Regulator rebukes Nova Scotia Power’s request for secrecy in cybersecurity inquiry

Windwhistler
7 Min Read
Regulator rebukes Nova Scotia Power’s request for secrecy in cybersecurity inquiry

Nova ScotiaNova Scotia Power wants special rules and blanket secrecy during an inquiry into its cybersecurity breach, but the board in charge of the process is not keen on the proposal.Utility wants all information to be kept confidential while energy board investigatesTaryn Grant · CBC News · Posted: Aug 14, 2025 5:00 AM EDT | Last Updated: August 14Regulator blasts N.S. Power’s request for secrecy at cyberattack probeNova Scotia Power has asked for some concessions in an inquiry looking at a ransomware attack that affected hundreds of thousands of customers, but the board isn’t keen on the utility’s proposal. Taryn Grant has the story.Nova Scotia Power wants special rules and blanket secrecy during an inquiry into its massive cybersecurity breach earlier this year, but the board in charge of the process is not keen on the proposal.In a public letter submitted last week, Nova Scotia Power asked the Nova Scotia Energy Board, which is conducting the inquiry, to set aside its usual procedures and adopt those of a privacy regulator, and to keep all submissions confidential for at least the duration of the process.In a response letter this week, the energy board said the request for sweeping confidentiality concessions was “not acceptable or appropriate,” and that it is “unclear” why the procedures used by privacy regulators are relevant.The board highlighted that it follows an open courts principle and said it intends to conduct the inquiry “as publicly and transparently as possible.””It appears that NS Power believes it is entitled to unilaterally designate information it may file as ‘Board Confidential’ and expects that this claimed status will be accepted without review or question,” board clerk Crystal Henwood wrote.She said that is not the way the inquiry will be conducted.Secrecy requires justification, board saysHenwood noted that some information to be submitted over the course of the inquiry may be “quite sensitive” and could warrant confidentiality, but added the utility will have to justify this in each instance.In the case of one recent letter, for which the utility requested confidentiality, the board said it needed a detailed and specific justification “for each and every paragraph.”WATCH| Nova Scotia Power leadership grilled by legislators:Politicians put Nova Scotia Power execs in the hot seatThe utility’s CEO and other staff were grilled by the public accounts committee about the cybersecurity breach that gave access to data belonging to 280,000 customers. Michael Gorman has the story.Nova Scotia Power’s cybersecurity breach began in March, when thieves accessed personal information for hundreds of thousands of customers from the utility’s networks and servers. The utility has said it did not know about the breach until more than a month later, at which point it notified the public.The energy board notified the utility in mid-May that it would conduct an inquiry into the matter, noting it wanted to ensure “regulatory oversight and accountability.”Since then, several third parties have applied to participate as interveners in the case, including the provincial Department of Energy, the non-profit group EfficiencyOne, a consortium of some of the province’s biggest industrial businesses, a small business advocate and a consumer advocate.Many of those groups are regular interveners in Nova Scotia Power matters that go before the board, giving them the opportunity to comment and question throughout the hearing process.Nova Scotia Power seeks to exclude intervenersIn last week’s letter, a lawyer representing Nova Scotia Power asked that no one but the board and the utility be allowed to participate. In other words, he asked that interveners be excluded.Adam Kardash — who, according to his law firm’s website, specializes in privacy and data management for businesses — said allowing third parties to participate would make the process too “adversarial.” He noted that privacy investigations do not allow third parties to intervene.The board said little by way of response to this proposal, except to note that several parties have already intervened.Nova Scotia Power has informed more than half of its current customers, about 280,000 people, that their personal information may have been compromised in the attack. An undisclosed number of former customers have been impacted, too. (Dylan Jones/CBC)Kardash wrote that the company’s justification for special rules and secret submissions could not be made publicly, and referred to a “Confidential Submission” for details.The board countered that it wasn’t clear why the confidential submission could not have been publicly disclosed.”Much of the information appears to have already been publicly disclosed, is broad or general in nature, or simply states a position rather than disclose anything that appears particularly sensitive,” Henwood said.Henwood asked for justification for keeping the submission confidential.Kardash asked that all submissions be kept secret until the board’s final report on the inquiry.Additionally, he asked that the board give Nova Scotia Power a draft of its final report before publication to comment on “factual accuracy, the confidentiality of any commercial information, and the Board’s legal conclusions.” Again, he noted this is how privacy investigations usually proceed.Henwood highlighted that the energy board is not a privacy regulator, and said Nova Scotia Power seemed to “not sufficiently recognize” that the board’s processes are based on an “open courts” principle.ABOUT THE AUTHORTaryn Grant covers daily news for CBC Nova Scotia, with a particular interest in housing and homelessness, education, and health care. You can email her with tips and feedback at taryn.grant@cbc.ca

Share This Article
x  Powerful Protection for WordPress, from Shield Security
This Site Is Protected By
Shield Security