Topic/Matter Intersection

Topic:"Information Disclosure" in M12273

Matter: Board Inquiry into Nova Scotia Power's Cybersecurity Incident
58 passages 18 documents

Information Disclosure across all matters →

N-1Letters of Comment - Redacted 21 passages
Section 9
The date submitted as a "decision" is the date of the letter I received from Nova Scotia Power. A copy can be provided, if necessary. How do they want the I want more detailed information about the breach including complaint resolved? more...

AI summary A customer raises concerns about Nova Scotia Power's (NSP) handling of a data breach, questioning the storage of personal information like social insurance numbers and demanding financial compensation for identity theft risks. The complaint includes requests for detailed breach information and references a matter (M12273) involving NSP and Nova Scotians.

Section 11
written request to ask him to pick up the ball, and start running with it. I would ask for a response to my email. May 25, 2025 Sent Via Email Premier Tim Houston Office of the NS Privacy Officer I am writing to formally complain about Nov...

AI summary The complainant reports a security breach by Nova Scotia Power, noting a two-month delay in notifying them and inadequate disclosure of stolen data, citing PIPEDA rights.

Section 12
’s security breach, and according to the Personal Information Protection and Electronic Documents Act (PIPEDA), I have a legal right to know the full scope of My Personal Data Theft. • The NS Power letter provided no guidance on what steps...

AI summary The complainant alleges a major NS Power data breach affecting half of Nova Scotia's population, criticizing NS Power for failing to provide identity theft protection guidance and for recommending TransUnion (linked to NS Power's parent company Emera) as a paid service. The request includes disclosure of stolen data, explanation of the 23-day breach notification delay, and mandatory identity protection.

Section 13
…/2 -2 - 3) Provide comprehensive identity protection through a credible provider; 4) Provide in writing, a clear acknowledgement that NS Power was the care holder of my Personal and Private information, as they had requested it from me, b...

AI summary The complainant alleges NS Power failed to protect personal data during a cyberattack, leading to the theft of 280,000 Nova Scotians' information. They demand identity protection, written acknowledgment of NS Power's data stewardship, and an explanation for restoring public trust, citing delayed breach disclosure and ongoing access barriers.

Section 27
oard, NSUARB ; [email protected]; Premier ; Information Privacy Commissioner for Nova Scotia Subject: Nova Scotia Power Privacy Some people who received this message don't often get email from Learn why this is important EXTERNAL EMAI...

AI summary A complaint is filed against Nova Scotia Power regarding a security breach where personal data was stolen by an unauthorized third party on March 19, 2025. The breach was discovered on April 25, 2025, but the complainant was notified only on May 23, 2025, two months later. The complainant criticizes the delayed response and inadequate handling of the incident.

Section 28
Power didn't notify me of the breach or that my information had been stolen until May 23, 2025 – two months after the breach and almost one month after your organization knew about it. As mentioned, I received your notification letter on M...

AI summary The complainant criticizes Nova Scotia Power (NSP) for delayed breach notification, lack of specific information about compromised data, absence of guidance on next steps, and insufficient support following a data breach. They reference PIPEDA to highlight the legal right to full disclosure.

Section 29
TransUnion credit monitoring services. When I called the number, I was connected with TransUnion. This limited response is not enough support for victims of a data breach of this size. In closing, I request that Nova Scotia Power immediate...

AI summary Melissa Marsh alleges a data breach by Nova Scotia Power (NSP) compromised her personal information, requesting detailed breach specifics, explanations for delayed notification, enhanced identity protection, and improved cybersecurity protocols. She criticizes NSP's current response as inadequate for protecting customer data and ensuring transparency.

Section 30
g-MacLean, Kimberly To: Painting-MacLean, Kimberly Subject: FW: Electricity Inquiry: Nova Scotia Power Personal Information Breach Date: May 27, 2025 8:01:06 AM From: Sent: May 26, 2025 4:18 PM To: Henwood, Crystal D Subject: Electricity I...

AI summary The email discusses a personal information breach by Nova Scotia Power (NSP), with the sender criticizing NSP's lack of specificity regarding the breach and the offer of a two-year credit reporting account with Transunion. The sender seeks clarity on the breach details and the adequacy of the provided remedy.

Section 32
and my questions and concerns are as follows: Precisely what personal information of mine was on file with you at the time your server was breached by an authorized third party? If I accept the Transunion account does that, from the perspe...

AI summary The customer raises concerns about a data breach at NS Power, inquiring about the personal information exposed, legal implications for class-action lawsuits, financial compensation for damages, and whether NS Power received data from third parties like solar providers.

Section 33
and what information was received, and, if applicable, what specific information, including the entity from which the information was derived, did an unauthorized third party gain access? What level of accountability will NSP and/or the Go...

AI summary The complainant alleges unauthorized access to personal information by NSP, attributing the breach to inadequate safeguards and the government's sale of the power entity to NSP without ensuring data protection. They demand accountability from NSP and the government, criticizing the monopoly and lack of safeguards.

Section 35
Additional details: I'm one of the thousands of people who's personal and financial information was compromised by a ransomware attack against NS Power. We are now vulnerable to identity thieves who picked up our sensitive information on t...

AI summary A customer of NS Power reports a data breach due to a ransomware attack, leaving personal and financial information exposed. NS Power offered limited credit monitoring services, but the customer argues that government oversight would have prevented the breach and demands stronger legal protections for affected consumers.

Section 36
whether or not to pay the ransom. We obviously don't count. I appreciate your attention in this matter. Many thanks. Did they contact the utility? No How did the utility respond? Page 2 of 3 How do they want the Legal protection against id...

AI summary A customer lodges a formal complaint against Nova Scotia Power (NSP) for negligence in safeguarding data, leading to a data breach that resulted in identity theft and $30,000 in fraudulent losses. The complainant demands legal protection, compensation, transparency, and policy changes to prevent future incidents.

Section 37
bers), hackers were able to directly contact my bank, , and use our personal information (from NS Power) to steal $30,000 by fraudulently transferring the money from . While I have received no response or communication from Nova Scotia Pow...

AI summary A customer alleges that Nova Scotia Power (NSP) failed to protect personal data, leading to a $30,000 fraud. The breach occurred in March 2025, but customers were notified only in May 2025. The complainant criticizes NSP's delayed response, lack of urgency in communication, and failure to address the breach promptly, holding NSP fully responsible for the theft.

Section 39
$30,000 that was stolen as a direct result of NS Power negligence, and a timeline for when I can expect it to be completed. Regards, Diane Newman Betts Michael Betts Type of complaint: Other Additional details: Breach of all my personal in...

AI summary A complaint alleges NS Power's negligence caused a ransomware attack, breaching personal and financial data of thousands. Victims report identity theft, phishing, and lack of legal protection. NS Power offered TransUnion monitoring but no further remedies.

Section 40
ite is convoluted for many of us and only offers monitoring services, which we, the victims, are responsible keep track of. There is no legal protection. Page 2 of 4 What I have been able to do so far is: -Informed my credit card company o...

AI summary A consumer reports identity theft and fraud, criticizing NS Power for inadequate notice and consumer protection. They describe limited actions taken (credit card alerts, mytrueidentity, CRA issues) and argue that government oversight would prevent such vulnerabilities. The complainant feels marginalized, with no decision-making input from NS Power during the ransom consideration.

Section 43
their date released to hackers / in the ransomware attack. Transunion is not effective in managing the monitoring. Supporting documents uploaded: Page 2 of 2 Type of complaint: Other Additional details: I received a letter on May 20,2025 f...

AI summary A customer received a letter from NS Power informing them of a data breach on March 19, 2025, but was notified on May 20, 2025, 8 weeks later. The customer was dissatisfied with the delayed notification and the response from Trans Union, which provided no immediate details about the stolen personal information.

Section 53
d how he/she may do that. I assume that the board can change the regulations? If so I request a meeting with the board to discuss why these regulations have little to no protections for its customers. I wish to escalate this to a higher au...

AI summary Sean Kelly is concerned about the lack of data protection in the board's regulations and has requested a meeting with the board. He also mentions the possibility of a class action lawsuit if the issue is not resolved. Don Farmer, the Dispute Resolution Officer, provided information on the current regulations and directed Sean Kelly to contact the Nova Scotia Energy Board for further assistance.

Section 66
Page 2 of 5 As a victim of the company’s security breach, and according to the Personal Information Protection and Electronic Documents Act (PIPEDA), I have a legal right to know the full scope of my personal data exposure. Only today, whe...

AI summary The complainant, a Nova Scotia Power customer, reports a data breach involving their SIN and requests detailed information about the breach, an explanation for the delay in notification, and comprehensive identity protection services. They criticize the lack of support and guidance provided by the company.

Section 74
lling notices, or make informed decisions about my energy usage and payments. During this period, I have now received a substantial bill with no warning or ability to track or dispute it in real time. Additionally, your offer of a complime...

AI summary The customer is disputing a high energy bill due to poor communication and lack of real-time tracking. They also reject an unsolicited TransUnion subscription offer and demand a credit, bill waiver, and service freeze until online access is restored securely. They threaten to escalate the matter to regulatory bodies and seek legal consultation.

Section 75
m stemming from your mishandling of personal information and the prolonged disruption of service access.​ I expect a written response outlining next steps and your resolution plan. Sincerely, Danielle Kristine Maillet From: Painting-MacLea...

AI summary A customer of Nova Scotia Power reports being mishandled during a data breach, including not receiving any communication about the breach and being unable to speak with a supervisor. The customer is disabled and expresses concern about potential misuse of their personal information.

Section 79
ce my information is out there forever? I feel that I am left to worry for the rest of my life about what is happening to my information while Nova Scotia Power walks away from this after two years. I am not sure of what power you have ove...

AI summary The text includes a letter from Susanne Roy expressing concerns about Nova Scotia Power's handling of customer information and the lack of long-term credit monitoring support. It also includes email correspondence related to fraud protection and accountability and transparency, with a focus on organizational responsibility and communication.

N-2NSPI (NSEB) RIR 1 to 12 - Redacted 8 passages
Section 8
1 The Incident has not caused any disruption to physical operations at NS Power’s 2 generation, transmission and distribution facilities, and the Incident has not impacted the 3 Company’s ability to safely or reliably serve customers in No...

AI summary NS Power confirms no operational disruption from the incident and outlines transparency measures, including multi-channel communication, media outreach, and advertising strategies to inform customers and reduce harm risks.

Section 10
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The document outlines an inquiry into Nova Scotia Power's cybersecurity incident (NSEB M12273), focusing on NSPI's responses to information requests by the Nova Scotia Energy Board. The content is redacted, limiting detailed analysis.

Section 11
1 Customer Notification Timeline 2 3 As noted above, the Company became aware of the Incident on Friday, April 25. The next 4 business day, on Monday, April 28, 2025, NS Power informed customers that it was 5 actively responding to a cyber...

AI summary NS Power notified customers of a cybersecurity incident starting April 28, 2025, with detailed updates on May 1, 2025, and formal notices to 277,000 customers on May 13, 2025. The company engaged third-party providers for notifications and issued press releases, with senior personnel participating in media interviews to inform the public.

Section 21
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The document outlines an inquiry into Nova Scotia Power's cybersecurity incident (NSEB M12273), focusing on NSPI's responses to information requests by the Nova Scotia Energy Board. The content is redacted, limiting detailed analysis.

Section 30
1 • Monday, April 28, 2025 2 • Thursday, May 1, 2025 3 • Wednesday, May 14, 2025 4 • Friday, May 23, 2025 5 • Wednesday, June 4, 2025 6 • Wednesday, June 25, 2025 7 8 Customers can access these public/media updates via a banner on the NS P...

AI summary NS Power communicated cyber incident updates via a homepage banner, social media, and direct emails to stakeholders, including a provincial media distribution list. On June 4, 2025, NS Power executives testified before the Standing Committee on Public Accounts regarding the incident and engaged with media post-session. Proactive notifications were sent to local media about customer support sessions.

Section 32
d Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED 1 Cape Breton – Monday, June 30, 2025 2 • The Coast 89.7FM Radio - Sydney - [email protected] 3 • MBS Radio – S...

AI summary The document outlines Nova Scotia Power's (NSPI) media responses to inquiries about customer bills and meter readers, alongside an ongoing NSEB inquiry into a cybersecurity incident (NSEB M12273). NSPI's Director of Customer Care, Chris Lanteigne, participated in interviews with media outlets and CBC programs.

Section 83
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The document outlines an inquiry into Nova Scotia Power's cybersecurity incident (NSEB M12273), focusing on NSPI's responses to information requests by the Nova Scotia Energy Board. The content is redacted, limiting detailed analysis.

Section 91
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The document outlines an inquiry into Nova Scotia Power's cybersecurity incident (NSEB M12273), focusing on NSPI's responses to information requests by the Nova Scotia Energy Board. The content is redacted, limiting detailed analysis.

N-3Incident Report - Redacted 2 passages
Section 37
1 Given that NS Power does not have updated contact information for its former customers, the 2 Company worked to share this indirect notification as broadly as possible. In addition to its 3 website, NS Power actively shared this informat...

AI summary NS Power notified 375,000 affected customers via media, social platforms, and advertising after a data incident. An investigation identified 97,000 additional impacted individuals, who received direct notices and credit monitoring offers. A dedicated call centre was established for customer support and information.

Section 68
1 8.2 Additional Security Audits, Policy Updates, and Employee Training 2 Section 4.1 addressed additional security audits, policy updates, and employee training as 3 summarized below. 4 5 Regarding security audits, NERC conducts extensive...

AI summary The document discusses NS Power's efforts to enhance cybersecurity through additional security audits, policy updates, and employee training. It mentions NERC audits, the OPC's ongoing investigation, and NS Power's alignment with the NIST Cybersecurity Framework. Employee training includes quarterly sessions and phishing simulations.

N-4NSPI (NSEB) RIR 13 to 15 1 passage
Section 1
Board Inquiry into Nova Scotia Power’s Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL

AI summary The Nova Scotia Energy Board (NSEB) is investigating a cybersecurity incident involving Nova Scotia Power (NSPI). NSPI has submitted responses to NSEB's information requests as part of the inquiry (NSEB M12273). The proceeding focuses on cybersecurity measures and compliance with regulatory disclosure requirements.

N-5Refiled Incident Report - NSPI - Redacted 9 passages
Section 3
Preventing Future Breaches ....................................... 38 20 8.2 Additional Security Audits, Policy Updates, and Employee Training.............................. 40 21 8.3 New Strategies and Proactive Measures .....................

AI summary The document outlines Nova Scotia Power's cybersecurity incident report, detailing measures to prevent future breaches through audits, policy updates, employee training, customer communication, and data retention policies.

Section 4
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 1.0 INTRODUCTION 2 3 In its July 14, 2025 letter regarding the cybersecurity incident (Incident) experienced by Nova 4 Scotia Powe...

AI summary Nova Scotia Power Inc. (NSP) is required by the Nova Scotia Energy Board (NSEB) to submit a cybersecurity incident report detailing the 2025 incident, including affected systems, root causes, and response actions. The NSEB also directed NSP to settle vendor dues and engage MNP to investigate data handling practices following a financial technology data compromise.

Section 9
1 The NSEB replied to the Premier by letter on December 10, 2025, providing, in part, the following: 2 3 Upon receipt of your letter, the Board opened a new matter (M12600). Given the 4 connection between these issues and the Board’s ongoi...

AI summary The NSEB opened a new matter (M12600) related to issues raised by the Premier, considering whether they should be addressed in the ongoing cybersecurity inquiry (M12273). NS Power argues that many issues were already addressed in prior reports and that the second set of Information Requests (IRs) under M12273 specifically handle customer billing concerns, making M12273 the appropriate proceeding.

Section 40
1 Former Customers 2 3 As the Company continued its investigation of the impacted data, NS Power determined that 4 personal information relating to former customers had also been impacted by the Incident. 5 6 On June 25, 2025, NS Power not...

AI summary NS Power identified former customers affected by a data incident, extended credit monitoring to five years, and notified them through media and advertising due to lack of contact info. Additional 97,000 customers were later identified, with direct notices sent on October 31, 2025, offering credit monitoring.

Section 82
1 Power was required to issue a T5 in connection with interest over $50 earned in a year on a 2 customer deposit. 3 4 In 2021, Nova Scotia Power initiated a customer energy management program called MyEnergy 5 Insights to better inform cus...

AI summary Nova Scotia Power implemented a customer energy management program called MyEnergy Insights in 2021, which involved exporting customer data to a cloud storage environment. This data was targeted by a threat actor, leading to the exposure of some customers' SINs. NS Power has since committed to permanently deleting SINs from its systems, with completion expected by March 31, 2026.

Section 93
1 The OPC initiated an investigation into the Incident on May 28, 2025, and the Company is 2 actively and fully cooperating with the OPC to support the OPC’s investigative efforts. 3 The Company has also provided updates to the Nova Scotia...

AI summary The OPC initiated an investigation into an incident on May 28, 2025, and the Company is fully cooperating. The incident did not disrupt operations or impact customer service. The Company has taken a transparent approach, communicating through various channels to inform affected individuals and stakeholders.

Section 96
1 the NS Power website and information appeared as the top search result when customers 2 used search engines (i.e. Google) to find information about the Incident. Social media 3 accounts have been regularly monitored, and where appropriat...

AI summary NS Power informed customers about a cybersecurity incident, providing updates on the impact of the incident and encouraging vigilance against scams. Notifications were sent to affected customers, and third-party service providers were engaged to assist with the process.

Section 117
1 These communications and releases to media occurred on the following dates: 2 3 • Monday, April 28, 2025 4 • Thursday, May 1, 2025 5 • Wednesday, May 14, 2025 6 • Friday, May 23, 2025 7 • Wednesday, June 4, 2025 8 • Wednesday, June 25, 2...

AI summary The document outlines the dates and methods used by NS Power to communicate updates regarding a cyber incident to the public and media. Key communications included appearances before the Standing Committee on Public Accounts and direct engagement with media.

Section 192
tion in accessing its internal resources and external advisors, and assumes that any such external advisors will execute a confidentiality undertaking prior to their receipt of such confidential data. Similarly, NS Power is assuming that a...

AI summary NS Power outlines its approach to handling confidential data in the cybersecurity incident proceeding, including requiring confidentiality undertakings from external advisors and intervenors. It also confirms its commitment to providing timely responses to the Board's information requests and submitting the Incident Report by December 31, 2025.

N-5(BC)Refiled Incident Report - Board Confidential Board Only 1 passage
Section 1
CONFIDENTIALITY NOTICE The document you are attempting to access has been filed in confidence. Some exhibits, noted as confidential, contain information which if released might cause financial or other harm to the party filing it, or which...

AI summary Confidentiality notice from the Nova Scotia Energy Board restricting access to sensitive documents. The notice explains that certain exhibits contain confidential information protected by privacy laws and outlines procedures for obtaining access via a Confidentiality Agreement. Contact details for the Board are provided.

98507Board Letter re: Reports required 1 passage
Section 5
or and response to the event that occurred. The Board believes NS Power should be able to file this incident report by the end Document: 322528 -3- of this year, but if NS Power does not believe this date is achievable, it may propose anot...

AI summary The Board requires NS Power to file an incident report by year-end, with monthly progress updates if the deadline isn't met. MNP will independently assess the incident for the Board. Customer concerns about data misuse and communication issues with credit monitoring services are addressed through Letters of Comment and upcoming information requests.

98677NSEB (NSPI) IR 1 to 12 1 passage
Section 5
misuse of your personal information, as a precaution, arrangements have been made with 37 the consumer reporting agency, TransUnion, to provide impacted individuals with a two-

AI summary The text references a precautionary measure involving TransUnion, a consumer reporting agency, to address potential misuse of personal information by providing impacted individuals with a two-year... (incomplete).

98858Notice of Intervention - DOE 1 passage
Section 2
l matters relating to energy resources. 2. The Department of Energy asks that all notices and information circulated in this proceeding be provided to the following individuals: Daniel Boyle Peter Craig Counsel Director, Clean Electricity...

AI summary The Department of Energy requests that all notices and information in the proceeding be directed to specified individuals, including Daniel Boyle, Peter Craig, and Girish Patel, with Daniel Boyle submitting on behalf of the Department of Energy.

98901Letter NSPI re: Application for Procedural Order and Request for Confidentiality 1 passage
Section 6
the information outlined in the Board’s letter of July 14, 2025 (the Report), subject to any extensions that NS Power may request and the Board may provide. 1 See, for example, the investigation procedures followed by the Office of the Pri...

AI summary The Board requests a report from NS Power by July 14, 2025, with potential extensions. NS Power may consolidate responses to Information Requests with the Report and designate submissions as 'Board Confidential,' limiting access to panel members, the Clerk, and Board counsel.

98924Board letter re additional information required 2 passages
Section 6
of Canada in many cases leading to and including Sherman Estate v Donovan, 2021 SCC 25. This was canvassed extensively in New Palace Cabaret Ltd. (Re), 2024 NSUARB 57 (Matter M11181). • The deadline for providing responses to Board Staff i...

AI summary The text references legal precedents involving confidentiality and disclosure obligations, citing Sherman Estate v Donovan and New Palace Cabaret Ltd. (Matter M11181). It emphasizes the Board's requirement for public transparency in responding to customer-related information requests, while NS Power seeks unilateral designation of sensitive information as 'Board Confidential'.

Section 9
• It may be appropriate for NS Power to review some filings in this proceeding for confidentiality, such as evidence filed by the parties (including Board Counsel consultants). The need for this may depend on the nature of the information...

AI summary The Board acknowledges NS Power's role in reviewing filings for confidentiality but emphasizes transparency in proceedings. It requests clarification on procedures related to utility investigations and information security, while balancing the need to protect sensitive data. The Board reaffirms its commitment to public disclosure where possible, despite security constraints.

98963Board Letter approving NS Power's extension request to filing IR responses 1 passage
Section 1
August 15, 2025 [email protected] Adam Kardash, Partner & Co-Chair Privacy and Data Management Osler, Hoskin & Harcourt LLP Box 50, 1 First Canadian Place Toronto, ON M5X 1B8 Dear Mr. Kardash: M12273 – Board Inquiry into Nova Scotia Power...

AI summary The Board grants NS Power's request to extend the deadline for responding to cybersecurity incident inquiries but emphasizes the need for timely responses to customer concerns regarding data compromise and credit monitoring.

99040Letter on behalf of NS Power re confidentiality - Redacted 1 passage
Section 4
t 15, 2025, permitting the responses to be delivered on or before September 5, 2025. NS Power will endeavor to prioritize its efforts to respond to the IRs earlier than September 5, 2025, if possible. NS Power also confirms that it will pr...

AI summary NS Power commits to submitting an Incident Report by December 31, 2025, and providing monthly updates. It also requests confidentiality for a submission under Rule 12 of the Board Regulatory Rules.

99375Board Letter re: Response to Monthly Update #1 and confidentiality 4 passages
Section 4
e’s content was underwhelming. It repeated information that generally was already provided in prior correspondence, and in the public domain. The Board would have expected more information about the Recovery Program Office, who is involved...

AI summary The Board criticized the Recovery Program Office's lack of transparency, customer concerns over data misuse, and delayed responses to Information Requests (IRs) related to cybersecurity. The Monthly Update failed to detail cybersecurity impacts on business systems or regulatory matters, with updates shared haphazardly through other filings.

Section 13
tion that was stolen. However, the Board emphasized [in a letter dated July 14, 2025] that it was important that this proceeding be conducted as publicly and transparently as possible. The “Board Confidential” letter that you sent on Augus...

AI summary The Board criticizes a 'Board Confidential' letter for insufficient transparency, emphasizing regulatory processes must be publicly open. It demands detailed justifications for confidentiality claims, arguing much of the letter's content is non-sensitive and should be publicly disclosed. Submissions are due August 20, 2025, with confidentiality claims requiring full rationale.

Section 14
tification must address not only the basis for the claim, but also why the information cannot be disclosed to intervenors under a confidentiality undertaking or with other protections. [Board Letter, August 12, 2025, p. 3] NS Power replied...

AI summary NS Power argues that privacy investigations by regulatory authorities provide useful models for the Board's confidentiality procedures. It emphasizes that such investigations typically occur confidentially, with limited disclosure, and acknowledges the Board's right to share 'Board Confidential' information with advisors who execute confidentiality undertakings.

Section 15
any external Document: 324221 -6- advisors will execute a confidentiality undertaking prior to their receipt of such confidential data. It added: Similarly, NS Power is assuming that all Intervenors in the Inquiry will execute a confidenti...

AI summary NS Power emphasizes the need for confidentiality undertakings by advisors and intervenors due to the sensitive nature of data related to a cybersecurity incident. It requests the Board to maintain strict confidentiality for certain information and seek assurances on data protection measures, while consenting to share Appendix B with Formal Intervenors under standard processes.

99535NSPI Monthly Update Report #2 1 passage
Section 29
respect to information technology, much of NSPML’s data was not accessible for a period. Some data has since been made accessible and NSPML continues to work with the corporate Emera team to complete accessibility efforts. b) There are no...

AI summary NSPML faced data accessibility issues due to a cybersecurity incident, impacting the Joint-Use Agreement Proceeding (M12149). NS Power could not analyze O&M costs for poles under the JUA or access historical installation data, citing the incident as the cause. No customer impact or 2026 O&M costs are proposed.

100677Affidavit - MacGillivray Law 1 passage
Section 4
the accuracy of the information provided. METHODS BY WHICH INFORMATION WAS RECEIVED 7. During the relevant period, complaints and inquiries were received through the following channels: a. telephone calls to the firm 's main phone line tha...

AI summary The document outlines methods for receiving complaints (telephone and online), collected contact information (name, phone, email), and estimates over 300 calls and 200 leads related to Nova Scotia Power. No identity verification of contacts was performed, and inquiries were directed to complete intake forms.

101155NSPI Monthly Update Report #6 1 passage
Section 31
Monthly Cybersecurity Update 6 Attachment 2 Page 3 of 6 Report 2 - Report 3 - Report 4 - Report 5 - Report 6 - Forecast Restoration of Normal Affected Regulatory Matters October 1 November 3 December 1 February 4 March 4 Activities Latest...

AI summary The document outlines a monthly cybersecurity update with attached reports detailing affected regulatory matters, including dates for report submissions and updates on financial reporting and fuel adjustment mechanisms. Key topics include cybersecurity, financial reporting, and fuel cost adjustments.

101657Board letter approving NS Power's extension 1 passage
Section 1
April 20, 2026 [email protected] Blake Williams VP, Legal and Regulatory Nova Scotia Power Inc. P.O. Box 910 1223 Lower Water Street Halifax, NS B3J 3S8 Dear Mr. Williams: M12273 – Board Inquiry into Nova Scotia Power Incorporated’...

AI summary Nova Scotia Power Inc. (NS Power) requested an extension to refile documents related to a cybersecurity incident and confidentiality claims, which the Board approved until April 27, 2026. The documents include submissions, letters, and reports previously filed under confidentiality.

Disclaimer: These summaries were generated by AI from the filings they describe. We take care to make them accurate, but errors are possible - and they aren't advice. Only the filings themselves are the record: if you're relying on something here, confirm it against the source documents or the Nova Scotia Energy Board's own record. Full disclaimer →