IESO · Vulnerability Disclosure

Ieso Vulnerability Disclosure

Vulnerability disclosure

IESO runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

EnergyCanadaElectricityEnergy MarketsGridSystem OperatorMarket DataOpen DataOntarioDemand ResponseRenewables
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
{"email" => "CyberIncidentReports@ieso.ca", "purpose" => "Ontario Cyber Security Standard (OCSS) incident reports, and voluntary reporting. Also submittable through the Lighthouse portal."}
Contact
{"email" => "cybersecurity@ieso.ca", "purpose" => "Program access, including participation in the Lighthouse portal."}
Contact
{"email" => "scs@ieso.ca", "purpose" => "IESO Market Manual incident reporting follow-up. Participants must first phone the IESO Shift Control Specialist at 905-855-6200 within 60 minutes, then email."}
Contact
{"phone" => "905-855-6200", "purpose" => "IESO Shift Control Specialist — 60-minute telephone reporting window for Market Manual incidents."}

Source

Vulnerability Disclosure

ieso-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-27'
method: searched
probe: true
source: >-
  probe-security-programs.py (no hit) plus targeted search of ieso.ca on 2026-07-27
has_vdp: false
has_bug_bounty: false
note: >-
  IESO publishes no responsible-disclosure or coordinated vulnerability disclosure policy for its own
  web properties and APIs, no security.txt, and no bug bounty on HackerOne, Bugcrowd or Intigriti.
  What it does publish — and this is genuinely IESO's security reporting channel — is a Cyber Security
  Incident Reporting program with named, monitored contact addresses, operated in its role as the
  Ontario sector's cyber security reporting authority. Recorded here honestly as what it is: a sector
  incident-reporting obligation, not a researcher-facing VDP.
policy: []
security_page: https://www.ieso.ca/Sector-Participants/Cyber-Security/Cyber-Security-Incident-Reporting
contact:
- email: CyberIncidentReports@ieso.ca
  purpose: >-
    Ontario Cyber Security Standard (OCSS) incident reports, and voluntary reporting. Also submittable
    through the Lighthouse portal.
- email: cybersecurity@ieso.ca
  purpose: Program access, including participation in the Lighthouse portal.
- email: scs@ieso.ca
  purpose: >-
    IESO Market Manual incident reporting follow-up. Participants must first phone the IESO Shift
    Control Specialist at 905-855-6200 within 60 minutes, then email.
- phone: 905-855-6200
  purpose: IESO Shift Control Specialist — 60-minute telephone reporting window for Market Manual incidents.
program:
  name: Cyber Security Incident Reporting
  kind: sector incident reporting obligation
  scope: >-
    Licensed Ontario transmission and distribution entities are required to report cyber security
    incidents as defined within the Ontario Cyber Security Standard. Market participants subject to
    NERC CIP-003 (Low impact BES Cyber Systems) or CIP-008 (Medium or High impact BES Cyber Systems)
    must also report under IESO Market Manual 7.1.
  standard: Ontario Cyber Security Standard V3.0
  standard_url: https://oeb.ca/sites/default/files/Ontario%20Cyber%20Security%20Standard_V3.0.pdf
  amendment_enacted: '2025-09-22'
  voluntary_reporting: true
  portal: Lighthouse
evidence:
- {source: 'https://www.ieso.ca/Sector-Participants/Cyber-Security/Cyber-Security-Incident-Reporting', kind: security-contact-page, status: 200, date: '2026-07-27'}
- {source: 'https://www.ieso.ca/.well-known/security.txt', kind: security.txt, status: 404, date: '2026-07-27'}
- {source: 'https://reports-public.ieso.ca/.well-known/security.txt', kind: security.txt, status: 404, date: '2026-07-27'}
- {source: 'https://online.ieso.ca/.well-known/security.txt', kind: security.txt, status: 404, date: '2026-07-27'}
pgp_key: none
gaps:
- No RFC 9116 security.txt on any host.
- No safe-harbour statement or researcher terms.
- No published triage SLA or disclosure timeline.
- No bug bounty program on any platform.
- >-
  No address exists for reporting a vulnerability in IESO's own public web properties as distinct from
  reporting a grid-sector incident; cybersecurity@ieso.ca is the nearest published channel.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/ieso-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.