by a cybersecurity incident, preventing updates to online maps and displays. NS Power is working offline to update data and models to ensure accurate information for distribution connection requests.
E1's Residential Behaviour Program As noted by the NSEB in its letter of September 17, 2025, the ability to provide relevant customer data to Efficiency One (E1) has been affected by the cybersecurity incident. Customer consumption data de...
AI summary The NSEB informed E1 that a cybersecurity incident has disrupted access to customer data from AMI meters and the MEI platform, impacting E1's programs. NS Power is working to restore data flows by 2026 and is discussing interim solutions with E1.
System Planning In response to Natural Forces IR-1 (and Energy Storage Canada IR-5) under the 2025 Evergreen IRP Action Plan and Roadmap Update proceeding (M12247), NS Power advised of its inability to access certain historical and simulat...
AI summary NS Power informed the proceeding that it cannot access certain historical and simulated data due to a cyber incident affecting its IT systems. It provided alternative data from the NS-NB Reliability Intertie model and the 2023 Load Forecast Report, and stated that this issue is not expected to impact customers.
Miscellaneous Nova Scotia Power Maritime Link Q2 2025 Quarterly Report As noted by the NSEB in its letter of September 17, 2025, the detailed allocation between the Maritime Link Project and sustaining capital costs is unavailable at this...
AI summary The cybersecurity incident at NS Power affected NSPML's ability to provide a detailed allocation between the Maritime Link Project and sustaining capital costs. NSPML confirmed that the incident did not impact operations but limited IT access to data. Restoration efforts are ongoing, and no O&M costs for 2026 are expected to be affected.
101524David MacLeod (NSPI) IR A-1 to G-5
39 passages
In the Matter of: THE PUBLIC UTILITIES ACT, R.S.N.S. 1989, c.380, as amended – and – In the Matter of: AN INQUIRY concerning the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer informat...
AI summary This proceeding concerns an inquiry into the impact of a cyber incident on Nova Scotia Power Incorporated's handling of customer information, customer service, billing processes, and regulatory matters.
PREAMBLE AND INSTRUCTIONS TO RESPONDENT - 1. These Information Requests (hereinafter "IRs" or "Interrogatories") are submitted pursuant to - the Nova Scotia Energy Board Act, S.N.S. 2021, c. 3, and the Nova Scotia Energy Board Rules - of P...
AI summary The Nova Scotia Energy Board has issued Information Requests to Nova Scotia Power Inc. regarding a cybersecurity incident that occurred in March 2025. NSP is required to provide detailed, accurate, and non-evasive responses, with specific procedures for handling confidential or privileged information.
DEFINITIONS - For the purposes of these Interrogatories, the following definitions apply: - "Advanced Persistent Threat" or "APT" means a prolonged and targeted cyber intrusion in - which an attacker establishes an undetected presence in a...
AI summary The document defines key terms related to cybersecurity, including Advanced Persistent Threats, Advanced Metering Infrastructure, and Critical Infrastructure, in the context of a ransomware attack on NSP. It references the Incident Report filed with the NSEB and mentions cybersecurity agencies like CISA and CCCS.
Nova Scotia Energy Board - 1 "UARB" means the Utility and Review Board, predecessor to the NSEB, before which NSP - 2 filed its IT-OT Cyber Security Control Implementation Phase 1 plan on February 27, 2025.
AI summary The document references the filing of an IT-OT Cyber Security Control Implementation Phase 1 plan by NSP with the predecessor of the NSEB, the Utility and Review Board, on February 27, 2025.
EVIDENTIARY FOUNDATION AND DISCUSSION - A. The Published Threat Landscape (2015–2025) - The following discussion summarizes the publicly available and authoritative threat intelligence - that NSP, as a regulated critical infrastructure ope...
AI summary This section outlines the published threat landscape from 2015 to 2025, emphasizing warnings from the Canadian Centre for Cyber Security (CCCS) regarding escalating cyber threats, especially from Russian-nexus actors, to Canada's critical infrastructure, including the electricity sector.
A.3 Corporate Threat Intelligence - Dragos OT/ICS Cybersecurity Year in Review (Dragos, Inc., 2024; 2025): Dragos, the - leading industrial cybersecurity firm, tracked 26 active OT-focused threat groups as of - 2025. Russian-nexus groups i...
AI summary The document highlights cybersecurity threats to critical infrastructure, particularly electric utilities, with a focus on OT networks. Russian-nexus threat groups like ELECTRUM, KAMACITE, and VOLTZITE are actively targeting Western infrastructure. Only 30% of OT networks have sufficient visibility to detect threats, and 56% lack visibility beyond the IT/OT boundary, a vulnerability exploited in the NSP Attack. There has also been a 44% increase in exploitation of public-facing applications and active ransomware groups.
A.4 The Ukrainian Grid Attacks as Proof of Concept - The academic and technical literature establishes beyond reasonable dispute that Russian-nexus - actors demonstrated both the capability and the intent to attack electricity infrastructu...
AI summary The text discusses the Ukrainian grid attacks as proof of concept, highlighting the capability and intent of Russian-nexus actors to attack electricity infrastructure. It outlines three major cyberattacks: the 2015 BlackEnergy/Sandworm attack, the 2016 Industroyer/CRASHOVERRIDE attack, and the 2022 Industroyer2 attack, all attributed to Sandworm, a GRU-affiliated group.
B. NSP's Acknowledged Risk and Inadequate Response - The evidentiary record before the Board contains a critical and damaging admission. On - February 27, 2025 NSP's Chief Operating Officer, Dave Pickles, filed a report with the UARB - tit...
AI summary Nova Scotia Power (NSP) acknowledged the rising cybersecurity threats but failed to implement a comprehensive response. Their plan focused only on operational technology (OT) systems, ignored IT systems and customer data, and did not address specific Russian-nexus threats. The breach went undetected for 37 days, and NSP lacked a backup site, leading to long-term system impairments and data exposure.
C. The Standard of Reasonableness Applied - The NSEB is asked to apply the standard of the reasonably prudent regulated utility operator - in assessing NSP's preparedness. This standard requires that NSP: - 1. Monitor and act upon publicly...
AI summary The NSEB is required to assess NSP's cybersecurity preparedness using the standard of a reasonably prudent regulated utility operator. This includes monitoring threat intelligence, implementing cybersecurity controls, maintaining detection capabilities, protecting customer data, ensuring business continuity, and complying with regulatory frameworks.
GROUP A — PRE-ATTACK THREAT AWARENESS AND GOVERNANCE - These Interrogatories address NSP's governance structures, threat intelligence practices, and - executive accountability for cybersecurity prior to March 19, 2025. They are grounded in...
AI summary This section outlines interrogatories related to NSP's governance, threat intelligence, and executive accountability for cybersecurity before March 19, 2025, based on the 'knew or ought to have known' standard and NSP's awareness of the threat environment.
IR A-1 — Threat Intelligence Program - (a) Did NSP maintain a formal threat intelligence program prior to March 19, 2025? If so, - provide a complete description of that program, including: - (i) the organizational unit responsible for thr...
AI summary The document outlines questions regarding Nova Scotia Power's (NSP) threat intelligence program, including its existence prior to March 19, 2025, its structure, threat intelligence sources, escalation processes, and efforts to collaborate with the Communications Security Establishment (CSE). It also asks whether NSP sought a Ministerial Designation for cybersecurity support.
IR A-2 — CCCS National Cyber Threat Assessments - (a) Confirm whether NSP reviewed each of the following CCCS publications prior to March - 19, 2025: (i) National Cyber Threat Assessment 2018; (ii) CCCS Cyber Threat Bulletin: The Cyber Thr...
AI summary The document requests Nova Scotia Power (NSP) to confirm whether it reviewed several cybersecurity threat assessments and advisories from the Canadian Centre for Cyber Security (CCCS) and the United States Cybersecurity and Infrastructure Security Agency (CISA). It also asks for details on the analysis conducted, any implemented cybersecurity measures, and internal documentation related to these reviews.
IR A-4 — Russian-Nexus Threat Awareness - (a) Prior to March 19, 2025, did NSP's cybersecurity program specifically address the threat posed by Russian-nexus threat actors, including: - (i) GRU-affiliated groups (Sandworm/ELECTRUM, APT28);...
AI summary The proceeding document inquires whether NSP's cybersecurity program addressed Russian-nexus threat actors, including specific groups like GRU, FSB, ransomware collectives, and pro-Russia hacktivists, prior to March 19, 2025, and requests documentation of threat modeling and risk assessments conducted.
IR A-5 — Board of Directors and Executive Accountability - (a) Describe the governance structure for cybersecurity at NSP prior to March 19, 2025, - including: - (i) the role and responsibilities of the Chief Information Security Officer (...
AI summary The document requests details on NSP's cybersecurity governance structure prior to March 19, 2025, including the role of the CISO, cybersecurity briefings to the Board and Executive Leadership Team, and the most recent cybersecurity risk assessment. It also requests meeting minutes, presentations, and a cybersecurity risk register.
IR A-6 — The February 27, 2025 UARB Filing - (a) NSP's Chief Operating Officer filed a report titled IT – OT Cyber Security Control - Implementation Phase 1 with the UARB on February 27, 2025, twenty days before the - Attack. With respect...
AI summary The document requests an explanation of NSP's cybersecurity plan focusing on OT systems and excludes IT systems, customer data systems, and billing platforms. It also asks about the review and approval of the plan's scope, existing cybersecurity controls for excluded systems, consideration of the NCTA 2025-2026 report, risk assessments for IT and customer data systems, and related documentation. Additionally, it seeks information on steps taken by NSP between February 27, 2025, and March 19, 2025, to address cybersecurity risks.
GROUP B — IT/OT ARCHITECTURE AND NETWORK SEGMENTATION - These Interrogatories address the technical architecture of NSP's IT and OT environments, the - degree of segmentation between them, and the vulnerability of NSP's systems to the atta...
AI summary This section of the document focuses on the IT/OT architecture and network segmentation of Nova Scotia Power (NSP), emphasizing the importance of proper segmentation in preventing ransomware attacks on utility systems.
IR B-1 — Network Architecture Documentation - (a) Produce a network architecture diagram depicting NSP's IT and OT environments as they existed on March 18, 2025 (the day before the Attack), including: - (i) the boundaries between IT and O...
AI summary The document requests a network architecture diagram of NSP's IT and OT environments as of March 18, 2025, including network segmentation, external access points, and connections to third-party systems. NSP may request confidential treatment but must provide a summary for the Board and MNP Digital to assess the architecture's adequacy.
IR B-2 — IT/OT Segmentation - (a) Describe the segmentation controls that existed between NSP's IT and OT networks as of March 18, 2025. - (b) NSP's Monthly Update 6 (March 2026) disclosed that post-attack remediation included "the continu...
AI summary The document requests details about IT/OT network segmentation controls at NSP as of March 2025, the replacement of virtual firewalls with physical devices post-attack, and the attack path used by the threat actor, including failed segmentation controls.
IR B-3 — Remote Access Infrastructure - (a) Describe all remote access mechanisms in use at NSP as of March 18, 2025, including: - (i) VPN solutions, including vendor, version, and patch level; - (ii) Remote Desktop Protocol (RDP) exposure...
AI summary The document requests details on NSP's remote access mechanisms as of March 18, 2025, including specific technologies, security measures, and compliance with CISA advisory AA22-110A. It also asks whether a remote access mechanism was involved in a cyberattack and which one.
IR B-4 — Third-Party and Supply Chain Risk (a) Identify all third-party vendors, managed service providers, and contractors with network access to NSP's IT or OT environments as of March 18, 2025. explain why. - (b) Describe NSP's third-pa...
AI summary The document outlines a regulatory inquiry into third-party and supply chain risk, specifically focusing on NSP's cybersecurity practices. It requests information on vendors, the cybersecurity risk management program prior to an attack, and whether the attack involved third-party access.
IR B-5 — AMI and Smart Meter Infrastructure - (a) Describe the cybersecurity architecture of NSP's AMI system as of March 18, 2025, - including the network connectivity between field devices, head-end systems, and billing - platforms. - (b...
AI summary The document outlines questions regarding the cybersecurity architecture of NSP's AMI system, the impact of a ransomware attack on AMI connectivity, and the measures in place for cybersecurity risk assessment and segmentation controls.
GROUP C — THREAT DETECTION AND INCIDENT RESPONSE - These Interrogatories address NSP's capability to detect intrusions and respond to cybersecurity - incidents. The 37-day detection gap — from initial intrusion on March 19, 2025 to NSP's -...
AI summary The text discusses NSP's capability to detect intrusions and respond to cybersecurity incidents, highlighting a 37-day detection gap from March 19, 2025, to late April 2025, which is a central issue in the proceeding.
IR C-1 — Security Monitoring and Detection Capabilities - (a) Describe NSP's security monitoring and threat detection capabilities as they existed on - March 18, 2025, including: - (i) Security Information and Event Management (SIEM) syste...
AI summary The document requests details on NSP's security monitoring and detection capabilities as of March 18, 2025, including SIEM systems, EDR solutions, OT-specific tools, and SOC capabilities. It also references a report indicating limited visibility in OT networks and asks whether NSP addressed this gap prior to an attack.
IR C-2 — The 37-Day Detection Gap - (a) Provide a detailed forensic timeline of the Attack from initial intrusion to NSP's awareness, - including: - (i) the date and method of initial access; - (ii) the lateral movement path taken by the t...
AI summary The document requests a detailed forensic timeline of a cyberattack on Nova Scotia Power (NSP), including the initial intrusion, lateral movement, data exfiltration, and ransomware deployment. It also asks for an explanation of why NSP's detection systems failed to identify the attack for 37 days and the handling of security alerts between March 19, 2025, and late April 2025.
IR C-3 — Incident Response Plan - (a) Did NSP have a formal Cybersecurity Incident Response Plan (IRP) in place prior to March - 19, 2025? If so, produce the most recent version of that plan as it existed prior to the Attack. - (b) Describ...
AI summary The document requests information about Nova Scotia Power's (NSP) incident response plan, including its existence prior to March 19, 2025, its coverage of ransomware and Russian-nexus attacks, and findings from previous drills and assessments.
IR D-2 — Data Protection Controls - (a) Describe the technical and organizational controls applied to protect customer personal information prior to March 19, 2025, including: - (i) encryption of personal information at rest and in transit...
AI summary The document outlines questions regarding data protection controls implemented by Nova Scotia Power (NSP) prior to March 19, 2025, focusing on encryption, access controls, data loss prevention, and monitoring for unauthorized access. It also asks for details on NSP's response to ransomware threats and the most recent privacy impact assessment conducted.
IR D-3 — Scope of Customer Data Compromise - (a) Provide a complete accounting of the personal information stolen in the Attack, including: - (i) the total number of customers affected; - (ii) the categories of personal information stolen...
AI summary The document requests a detailed accounting of the personal information stolen in a data breach, including affected customers, types of data compromised, and steps taken to remove the data. It also asks NSP to explain why it was not aware of the data exfiltration until notified by a third party in late April 2025 and what detection controls were in place.
IR E-1 — Backup and Disaster Recovery Infrastructure - (a) Describe NSP's backup and disaster recovery infrastructure as it existed on March 18, 2025, - including: - (i) the backup solutions in use for each critical system (billing, AMI, f...
AI summary The document requests Nova Scotia Power (NSP) to describe its backup and disaster recovery infrastructure as of March 18, 2025, confirm whether it had an operational off-site BDR site prior to March 19, 2025, and produce its Business Continuity and Disaster Recovery Plans. It references cybersecurity threats, including ransomware, and industry best practices.
IR F-1 — NERC CIP Compliance - (a) Identify which, if any, of NSP's assets are classified as Bulk Electric System (BES) Cyber - Systems subject to mandatory NERC CIP standards. - (b) For each applicable NERC CIP standard (CIP-002 through C...
AI summary The document outlines a request for information regarding Nova Scotia Power's compliance with NERC CIP standards, specifically identifying which assets are classified as BES Cyber Systems and detailing NSP's compliance status, audit findings, and remediation actions as of March 18, 2025.
IR F-2 — NIST Cybersecurity Framework - (a) Describe NSP's adoption of the NIST Cybersecurity Framework (CSF) or equivalent - framework prior to March 19, 2025. - (b) Produce any maturity assessments conducted against the NIST CSF or equiv...
AI summary The document requests Nova Scotia Power (NSP) to describe its adoption of the NIST Cybersecurity Framework (CSF) or equivalent prior to March 19, 2025, provide maturity assessments conducted in the three years before the Attack, and detail its self-assessed maturity levels for each of the five NIST CSF functions as of March 18, 2025, along with any identified gaps and remediation plans.
IR F-3 — Third-Party Cybersecurity Assessments - (a) Identify all third-party cybersecurity assessments, audits, penetration tests, vulnerability - assessments, or red team exercises conducted for NSP in the five years prior to the Attack,...
AI summary The document requests information on third-party cybersecurity assessments conducted for Nova Scotia Power (NSP) in the five years prior to a cyberattack, including details on the firms involved, assessment scope, findings, and NSP's responses. It also asks for unaddressed findings at the time of the attack and explanations for their non-remediation.
IR F-4 — Cybersecurity Investment and Resource Allocation - (a) Provide NSP's cybersecurity budget for each of the five fiscal years prior to the Attack - (2020–2024), including: - (i) total cybersecurity expenditure; - (ii) allocation bet...
AI summary The document requests details on Nova Scotia Power's cybersecurity budget from 2020 to 2024, including expenditure breakdowns, staffing levels, and capital investments. It also asks about unapproved resource requests and how NSP benchmarked its cybersecurity investments against industry standards.
GROUP G — POST-INCIDENT REMEDIATION AND FORWARD COMMITMENTS - These Interrogatories address NSP's post-attack remediation program, the adequacy and pace - of that program, and NSP's forward commitments to prevent recurrence. They are relev...
AI summary This section addresses NSP's post-incident remediation efforts, their adequacy and pace, and forward commitments to prevent recurrence. It is relevant to the Board's evaluation of NSP's accountability and whether ratepayers should bear remediation costs.
IR G-1 — Remediation Program Scope and Governance - (a) Produce NSP's complete post-incident remediation roadmap, including: - (i) all remediation initiatives identified; - (ii) the status of each initiative as of the date of filing; - (ii...
AI summary The remediation program scope and governance for NSP is requested, including a roadmap of initiatives, their status, completion dates, costs, and governance structure. The process for determining the scope of the program, including a gap analysis against various cybersecurity standards and threat intelligence findings, is also required.
IR G-2 — Specific Remediation Measures - For each of the following remediation measures referenced in NSP's Monthly Updates or - Incident Report, provide the current status, target completion date, and estimated cost: - (a) Replacement of...
AI summary The document outlines specific remediation measures required by the Nova Scotia Energy Board, including the replacement of virtual firewalls, construction of a backup and disaster recovery site, and implementation of cybersecurity enhancements. Each measure includes a request for current status, target completion date, and estimated cost.
IR G-3 — Attribution and Threat Actor Identification - (a) NSP's Monthly Update 6 (March 2026) and related reporting attributed the Attack to - "Russian threat actors." Provide all information available to NSP regarding the attribution - o...
AI summary The document requests Nova Scotia Power (NSP) to provide details on the attribution of a cyberattack, including the identity of the threat actor, methodology used, and whether the threat actor is subject to sanctions. It also asks how this knowledge has informed NSP's cybersecurity strategy.
IR G-4 — Cost Recovery and Ratepayer Implications - (a) Identify all costs associated with the Attack and its remediation that NSP intends to seek to - recover through regulated rates, including: - (i) the total quantum of costs to be soug...
AI summary The document outlines the need for Nova Scotia Power (NSP) to identify and justify the costs associated with a cyber attack and its remediation for recovery through regulated rates. It also asks NSP to explain whether ratepayers should bear these costs, considering NSP's prior knowledge of risks, gaps in cybersecurity planning, and the availability of threat intelligence. Additionally, it requests information on cybersecurity insurance held by NSP.
IR G-5 — Forward Cybersecurity Strategy - (a) Produce NSP's updated cybersecurity strategy, policy, and multi-year investment plan, as approved by NSP's Board of Directors following the Attack. - (b) Describe how NSP's forward cybersecurit...
AI summary The document requests Nova Scotia Power (NSP) to provide an updated cybersecurity strategy, policy, and investment plan, addressing specific threats from Russian-nexus actors as outlined in the CCCS NCTA 2025-2026. It also asks about mechanisms for reviewing threat advisories and participation in cybersecurity information sharing organizations.
REFERENCES Canadian Centre for Cyber Security. (2018). National cyber threat assessment 2018 . Government of Canada. https://www.cyber.gc.ca/en/guidance/national-cyber-threat-assessment-2018 Canadian Centre for Cyber Security. (2020a). Cyb...
AI summary The document references multiple cyber threat assessments and reports from the Canadian Centre for Cyber Security and other international agencies, focusing on threats to critical infrastructure, including the electricity and oil and gas sectors, and highlighting specific malware like Industroyer.
101692CA (NSPI) IR-1 to IR-11
12 passages
1 M12600 2 3 4 NOVA SCOTIA ENERGY BOARD 5 6 7 IN THE MATTER OF: The Public Utilities Act 8 9 – and – 10 IN THE MATTER OF: AN INQUIRY about the impact of the cyber incident on NOVA 11 SCOTIA POWER INCORPORATED's collection and retention 12...
AI summary The Nova Scotia Energy Board has issued an information request to Nova Scotia Power Inc. regarding the impact of a cyber incident on customer information management, customer service, billing processes, and regulatory matters. Responses are due by May 6, 2026.
1 Request IR-1: Cyber Security Program Effectiveness 2
AI summary The document introduces Request IR-1, which focuses on evaluating the effectiveness of the Cyber Security Program. However, the content is limited to the heading and a page number, providing no substantive discussion or analysis of the program's effectiveness.
3 Reference: Exhibit N-3 - 2025 Nova Scotia Power's Cybersecurity Incident Report, Page 18, 4 ll 1-4 5
AI summary The text references a 2025 Nova Scotia Power's Cybersecurity Incident Report, specifically Page 18, lines 1-4, but does not provide additional details about the incident or its implications.
6 Quote: 7 NS Power maintains a cybersecurity training and awareness program and conducts mandatory 8 quarterly cyber training and monthly phishing simulation testing exercises with all employees to 9 educate employees about NS Power's inf...
AI summary NS Power implements a cybersecurity training program with mandatory quarterly training and monthly phishing simulations for all employees to educate them on information security policies and responsibilities.
12 Question 13 14 a. For the twelve-month period ending March 2025, please provide the results of the 15 quarterly cyber training and monthly phishing simulation testing. 16 17 b. Please describe NSPI's training standards for cybersecurity...
AI summary The questions focus on NSPI's cybersecurity measures, including training standards, testing frequency, employee training completion rates, cybersecurity readiness targets, and a summary of past cyber incidents and improvements made.
42 Question 43 44 a. Please provide the retention standards referenced in the above quote. 45 1 b. Please confirm that these standards are compliant with the Personal Information 2 Protection and Electronic Documents Act (PIPEDA). 3 4 5 Re...
AI summary The text requests confirmation on the retention and purging of customer social insurance numbers (SINs) by NSPI, compliance with PIPEDA, and the number of closed accounts with retained SINs. It references a 2025 cybersecurity incident report and quotes from Peter Gregg's statement regarding SIN collection and removal.
42 43 1 Request IR-4: Data Retention Policy Compliance with Legislation 2 3 4 Reference: Exhibit N-3 - 2025 Nova Scotia Power's Cybersecurity Incident Report, Page 40, ll 3-5 5 6 7 8 9 Quote: At the time of the Incident, NS Power had forma...
AI summary The document contains a series of requests related to data retention policies and customer account collections by NSPI. It references a cybersecurity incident and asks about NSPI's compliance with privacy and security policies, as well as actions taken in response to the incident and its impact on customer billing.
18 Reference: Exhibit N-3 - 2025 Nova Scotia Power's Cybersecurity Incident Report, Page 14, 19 ll 18-25 20
AI summary The text references a cybersecurity incident report by Nova Scotia Power from 2025, specifically page 14 of Exhibit N-3. It does not provide further details about the incident or its implications.
21 Quote: 22 Immediately following detection of unauthorized access, NS Power activated its incident response 23 and business continuity protocols, engaged leading third-party cybersecurity experts, and took 24 actions to contain and isola...
AI summary NS Power responded to a cybersecurity incident by activating its incident response protocols, engaging third-party experts, and taking steps to contain and isolate affected servers. The company prioritized containment, eradication, and remediation of the threat, as well as analyzing the full scope of the incident.
45 46 1 Request IR-7: Cybersecurity Risk Management 2 3 Reference: Exhibit N-3 - 2025 Nova Scotia Power's Cybersecurity Incident Report, Page 17, 4 ll 11-24 5 6 Quote: 7 NS Power's cybersecurity framework (which applies to its information...
AI summary The document discusses cybersecurity risk management and customer risk mitigation measures taken by Nova Scotia Power Inc. (NSPI) following a cybersecurity incident. It references a 2025 cybersecurity incident report and outlines NSPI's cybersecurity framework aligned with NIST's Core Functions. The request also includes inquiries about insurance coverage, the unauthorized access event, and measures to prevent future breaches. Customer mitigation steps such as credit monitoring were provided.
12 Request IR-9: Data Breach Mitigation 13
AI summary The document outlines Request IR-9, which focuses on data breach mitigation. It highlights the need for measures to protect personal information, referencing the PIPEDA and the role of NSP and the CA in addressing data security concerns.
14 Reference: Exhibit N-3 - 2025 Nova Scotia Power's Cybersecurity Incident Report, Page 15 38, ll 25-28 16
AI summary The document references Exhibit N-3 from Nova Scotia Power's 2025 Cybersecurity Incident Report, specifically Page 38, lines 25-28. It does not provide detailed content about the incident or its implications.
101694NSEB (NSPI) IR-1 to IR-25
10 passages
NOVA SCOTIA ENERGY BOARD IN THE MATTER OF: THE PUBLIC UTILITIES ACT - and - IN THE MATTER OF: AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer information, customer...
AI summary The Nova Scotia Energy Board is conducting an inquiry under the Public Utilities Act regarding the impact of a cyber incident on Nova Scotia Power Incorporated's handling of customer information, customer service, billing processes, and regulatory matters.
Request IR-1: - In response to the Board's IR-13 and IR-14 (Exhibit N-4), the utility provided the following response: - (d) …When NS Power lost the ability to communicate with that network through the cyber incident, the estimation logic...
AI summary The document outlines a request for information regarding the CIS subroutine used by NS Power during a cybersecurity incident. The request includes details about how the subroutine estimates energy usage, its validation, and performance metrics. It also asks for specific data, including energy bills and validation reports.
Request IR-2: - a) How does the CIS subroutine work for a customer with net-metering? - b) Why did the utility not consider providing estimated credits for customers with net metering? - c) How many net-metering customers does the utility...
AI summary Request IR-2 contains a series of questions regarding the CIS subroutine, net-metering credits, reconciliation of bills, and customer validation of energy usage data. The questions focus on operational procedures, customer billing, and cybersecurity impacts.
Request IR-3: - Please refer to the Net Metering 2025 Annual Report (Matter M12783) - At pages 7-8, the Report states: Please note that, due to the cyber incident, NS Power is still in - the process of recovering information on changes (e....
AI summary The document outlines a request (IR-3) for clarification regarding the accuracy and availability of data in the Net Metering 2025 Annual Report, including questions about whether data is actual or estimated, how estimates were made, and when lost data from 2020-2024 might be recovered due to a cyber incident.
Request IR-9: - Please provide specific and detailed information addressing whether all or any part of the information about current NS Power customers was available in NS Power's systems to be stolen in the cyber attack in circumstances w...
AI summary Request IR-9 asks NS Power to provide detailed information on whether customer data was available for theft during a cyber attack, considering data collection policies, data destruction requirements, and compliance with provincial and federal laws.
Request IR-10: - Please provide specific and detailed information addressing whether all or any part of the information about former NS Power customers was available in NS Power's systems to be stolen in the cyber attack in circumstances w...
AI summary Request IR-10 seeks detailed information on whether former NS Power customer data was accessible during a cyber attack, questioning if the data was collected or retained in violation of NS Power's policies or provincial/federal laws, and whether it should have been destroyed.
Request IR-12: - Please confirm that, at all material times relating to the cyber attack, NS Power was fully compliant with all its internal policies relating to the collection and retention of personal information of customers. - a) If no...
AI summary The request asks NS Power to confirm compliance with internal policies on customer personal information collection and retention during a cyber attack. If non-compliance occurred, the request seeks details on the policies violated, reasons for non-compliance, and corrective actions.
Request IR-13: Please provide any memos, assessments, reports or email messages prepared on or after April 25, 2025, discussing how customers would be advised about the cybersecurity breach and the theft of their personal information, and...
AI summary Request IR-13 asks for documents from April 25, 2025 onwards that discuss how customers would be informed about a cybersecurity breach and the theft of their personal information, including the details to be communicated.
Request IR-16: - Please provide any memos, assessments, reports or email messages prepared by NS Power or - on its behalf about the difficulties that customers experienced contacting NS Power's Customer - Care Centre and TransUnion in the...
AI summary Request IR-16 asks NS Power to provide memos, assessments, reports, and emails regarding customer difficulties contacting NS Power's Customer Care Centre and TransUnion after a cybersecurity breach and data theft. It also seeks detailed call statistics related to the incident from April 25, 2025, to October 31, 2025.
Request IR-20: - Please provide any memos, assessments, reports or email messages prepared by NS Power or - on its behalf about its initial pause to customer billing after the cyber attack and its resumption of - billing, including any dis...
AI summary Request IR-20 seeks information from NS Power regarding its handling of customer billing following a cyber attack, including memos, assessments, and discussions on estimating bills and manually reading meters during the system outage.
101697SBA (NSPI) IR-1 to IR-20
13 passages
1 M12600 2 3 NOVA SCOTIA ENERGY BOARD 4 5 IN THE MATTER OF: The Public Utilities Act, R.S.N.S. 1989, c.380, as amended 6 7 8 9 IN THE MATTER OF: AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collecti...
AI summary The Nova Scotia Energy Board is conducting an inquiry regarding the impact of a cyber incident on Nova Scotia Power Incorporated's collection and retention of customer information, customer service, billing processes, and regulatory matters. A response is requested from Blake Williams, Vice President, Legal and Regulatory at Nova Scotia Power Incorporated.
Request IR-2: Please refer to the Report, Page 8, Lines 1-3: Immediately following detection of the Incident, NS Power activated its established incident response and business continuity protocols, engaging Osler, and through Osler, Mandia...
AI summary Request IR-2 seeks information about NS Power's incident response and business continuity protocols, including their development, updates, research basis, and Osler's role in responding to an incident.
Request IR-3: Please refer to the Report, Page 8, Line 19-22: NS Power notified law enforcement of the Incident. More specifically, NS Power notified the Canadian Centre for Cybersecurity (CCCS), the Royal Canadian Mounted Police (RCMP), a...
AI summary NS Power notified law enforcement on April 27, 2025, about an incident, but there was a two-day gap between when they first became aware of the issue on April 25, 2025, and the notification. Questions are raised about the delay, notification of the FBI, discussions on timing, and whether protocols existed for notifications.
Request IR-6: Please refer to the Report, Page 17, Lines 3-6: At the time of the Incident, NS Power had implemented a common set of cybersecurity standards and policies that are informed, in part, by the National Institute of Standards and...
AI summary The text contains a request (IR-6) asking for clarification on NS Power's cybersecurity standards, their relationship to other protocols, the sources of guidance used, the meaning and timing of regulatory reviews, and whether NS Power receives updates from other organizations like NERC and E-ISAC.
Request IR-7: Please refer to the Report, Page 17, Lines 19-20: Detect – Establishes the appropriate activities to identify the occurrence of a cybersecurity event. a) Did the 'Detect' part of the Cybersecurity Framework operate as expecte...
AI summary The text from Request IR-7 asks whether the 'Detect' part of the Cybersecurity Framework operated as expected, inquires about delays in becoming aware of a breach, and seeks confirmation on why the framework may not have functioned properly if it did not operate as intended.
Request IR-8: Please refer to the Report, Page 17, Lines 26-20: In relation to NS Power's operational program, NS Power's core energy operations are designed to comply with other industry-specific rules and standards relating to cybersecur...
AI summary The document requests information about NS Power's last NERC audit related to cybersecurity and IT, and whether NERC provides audit reports on these matters.
Request IR-9: Please refer to the Report, Page 18, Lines 1-4: NS Power maintains a cybersecurity training and awareness program and conducts mandatory quarterly cyber training and monthly phishing simulation testing exercises with all empl...
AI summary The document requests detailed information about NS Power's cybersecurity training and phishing simulation exercises, including content, evaluation methods, participation rates, and any changes made post-incident. It focuses on the effectiveness and tracking of these programs.
Request IR-10: Please refer to the Report, Page 18, Lines 19-29: NS Power implemented a previously developed and tested consistent multi-channel approach throughout the response efforts for all public communications. For each update, the t...
AI summary NS Power used a multi-channel approach for public communications during a cybersecurity incident, including a dedicated landing page, social media, local media, and direct communications with stakeholders. A paid media strategy was also employed to ensure visibility. The incident was first reported on April 25, 2025, with customer notification on April 28, 2025.
Request IR-13: Please refer to the Report, Page 37, Lines 15-16: …In connection with these efforts, NS Power has recently completed an extensive two- year update to its cybersecurity practices to comply with current policies and anticipate...
AI summary NS Power completed a two-year update to its cybersecurity practices to align with current policies and anticipated changes in standards communicated by NIST. The question asks when this update was completed.
Request IR-14: Refer to M12600, Exhibit N-1, Nova Scotia Energy Board (NESB) IR 4(a): As noted above, NS Power extended the offer of credit monitoring by three additional years beyond the two-year industry standard, providing additional pr...
AI summary The text discusses NS Power's extension of credit monitoring for customers affected by a security breach, raising questions about the definition of the 'industry standard,' how it was determined, and whether any customers have suffered identity breaches or damages.
Request IR-17: Refer to M12600, Exhibit N-1, NSEB IR 12, Page 2-3, Lines 8-9: …Also, the Company has not applied late charges, or penalties on any outstanding balances since the incident. NS Power will communicate directly with customers b...
AI summary The document references NS Power's handling of late fees and a cybersecurity incident. It asks about the reinstatement of late fees, their financial impact, and cybersecurity measures in place during a breach. It also cites a compliance letter to the OPC regarding a data breach in 2025.
Request IR-19: Refer to Compliance Letter to the Office of the Privacy Commissioner of Canada ("OPC") dated March 18, 2026 [(https://www.priv.gc.ca/en/opc-actions-and-](https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/inv...
AI summary The document refers to a compliance letter from the Office of the Privacy Commissioner of Canada dated March 18, 2026, concerning a cybersecurity breach at NS Power. It asks whether NS Power maintained other backups beyond those destroyed by a threat actor on April 25, 2025.
1 evidence has yet emerged that this sensitive data has been made public or sold. After its 2 assessment of applicable sanctions laws and alignment with law enforcement guidance, 3 Nova Scotia Power did not pay a ransom to the threat actor...
AI summary The text discusses Nova Scotia Power's response to a cyber threat, noting that no ransom was paid and that evidence has not yet emerged showing sensitive customer data was made public or sold. It also raises a question about when NS Power first obtained proof that the threat actor had obtained sensitive customer information.
20260818-1Hearing Transcript — 08/18/2026 (Chris Lanteigne, Lia MacDonald, Glen MacLeod, Blake Williams)
19 passages
NOVA SCOTIA ENERGY BOARD IN THE MATTER OF: THE PUBLIC UTILITIES ACT - and - IN THE MATTER OF: AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer information, customer...
AI summary The Nova Scotia Energy Board is conducting an inquiry under the Public Utilities Act regarding the impact of a cyber incident on Nova Scotia Power Incorporated's handling of customer information, customer service, billing processes, and regulatory matters.
LIST OF UNDERTAKINGS NO. PAGE NO. 11 reliability screening or clearance. This demographic 12 includes public service employees, retirees, veterans, 13 military personnel, research staff, and those working in 14 the manufacturing of militar...
AI summary The text discusses the vulnerabilities faced by individuals with security clearances due to a 2025 cyber breach by Nova Scotia Power. It highlights the risks of data breaches for this group, including exposure to foreign threat actors and criminal networks, which can be used for social engineering and blackmail.
held by Nova Scotia Power was actually affected by the attack? A. (Williams) That's correct. We cannot definitively say what was taken by the threat actor. Q. And why is that? A. (Williams) Well, the nature of the systems and what was done...
AI summary The testimony discusses the difficulty in determining the exact data affected by a cyberattack on Nova Scotia Power's systems. While the volume and origin of removed data can be identified, the specific contents of the affected data remain unknown, likened to being unable to determine which books were viewed in a box that was opened.
BY MR. ROBERTS: Q. And I apologize again if this sounds like a simplistic question, but was any of the data personal information that you gathered from your customers retained in such a way that there would not be access to it from the int...
AI summary Mr. Roberts asks if customer personal data is retained in a way that prevents internet access. Williams responds that the systems in question are not directly linked to the internet and suggests discussing cybersecurity aspects in the appropriate section of the process.
NOVA SCOTIA POWER PANEL 83 Cr-ex, (Roberts) 1 still Social Insurance Numbers customer Social 2 Insurance Numbers in the system that would have been 3 accessed, or potentially accessed? 4 A. (Williams) So I just want to make 5 sure we're (i...
AI summary The discussion revolves around the removal of Social Insurance Numbers (SINs) from the Customer Information System (CIS) in 2024 and the potential presence of SINs in the Data Lake at the time of a cyberattack in 2021. The witness, Williams, confirms the purge was completed but does not know the number of SINs in the Data Lake and cannot definitively say if it is obtainable.
NOVA SCOTIA POWER PANEL 135 Cr-ex, (Roberts) 1 failure rate among employees in their monthly phishing 18 employees. So there's items in there that really try to 19 trick employees. 1 And I actually think, like reviewing 2 this, that's it's...
AI summary The discussion focuses on Nova Scotia Power's cybersecurity training program, specifically their monthly phishing simulations. In November 2024, 14.3% of employees failed the test, prompting a response involving senior management updates and mandatory additional training for those who failed.
failures. And if an employee fails multiple times, you know, obviously the severity of any discussions that is –– are had with that employee would increase. And maybe I'll pass it on to Mr. Williams just to elaborate a little bit on that,...
AI summary The discussion outlines Nova Scotia Power's approach to cybersecurity training, including financial consequences for repeated phishing test failures and the emphasis on addressing these issues through senior leadership meetings. The failure rate of 14.3% and its context in early 2025 are highlighted.
NOVA SCOTIA POWER PANEL 141 Cr-ex, (Roberts) 6.4 percent and 3.3 percent. Are those numbers concerning? A. (Williams) I would suggest, sir, that anything above zero is concerning, given what we know can happen. But as Mr. Lanteigne has poi...
AI summary The discussion addresses concerns about cybersecurity testing results, with a response indicating that while the numbers are concerning, there have been efforts to address issues through training and follow-up. The witness also clarifies that the incident involved more than just a phishing attempt and defers further technical details to another proceeding.
NOVA SCOTIA POWER PANEL 143 Cr-ex, (Roberts) Not up here; I mean at the next proceeding. Q. I'm in the hands of the Board on this. I mean, I would expect that you might be able to characterize, if not answer in any technical details, at le...
AI summary The discussion revolves around cybersecurity training and cultural changes at Nova Scotia Power Inc. following a phishing attack. The witness explains that training remains monthly but there has been a significant cultural shift in understanding the importance of cybersecurity after experiencing a breach.
to date? 1 (Williams) We can provide that. A. 2 MS. MacADAM: If I could have that as 3 an undertaking? 4 THE CHAIR: It'll be Undertaking U-5. 5 UNDERTAKING U-5 - To provide an 6 updated phishing failure rate for 7 the period of April 2025...
AI summary The discussion revolves around the provision of an updated phishing failure rate for April 2025 to date and a request for information on cyber incidents recorded by NSPI over the last five years. The participants are discussing the appropriate handling of undertakings and commitments related to cybersecurity.
NOVA SCOTIA POWER PANEL 209 Cr-ex, (Rudderham) I just said, it would be anything in the future would be up to this Board to make a determination as to whether it was prudent or imprudent. Q. Okay. So that's not –– the assurance doesn't go...
AI summary The discussion centers on the costs associated with cybersecurity restoration efforts by Nova Scotia Power Inc. (NSPI), with the assurance that the Board will determine the prudence of future costs, while current restoration costs incurred in 2025 and 2026 are being accounted for by the utility and ultimately the shareholder.
1 that it's necessarily going to match up. And that's, I 2 guess, why I cautioned you when we first began this 3 discussion about this document, that there's no-one up 4 here prepared to speak to this document from a different 5 proceeding...
AI summary The discussion revolves around the confidentiality of a document related to a cybersecurity incident, with the witness explaining that detailed breakdowns and forecasts are kept confidential, while some figures may be made public.
1 capital". So I had said, "Okay. Well, then, is capital 2 not included or" I'm just I can't quite understand 3 what I'm looking at, what's actually being tracked, what's 4 actually being recorded. 5 I just want to understand what I'm 6 lo...
AI summary The discussion revolves around the transparency of cybersecurity incident costs, with a concern about what is being tracked and recorded. The Chair asks whether the issue stems from confidentiality or if there are other factors, and the speaker responds that some costs are actuals and should be on the public record.
NOVA SCOTIA POWER PANEL 233 Cr-ex, (Rudderham) 1 because it's reported in one proceeding, not reported 15 it's they're tracking using specific codes similar to, 16 you know, the storm costs. So in the storm cost 17 proceedings, all those c...
AI summary The discussion revolves around the handling of cybersecurity incident costs in regulated statements and the concern over the confidentiality of forecast numbers, particularly for 2025. The witness notes that specific codes are used to track such costs, similar to those used in storm cost proceedings, but they are not included in the current record.
INTERNATIONAL REPORTING INC. CERTIFIED COURT REPORTERS 1 and the impacts of the attack. 2 Q. So costs from, like, all those 3 lawyers, I think you said, KPMG, LevelBlue, those types of 4 costs is what you're describing, or...? 5 A. (Willia...
AI summary The text discusses cybersecurity-related costs, including those from external firms like Mandiant and KPMG, as well as customer-related restoration activities such as account recovery and AMI system restoration.
NOVA SCOTIA POWER PANEL 273 Cr-ex, (Rudderham) 1 it subject to check, yes. 2 Okay. And at least some of those Q. 3 projects in 2025 would have been deferred because of the 4 cyberattack or the activities that came afterwards, 5 decreased s...
AI summary The discussion focuses on the impact of a cyberattack on Nova Scotia Power Inc.'s projects, particularly the delay of the Customer Care Modernization Project in 2025. The witness explains that the project was paused after the attack and resumed in June, with implementation eventually taking place in March.
NOVA SCOTIA POWER PANEL 275 Cr-ex, (Rudderham) 1 to be June of last year. So despite the fact that that 2 project came in nine months later, we did come in under 3 the budget for that still. So it's an example where the 4 investment had be...
AI summary The discussion centers on the impact of a cybersecurity attack on capital projects, with NSPI stating that while delays occurred, the financial impact has not been analyzed or quantified on a general level due to the unique nature of each project.
1 approved by the Board, and so any to the extent that 2 there is any costs associated with a delay, and that that 3 delay is determined to be imprudent, then those costs 4 would be dealt with by the Board in the normal course. 5 Q. And on...
AI summary The discussion focuses on the Board's handling of costs associated with delays, particularly in the context of a cybersecurity incident. The witness explains that any costs resulting from delays, including those caused by the incident, are identified and explained in capital plans.
NOVA SCOTIA POWER PANEL 279 Cr-ex, (Rudderham) 1 where I'm meant to be looking. 18 MR. CLARKE: Excuse me for a second. 19 Mr. Chair, I was just wondering about INTERNATIONAL REPORTING INC. CERTIFIED COURT REPORTERS 1 the mid-afternoon brea...
AI summary The discussion revolves around the impact of a cybersecurity incident on capital project schedules, with a focus on whether other factors may have influenced project timelines. The panel is questioning the completeness of the information provided and considering the possibility that some projects may no longer be delayed.
20260819-1Hearing Transcript — 08/19/2026 (Chris Lanteigne, Lia MacDonald, Glen MacLeod, Blake Williams)
14 passages
NOVA SCOTIA ENERGY BOARD IN THE MATTER OF: THE PUBLIC UTILITIES ACT - and - IN THE MATTER OF: AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer information, customer...
AI summary The Nova Scotia Energy Board is conducting an inquiry under the Public Utilities Act regarding the impact of a cyber incident on Nova Scotia Power Incorporated's handling of customer information, customer service, billing processes, and regulatory matters.
I N D E X O F P R O C E E D I N G S August 18, 2026 PAGE NO. Hearing opens 1 Preliminary matters 1 Opening Statement by Consumer Advocate 8 Opening Statement by Small Business Advocate 12 Opening Statement by Mr. David MacLeod 14 NOVA SCOT...
AI summary The document outlines the proceedings of a regulatory hearing involving Nova Scotia Power, including opening statements by various advocates, cross-examinations, and the submission of exhibits. Key topics include the Equifax data breach settlement and the 2025 financial statements.
NOVA SCOTIA POWER PANEL 407 Questions, (Melanson) 1 been notification to the senior leadership of the 1 And interestingly enough, Mr. Williams 2 talked yesterday kind of about the cultural changes that 3 we've seen at Nova Scotia Power wit...
AI summary The text discusses Nova Scotia Power's approach to cybersecurity, including employee training for phishing attacks and the validation of successful phishing tests. It also addresses the company's rebuttal to recommendations regarding computer access controls, emphasizing the balance between risk and employee needs.
NOVA SCOTIA POWER PANEL 469 Questions, (Deveau) 1 So I'm just wondering, what's the INTERNATIONAL REPORTING INC. CERTIFIED COURT REPORTERS a page. Sorry; can you search in there Rob, can you do a quick search for me, just search for the wo...
AI summary The discussion focuses on the security measures taken by Nova Scotia Power Inc. regarding the MyEnergy Insights Program, specifically the encryption of data in the Azure environment and the breach that allowed unauthorized access despite these protections.
1 would move on and the assumption would be you've dealt 2 within the 14 days. 3 Q. Okay. 4 A. (Williams) Any data that hasn't 5 been touched would remain for 90 days with the assumption 6 that we may still need it, we just haven't gotten...
AI summary The discussion revolves around data retention policies and security risks associated with storing data in a Data Lake and CIS system. It highlights that data not accessed within 90 days is lost, and there are concerns about unauthorized access to data stored in these systems.
NOVA SCOTIA POWER PANEL 475 Questions, (Deveau) 1 you're expanding it to other platforms or well, the SIN 2 numbers probably wouldn't make it to MyEnergy, but when 3 you're copying it from the CIS system to the Azure system, 4 it's just an...
AI summary The discussion revolves around data security and migration from the CIS system to the Azure system, with concerns raised about potential unauthorized access and data manipulation. The response highlights the use of automated destruction tools and secure environments to mitigate risks.
NOVA SCOTIA POWER PANEL 483 Questions, (Deveau) 1 [11:50:29] So obviously it's the paragraph Q. 2 at the top of page 22 of 30 there, and it's the reference 3 highlighted it's a reference to the Company maintaining 4 cyber insurance coverag...
AI summary The text discusses Nova Scotia Power's cybersecurity insurance coverage, noting that the company's coverage may be exhausted due to a sophisticated cyberattack or multiple events, and that there is no guarantee of renewal on acceptable terms. This is linked to the company's experience over the past year and a half.
NOVA SCOTIA POWER PANEL 493 Questions, (Deveau) 1 Okay. Q. 2 A. (Williams) So I certainly take 3 you –– take your word for that, sir. 4 Q. Yeah. Okay. 5 I'll take you to the rebuttal, N-17, 6 page 10 and 11. And I think it's the same sente...
AI summary The text discusses cybersecurity standards and policies at Nova Scotia Power, referencing a two-year update to practices in alignment with the NIST Cybersecurity Framework. It clarifies that while practices were updated, the 13 core policies remained unchanged.
INTERNATIONAL REPORTING INC. CERTIFIED COURT REPORTERS page 43. BY VICE CHAIR DEVEAU: Q. That one, I do not see I didn't see a date on it when it was last updated. A. (Williams) I'm not aware of a date on here, sir. And the reason for that...
AI summary The discussion revolves around the lack of a specific date on a document related to Nova Scotia Power's data protection measures and the clarification regarding the company's audit program. The document is described as a screenshot from a web page and not updated in recent years. An information protection audit was conducted in December 2024 as part of the company's annual audit program.
NOVA SCOTIA POWER PANEL 531 Questions, (Chair) 1 that has files and folders, is the technical difficulty 14 documentation would be included. 15 And were either SharePoint or Q. 16 OneDrive impacted by the cyberattack? 17 (Williams) No, the...
AI summary The discussion revolves around the use of SharePoint by Nova Scotia Power, specifically the impact of a cyberattack on its on-premises version. The company has used SharePoint for several years, but the online version was not affected, while the on-premises version had functional limitations post-attack.
NOVA SCOTIA POWER PANEL 611 Questions, (Chair) 1 levels in terms of invoice payments? 2 A. (Williams) I don't have a 3 specific date, sir, but as referenced in the body of the 4 report, that it's indicated that those numbers are 5 expected...
AI summary The discussion centers on the expected reduction in invoice payment levels over time due to operational familiarity with a new system, and the commitment by Nova Scotia Power to not pass on cyber incident costs to customers, excluding overearnings scenarios.
In-ch, (Clarke) 1 JENA VALDETERO, Solemnly affirmed: 2 THE CHAIR: Go ahead, Mr. Clarke. 3 MR. CLARKE: Thank you, Mr. Chair. 4 EXAMINATION ON QUALIFICATIONS BY MR. CLARKE 5 Q. Ms. Valdetero, can you please 6 confirm you filed evidence in th...
AI summary The examination of Jena Valdetero by Mr. Clarke confirms her submission of evidence and qualifications, including her role as a practising attorney and co-chair of the U.S. Data Privacy and Cybersecurity Practice at Greenberg Traurig. She has extensive experience in data breach investigations and incident response, including work with vendors similar to those retained by Nova Scotia Power.
me, Ms. Valdetero, are any of those utilities that you mentioned, are they similar to Nova Scotia Power in that they're vertically integrated single providers within the jurisdiction they operate? A. Yes. The energy company is. Q. Okay. An...
AI summary The discussion centers on the scope of an expert's retainer in a regulatory proceeding, with questions about data minimization and best practices. The expert clarifies that her retainer was related to responding to a cyberattack and not to data minimization practices. Counsel and the Chair discuss the relevance of the expert's qualifications and the scope of her involvement.
Questions, (Melanson) 1 of having a real experienced understanding of exactly what 2 happens in these incidents and how difficult it is to get 3 it right. 4 I have what's becoming kind of a tired 5 saying, but I always say in a large incid...
AI summary The text discusses the challenges faced by a company during a large incident, emphasizing the difficulty of making decisions with no perfect options. It highlights Nova Scotia Power's response, noting their efforts to raise awareness about encryption and service issues, as well as the potential impact on customer information.