Nova Scotia Power says it cannot explain why some customer data that was accessed in a cyberattack was not deleted according to the company’s stated processes. At a regulatory hearing, executive Blake Williams testifies that the utility has mechanisms designed to automatically delete certain data, with deletion cycles of no more than 90 days.
The regulatory testimony focuses on a gap between those safeguards and what happened after the breach. Both outlets report the company is unable to give a clear reason for the failure of the deletion plan for the affected customer information. The reporting centers on the company’s limitations in explaining whether the automatic deletion controls did not function as intended, were not applied to the relevant data, or were otherwise interrupted.
While the sources agree on the core point—that Nova Scotia Power cannot currently account for why the data was not deleted as planned—they describe the issue through the lens of the company’s regulatory explanations and the scrutiny of oversight mechanisms after the hack.