The Nova Scotia Energy Board is criticizing Nova Scotia Power for providing insufficient information in its first monthly report on the cyberattack that impacted hundreds of thousands of customers earlier this year. In an open letter to Nova Scotia Power, the energy board said the utility’s inaugural monthly report on the cyber incident was “underwhelming” and contained information that was already publicly available. “The Board would have expected more detail about the impact of the cybersecurity incident on its business systems and how it is affecting customers, interested parties and any ongoing regulatory matters before the Board,” the letter reads. The energy board is conducting a full investigation into the cyberattack that happened last March and it has also ordered Nova Scotia Power to file monthly updates on new information gleaned from the incident. Additionally, the board has asked Nova Scotia Power to submit a full report on the cyberattack by the end of the year. The first monthly report was due Aug. 1, but the power utility requested and received an extension. They ultimately filed the report on Aug. 20. The board notes it has received information about the cyberattack in a “haphazard manner” through filings on different matters. “There appears to be no coordinated communication of these impacts to interested parties (and to the Board), and they are only advised on an ad hoc basis as these matters arise,” the letter reads. “These impacts from the cybersecurity incident affect many customers and how interested parties interact with the Company. The Board would have expected these various impacts to be collected in a combined reporting and included in NS Power’s Monthly Update.” The next monthly report is due Oct. 1. Additional information Separate from the monthly reports, the board filed information requests regarding frequently raised concerns and questions from customers on July 24. The report, which was submitted in early September, said all customers may have been impacted by the cyberattack. Nova Scotia Power previously said it had notified roughly 277,000 customers they had been affected by the breach. Timeline On April 25, Nova Scotia Power said it found certain applications on its systems were not functional. Following an investigation, they learned a “threat actor” had gained unauthorized access to parts of their network on or around March 19. The utility informed customers about the incident in May. They determined some of the stolen information – including birth dates, social insurance numbers and bank account information – was published on the dark web. The utility has said it will delete all customers’ social insurance numbers from its files. It is also offering a free, five-year credit monitoring service through TransUnion for impacted customers. Separate from the energy board investigation, the Office of the Privacy Commissioner of Canada launched an investigation into the cyberattack on May 28. For more Nova Scotia news, visit our dedicated provincial page