N-1LOCs Redacted (N-1 from M12273)
7 passages
From: Painting-MacLean, Kimberly To: Painting-MacLean, Kimberly Subject: M12273 Administrative Demand for Structural Redress – NSUARB Oversight Failure and NS Power Identity Breach Date: May 23, 2025 10:11:33 AM Attachments: Administrative...
AI summary An administrative demand for structural redress has been filed regarding NSUARB oversight failure and an NS Power identity breach. The demand is related to unlawful contracting structures enabled by NSERBT oversight failures, citing previous decisions and responses from NSERBT.
\ \ EXTERNAL EMAIL / COURRIEL EXTERNE \ \ Exercise caution when opening attachments or clicking on links / Faites preuve de prudence si vous ouvrez une pièce jointe ou cliquez sur un lien To: Michael Savage acting as Chief Executive Office...
AI summary This email requests formal review and structural accountability from Nova Scotia's executive leadership regarding governance failures by the Nova Scotia Energy and Regulatory Boards Tribunal (NSERBT) and Nova Scotia Power's (NS Power) use of unconscionable contracting mechanisms. It highlights concerns about unlawful contract formation and identity breach issues.
1. Contracts Without Capacity, Consent, or Jurisdiction NS Power has been permitted to "deem" contractual relationships into existence with residential customers under Board-approved Regulation 2.2. This allows an essential service to be d...
AI summary NS Power is allowed to create presumed contractual relationships with residential customers without signed agreements, visible terms, or clear jurisdictional authority, raising concerns about lawful contracting and consumer rights.
2. NSERBT Denial of Remedy Despite Structural Invalidity In Matter M11099, I formally contested these conditions. While the NSERBT acknowledged that the Regulations were not in plain sight and required multiple navigational steps to locate...
AI summary In Matter M11099, the NSERBT upheld a deemed contract despite acknowledging that the Regulations were not clearly visible and required multiple steps to locate. No signed agreement or record of informed digital acceptance was produced, and the Board's position treats passive access as lawful consent, contradicting Canadian legal standards of equity and consent.
3. Identity Breach as Confirmation of Administrative Failure I am in possession of an identity breach notification issued by NS Power to a customer whose relationship with the company is governed by the same presumed contract structure I c...
AI summary The text discusses an identity breach by NS Power, highlighting administrative failures in the contracting frameworks approved by NSERBT. It argues that these frameworks fail to protect residents and lack legal authority to handle sensitive personal information without valid contracts.
Demands for Structural Redress As the public authority responsible for overseeing the composition, mandate, and accountability of the NSERBT, I demand the following: - 1. A formal administrative review of the NSERBT's continued enforcement...
AI summary The document outlines demands for structural redress concerning the NSERBT's enforcement of Regulation 2.2, concerns about residents being subrogated into contracts with NS Power without informed consent, and the need for accountability in regulatory oversight. It also calls for a moratorium on rate increases until contractual relationships are based on lawful consent and a clear statement of ministerial responsibility.
Sent Via Email Premier Tim Houston Office of the NS Privacy Officer I am writing to formally complain about Nova Scotia Power's handling of its recent security breach. I am deeply concerned about both the theft of my personal information a...
AI summary The letter from the Premier Tim Houston Office of the NS Privacy Officer expresses concern over Nova Scotia Power's delayed and inadequate response to a security breach that occurred in March 2025, with notification only given in May 2025.
N-11NSPI (SBA) RIRs 1-20 - Redacted
2 passages
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to Small Business Advocate Information Requests 1 Request IR-01: 21 obligations and responsibilities of NS Power in connection therewith, including rega...
AI summary The document outlines the obligations and responsibilities of Nova Scotia Power (NS Power) in incident response, including communication with stakeholders, risk assessment, containment efforts, forensic investigations, and data analysis. Osler, as counsel, provided guidance and support in managing the Incident.
REDACTED 1 Request IR-20: 2 3 Refer to Compliance Letter to the Office of the Privacy Commissioner of Canada ("OPC") 4 dated March 18, 2026 (https://www.priv.gc.ca/en/opc-actions-and 5 decisions/investigations/investigations-into-businesse...
AI summary Nova Scotia Power (NSP) received communications from a threat actor claiming to have obtained sensitive customer information, but no evidence of public disclosure or sale has emerged. NSP did not pay a ransom. The incident was first identified on April 25, 2025, and an investigation confirmed likely impact to customer information by May 1, 2025.
N-13Evidence - InterGroup, on behalf of CA - Redacted
3 passages
This testimony has been prepared for the Consumer Advocate ("CA") by or under the direction of Ed Mollard of InterGroup Consultants Ltd. ("InterGroup"). This report reviews the Nova Scotia Power ("NSP", "NSPI", "NS Power") Cybersecurity In...
AI summary This testimony, prepared by Ed Mollard of InterGroup Consultants Ltd. for the Consumer Advocate, reviews a cybersecurity incident at Nova Scotia Power. Mollard outlines his qualifications, the scope of his review, and his commitment to providing fair and objective evidence to the Nova Scotia Energy Board.
2.0 SUMMARY OF RECOMMENDATIONS Based on the analysis summarized in this report, InterGroup makes the following recommendations to the Board: - Recommendation 1: InterGroup recommends NSPI be directed to update its staff training policies a...
AI summary InterGroup recommends several measures to NSP and NSPI, including updating staff training policies, enhancing privacy practices, conducting compliance audits, improving customer notifications, and managing credit monitoring services. These recommendations aim to improve cybersecurity, privacy, and customer communication following a data breach incident.
s Retention Schedule[31](#page-12-9) maintained by Emera but no further specific information was provided. InterGroup's review of NSP's customer data retention process indicates a number of concerns: - 1. Lack of transparency in NSP's inte...
AI summary The document highlights concerns about the lack of transparency in Nova Scotia Power's (NSP) customer data retention policies. NSP relies on its parent company Emera's records management standards, but no specific documentation was provided to support its 'Records Retention Schedule'. This lack of clarity raises concerns about how long customer data is retained.
N-14Evidence & Appendix A Resume - Tricia Ralph INQ Law/Consulting - BCC
3 passages
- o Personal information inventory, policies, risk assessment tools, training and education, breach and incident management response protocols, service provider management, and external communication. - 10. As set out in its non-confidenti...
AI summary The document discusses NSPI's privacy governance program, including its policies, procedures, and compliance with PIPEDA. It notes the presence of a Privacy Officer and Office, but highlights gaps in senior management oversight and the lack of a complete PI inventory, which raises concerns about the effectiveness of NSPI's privacy program.
open and transparent, best practice would be to identify that SINs were collected in the public facing Customer Privacy Policy . In my opinion, it was not best practice to omit this from the policy. - 68. In my opinion, aside from where ne...
AI summary The text argues that it was unreasonable for NSPI to collect SINs for customer authentication and identification, as it was unnecessary and not in line with best practices. It also criticizes NSPI's delayed and incomplete process to purge SINs from its systems, which left sensitive data vulnerable to exfiltration.
Reasonableness of length of Time PI was Retained - 76. As NSPI's record retention schedule was not provided, it is not possible for me to opine on whether the periods of time that NSPI established by information/record type were reasonable...
AI summary The review found that NSPI did not adhere to its own internal record retention standards for personal information, leading to unreasonable retention periods. This lack of compliance negatively impacted customer services by allowing threat actors to exfiltrate data that should have been deleted.
N-17NS Power Rebuttal Evidence - Redacted
7 passages
4.0 EVIDENCE OF INTERGROUP CONSULTANTS The InterGroup Evidence makes 13 recommendations focused on areas where NS Power's cybersecurity, privacy, communications, customer notification, billing contingency, and governance practices could be...
AI summary The InterGroup Evidence provides 13 recommendations to NS Power to improve cybersecurity, privacy, communication, and governance practices. NS Power agrees with the need for continuous improvement and highlights existing initiatives, noting that some recommendations align with OPC guidance. Specific emphasis is placed on updating staff training policies and addressing system access restrictions for non-compliance.
- To collect and process past due accounts; - To avoid and investigate fraud and/or identity theft; - To address and respond to issues related to the usage of critical power dependent medical equipment during an outage; - To offer personal...
AI summary NS Power outlines the purposes for collecting and processing customer information, including managing past due accounts, fraud prevention, responding to critical power needs, and meeting legal obligations. The company also explains that customer data may be retained even after the customer relationship ends and that customers may withdraw consent for data use, which could affect service provision.
5.0 EVIDENCE OF INQ LAW - NS Power acknowledges that the INQ Evidence may assist the Board in understanding privacy - concepts and generally accepted privacy practices. However, care must be taken in assessing Ms. - Ralph's conclusions reg...
AI summary NS Power acknowledges the INQ Evidence may help the Board understand privacy practices but argues that the Board's task is to assess the reasonableness of its actions as a regulated utility, not whether it complied with privacy law. The OPC is recognized as having expertise in privacy compliance.
Cybersecurity Accountability REDACTED In addition, as set out above, NSPI stated that factors affecting its ability to determine specificity were the nature of the impacted records and the structure of the data available. While I do not ha...
AI summary The document discusses NS Power's handling of customer notifications following a data breach, focusing on the specificity of information provided. It notes that while the customer notices were deemed insufficient by some, NS Power argued that it met industry standards and was compliant with PIPEDA, considering the complexity and scale of the breach.
7.0 NS POWER'S ENHANCED PRIVACY GOVERNANCE PROGRAM Beyond the circumstances of this Attack and the response to it, the Company recognizes that the privacy, cybersecurity, and related regulatory landscape is ever evolving with significant a...
AI summary NS Power is enhancing its privacy governance program in response to evolving regulatory and technological challenges, including Bill C-36 and the increasing use of AI. The company is strengthening its privacy framework, policies, and oversight mechanisms, with a dedicated Privacy Officer role being formalized and elevated in the organizational structure.
9 2.0 QUALIFICATIONS - 10 I am Co-Chair of Greenberg Traurig's U.S. Data Privacy and Cybersecurity Practice. Since 2012, - 11 I have advised clients on more than a thousand data security incidents, including ransomware, - 12 extortion, bus...
AI summary The individual is a Co-Chair of Greenberg Traurig's U.S. Data Privacy and Cybersecurity Practice, with extensive experience in data security incidents and breach response. They have advised on breach notification obligations, including Canadian requirements, and have reviewed findings from the Ralph Report and Mollard Report, noting areas of disagreement and overlooked considerations.
13 (d) Multi-Channel Public Notice Was a Relevant Mitigating Factor - 14 Ms. Ralph acknowledges at paragraph 45 of the Ralph Report that NS Power "actively shared this - 15 information with media, on social media, with stakeholders, throug...
AI summary The text discusses the relevance of multi-channel public notice as a mitigating factor in NS Power's cybersecurity incident, noting that NS Power utilized various communication methods. It also highlights that Ms. Ralph's analysis did not fully credit this effort and found the delay in notifying additional customers unreasonable.
100853NS Power's Monthly Update #2 (M12273)
2 passages
Additional Capabilities The Incident affected several enabling business systems, including energy trading platforms, performance and fuel data, asset management, and regulatory reporting tools. This required business units to adopt manual...
AI summary The Incident disrupted several critical systems, including energy trading, performance and fuel data, asset management, and regulatory reporting, forcing manual processes. Core trading functions have been restored, but performance and fuel data systems, along with asset management and document integrity functions, are still being re-established. NS Power expects some restoration to be completed by Q4 2025, with some work extending into 2026. Regulatory reporting continues using interim processes.
Recovery Program Office The RPO has continued to advance recovery activities across all major business and technology areas. The RPO was established following the incident response to coordinate recovery and restoration efforts across the...
AI summary The Recovery Program Office (RPO) was established to coordinate recovery and restoration efforts after an incident. It manages program delivery, regulatory and insurance obligations, resourcing, internal controls, cybersecurity, enterprise architecture, organizational change management, reporting, and data privacy across all major business and technology areas.
101524David MacLeod (NSPI) IR A-1 to G-5
5 passages
IR C-4 — Regulatory and Law Enforcement Notification - (a) Provide a complete timeline of NSP's notifications to regulatory and law enforcement - bodies following discovery of the Attack, including: - (i) notification to the NSEB / UARB; -...
AI summary The document requests a timeline of NSP's notifications to regulatory and law enforcement bodies after a cyberattack, identifies the legal obligations for each notification, and explains NSP's rationale for not making a ransom payment.
M12600 Nova Scotia Energy Board 1 (ii) the number of customers receiving estimated rather than actual bills in each month 2 from May 2025 to April 2026; 3 (iii) the total number of customers who may have been overcharged as a result of 4 e...
AI summary The document requests information on billing practices and the financial impact of a cyber attack on NSP, including the number of customers affected and the basis for cost recovery through regulated rates, given NSP's inadequate preparedness.
IR F-1 — NERC CIP Compliance - (a) Identify which, if any, of NSP's assets are classified as Bulk Electric System (BES) Cyber - Systems subject to mandatory NERC CIP standards. - (b) For each applicable NERC CIP standard (CIP-002 through C...
AI summary The document outlines a request for information regarding Nova Scotia Power's compliance with NERC CIP standards, specifically identifying which assets are classified as BES Cyber Systems and detailing NSP's compliance status, audit findings, and remediation actions as of March 18, 2025.
GROUP G — POST-INCIDENT REMEDIATION AND FORWARD COMMITMENTS - These Interrogatories address NSP's post-attack remediation program, the adequacy and pace - of that program, and NSP's forward commitments to prevent recurrence. They are relev...
AI summary This section addresses NSP's post-incident remediation efforts, their adequacy and pace, and forward commitments to prevent recurrence. It is relevant to the Board's evaluation of NSP's accountability and whether ratepayers should bear remediation costs.
IR G-3 — Attribution and Threat Actor Identification - (a) NSP's Monthly Update 6 (March 2026) and related reporting attributed the Attack to - "Russian threat actors." Provide all information available to NSP regarding the attribution - o...
AI summary The document requests Nova Scotia Power (NSP) to provide details on the attribution of a cyberattack, including the identity of the threat actor, methodology used, and whether the threat actor is subject to sanctions. It also asks how this knowledge has informed NSP's cybersecurity strategy.