Topic/Matter Intersection

Topic:"Regulatory Compliance" in M12600

Matter: Nova Scotia Power - Cybersecurity Accountability IN THE MATTER OF AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED’s collection and retention of customer information, customer service and communications, billing processes and regulatory matters
48 passages 22 documents

Regulatory Compliance across all matters →

N-1LOCs Redacted (N-1 from M12273) 7 passages
Preamble p. p. 6
From: Painting-MacLean, Kimberly To: Painting-MacLean, Kimberly Subject: M12273 Administrative Demand for Structural Redress – NSUARB Oversight Failure and NS Power Identity Breach Date: May 23, 2025 10:11:33 AM Attachments: Administrative...

AI summary An administrative demand for structural redress has been filed regarding NSUARB oversight failure and an NS Power identity breach. The demand is related to unlawful contracting structures enabled by NSERBT oversight failures, citing previous decisions and responses from NSERBT.

\ \ EXTERNAL EMAIL / COURRIEL EXTERNE \ \ p. pp. 6-36
\ \ EXTERNAL EMAIL / COURRIEL EXTERNE \ \ Exercise caution when opening attachments or clicking on links / Faites preuve de prudence si vous ouvrez une pièce jointe ou cliquez sur un lien To: Michael Savage acting as Chief Executive Office...

AI summary This email requests formal review and structural accountability from Nova Scotia's executive leadership regarding governance failures by the Nova Scotia Energy and Regulatory Boards Tribunal (NSERBT) and Nova Scotia Power's (NS Power) use of unconscionable contracting mechanisms. It highlights concerns about unlawful contract formation and identity breach issues.

1. Contracts Without Capacity, Consent, or Jurisdiction p. p. 6
1. Contracts Without Capacity, Consent, or Jurisdiction NS Power has been permitted to "deem" contractual relationships into existence with residential customers under Board-approved Regulation 2.2. This allows an essential service to be d...

AI summary NS Power is allowed to create presumed contractual relationships with residential customers without signed agreements, visible terms, or clear jurisdictional authority, raising concerns about lawful contracting and consumer rights.

2. NSERBT Denial of Remedy Despite Structural Invalidity p. p. 6
2. NSERBT Denial of Remedy Despite Structural Invalidity In Matter M11099, I formally contested these conditions. While the NSERBT acknowledged that the Regulations were not in plain sight and required multiple navigational steps to locate...

AI summary In Matter M11099, the NSERBT upheld a deemed contract despite acknowledging that the Regulations were not clearly visible and required multiple steps to locate. No signed agreement or record of informed digital acceptance was produced, and the Board's position treats passive access as lawful consent, contradicting Canadian legal standards of equity and consent.

3. Identity Breach as Confirmation of Administrative Failure p. p. 6
3. Identity Breach as Confirmation of Administrative Failure I am in possession of an identity breach notification issued by NS Power to a customer whose relationship with the company is governed by the same presumed contract structure I c...

AI summary The text discusses an identity breach by NS Power, highlighting administrative failures in the contracting frameworks approved by NSERBT. It argues that these frameworks fail to protect residents and lack legal authority to handle sensitive personal information without valid contracts.

Demands for Structural Redress p. p. 6
Demands for Structural Redress As the public authority responsible for overseeing the composition, mandate, and accountability of the NSERBT, I demand the following: - 1. A formal administrative review of the NSERBT's continued enforcement...

AI summary The document outlines demands for structural redress concerning the NSERBT's enforcement of Regulation 2.2, concerns about residents being subrogated into contracts with NS Power without informed consent, and the need for accountability in regulatory oversight. It also calls for a moratorium on rate increases until contractual relationships are based on lawful consent and a clear statement of ministerial responsibility.

Sent Via Email p. p. 8
Sent Via Email Premier Tim Houston Office of the NS Privacy Officer I am writing to formally complain about Nova Scotia Power's handling of its recent security breach. I am deeply concerned about both the theft of my personal information a...

AI summary The letter from the Premier Tim Houston Office of the NS Privacy Officer expresses concern over Nova Scotia Power's delayed and inadequate response to a security breach that occurred in March 2025, with notification only given in May 2025.

N-3Incident Report - Redacted (N-3 from M12273) 1 passage
2025 Nova Scotia Power's Cybersecurity Incident Report REDACTED p. pp. 14-36
2025 Nova Scotia Power's Cybersecurity Incident Report REDACTED 1 Existing Safeguards 2 3 At the time of the Incident, NS Power had implemented a common set of cybersecurity standards 4 and policies that are informed, in part, by the Natio...

AI summary This document outlines Nova Scotia Power's cybersecurity safeguards, including alignment with NIST's Cybersecurity Framework and compliance with NERC standards. It highlights the company's continuous improvements and recent two-year update to its cybersecurity practices to ensure alignment with current policies and anticipated changes.

N-6NSPI (CA) RIR 1-11 - Redacted 1 passage
Section 16
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to Consumer Advocate Information Requests

AI summary The Minister of Energy is seeking accountability from Nova Scotia Power Inc. (NSPI) regarding responses to information requests from the Consumer Advocate. This proceeding involves NSPI's compliance with information disclosure requirements and transparency in its operations.

N-7NSPI (David MacLeod) RIRs C-4 to E-2 1 passage
1 Request IR C-4: p. p. 3
1 Request IR C-4: 2 3 (a) Provide a complete timeline of NSP's notifications to regulatory and law 4 enforcement bodies following discovery of the Attack, including: 5 6 (i) notification to the NSEB / UARB; 7 8 (ii) notification to the Off...

AI summary The document requests a timeline of NSP's notifications to regulatory and law enforcement bodies following a cyber attack, and details on NSP's data inventory and retention practices. NSP responded by referencing sections of the Incident Report and existing information requests for data inventory details.

N-11NSPI (SBA) RIRs 1-20 - Redacted 2 passages
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to Small Business Advocate Information Requests
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to Small Business Advocate Information Requests 1 Request IR-01: 21 obligations and responsibilities of NS Power in connection therewith, including rega...

AI summary The document outlines the obligations and responsibilities of Nova Scotia Power (NS Power) in incident response, including communication with stakeholders, risk assessment, containment efforts, forensic investigations, and data analysis. Osler, as counsel, provided guidance and support in managing the Incident.

REDACTED
REDACTED 1 Request IR-20: 2 3 Refer to Compliance Letter to the Office of the Privacy Commissioner of Canada ("OPC") 4 dated March 18, 2026 (https://www.priv.gc.ca/en/opc-actions-and 5 decisions/investigations/investigations-into-businesse...

AI summary Nova Scotia Power (NSP) received communications from a threat actor claiming to have obtained sensitive customer information, but no evidence of public disclosure or sale has emerged. NSP did not pay a ransom. The incident was first identified on April 25, 2025, and an investigation confirmed likely impact to customer information by May 1, 2025.

N-13Evidence - InterGroup, on behalf of CA - Redacted 3 passages
Preamble p. p. 2
This testimony has been prepared for the Consumer Advocate ("CA") by or under the direction of Ed Mollard of InterGroup Consultants Ltd. ("InterGroup"). This report reviews the Nova Scotia Power ("NSP", "NSPI", "NS Power") Cybersecurity In...

AI summary This testimony, prepared by Ed Mollard of InterGroup Consultants Ltd. for the Consumer Advocate, reviews a cybersecurity incident at Nova Scotia Power. Mollard outlines his qualifications, the scope of his review, and his commitment to providing fair and objective evidence to the Nova Scotia Energy Board.

2.0 SUMMARY OF RECOMMENDATIONS p. pp. 2-3
2.0 SUMMARY OF RECOMMENDATIONS Based on the analysis summarized in this report, InterGroup makes the following recommendations to the Board: - Recommendation 1: InterGroup recommends NSPI be directed to update its staff training policies a...

AI summary InterGroup recommends several measures to NSP and NSPI, including updating staff training policies, enhancing privacy practices, conducting compliance audits, improving customer notifications, and managing credit monitoring services. These recommendations aim to improve cybersecurity, privacy, and customer communication following a data breach incident.

5.2 FORMER CUSTOMER DATA p. pp. 12-14
s Retention Schedule[31](#page-12-9) maintained by Emera but no further specific information was provided. InterGroup's review of NSP's customer data retention process indicates a number of concerns: - 1. Lack of transparency in NSP's inte...

AI summary The document highlights concerns about the lack of transparency in Nova Scotia Power's (NSP) customer data retention policies. NSP relies on its parent company Emera's records management standards, but no specific documentation was provided to support its 'Records Retention Schedule'. This lack of clarity raises concerns about how long customer data is retained.

N-14Evidence & Appendix A Resume - Tricia Ralph INQ Law/Consulting - BCC 3 passages
Privacy Governance Program p. p. 4
- o Personal information inventory, policies, risk assessment tools, training and education, breach and incident management response protocols, service provider management, and external communication. - 10. As set out in its non-confidenti...

AI summary The document discusses NSPI's privacy governance program, including its policies, procedures, and compliance with PIPEDA. It notes the presence of a Privacy Officer and Office, but highlights gaps in senior management oversight and the lack of a complete PI inventory, which raises concerns about the effectiveness of NSPI's privacy program.

Reasonableness of Type of PI Collected p. p. 14
open and transparent, best practice would be to identify that SINs were collected in the public facing Customer Privacy Policy . In my opinion, it was not best practice to omit this from the policy. - 68. In my opinion, aside from where ne...

AI summary The text argues that it was unreasonable for NSPI to collect SINs for customer authentication and identification, as it was unnecessary and not in line with best practices. It also criticizes NSPI's delayed and incomplete process to purge SINs from its systems, which left sensitive data vulnerable to exfiltration.

Reasonableness of length of Time PI was Retained p. p. 17
Reasonableness of length of Time PI was Retained - 76. As NSPI's record retention schedule was not provided, it is not possible for me to opine on whether the periods of time that NSPI established by information/record type were reasonable...

AI summary The review found that NSPI did not adhere to its own internal record retention standards for personal information, leading to unreasonable retention periods. This lack of compliance negatively impacted customer services by allowing threat actors to exfiltrate data that should have been deleted.

N-15INQ Law/Consulting (CA) RIRs 1-4 1 passage
2 3 NOVA SCOTIA ENERGY BOARD 4 5 6 IN THE MATTER OF: The Public Utilities Act 7 8 – and – 9 10 IN THE MATTER OF: AN INQUIRY about the impact of the cyber in
2 3 NOVA SCOTIA ENERGY BOARD 4 5 6 IN THE MATTER OF: The Public Utilities Act 7 8 – and – 9 10 IN THE MATTER OF: AN INQUIRY about the impact of the cyber incident on NOVA 11 SCOTIA POWER INCORPORATED's collection and retention 12 of custom...

AI summary This document outlines an inquiry by the Nova Scotia Energy Board regarding the impact of a cyber incident on Nova Scotia Power Incorporated's data handling practices, customer service, billing processes, and regulatory compliance. The inquiry was initiated under the Public Utilities Act, with responses due by July 29, 2026.

N-16NSPI Refiled Formal Incident Report - Redacted (filed in M12273 as N-5 on April 27, 2026) 2 passages
A. Clarification of the Procedural Order Sought
onovan , 2021 SCC 25, at para 38. Page 2 process it will adopt for this matter. Excerpts of sample statutory provisions under Canadian and foreign privacy legislation are attached as Appendix A. At the same time, NS Power expects that the...

AI summary NS Power requests the Board to carefully review confidentiality claims during the Inquiry and provide an opportunity to explain the necessity of keeping certain information confidential, including potentially through an oral hearing with cybersecurity experts. NS Power also acknowledges the Board's need to consult with advisors and expects external advisors to sign confidentiality agreements before receiving sensitive data.

Unofficial Translation
Unofficial Translation Art II The commission's agents are bound to secrecy with regard to facts, acts or information of which they may have become aware by reason of their functions, under penalty of the sanctions provided for in Article 4...

AI summary This section outlines the confidentiality obligations of the commission's agents, requiring them to maintain secrecy regarding information obtained through their functions, with penalties under the Penal Code. It also mentions the exception for information necessary for the annual report.

N-17NS Power Rebuttal Evidence - Redacted 7 passages
4.0 EVIDENCE OF INTERGROUP CONSULTANTS p. pp. 9-20
4.0 EVIDENCE OF INTERGROUP CONSULTANTS The InterGroup Evidence makes 13 recommendations focused on areas where NS Power's cybersecurity, privacy, communications, customer notification, billing contingency, and governance practices could be...

AI summary The InterGroup Evidence provides 13 recommendations to NS Power to improve cybersecurity, privacy, communication, and governance practices. NS Power agrees with the need for continuous improvement and highlights existing initiatives, noting that some recommendations align with OPC guidance. Specific emphasis is placed on updating staff training policies and addressing system access restrictions for non-compliance.

Section 33 p. pp. 23-24
- To collect and process past due accounts; - To avoid and investigate fraud and/or identity theft; - To address and respond to issues related to the usage of critical power dependent medical equipment during an outage; - To offer personal...

AI summary NS Power outlines the purposes for collecting and processing customer information, including managing past due accounts, fraud prevention, responding to critical power needs, and meeting legal obligations. The company also explains that customer data may be retained even after the customer relationship ends and that customers may withdraw consent for data use, which could affect service provision.

5.0 EVIDENCE OF INQ LAW p. pp. 38-41
5.0 EVIDENCE OF INQ LAW - NS Power acknowledges that the INQ Evidence may assist the Board in understanding privacy - concepts and generally accepted privacy practices. However, care must be taken in assessing Ms. - Ralph's conclusions reg...

AI summary NS Power acknowledges the INQ Evidence may help the Board understand privacy practices but argues that the Board's task is to assess the reasonableness of its actions as a regulated utility, not whether it complied with privacy law. The OPC is recognized as having expertise in privacy compliance.

Cybersecurity Accountability REDACTED p. pp. 48-50
Cybersecurity Accountability REDACTED In addition, as set out above, NSPI stated that factors affecting its ability to determine specificity were the nature of the impacted records and the structure of the data available. While I do not ha...

AI summary The document discusses NS Power's handling of customer notifications following a data breach, focusing on the specificity of information provided. It notes that while the customer notices were deemed insufficient by some, NS Power argued that it met industry standards and was compliant with PIPEDA, considering the complexity and scale of the breach.

7.0 NS POWER'S ENHANCED PRIVACY GOVERNANCE PROGRAM p. pp. 57-59
7.0 NS POWER'S ENHANCED PRIVACY GOVERNANCE PROGRAM Beyond the circumstances of this Attack and the response to it, the Company recognizes that the privacy, cybersecurity, and related regulatory landscape is ever evolving with significant a...

AI summary NS Power is enhancing its privacy governance program in response to evolving regulatory and technological challenges, including Bill C-36 and the increasing use of AI. The company is strengthening its privacy framework, policies, and oversight mechanisms, with a dedicated Privacy Officer role being formalized and elevated in the organizational structure.

9 2.0 QUALIFICATIONS p. p. 67
9 2.0 QUALIFICATIONS - 10 I am Co-Chair of Greenberg Traurig's U.S. Data Privacy and Cybersecurity Practice. Since 2012, - 11 I have advised clients on more than a thousand data security incidents, including ransomware, - 12 extortion, bus...

AI summary The individual is a Co-Chair of Greenberg Traurig's U.S. Data Privacy and Cybersecurity Practice, with extensive experience in data security incidents and breach response. They have advised on breach notification obligations, including Canadian requirements, and have reviewed findings from the Ralph Report and Mollard Report, noting areas of disagreement and overlooked considerations.

13 (d) Multi-Channel Public Notice Was a Relevant Mitigating Factor p. pp. 72-76
13 (d) Multi-Channel Public Notice Was a Relevant Mitigating Factor - 14 Ms. Ralph acknowledges at paragraph 45 of the Ralph Report that NS Power "actively shared this - 15 information with media, on social media, with stakeholders, throug...

AI summary The text discusses the relevance of multi-channel public notice as a mitigating factor in NS Power's cybersecurity incident, noting that NS Power utilized various communication methods. It also highlights that Ms. Ralph's analysis did not fully credit this effort and found the delay in notifying additional customers unreasonable.

N-23M12835 Exhibit N-2 Att 3 2025 Managements Discussion AnalysisHIGHLIGHTED 2 passages
Environmental Legislation and Climate Change
Environmental Legislation and Climate Change NSPI is subject to environmental laws and regulations as set by both the Government of Canada and the Nova Scotia Provincial Government (the "Province"). NSPI continues to work with both levels...

AI summary NSPI is subject to environmental laws from both the Canadian and Nova Scotia governments. It aims to comply with these regulations while minimizing costs to customers. NSPI expects to recover prudently incurred compliance costs through its regulatory framework but faces risks related to non-compliance with climate and environmental legislation.

Regulatory and Political Risk
Regulatory and Political Risk NSPI is subject to complex legislative and regulatory frameworks that cover material aspects of their businesses. These frameworks influence key factors such as rates and cost structures, revenue requirements,...

AI summary NSPI operates under a complex regulatory framework that influences rates, revenue, and capital investments. Regulatory delays, disallowance of costs, or changes in policy could lead to Material Adverse Effects. The IESO Nova Scotia's operational status remains uncertain, and changes in environmental legislation may further impact regulatory stability.

N-24Undertaking Responses - NS Power - Redacted 1 passage
Q: Who/What is responsible for the incident?
Q: Who/What is responsible for the incident? Our IT team is actively working with external cybersecurity experts to investigate this incident. We have also notified law enforcement and regulatory authorities. We cannot speculate or share u...

AI summary The incident is under investigation by the IT team in collaboration with external cybersecurity experts. Law enforcement and regulatory authorities have been notified. No unverified information is being shared during the ongoing investigation.

102158Board Decision Letter - Request for Pre-Approval of Intervener Costs 1 passage
Section 4 p. p. 0
siderable experience dealing with virtual and hybrid proceedings. This experience has demonstrated that virtual processes can facilitate access and participation in Board proceedings and reduce costs. The Board is not satisfied that you ha...

AI summary The Board emphasizes that virtual processes in regulatory proceedings are effective, reduce costs, and do not compromise procedural rights. It notes that virtual cross-examination is routine and that electronic document management is standard. The Board also acknowledges potential technological issues but has processes in place to address them and offers platform demonstrations.

100853NS Power's Monthly Update #2 (M12273) 2 passages
Additional Capabilities p. p. 0
Additional Capabilities The Incident affected several enabling business systems, including energy trading platforms, performance and fuel data, asset management, and regulatory reporting tools. This required business units to adopt manual...

AI summary The Incident disrupted several critical systems, including energy trading, performance and fuel data, asset management, and regulatory reporting, forcing manual processes. Core trading functions have been restored, but performance and fuel data systems, along with asset management and document integrity functions, are still being re-established. NS Power expects some restoration to be completed by Q4 2025, with some work extending into 2026. Regulatory reporting continues using interim processes.

Recovery Program Office p. p. 0
Recovery Program Office The RPO has continued to advance recovery activities across all major business and technology areas. The RPO was established following the incident response to coordinate recovery and restoration efforts across the...

AI summary The Recovery Program Office (RPO) was established to coordinate recovery and restoration efforts after an incident. It manages program delivery, regulatory and insurance obligations, resourcing, internal controls, cybersecurity, enterprise architecture, organizational change management, reporting, and data privacy across all major business and technology areas.

101156NSPI Monthly Update Report #6 (M12273) 2 passages
Recovery Timeline p. p. 0
Recovery Timeline Recovery activities remain ongoing and are expected to continue through 2026. Current priorities include restoring systems to perform reliably under normal operating conditions, strengthening disaster recovery and resilie...

AI summary Recovery activities are ongoing and will continue through 2026, focusing on restoring system reliability, enhancing disaster resilience, and managing interdependencies and resource constraints. NS Power is committed to providing monthly updates on progress.

Update on OPC Investigation p. p. 0
Update on OPC Investigation As noted in previous reports, the Office of the Privacy Commissioner of Canada (OPC) initiated an investigation into the Incident. The Company continues to fully cooperate with the OPC and remains committed to a...

AI summary The Office of the Privacy Commissioner of Canada (OPC) has initiated an investigation into an incident, and the Company is cooperating fully with the OPC to address concerns and resolve the investigation efficiently.

101524David MacLeod (NSPI) IR A-1 to G-5 5 passages
IR C-4 — Regulatory and Law Enforcement Notification
IR C-4 — Regulatory and Law Enforcement Notification - (a) Provide a complete timeline of NSP's notifications to regulatory and law enforcement - bodies following discovery of the Attack, including: - (i) notification to the NSEB / UARB; -...

AI summary The document requests a timeline of NSP's notifications to regulatory and law enforcement bodies after a cyberattack, identifies the legal obligations for each notification, and explains NSP's rationale for not making a ransom payment.

M12600
M12600 Nova Scotia Energy Board 1 (ii) the number of customers receiving estimated rather than actual bills in each month 2 from May 2025 to April 2026; 3 (iii) the total number of customers who may have been overcharged as a result of 4 e...

AI summary The document requests information on billing practices and the financial impact of a cyber attack on NSP, including the number of customers affected and the basis for cost recovery through regulated rates, given NSP's inadequate preparedness.

IR F-1 — NERC CIP Compliance
IR F-1 — NERC CIP Compliance - (a) Identify which, if any, of NSP's assets are classified as Bulk Electric System (BES) Cyber - Systems subject to mandatory NERC CIP standards. - (b) For each applicable NERC CIP standard (CIP-002 through C...

AI summary The document outlines a request for information regarding Nova Scotia Power's compliance with NERC CIP standards, specifically identifying which assets are classified as BES Cyber Systems and detailing NSP's compliance status, audit findings, and remediation actions as of March 18, 2025.

GROUP G — POST-INCIDENT REMEDIATION AND FORWARD COMMITMENTS
GROUP G — POST-INCIDENT REMEDIATION AND FORWARD COMMITMENTS - These Interrogatories address NSP's post-attack remediation program, the adequacy and pace - of that program, and NSP's forward commitments to prevent recurrence. They are relev...

AI summary This section addresses NSP's post-incident remediation efforts, their adequacy and pace, and forward commitments to prevent recurrence. It is relevant to the Board's evaluation of NSP's accountability and whether ratepayers should bear remediation costs.

IR G-3 — Attribution and Threat Actor Identification
IR G-3 — Attribution and Threat Actor Identification - (a) NSP's Monthly Update 6 (March 2026) and related reporting attributed the Attack to - "Russian threat actors." Provide all information available to NSP regarding the attribution - o...

AI summary The document requests Nova Scotia Power (NSP) to provide details on the attribution of a cyberattack, including the identity of the threat actor, methodology used, and whether the threat actor is subject to sanctions. It also asks how this knowledge has informed NSP's cybersecurity strategy.

101623NSPI Monthly Update Report #7 (M12273) 1 passage
Customer SIN Deletion p. p. 0
Customer SIN Deletion In the Compliance Letter, NS Power committed to the OPC that by March 31, 2026, NS Power would initiate a process to identify and remove instances of customer social insurance numbers (SINs) contained within its syste...

AI summary NS Power committed to the OPC to delete customer SINs by March 31, 2026, except for those required by law. The process was completed on March 27, 2026, with Legally Required SINs segregated and protected for lawful use only.

101930Confidential Undertaking 1 passage
Section 7
laws and procedures but under seal and designated confidential. - 9. (a) Unless otherwise precluded by law, within 30 days after the Board has reached a final decision in this proceeding, each person to whom Designated Confidential Informa...

AI summary The text outlines procedures for returning and handling Designated Confidential Information following a final decision by the Board. It specifies that recipients must return or destroy such information, with exceptions for members of the Nova Scotia Barrister's Society who may retain it for client-related purposes. The use of this information is restricted to regulatory proceedings involving NS Power.

101989Letter David MacLeod re: Request for Pre-Approved Intervenor Cost - Cost Rules 1 passage
Fit with sections 7 to 15 of the Costs Rules
Fit with sections 7 to 15 of the Costs Rules Although I appear as an individual, my situation and participation align with the considerations the Board applies to non-profit intervenors under sections 7 to 15: - a. I represent a specific p...

AI summary The individual argues that their participation in the proceeding aligns with the considerations for non-profit intervenors under sections 7 to 15 of the Costs Rules, citing their representation of public interest, limited financial resources, and intent to participate responsibly and only seek reasonable costs.

102111Reply Comments - David MacLeod 1 passage
C. NSP's Argument lmproperlv Narrows the Scope of the Proceeding p. p. 0
C. NSP's Argument lmproperlv Narrows the Scope of the Proceeding NSP's argument appears to rest on an improperly narrow construction of the proceeding's scope. If followed, it would limit the Board's inquiry to technical compliance with mi...

AI summary NSP's argument is criticized for narrowly defining the proceeding's scope, which would limit the Board's inquiry to technical compliance rather than a holistic assessment of NSP's cybersecurity posture. This approach is deemed inconsistent with the Board's mandate and the public interest in ensuring reasonable cybersecurity practices.

20260818-1Hearing Transcript — 08/18/2026 (Chris Lanteigne, Lia MacDonald, Glen MacLeod, Blake Williams) 1 passage
NOVA SCOTIA ENERGY BOARD
NOVA SCOTIA ENERGY BOARD IN THE MATTER OF: THE PUBLIC UTILITIES ACT - and - IN THE MATTER OF: AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer information, customer...

AI summary The Nova Scotia Energy Board is conducting an inquiry under the Public Utilities Act regarding the impact of a cyber incident on Nova Scotia Power Incorporated's handling of customer information, customer service, billing processes, and regulatory matters.

20260820-1Hearing Transcript — 08/20/2026 (Jena Valdetero, Ed Mollard, Tricia Ralph) 2 passages
NOVA SCOTIA ENERGY BOARD
NOVA SCOTIA ENERGY BOARD IN THE MATTER OF: THE PUBLIC UTILITIES ACT - and - IN THE MATTER OF: AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer information, customer...

AI summary The Nova Scotia Energy Board is conducting an inquiry under the Public Utilities Act regarding the impact of a cyber incident on Nova Scotia Power Incorporated's handling of customer information, customer service, billing processes, and regulatory matters.

1 Anyone else have any comments they 2 want to make? 3 Mr. Roberts? 4 ROBERTS: Yes, thank you. MR. 5 I also agree with Mr. Mahody's 6 summary. And I think part of the concern in these very 7 preliminary discussions that we were having, is...

AI summary The discussion focuses on procedural considerations regarding the Board's handling of submissions and potential delays in setting dates, with concerns about the interplay between this proceeding and others. There is a suggestion to address substantive issues in phases and potentially revisit remedies in a later appearance.

Disclaimer: These summaries were generated by AI from the filings they describe. We take care to make them accurate, but errors are possible - and they aren't advice. Only the filings themselves are the record: if you're relying on something here, confirm it against the source documents or the Nova Scotia Energy Board's own record. Full disclaimer →