IESO · Vulnerability Disclosure
Ieso Vulnerability Disclosure
Vulnerability disclosure
IESO runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
EnergyCanadaElectricityEnergy MarketsGridSystem OperatorMarket DataOpen DataOntarioDemand ResponseRenewables
Program: Hackerone
security.txt present
Disclosure Policy
Security Contact
Contact
{"email" => "CyberIncidentReports@ieso.ca", "purpose" => "Ontario Cyber Security Standard (OCSS) incident reports, and voluntary reporting. Also submittable through the Lighthouse portal."}
Contact
{"email" => "cybersecurity@ieso.ca", "purpose" => "Program access, including participation in the Lighthouse portal."}
Contact
{"email" => "scs@ieso.ca", "purpose" => "IESO Market Manual incident reporting follow-up. Participants must first phone the IESO Shift Control Specialist at 905-855-6200 within 60 minutes, then email."}
Contact
{"phone" => "905-855-6200", "purpose" => "IESO Shift Control Specialist — 60-minute telephone reporting window for Market Manual incidents."}