Cyber Security Incident Reporting
This page provides an overview of the requirements for reporting cyber security incidents to the IESO as defined within the Ontario Cyber Security Standard (OCSS) and within section 6 of Market Manual 7.1 IESO Controlled grid Operating Procedures.
This page is not inclusive of all event and incident reporting requirements - other reporting requirements may apply during a cyber security incident.
Where a cyber security incident meets more than one set of reporting requirements it must be reported separately for each set. For example, a cyber security incident that meets the definition in the OCSS and which results in a market rule violation must be reported under both applicable reporting requirements.
Review the IESO Market Rules and Manuals, the OEB’s Ontario Cyber Security Standard, Transmission System Code, and Distribution System Code, and any other applicable rules, standards, or laws for reporting requirements.
Organizations are responsible for ensuring that they meet all applicable reporting requirements and obligations.