HomeCybersecurityM12273Evidence
Topic/Matter Intersection

Topic:"Cybersecurity" in M12273

Matter: Board Inquiry into Nova Scotia Power's Cybersecurity Incident
591 passages 48 documents

Cybersecurity across all matters →

N-1Letters of Comment - Redacted 42 passages
Section 7
llace acting as Chief Clerk of the Nova Scotia Energy and Regulatory Boards Tribunal Kim Adair acting as Auditor General for the Office of the Auditor General of Nova Scotia Enclosed Documentation 1.​ NSERBT Decision – Matter M11099 (Augus...

AI summary A data breach at Nova Scotia Power (NSP) has raised concerns about customer data security and fairness, with NSP's lack of infrastructure upgrades and privatization-related price increases exacerbating public dissatisfaction. The breach notification offers a monitoring service, but customers question accountability and cost distribution.

Section 8
aspects as a cost will be downloaded to the voters who are also customers. Where is the fairness? NSP has not maintained upgrades to the grid in an acceptable manner, nor to its data infrastructure. I am very angry about this as I have no...

AI summary Katie Campbell criticizes NSP for poor grid/data infrastructure maintenance and lack of alternatives, demanding government intervention. A DRO decision on May 13, 2025, addresses a complaint about mishandled data breaches, delayed notifications, and unresolved privacy issues.

Section 13
…/2 -2 - 3) Provide comprehensive identity protection through a credible provider; 4) Provide in writing, a clear acknowledgement that NS Power was the care holder of my Personal and Private information, as they had requested it from me, b...

AI summary The complainant alleges NS Power failed to protect personal data during a cyberattack, leading to the theft of 280,000 Nova Scotians' information. They demand identity protection, written acknowledgment of NS Power's data stewardship, and an explanation for restoring public trust, citing delayed breach disclosure and ongoing access barriers.

Section 15
ainting-MacLean, Kimberly To: Painting-MacLean, Kimberly Subject: FW: NOVA SCOTIA POWER - FURTHER COSTLY OUTCOMES TO ALL CANADIANS Date: May 26, 2025 9:24:14 AM From: Susan Simons Sent: May 25, 2025 5:27 PM To: Premier ; [email protected]...

AI summary The email highlights the risks of Nova Scotia Power's security breach, exposing 280,000 Nova Scotians' personal data on the dark web. It warns of potential large-scale fraud and theft, drawing parallels to pandemic-era tax fraud. The breach is argued to empower criminals and terrorists to exploit data for financial gain.

Section 18
repeated, given the NS Power security breach? A reply is requested and sincerely would be appreciated, by both levels of government to both questions. Thank you. Type of complaint: Other

AI summary The text raises concerns about a repeated security breach by NS Power and requests a response from both levels of government. The complaint is categorized as 'Other,' indicating it does not fall under standard regulatory or program topics.

Section 19
Additional details: Cyber Security management negligence: I have contacted the NS Energy Board regarding the NS Power cyber security breach on 23 May 25. I noted that on 10 Mar 25 CBC (Blair Rhodes) issued a story that NS Power had request...

AI summary The text highlights NS Power's cybersecurity vulnerabilities, citing a $6.8M upgrade request and 12 critical sites exposed in a 2025 breach. The author argues that core cybersecurity services should be baseline-funded by NS Power, not requiring regulatory approval, due to federal obligations and current threat levels.

Section 21
Page 2 of 3 How do they want the I expect PROMPT action from the NS Energy Board on this complaint resolved? ongoing cyber threat. The fact that the NS Energy Board continued to pursue a standard 90 day review period without triaging and e...

AI summary A complainant criticizes the NS Energy Board for delaying action on a cybersecurity threat, urging expedited review and self-funding by NS Power. They argue the board's standard 90-day process is inadequate, NS Power's negligence exposed 280,000 Nova Scotians to data theft, and a special board could have accelerated approval for cybersecurity measures.

Section 22
making cyber security vulnerabilities a priority has resulted in mine and 280,000 other Nova Scotians vital credit information to be stolen and sold on the Dark Web. My financial vulnerability was wholly avoidable if NS Power had acted muc...

AI summary A data breach involving NS Power exposed 280,000 Nova Scotians' credit information due to cybersecurity vulnerabilities. The complainant criticizes NS Power for delayed action and demands the NS Energy Board improve consumer protection and regulatory oversight. Supporting documents include security risk analyses and privacy complaints.

Section 23
C.pdf Raw Headers Missing Policies.pdf Obfuscated JS Snippet.pdf Missing Headers Summary.pdf Footer 2019 Timestamp.pdf From: Jame Y Sent: May 26, 2025 7:06 AM To: [email protected]; [email protected]; [email protected]; chie...

AI summary A privacy complaint is submitted regarding a Nova Scotia Power data breach and the use of an insecure remedial platform (mytrueidentity.ca). The complainant, YungYu Yeh, argues the platform exposes affected individuals to further cyber risks, citing technical analysis and evidence from IT student Meng Cheng Yeh.

Section 24
ce of the Information and Privacy Commissioner for Nova Scotia Subject: Formal Privacy Complaint Regarding NS Power Data Breach and Insecure Remedial Platform (mytrueidentity.ca) Dear Commissioner, My name is YungYu Yeh, A victim of NS pow...

AI summary A privacy complaint is filed against NS Power regarding a data breach and the insecure remedial platform mytrueidentity.ca. The complainant highlights significant security flaws in the site, including unsafe headers, broken code, lack of HTTPS enforcement, and reliance on third-party scripts, which could expose sensitive data to attacks.

Section 25
tive Summary: Security Risks of Entering Credit Card Information on mytrueidentity.ca 2025年5⽉24⽇ 晚上8:37 收件者: Grace C Based on a thorough technical analysis of the mytrueidentity.ca website due to the recent cyber incident impacting Nova Sc...

AI summary A technical analysis of mytrueidentity.ca reveals significant security risks, including missing security headers, broken JavaScript, lack of HTTPS redirection, and outdated practices. These vulnerabilities expose users to data breaches and cyber threats, particularly concerning Nova Scotia Power's recent cyber incident.

Section 26
19, suggesting a lack of ongoing maintenance or security review. Use of deprecated practices like X-XSS-Protection and reliance on legacy JavaScript libraries further confirms this. Conclusion: mytrueidentity.ca does not meet modern web se...

AI summary The document highlights significant web security vulnerabilities on mytrueidentity.ca, including outdated practices and missing security headers, which expose users to cyber risks when handling financial data. It advises Nova Scotians against submitting personal information on the platform. The analysis was conducted by Meng Cheng Yeh, an IT student, with attached evidence of security flaws.

Section 29
TransUnion credit monitoring services. When I called the number, I was connected with TransUnion. This limited response is not enough support for victims of a data breach of this size. In closing, I request that Nova Scotia Power immediate...

AI summary Melissa Marsh alleges a data breach by Nova Scotia Power (NSP) compromised her personal information, requesting detailed breach specifics, explanations for delayed notification, enhanced identity protection, and improved cybersecurity protocols. She criticizes NSP's current response as inadequate for protecting customer data and ensuring transparency.

Section 42
Page 3 of 4 Supporting documents • 1000004479.jpg uploaded: Page 4 of 4 Type of complaint: Other Additional details: The recent cyber attack at NS Power has left me feeling vulnerable. The 2 yr credit monitoring with Transunion offered is...

AI summary A customer is concerned about the vulnerability caused by a recent cyber attack at NS Power and the inadequate credit monitoring solution provided. The customer finds the process of managing credit monitoring with Transunion cumbersome and believes NS Power should not require customers to provide their SIN. They also call for better data protection measures.

Section 46
of the Privacy Commissioner of Canada Crystal Henwood, Clerk of the Board, Nova Scotia Energy and Regulatory Boards Tribunal Rod Wilson, MLA Halifax Armdale Lena Metlege Diab, MP Halifax West From: Painting-MacLean, Kimberly To: Painting-M...

AI summary This email discusses a potential source of a cyber breach on the NS Power corporate network and includes various attachments related to the incident, including articles and job postings. The email was sent to Rebecca Brown and includes a warning about external emails and caution regarding attachments and links.

Section 47
ng, As discussed today, please consider this synopsis of a potential source of the cyber breach on the NS Power corporate (non-operational) network. For your further review and further investigation. On or about 20 May 2025, I received a l...

AI summary The letter discusses a cyber breach on NS Power's corporate network, referencing a 2019 project (M09301) that implemented a Security Information Event Monitoring (SIEM) tool and Security Operations Centre (SOC) service. The author requests disclosure of costs associated with the SOC service provided by Service Now.

Section 48
vendor have not been reflected anywhere in this capital project. I suggest that NS Power be asked to disclose what they have spent for this SOC service from the inception of this project to its close. The SOC “is designed to identify in re...

AI summary The text raises concerns about the lack of transparency in NS Power's spending on the SOC service and questions whether necessary software updates have been performed, given the hybrid lower-cost option chosen, which places the onus on internal IT staff.

Section 49
ption appears to have left the onus with internal NS Power IT employees to setup new server hardware and software and to perform routinely and timely software updates on this new software as required. As I understand it, NS Power is oblige...

AI summary The document highlights concerns about NS Power's delayed implementation of cybersecurity measures for its corporate network, noting that the project was put on hold from 2017 to 2018 due to dependencies with other IT work. Despite known threats, the corporate network lacks adequate safeguards, raising questions about regulatory oversight and resource allocation.

Section 50
2 that “this capability does not exist today”. With well know threats and vulnerabilities, it appears that NS Power carried on operating the corporate network for years without suitable safeguarding. It is not clear how long NS Power has c...

AI summary The document highlights concerns about NS Power's cybersecurity practices, specifically the lack of adequate safeguards for the corporate network and the unclear timeline for establishing SOC vendor services from Service Now. It questions the effectiveness of the hybrid approach used to connect to Service Now's SOC services.

Section 51
demands. Further, regarding IR-6, it is not clear how the ‘hybrid’ approach allowed NS Power to safely and securely establish a network connection to Service Now while using Service Now SOC services. IR-20 discusses the in-house and hybrid...

AI summary The text raises concerns about NS Power's implementation of a hybrid approach for network security with Service Now, questions whether the hybrid model is still in use, and highlights potential vulnerabilities due to unpatched software. It also connects a data breach to a known security vulnerability exploited by hackers.

Section 52
From: Painting-MacLean, Kimberly To: Painting-MacLean, Kimberly Subject: FW: DRO 31 May re Sean Kelly re Data Breech Date: June 4, 2025 9:50:04 AM From: Sean Kelly Sent: June 3, 2025 10:27 PM To: [email protected] Cc: customer...

AI summary Sean Kelly criticizes the poor quality of regulations, arguing they favor the company and neglect customer privacy and data security. He questions the board's role in protecting Nova Scotians and highlights the lack of clarity on who is responsible for creating the regulations. He also references CMMC data security requirements and requests a meeting with the board.

Section 56
Disput e Resolution Officer From: Sean Kelly Sent: May 26, 2025 7:19 PM To: [email protected] Subject: Data Breech I am writing on behalf of myself and my wife Michelle Kelly. We live at Nova Scotia. We have received a letter...

AI summary Sean Kelly and Michelle Kelly are reporting a data breach involving their personal information, which was published without their knowledge. They express dissatisfaction with the lack of notification, inadequate security measures, and the 2-year credit coverage offered as compensation, which they consider insufficient. They seek fair compensation based on previous data breach settlements.

Section 59
Page 2 of 4 We are left unsure of what steps to take or what risks we truly face. 3. Inadequate Support NS Power offered 2 years of free credit monitoring via TransUnion of Canada Inc. While somewhat helpful, this offer falls short. Expert...

AI summary The customer expresses concerns about inadequate support following a data breach, questioning NS Power's data retention practices and requesting a meter inspection and billing review. They demand a full investigation into data security practices, compliance with privacy laws, and expanded protection for affected customers.

Section 64
nd other relevant bodies. I hope NS Power will do the right thing and take this matter seriously. Sincerely, Elizabeth Hartling Type of complaint: Other Additional details: I am writing to formally complain about Nova Scotia Power's handli...

AI summary A customer is complaining about Nova Scotia Power's delayed and inadequate response to a data breach that occurred in March 2025, which was only disclosed in May 2025. The customer is concerned about the lack of specific information provided regarding the stolen data and the delayed notification.

Section 67
ormation of mine was compromised in this breach. Explain the delay between discovering the breach (April 25) and notifying me (May 13). Offer comprehensive identity protection services beyond basic credit monitoring, and for an adequate le...

AI summary The letter from Lesley Hartman addresses a data breach involving the compromise of personal information, expressing concerns over the delay in notification and the adequacy of the response. The letter requests comprehensive identity protection services, improved cybersecurity protocols, and a more transparent and detailed response to the breach.

Section 69
How do they want the I request that you urge Nova Scotia Power to: Provide me with complaint resolved? a detailed, specific account of exactly what personal information of mine was compromised in this breach. Explain the delay between disc...

AI summary The complainant requests Nova Scotia Power to provide detailed information about the data breach, explain the delay in notification, offer comprehensive identity protection, and improve cybersecurity protocols to prevent future incidents and ensure transparency and support for affected customers.

Section 76
lamed for things I didn’t do. I can’t afford any costs incurred, I can barely afford food. I got a call back from the same rep, not his supervisor and was told that I wasn’t one of the people hacked. I don’t think allowing the same people...

AI summary The text includes a customer's complaint about a cyber incident involving Nova Scotia Power, expressing concerns about accountability, transparency, and potential harm from negligence. A follow-up email from Kimberly Painting-MacLean references the incident to the NSUARB.

Section 77
chments or clicking on links / Faites preuve de prudence si vous ouvrez une pièce jointe ou cliquez sur un lien Good Day, I am writing this morning about the recent Nova Scotia Power cyber incident. After this issue came to light, NSP sent...

AI summary Clarence Whynot criticizes Nova Scotia Power (NSP) for its inadequate response to a cybersecurity incident that exposed customer personal information. He argues that NSP should provide detailed disclosure of affected data and explain why SINs were stored. He also expresses frustration over the lack of accountability and transparency.

Section 78
unacceptable. Customers should not be on the hook for any losses accrued as a result of this outage. Did they contact the utility? No How did the utility respond? How do they want the NS Power should not be permitted to increase rates to c...

AI summary A customer is expressing concern over a data breach at Nova Scotia Power, highlighting the lack of long-term protection for personal information and dissatisfaction with the two-year credit monitoring offer. The customer feels abandoned after this period and fears ongoing risks to their credit and identity.

Section 81
m really asking and if you are correct point of contact that it be disscussed within your group. The situation with NSP may not change I understand. Jim Charumski Type of complaint: Other Additional details: corporate responsibility: 1) wh...

AI summary The complaint discusses NSP's handling of a cyber attack and billing practices, including why NSP informed the complainant of a cyber attack but did not provide email coverage for 5 years, and how NSP covers penalties for double billing without informing customers. The complainant also references a CBC News article about NSP's billing practices following a ransomware attack.

Section 84
loaded: Page 2 of 2 Yours truly, Timothy Leary ++++++++++++++++++++++++++++++++++++++++++ On 2025-07-15 3:01 p.m., Privacy Officer wrote: Dear Mr. Leary, We are writing in response to your request for a detailed account of what personal in...

AI summary Nova Scotia Power's Privacy Officer informed Timothy Leary that it is not possible to determine precisely what personal information, if any, was compromised in a recent cyber attack on their systems. The investigation is ongoing with cybersecurity experts, and further updates will be provided if more specific information is identified.

Section 85
dividual basis. However, if we are able to determine more specific information in the future, we remain committed to keeping our customers informed and will communicate any material updates directly. From our investigation, we do know that...

AI summary Nova Scotia Power has experienced a data breach involving personal customer information. The company is offering free credit monitoring to all customers and encourages them to sign up using a provided verification form. The breach included sensitive data such as names, contact details, account history, and financial information.

Section 87
.ca Cc: Board, NSUARB ; Premier ; Subject: Complaint Some people who received this message don't often get email from . Learn why this is important EXTERNAL EMAIL / COURRIEL EXTERNE Exercise caution when opening attachments or clicking on...

AI summary The complainant expressed frustration with NS Power's process for handling a cyber incident, particularly the difficulties encountered when trying to set up an account with TransUnion and the ineffective callback system provided by the representative.

Section 91
Alternate phone number: Complaint Information Page 1 of 2 Type of complaint: Other Additional details: The NSP cyber breach occurred on 19 March 2025, but NSP only became aware on 25 April 2025, 37 days later. My notification was received...

AI summary The complainant alleges that Nova Scotia Power (NSP) delayed notification of a cyber breach that occurred on 19 March 2025, with NSP becoming aware on 25 April 2025 and the complainant being notified 63 days later. The complainant criticizes NSP's response as ineffective and requests a complete answer regarding the information liability and exposure related to the breach.

Section 92
ire a complete answer concerning my information liability complaint resolved? and exposure. In other words, what information of mine did the cyber criminals take? Supporting documents • NSP Privacy Officer.pdf uploaded: • 2025-07-18 Peter...

AI summary The document is a complaint regarding a data breach at Nova Scotia Power (NSP), highlighting concerns about delayed notification, inadequate cybersecurity measures, and the potential exposure of customer information. The complainant seeks answers on whether the breach is ongoing, the cause of the delay, how security was bypassed, and whether the breach was deliberate or due to human error.

Section 93
April?) How were your security procedures bypassed? (For example, social engineering, malware, tech failure etc.) Was this a deliberate attack or was this human error? I request that NSP provide: Detailed list of my information that was ac...

AI summary A complaint regarding a data breach involving Nova Scotia Power (NSP) is raised, with concerns about how security procedures were bypassed and whether personal and spouse’s information was compromised. The complainant requests detailed information about the breach and emphasizes the need for critical infrastructure corporations to protect personal data.

Section 99
Page 2 of 5 Additional details: Primary Complaint is attempted Secrecy. On July 18, 2025, I wrote to Peter Gregg and asked a simple, sincere question: “Why should I pay my power bill?” Months after Nova Scotia Power’s (NSP) cyber incident,...

AI summary The text discusses a complaint regarding Nova Scotia Power's (NSP) cybersecurity incident and its attempts to maintain secrecy. The complainant is demanding an apology, full explanation, and a moratorium on rate increases for two years. The text highlights the risks posed by supply chain vulnerabilities and the persistent targeting of the electricity sector by state-sponsored cybercriminals.

Section 100
ss network defences. If NSP uses components with these vulnerabilities, the problem is not only mismanagement but a systemic exposure that demands more than an apology. The purpose of targeting utility telecommunications is clear: harvest...

AI summary The text highlights concerns about NSP's cybersecurity vulnerabilities, emphasizing that systemic exposure from unaddressed network weaknesses could lead to serious consequences, including disruptions to critical infrastructure and operations at strategic sites like CFB Halifax. It criticizes NSP's lack of effective cyber defense measures, such as real-time threat detection and zero trust architecture.

Section 101
d a zero trust architecture— measures that detect and limit the damage of targeted campaigns. I am informed these measures are not fully in place at NSP.

AI summary The text mentions the need for a zero trust architecture to detect and limit damage from targeted campaigns, noting that these measures are not fully implemented at NSP.

Section 103
ny rate increases is a reasonable and necessary measure while trust is being rebuilt. Finally, regulators should require a third party audit of NSP’s supply chain and cyber defences. Longer term, this incident should prompt legislative and...

AI summary The text argues that rate increases are necessary while trust is rebuilt, calls for third-party audits of NSP’s supply chain and cyber defences, and advocates for legislative changes to improve breach notification and cyber security standards. It questions the justification for paying higher bills and emphasizes the need for competence and accountability from NSP.

Section 104
? How do they want the The Board inquiry into the cyber security breach must be public complaint resolved? in it's entirety. Supporting documents • image.png uploaded: Page 5 of 5 From: Board, NSUARB To: Painting-MacLean, Kimberly Cc: Henw...

AI summary A concerned individual, Weldon Young, is inquiring about the transparency of NS Power's handling of a cyber security breach that occurred in Spring 2025, emphasizing the need for NS Power to inform customers about the personal information that was accessed and retained.

Section 108
Hello, to whom it may concern, I pre-apologize for my grammar. this is an email i'm sending to be brought forward to the top levels of nova scotia power to understand and let people know that your recent cyber attack that you mentioned was...

AI summary The email discusses a customer's experience with Nova Scotia Power following a cyber attack, expressing concerns about ongoing security issues and an unusual account verification process involving excessive personal information questions.

N-2NSPI (NSEB) RIR 1 to 12 - Redacted 101 passages
Section 1
REDACTED (CONFIDENTIAL INFORMATION REMOVED) Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The document outlines a Board Inquiry into Nova Scotia Power's cybersecurity incident, referenced as NSEB M12273, with responses from Nova Scotia Power to information requests.

Section 2
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED 1 Request IR-1: 2 3 Please provide a timeline of this cybersecurity incident, including: 4 5 (a) the date of the bre...

AI summary Nova Scotia Power's cybersecurity incident (NSEB M12273) was discovered on April 25, 2025, with an ongoing investigation. NS Power engaged Osler and Mandiant for response, but details remain under investigation.

Section 3
er activated its established 29 incident response and business continuity protocols, and engaged Osler, and through Osler, 30 Mandiant’s cybersecurity and incident response team. Date Filed: September 5, 2025 NSPI (NSEB) IR-1 Page 1 of 18...

AI summary Nova Scotia Power (NSPI) activated incident response protocols and engaged Osler and Mandiant's cybersecurity team following a cybersecurity incident. The Board Inquiry (NSEB M12273) is examining the incident, with NSPI providing responses to information requests.

Section 4
d Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The document outlines an inquiry into Nova Scotia Power's (NSPI) cybersecurity incident, referencing responses provided to Nova Scotia Energy Board (NSEB) information requests. The matter is designated as NSEB M12273, with content redacted beyond the heading and entity mentions.

Section 5
1 Under the direction of Osler, Mandiant assisted the Company and other cybersecurity 2 experts with containment, investigation, and remediation efforts, and took immediate 3 actions to contain and remediate the unauthorized activity, 4 5...

AI summary NS Power reported a cybersecurity incident involving unauthorized access and data exfiltration, notifying law enforcement agencies (RCMP, FBI, CSIS) and the OPC. The company asserts no operational systems were breached and is cooperating with investigations. The Nova Scotia Energy Board was also informed.

Section 6
ively and fully cooperating with the OPC to support the OPC’s investigative efforts. 26 The Company has also provided updates to the Nova Scotia Energy Board, as well as other 27 relevant government officials throughout the Incident and in...

AI summary Nova Scotia Power (NSPI) is cooperating with the Office of the Privacy Commissioner of Canada (OPC) during a cybersecurity incident investigation and has provided updates to the Nova Scotia Energy Board (NSEB) and government officials. The context is a regulatory inquiry into the incident, referenced as NSEB M12273.

Section 7
rd Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The Nova Scotia Energy Board (NSEB) is conducting an inquiry into a cybersecurity incident involving Nova Scotia Power (NSPI), with NSPI providing responses to NSEB information requests. The matter is designated as NSEB M12273, though details are redacted.

Section 9
s the top search result when customers 26 used search engines (i.e. Google) to find information about the Incident. Social media 27 accounts have been regularly monitored, and where appropriate, the Company has provided 28 answers to relat...

AI summary Nova Scotia Power (NSPI) managed a cybersecurity incident by monitoring social media, addressing customer inquiries online, and maintaining operational Customer Care Centre services. The NSEB initiated a Board Inquiry (M12273) into the incident, with NSPI providing responses to information requests.

Section 10
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The document outlines an inquiry into Nova Scotia Power's cybersecurity incident (NSEB M12273), focusing on NSPI's responses to information requests by the Nova Scotia Energy Board. The content is redacted, limiting detailed analysis.

Section 11
1 Customer Notification Timeline 2 3 As noted above, the Company became aware of the Incident on Friday, April 25. The next 4 business day, on Monday, April 28, 2025, NS Power informed customers that it was 5 actively responding to a cyber...

AI summary NS Power notified customers of a cybersecurity incident starting April 28, 2025, with detailed updates on May 1, 2025, and formal notices to 277,000 customers on May 13, 2025. The company engaged third-party providers for notifications and issued press releases, with senior personnel participating in media interviews to inform the public.

Section 12
identify what data was impacted has been extremely complex and remains 28 ongoing. As set out in the notices sent to impacted customers, the impacted data would 29 have varied by customer, and depended, in part, on the information a custom...

AI summary The document outlines a cybersecurity incident involving Nova Scotia Power (NSPI), with the Nova Scotia Energy Board (NSEB) conducting an inquiry. Identifying impacted data remains complex and ongoing, varying by customer based on the information they provided.

Section 13
d Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The document outlines an inquiry into Nova Scotia Power's (NSPI) cybersecurity incident, referencing responses provided to Nova Scotia Energy Board (NSEB) information requests. The matter is designated as NSEB M12273, with content redacted beyond the heading and entity mentions.

Section 15
tary credit 22 monitoring to five years on June 25, 2025. 23 24 The credit monitoring service offered to customers is provided by TransUnion and has been 25 specifically designed to protect individuals in the case of a data breach, and off...

AI summary Nova Scotia Power (NSPI) offers credit monitoring services via TransUnion, extending protection for five years. The service includes daily credit report access to detect identity theft. The document also references a regulatory inquiry into NSPI's cybersecurity incident (NSEB M12273) and NSPI's responses to information requests.

Section 16
d Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED 1 • Unlimited online access to their credit score, updated daily. 2 3 • Credit monitoring, which provides individu...

AI summary Nova Scotia Power (NSPI) provided customers with cybersecurity incident response measures, including credit monitoring, identity theft protection, and reimbursement insurance, following a data breach. NSPI kept customers informed through updates and addressed the incident's impact via dark web monitoring and identity restoration services.

Section 17
ter discovering that the threat actor had published data on the dark 26 web, NS Power promptly provided an update to customers through the same channels as 27 previous updates. 28 Date Filed: September 5, 2025 NSPI (NSEB) IR-1 Page 6 of 18...

AI summary NS Power informed customers of a cybersecurity incident where threat actors published data on the dark web, with updates provided through existing channels. The NSEB is conducting an inquiry (M12273) into the incident, with NSPI responding to information requests.

Section 18
d Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The document outlines an inquiry into Nova Scotia Power's (NSPI) cybersecurity incident, referencing responses provided to Nova Scotia Energy Board (NSEB) information requests. The matter is designated as NSEB M12273, with content redacted beyond the heading and entity mentions.

Section 20
ure that the call centre had sufficient 27 capacity to handle the volume of calls and allow NS Power’s customer service team to 28 focus on a subset of escalated queries, this call centre was staffed by TransUnion 29 employees who had been...

AI summary The document outlines NSPI's response to NSEB's inquiry regarding a cybersecurity incident, including arrangements for a call centre managed by TransUnion to handle customer inquiries, with escalated issues directed to NS Power. The proceeding is referenced as NSEB M12273.

Section 21
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The document outlines an inquiry into Nova Scotia Power's cybersecurity incident (NSEB M12273), focusing on NSPI's responses to information requests by the Nova Scotia Energy Board. The content is redacted, limiting detailed analysis.

Section 23
s also actively encouraged customers and its employees to reach out to their family and 25 neighbours to encourage them to sign up. Please refer to Attachment 3. 26 27 In addition, the Company deployed dozens of employees to communities ac...

AI summary Nova Scotia Power (NSPI) actively engaged customers and employees to promote program participation, including in-person support. The text references a regulatory inquiry into NSPI's cybersecurity incident (NSEB M12273) and NSPI's responses to NSEB information requests, with redacted details.

Section 24
d Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The document outlines an inquiry into Nova Scotia Power's (NSPI) cybersecurity incident, referencing responses provided to Nova Scotia Energy Board (NSEB) information requests. The matter is designated as NSEB M12273, with content redacted beyond the heading and entity mentions.

Section 25
1 these community sessions have been held to date, and have assisted hundreds of customers 2 in signing up for the service. The NS Power website also has been updated with additional 3 tips and tools to help customers navigate support serv...

AI summary NS Power has conducted community sessions to support customer engagement, updated its website with tools, and implemented cybersecurity measures aligned with NIST and NERC standards. The company conducts regular training, audits, and compliance reviews to ensure robust cybersecurity practices.

Section 26
onducts 26 mandatory quarterly cyber training and monthly phishing simulation testing exercises with 27 all employees to educate employees about NS Power’s information security policies and 28 common risks, and to help them understand thei...

AI summary Nova Scotia Power (NSPI) disclosed a cybersecurity incident, detailing immediate response actions including containment, engagement with third-party experts, and ongoing remediation efforts. The company also implements mandatory quarterly cyber training and monthly phishing simulations for employees. The NSEB is conducting an inquiry into the incident (NSEB M12273).

Section 27
nquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED 1 2 3 4 5 6 7 8 9 10 11 12 13 14 NS Power is also advancing efforts to restore and, where necessary, rebuild core bus...

AI summary Nova Scotia Power (NSPI) is responding to the NSEB's inquiry regarding a cybersecurity incident, detailing efforts to restore business systems, establish a restoration office, and notify customers. Recovery focuses on system continuity and security protocols, with ongoing communication updates.

Section 28
notifications and updates to customers throughout 26 the next several weeks of response efforts. 27 28 These communications and releases to media occurred on the following dates: Date Filed: September 5, 2025 NSPI (NSEB) IR-1 Page 12 of 18...

AI summary The document references a regulatory inquiry into Nova Scotia Power's cybersecurity incident (NSEB M12273) and NSPI's responses to information requests from the Nova Scotia Energy Board. The text highlights ongoing communications and media releases related to the incident.

Section 29
rd Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The Nova Scotia Energy Board (NSEB) is conducting an inquiry into a cybersecurity incident involving Nova Scotia Power (NSPI), with NSPI providing responses to NSEB information requests. The matter is designated as NSEB M12273, though details are redacted.

Section 31
to share 27 information about upcoming customer support sessions in local communities to help 28 customers sign up for the free credit monitoring being offered by the company. 29 Date Filed: September 5, 2025 NSPI (NSEB) IR-1 Page 13 of 18...

AI summary The Nova Scotia Energy Board (NSEB) is conducting an inquiry into Nova Scotia Power's (NSPI) cybersecurity incident (NSEB M12273), with NSPI providing responses to NSEB information requests. NSPI also plans to share details about customer support sessions promoting free credit monitoring.

Section 32
d Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED 1 Cape Breton – Monday, June 30, 2025 2 • The Coast 89.7FM Radio - Sydney - [email protected] 3 • MBS Radio – S...

AI summary The document outlines Nova Scotia Power's (NSPI) media responses to inquiries about customer bills and meter readers, alongside an ongoing NSEB inquiry into a cybersecurity incident (NSEB M12273). NSPI's Director of Customer Care, Chris Lanteigne, participated in interviews with media outlets and CBC programs.

Section 33
Mainland (noted in chart below), as well as information being shared with 28 AllNovaScotia.com, Global Halifax, MBS Radio, Halifax Examiner and the Chronicle 29 Herald. 30 Date Filed: September 5, 2025 NSPI (NSEB) IR-1 Page 14 of 18 REDACT...

AI summary The document outlines a regulatory inquiry by the Nova Scotia Energy Board (NSEB) into a cybersecurity incident involving Nova Scotia Power (NSPI), including NSPI's responses to information requests. The proceeding is referenced as NSEB M12273, with redacted confidential details.

Section 34
d Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The document outlines an inquiry into Nova Scotia Power's (NSPI) cybersecurity incident, referencing responses provided to Nova Scotia Energy Board (NSEB) information requests. The matter is designated as NSEB M12273, with content redacted beyond the heading and entity mentions.

Section 35
1 (f) Please see the following table for details on public interviews provided: 2 Member of NSP senior Date Media Outlet Format Reporter Topic leadership team Amy Smith, Peter Gregg, Anchor Cyber incident May 23, 2025 CBC TV President and...

AI summary Nova Scotia Power (NSP) provided updates on a cyber incident through public interviews on May 23, 2025, with media outlets including CBC and allnovascotia.ca. NSP leadership, including President and CEO Peter Gregg, participated in televised, radio, and print interviews.

Section 36
Cyber incident May 23, 2025 allnovascotia.ca Print/Online President and Cormier update CEO Peter Gregg, Mike Cyber incident May 29, 2025 Canadian Press Print/Online President and Tutton update CEO Peter Gregg, Cyber incident May 29, 2025 C...

AI summary Nova Scotia Power (NSP) is responding to a cyber incident, with updates provided by President and CEO Peter Gregg and other officials through multiple media outlets including Canadian Press, CTV, and CBC, dated May 23-30, 2025.

Section 37
Chris Customer Ryan Lanteigne, June 17, 2025 CTV TV support MacDonald Director sessions in Customer Care communities across NS CBC Chris Billing/custom Information Lanteigne, er support June 17, Morning Radio Director sessions for 2025 Mai...

AI summary The document references a cybersecurity incident involving Nova Scotia Power (NSPI) under investigation by the Nova Scotia Energy Board (NSEB) (M12273). NSPI has submitted responses to NSEB's information requests, with the document being part of the inquiry process.

Section 38
rd Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED Cyber incident update Billing Chris concerns CBC Nova Elizabeth Lanteigne, July 9, 2025 Radio Customer Scotia McM...

AI summary Inquiry into Nova Scotia Power's cybersecurity incident (NSEB M12273) and responses to NSEB information requests. Media engagements include CBC Nova Scotia Radio interviews discussing the cyber incident, billing concerns, and customer support initiatives. Community sessions and meter reader interactions were also highlighted.

Section 39
Mainland Customer Care asked about (to air Monday, cyber incident) July 13) 1 Date Filed: September 5, 2025 NSPI (NSEB) IR-1 Page 18 of 18 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Cybersecurity Incident NSEB IR-01 Attachment 1 Page 1 of...

AI summary Nova Scotia Power (NSPI) notified customers of a cybersecurity incident, urging vigilance against unsolicited communications. The company apologized and committed to enhancing system security through additional safeguards. Peter Gregg, President & CEO, emphasized the importance of protecting customer data.

Section 40
Cybersecurity Incident NSEB IR-01 Attachment 1 Page 3 of 4 Services Description We have retained the assistance of Trans Union of Canada, Inc. (“TransUnion Canada”), one of Canada’s leading consumer reporting agencies and arranged a 24-mon...

AI summary The Nova Scotia Energy Board (NSEB) offers a 24-month subscription to TransUnion Canada's myTrueIdentity® service for credit monitoring and identity restoration, following a cybersecurity incident. Customers are encouraged to activate the service using a provided code before 9/30/2025.

Section 44
hat the creditor contact you prior to establishing any accounts in your name. To place a fraud alert on your credit report, contact TransUnion Canada and Equifax Canada using the information above. 4/4 REDACTED (CONFIDENTIAL INFORMATION RE...

AI summary Nova Scotia Power has experienced a cybersecurity incident and is urging customers to be cautious of unsolicited communications requesting personal information. The company has established a dedicated customer hotline and is taking steps to strengthen system security to prevent future incidents.

Section 45
Cybersecurity Incident NSEB IR-01 Attachment 2 Page 3 of 4 Services Description We have retained the assistance of Trans Union of Canada, Inc. (“TransUnion Canada”), one of Canada’s leading consumer reporting agencies and arranged a 24-mon...

AI summary The document describes a cybersecurity incident involving the Nova Scotia Energy Board (NSEB) and outlines a service provided to affected individuals, including a 24-month subscription to myTrueIdentity® for credit monitoring and identity restoration.

Section 49
hat the creditor contact you prior to establishing any accounts in your name. To place a fraud alert on your credit report, contact TransUnion Canada and Equifax Canada using the information above. 4/4 REDACTED (CONFIDENTIAL INFORMATION RE...

AI summary The document provides guidance to customers of Nova Scotia Power affected by a cybersecurity incident, advising them to sign up for TransUnion’s credit monitoring service using a unique activation code provided in their letter.

Section 51
cess cannot be paused or resumed after periods of inactivity. If you aren’t able to complete the enrolment process in one session, you will have to call TransUnion to complete the process. Dark Web Monitoring: Once you’ve signed up, What i...

AI summary The text provides guidance on enrolling in TransUnion's Dark Web Monitoring service and steps to take following a cybersecurity incident. It emphasizes the importance of monitoring personal information and contacting relevant authorities if suspicious activity is detected.

Section 52
ments. If you notice any suspicious activity related to your Social Insurance Number, report it to the police and contact the Canadian Anti-Fraud Centre at 1-888-495-8501. 2 Sign up for Equifax’s fraud alerts and security freezes through t...

AI summary The text discusses steps for customers to take in response to a cybersecurity incident, including reporting suspicious activity, signing up for fraud alerts, and contacting financial institutions. Nova Scotia Power is offering in-person support and guidance on credit monitoring and estimated bills.

Section 53
REMOVED) Cybersecurity Incident NSEB IR-01 Attachment 4 Page 1 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) CYBER INCIDENT UPDATES NEWS July 8, 2025 Since the cyber incident discovered on April 25, power m...

AI summary Following a cyber incident discovered on April 25, NS Power has been unable to communicate data from power meters to their systems, leading to paused and estimated billing. Meter readers are now being deployed to collect actual energy usage data to resume accurate billing.

Section 54
REMOVED) Cybersecurity Incident NSEB IR-01 Attachment 4 Page 2 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) Wednesday, June 25, 2025 Update A dedicated team within Nova Scotia Power, along with third-party...

AI summary Nova Scotia Power is updating customers about the ongoing investigation into a ransomware attack that affected personal data of both current and former customers. The company is offering five years of free credit monitoring to all customers and has confirmed that personal information was accessed on or around March 19, 2025.

Section 55
and customer correspondence), and driver’s license number. For some of our former customers, bank account numbers (for pre-authorized payment) and Social Insurance Numbers may also have been impacted. We intend to do everything we can to s...

AI summary Nova Scotia Power has experienced a cybersecurity incident impacting customer data, including personal and financial information. The company is offering expanded credit monitoring services and is advising customers to be cautious of unsolicited communications to prevent identity theft.

Section 56
to be from Nova Scotia Power asking you to provide your personal information. Please avoid clicking on suspicious links or downloading attachments without confirming they are from a legitimate source. We have heard concerns about SINs, whi...

AI summary Nova Scotia Power is addressing a cybersecurity incident involving the collection of SINs and is cooperating with the Office of the Privacy Commissioner of Canada and the Nova Scotia Energy Board. The company is committed to transparency and is working to regain customer confidence.

Section 57
on and response efforts remain ongoing, we have committed to be as open and transparent as possible. This meeting today is a part of that transparency. Opening remarks by Peter Gregg, President & CEO On behalf of our entire team at Nova Sc...

AI summary Nova Scotia Power's President and CEO, Peter Gregg, discusses a cybersecurity incident affecting the company and its customers. He emphasizes the company's commitment to transparency and ongoing efforts to address the breach and strengthen systems. The incident is described as a sophisticated attack by a criminal, with data stolen from the company's systems.

Section 58
N REMOVED) Cybersecurity Incident NSEB IR-01 Attachment 4 Page 5 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) The privacy commissioner of Canada stated last week that: “Data breaches have surged over the p...

AI summary Nova Scotia Power discusses a recent cybersecurity incident, emphasizing their commitment to cybersecurity and alignment with NIST and NERC standards. They mention no payments to criminals and describe their response protocols, including engaging third-party experts and isolating affected systems.

Section 59
ng swift actions to contain and isolate the affected systems to prevent further intrusion. Our cybersecurity program ensured that our operations systems and electric grid continue to perform as usual. As you know, the criminals stole data,...

AI summary Nova Scotia Power has taken steps to contain a cybersecurity incident, ensuring grid operations continue normally. The breach involved the theft of customer data, and affected individuals have been notified with offers of free credit monitoring. Investigations are underway by the Nova Scotia Energy Board and the Office of the Privacy Commissioner of Canada.

Section 60
ns of the incident have been initiated by both the Nova Scotia Energy Board and the Office of the Privacy Commissioner of Canada. Nova Scotia Power will fully cooperate with both of these proceedings. You have my commitment that our team i...

AI summary Nova Scotia Power has confirmed a ransomware attack and is working with cybersecurity experts to restore systems and investigate. No payment has been made to the threat actor, and data has been published by the threat actor. The incident is being investigated by the Nova Scotia Energy Board and the Office of the Privacy Commissioner of Canada.

Section 61
the threat actor has published data that was stolen from our systems. We are actively working with cybersecurity experts to assess the nature and scope of the information that may have been impacted. Notifications have been mailed to impac...

AI summary Nova Scotia Power is investigating a cybersecurity incident that has impacted certain IT systems. They are working with external experts to determine the scope of the impact and restore systems. Affected customers have been notified and provided with free credit monitoring services.

Section 62
as impacted certain IT systems in our network. We are working with external cybersecurity experts to determine the scope of the impact and safely and securely restore and rebuild our impacted systems. While the investigation remains ongoin...

AI summary Nova Scotia Power experienced a cybersecurity incident where customer information was accessed and taken by an unauthorized third party on or around March 19, 2025. Affected customers are being notified and offered free credit monitoring. The company is working with cybersecurity experts to restore systems and is advising customers to be cautious of unsolicited communications.

Section 63
be from Nova Scotia Power asking you to provide your personal information. Please avoid clicking on suspicious links or downloading attachments without confirming they are from a legitimate source. 8 REDACTED (CONFIDENTIAL INFORMATION REMO...

AI summary Nova Scotia Power detected a cyber incident on April 25, 2025, and has initiated an investigation with external cybersecurity experts. The incident involved unauthorized access to customer personal information, and law enforcement has been notified. Customers are being informed and provided with credit monitoring services.

Section 64
very seriously. The security of your information is our top priority. We are working urgently to determine the full nature and scope of the data that may have been affected, and individuals impacted. If we determine that your data was affe...

AI summary Nova Scotia Power and Emera Inc. have discovered a cybersecurity incident involving unauthorized access to parts of their Canadian network and servers. The incident has not disrupted operations, but the company is investigating and advising customers to be cautious of unsolicited communications.

Section 65
iscovered and are actively responding to a cybersecurity incident involving unauthorized access into certain parts of its Canadian network and servers supporting portions of its business applications. Immediately following detection of the...

AI summary Nova Scotia Power is responding to a cybersecurity incident involving unauthorized access to parts of its Canadian network and servers. The company has activated incident response protocols, engaged cybersecurity experts, and contained the affected systems. No disruption to physical operations or customer service has been reported, and no material financial impact is expected.

Section 66
curity Incident NSEB IR-01 Attachment 4 Page 12 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) LATEST UPDATES July 8, 2025 • Power meters have continued to function and gather accurate energy usage data from...

AI summary Nova Scotia Power is updating customers about the ongoing cyber incident affecting their power meters. Meters are functioning but cannot communicate data, leading to estimated billing. Meter readers are now visiting homes to collect accurate data, and customers are being informed about the process and what to expect.

Section 68
• We are focused on supporting our customers. We are here for regular business from 8 AM–6 PM, Monday through Friday. Please contact us at 1-800-428-6230. Wednesday, June 5, 2025 • Nova Scotia Power leadership appeared before the Nova Scot...

AI summary Nova Scotia Power experienced a ransomware attack, leading to stolen customer data. The company did not make a ransom payment, complied with sanctions laws, and is working with cybersecurity experts and law enforcement to restore systems and support affected customers.

Section 69
been impacted. • Since the incident began several weeks ago, we have been actively working with the assistance of third-party cyber security experts to restore our systems safely 13 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Cybersecurity...

AI summary Nova Scotia Power has experienced a cybersecurity incident and is working with third-party experts to restore systems and investigate the breach. Affected customers have been notified and provided with free credit monitoring services. The company expressed regret over the incident and emphasized its commitment to protecting customer data.

Section 70
ely sorry that this issue has occurred. Protecting the privacy and security of information held by Nova Scotia Power is something we take very seriously. Wednesday, May 14, 2025 • Nova Scotia Power continues to investigate a cyber incident...

AI summary Nova Scotia Power is investigating a cyber incident that compromised customer information stored on impacted servers. The breach occurred around March 19, 2025, and affected personal information varies by customer. Notifications are being sent to impacted account holders, and a two-year credit monitoring service is being provided at no cost.

Section 71
systems in our network. • While our investigation is ongoing, we have identified that certain customer personal information was accessed and taken by an unauthorized third party. 14 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Cybersecurity...

AI summary Nova Scotia Power is informing customers of a cybersecurity incident where personal information was accessed by an unauthorized third party. The investigation is ongoing, and customers will be notified if their data was affected, with resources and support provided.

Section 72
ou to provide your personal information. Please avoid clicking on suspicious links or downloading attachments without confirming they are from a legitimate source. Monday, April 28, 2025 • Emera and Nova Scotia Power discovered and are act...

AI summary Emera and Nova Scotia Power discovered a cybersecurity incident involving unauthorized access to parts of their network and servers. They have activated incident response protocols and engaged third-party experts to contain the breach, with no disruption to physical operations or customer service.

Section 73
4 Page 16 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) FAQS What happened? Last updated: Tuesday, June 24, 2025 On April 25, we discovered and began actively responding to a cybersecurity incident involvin...

AI summary Nova Scotia Power experienced a ransomware attack on April 25, 2025, leading to unauthorized access to customer personal information. No ransom was paid due to legal restrictions. The company is working with cybersecurity experts and law enforcement to investigate and remediate the incident.

Section 74
ION REMOVED) Cybersecurity Incident NSEB IR-01 Attachment 4 Page 17 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) • Informed impacted customers via mail and provided a free subscription to TransUnion’s cred...

AI summary Nova Scotia Power informed impacted customers about a cybersecurity incident where personal information was accessed and published on the dark web. The company is offering free credit monitoring to all customers and has resumed billing through estimated methods. The investigation is ongoing, and the ransomware attack has complicated the restoration process.

Section 75
s of Nova Scotia Power—past and present—regardless of whether you received a letter from us about the incident. I’m a current customer, but I did not get a letter. Does that mean I was not affected? 17 REDACTED (CONFIDENTIAL INFORMATION RE...

AI summary Nova Scotia Power is offering five years of free credit monitoring to all current and past customers following a cybersecurity incident, regardless of whether they received a letter about the incident. Customers who already signed up for two years will be automatically extended to five years. The company is expanding the offer to ensure customer protection and reassurance.

Section 76
a code and already signed up for two years of monitoring, you will be automatically extended to five years. Why didn’t you offer credit monitoring to everyone right away when this happened? Why now? Last updated: Wednesday, June 25, 2025 O...

AI summary Nova Scotia Power is expanding free credit monitoring to all customers, including former ones, following a data breach. They initially targeted confirmed affected customers but now aim to ensure broader protection. Efforts are underway to reach former customers without contact information through media and advertising.

Section 77
as broadly as possible. We are actively sharing this information with media, on social media, with stakeholders, and through paid advertising to reach as many current and former customers as possible. We strongly encourage anyone who is co...

AI summary Nova Scotia Power (NSPI) is informing customers about a cybersecurity incident affecting IT systems and customer care, leading to disruptions in billing and online portal access. NSPI is offering free credit monitoring and encourages sharing information with former customers. The NSEB is conducting an inquiry into the incident.

Section 78
nquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL 1 Request IR-2: 2 3 NS Power’s Thursday, May 1, 2025, cybersecurity update letter stated: 4 While our investi...

AI summary Nova Scotia Power is responding to an inquiry regarding a cybersecurity incident that may have affected customer personal information. The company is still investigating and has not yet confirmed the number of affected customers or whether former customers were impacted.

Section 79
been complex given the severe nature of Date Filed: September 5, 2025 NSPI (NSEB) IR-2 Page 1 of 2 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NS...

AI summary Nova Scotia Power (NSPI) is responding to the NSEB's inquiry regarding a cybersecurity incident that may have impacted all of its customers. The company has offered free credit monitoring for five years and has notified approximately 277,000 active customers about the incident.

Section 80
d Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED 1 Request IR-3: 2 3 NS Power, in its Thursday, May 14, 2025, cybersecurity update letter stated: 4 5 Beginning tod...

AI summary The NSEB is inquiring about Nova Scotia Power's cybersecurity incident, focusing on how the utility determined no misuse of personal information, communication with customers, and the selection of credit monitoring services. Specific questions address notice letters, service components, and costs.

Section 81
lease list the components of this service and provide comment of their 30 appropriateness. 31 (ii) What is the cost of two-year and five-year service to the utility? 32 Date Filed: September 5, 2025 NSPI (NSEB) IR-3 Page 1 of 7 REDACTED (C...

AI summary The document outlines a series of inquiries related to Nova Scotia Power's response to a cybersecurity incident, focusing on credit monitoring periods, customer protection, and communication efforts. It includes questions about the appropriateness of service components and the cost of two-year and five-year monitoring services.

Section 82
CTED (CONFIDENTIAL INFORMATION REMOVED) Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The document outlines the Nova Scotia Energy Board's inquiry into a cybersecurity incident involving Nova Scotia Power, along with NSPI's responses to information requests. The content is redacted and contains confidential information.

Section 83
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The document outlines an inquiry into Nova Scotia Power's cybersecurity incident (NSEB M12273), focusing on NSPI's responses to information requests by the Nova Scotia Energy Board. The content is redacted, limiting detailed analysis.

Section 85
direct notifications, the Company sent two versions of letters to impacted 25 current customers, samples of which are attached as Attachments 1 and 2 to IR-1. The 26 notices are identical, except that one of the notices indicates that base...

AI summary Nova Scotia Power (NSPI) provided two versions of letters to impacted customers regarding a cybersecurity incident, with one letter indicating potential impact on customers' social insurance numbers. TransUnion’s myTrueIdentity® service is highlighted as a credit monitoring and identity protection service.

Section 86
d Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The document outlines an inquiry into Nova Scotia Power's (NSPI) cybersecurity incident, referencing responses provided to Nova Scotia Energy Board (NSEB) information requests. The matter is designated as NSEB M12273, with content redacted beyond the heading and entity mentions.

Section 87
1 notification and call centre services to companies which have been the victim of security 2 incidents The credit monitoring service offered to customers is provided by TransUnion 3 and has been specifically designed to protect individual...

AI summary The text outlines a credit monitoring service provided by TransUnion to individuals affected by data breaches, offering features such as credit reports, credit scores, credit monitoring, educational resources, identity restoration assistance, expense reimbursement insurance, and dark web monitoring.

Section 88
ring, which monitors surface, social, deep, and dark websites for 28 potentially exposed personal, identity and financial information and helps protect 29 individuals against identity theft. 30 Date Filed: September 5, 2025 NSPI (NSEB) IR-...

AI summary The document outlines a regulatory inquiry into a cybersecurity incident at Nova Scotia Power, with responses provided by NSPI to information requests from the Nova Scotia Energy Board. The inquiry involves confidential information that has been redacted.

Section 89
rd Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED 1 Nova Scotia Power anticipates that a portion of the cost for credit monitoring will be 2 covered by insurance,...

AI summary Nova Scotia Power (NSPI) is offering complimentary credit monitoring services to affected customers following a cybersecurity incident. The company extended the service to five years, citing customer feedback and concerns, and stated that insurance will cover part of the cost, ensuring customers do not bear any financial burden.

Section 90
ast 30 NS Power customers. Date Filed: September 5, 2025 NSPI (NSEB) IR-3 Page 5 of 7 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Informatio...

AI summary The document outlines NSPI's responses to information requests from the NSEB regarding a cybersecurity incident involving NS Power customers. The inquiry was filed on September 5, 2025, and includes redacted confidential information.

Section 91
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The document outlines an inquiry into Nova Scotia Power's cybersecurity incident (NSEB M12273), focusing on NSPI's responses to information requests by the Nova Scotia Energy Board. The content is redacted, limiting detailed analysis.

Section 93
,000 of expense reimbursement insurance related to identity theft. 27 28 • Dark Web Monitoring, which monitors surface, social, deep, and dark websites for 29 potentially exposed personal, identity and financial information and helps prote...

AI summary The document outlines Nova Scotia Power's responses to the NSEB's information requests regarding a cybersecurity incident. It includes details on expense reimbursement insurance related to identity theft and Dark Web Monitoring services aimed at protecting individuals from identity theft.

Section 94
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL

AI summary The document outlines an inquiry into a cybersecurity incident involving Nova Scotia Power, with responses provided to information requests by the Nova Scotia Energy Board. The text is marked as non-confidential.

Section 96
nd 28 comprehensive solution. Date Filed: September 5, 2025 NSPI (NSEB) IR-4 Page 1 of 1 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Informa...

AI summary Nova Scotia Power (NSPI) responded to a request regarding credit monitoring services, clarifying that the service was not intended as a financial reimbursement and that customers would not be charged for the service regardless of participation.

Section 97
nquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL

AI summary The document outlines an inquiry into Nova Scotia Power's cybersecurity incident, referencing NSEB M12273 and NSPI's responses to NSEB information requests. It is marked as non-confidential.

Section 98
1 Request IR-6: 2 3 NS Power, in its Thursday, May 14, 2025, cybersecurity update letter stated: 4 5 The types of impacted personal information varied by individual customer and 6 depended, in part, on the information provided by each cust...

AI summary The document discusses a cybersecurity incident involving Nova Scotia Power, outlining the types of personal information potentially compromised. It also raises questions about the process for customers to obtain details about their compromised information, the reasons for not sending personalized letters, and the availability of customer support.

Section 99
eived by the Board and filed as Letters of Comment have noted that 31 the dedicated number (1-844-818-0376) connects users to TransUnion instead of NS 32 Power representatives: 33 Date Filed: September 5, 2025 NSPI (NSEB) IR-6 Page 1 of 3...

AI summary The document discusses a cybersecurity incident involving Nova Scotia Power (NSPI) and the Nova Scotia Energy Board (NSEB) inquiry into the incident. It mentions a dedicated phone number that incorrectly connects to TransUnion instead of NS Power representatives.

Section 100
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL

AI summary This document outlines an inquiry into a cybersecurity incident involving Nova Scotia Power, with responses provided by NSPI to information requests from the Nova Scotia Energy Board (NSEB).

Section 102
scalated queries, this call centre was staffed by TransUnion, which 29 had been provided with prepared responses from NS Power, and instructed to escalate any 30 queries that could not be addressed to the Company so that customers could re...

AI summary Nova Scotia Power (NSPI) used TransUnion to manage a call centre for customer inquiries related to a cybersecurity incident. TransUnion was provided with prepared responses from NS Power and instructed to escalate unresolved queries to the company. This arrangement allowed for flexible staffing and direct customer support for credit monitoring services.

Section 103
iry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL 1 Request IR-7: 2 3 NS Power’s Thursday, May 23, 2025, cybersecurity update letter stated: 4 5 Notifications hav...

AI summary Nova Scotia Power (NSPI) has responded to information requests regarding resources and support provided to impacted account holders following a cybersecurity incident. The response includes customer support measures, guidance on credit monitoring registration, and outreach through various channels.

Section 104
locations throughout the province. This Date Filed: September 5, 2025 NSPI (NSEB) IR-7 Page 1 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NS...

AI summary Nova Scotia Power (NSPI) has taken multiple steps to assist customers in signing up for a credit monitoring service following a cybersecurity incident. These include distributing fact sheets, providing in-person support, and updating the website with additional resources.

Section 105
signing up for the service. The NS Power website also has been updated with additional 17 tips and tools to help customers navigate support services. 18 19 Credit Monitoring 20 NS Power’s notice to impacted customers included guidance for...

AI summary NS Power has taken steps to support impacted customers following a cybersecurity incident, including offering complimentary credit monitoring services for five years. The NSPI has responded to information requests from the NSEB regarding the incident.

Section 106
nquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL

AI summary The document outlines an inquiry into a cybersecurity incident at Nova Scotia Power, referencing NSEB M12273 and NSPI's responses to information requests from the Nova Scotia Energy Board.

Section 108
ntinued to keep customers updated regarding the ongoing incident 28 and investigation. See response to IR-1 for additional details on NS Power’s customer 29 communication efforts. Date Filed: September 5, 2025 NSPI (NSEB) IR-7 Page 3 of 4...

AI summary Nova Scotia Power (NSPI) has been communicating with customers about a cybersecurity incident and provided guidance to protect against identity theft or fraud. Information was shared via mailed letters and made available on the NSPI website.

Section 109
nquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL

AI summary The document outlines an inquiry into a cybersecurity incident involving Nova Scotia Power, with responses provided by NSPI to information requests from the Nova Scotia Energy Board (NSEB).

Section 111
monitoring service. The community partners or stakeholders who have reached 29 out to the Company worked to share that information with the people and groups they heard 30 from. Date Filed: September 5, 2025 NSPI (NSEB) IR-8 Page 1 of 2 RE...

AI summary The document discusses NSPI's responses to the NSEB's inquiry regarding a cybersecurity incident, including the existence of a communication policy for such incidents. NSPI provides a 'Cyber Incident Communication Playbook' as part of its response.

Section 112
as Board Confidential 14 Attachment 1. Date Filed: September 5, 2025 NSPI (NSEB) IR-9 Page 1 of 1 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Cybersecurity Incident NSEB IR-9 Attachment 1 has been removed due to confidentiality. REDACTED (...

AI summary The document outlines a Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) and includes NSPI's responses to NSEB Information Requests. The content is labeled as non-confidential and includes an attachment that was redacted due to confidentiality.

Section 113
uiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL

AI summary The document pertains to an inquiry into a cybersecurity incident involving Nova Scotia Power, with responses provided by NSPI to information requests from the Nova Scotia Energy Board (NSEB). The matter is referenced as NSEB M12273.

Section 114
1 Request IR-10: 2 3 (a) Please list the customer services, such as pole relocation and new connection service 4 requests, that have been impacted by this breach due to the shifting of resources away 5 from these activities to support NS P...

AI summary NS Power responded to a request about customer service impacts due to a cybersecurity breach, stating there was no disruption to generation, transmission, or distribution. They acknowledged challenges in customer communication initially but resolved the issue by May 5, 2025, and implemented workarounds for service requests.

Section 115
mpany during a limited timeframe. The team worked quickly to 29 address this and implemented a workaround for customers requiring service hook-ups, 30 service closures, or moves. Date Filed: September 5, 2025 NSPI (NSEB) IR-10 Page 1 of 2...

AI summary The document refers to a cybersecurity incident at Nova Scotia Power and the subsequent Board Inquiry (NSEB M12273), along with NSPI's responses to information requests from the NSEB. A team implemented a workaround for customers needing service hook-ups, closures, or moves during a limited timeframe.

Section 116
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL 1 This was communicated via the NS Power website on April 30th, and the Company 2 continued to provide servi...

AI summary Nova Scotia Power (NSPI) responded to the NSEB's inquiry regarding a cybersecurity incident by expanding customer care services, providing online workarounds, and establishing an incident response line. The company continued to provide essential services and manage customer inquiries throughout the incident.

Section 118
nquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL 1 Request IR-12: 2 3 Board staff understands the billing of many customers was affected by the breach, and th...

AI summary The inquiry addresses a cybersecurity incident affecting Nova Scotia Power's billing systems, leading to delayed and inflated bills for customers. NSPI confirms that billing issues are being resolved, estimated bills were issued to prevent large unexpected bills, and customers were not charged penalties or faced credit impacts.

Section 120
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL

AI summary The document outlines an inquiry into Nova Scotia Power's cybersecurity incident, with NSPI providing responses to information requests from the NSEB. The inquiry is referenced as NSEB M12273.

Section 122
ly to ensure that the meters are 24 safely reconnected with the system. The Company continues to work diligently to resolve 25 this as soon as possible. The use of manual meter reading is a temporary measure that was 26 implemented to prod...

AI summary Nova Scotia Power (NSPI) is addressing a cybersecurity incident and is working to restore automated meter reading processes, currently using manual readings as a temporary measure. The NSEB has initiated a Board Inquiry into the incident, and NSPI has provided responses to information requests.

Section 123
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL

AI summary The document outlines an inquiry into a cybersecurity incident involving Nova Scotia Power, with NSPI providing responses to information requests from the Nova Scotia Energy Board (NSEB).

N-3Incident Report - Redacted 90 passages
Section 1
REDACTED (CONFIDENTIAL INFORMATION REMOVED) Nova Scotia Energy Board IN THE MATTER OF The Public Utilities Act, R.S.N.S. 1989, c.380, as amended M12273 Board Inquiry into Nova Scotia Power’s Cybersecurity Incident Nova Scotia Power Inciden...

AI summary This document outlines Nova Scotia Power's cybersecurity incident report, submitted under the Public Utilities Act. The inquiry investigates the incident, including affected systems, data breaches, response actions, and customer communications. Key details are redacted due to confidentiality.

Section 2
..................................................... 14 10 4.2 Communications to Customers ......................................................................................... 18 11 4.3 Other Stakeholders ...............................

AI summary The document outlines a regulatory proceeding structure, including sections on stakeholder communication, personal information handling, impact analysis, and recommendations for enhancing cybersecurity, policy updates, and customer engagement. It references a specific direction (M12457) and emphasizes data privacy, security measures, and procedural improvements.

Section 3
.............................................................. 38 23 8.5 Collection and Retention of Personal Information ........................................................... 40 24 9.0 CONCLUSION .......................................

AI summary The document references a redacted 2025 cybersecurity incident report by Nova Scotia Power, filed on December 22, 2025. The report's content is confidential, with no details provided about the incident or its implications.

Section 4
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 1.0 INTRODUCTION 2 3 In its July 14, 2025 letter regarding the cybersecurity incident (Incident) experienced by Nova 4 Scotia Pow...

AI summary The Nova Scotia Energy Board (NSEB) requires Nova Scotia Power Inc. (NS Power) to submit a cybersecurity incident report detailing the 2025 incident, including affected systems, root causes, and recovery actions. The NSEB also directed NS Power to settle vendor dues and engage MNP to investigate financial technology data compromise and data handling practices.

Section 5
va Scotia Power’s Cybersecurity Incident, NSEB Letter, July 14, 2025, page 1. 2 M12273, NSEB Letter, July 14, 2025, pp. 2-3. 3 M12273, NSEB Letter, November 7, 2025, pp. 1-2. DATE FILED: December 22, 2025 Page 3 of 43 REDACTED (CONFIDENTIA...

AI summary Nova Scotia Power (NS Power) is required to submit a cybersecurity incident report, including a Gantt chart detailing recovery tasks, timelines, and progress. The Nova Scotia Energy Board (NSEB) has issued letters (M12273) requesting this information, emphasizing transparency and accountability in incident management.

Section 7
M12273, NSEB Letter, November 7, 2025, p. 2. 5 M12600, Minister of Energy – Accountability for Nova Scotia Power Inc., Minister of Energy Letter, December 3, 2025. DATE FILED: December 22, 2025 Page 4 of 43 REDACTED (CONFIDENTIAL INFORMATI...

AI summary A redacted cybersecurity incident report from Nova Scotia Power Inc. (NSP) is referenced in regulatory filings (M12273, M12600). The report, dated December 2025, was submitted to the Nova Scotia Energy Board (NSEB) and the Minister of Energy. Key details remain confidential, with no explicit claims or arguments presented in the provided text.

Section 8
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power (NSP) is referenced, though specific details are confidential. The document pertains to cybersecurity measures and incidents within the organization.

Section 9
1 The NSEB replied to the Premier by letter on December 10, 2025, providing, in part, the following: 2 Upon receipt of your letter, the Board opened a new matter (M12600). Given the 3 connection between these issues and the Board’s ongoing...

AI summary The NSEB opened a new matter (M12600) related to issues raised by the Premier, linking it to an ongoing cybersecurity inquiry (M12273). NS Power argues that many issues, including customer billing and communications, were addressed in prior reports and that M12273 is the appropriate proceeding. The NSEB also provided additional direction due to a customer complaint (M12457).

Section 11
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 2.0 THE INCIDENT 2 3 In its letter of July 14, 2025, the NSEB directed the following be included in the Report regarding 4 the In...

AI summary NS Power's 2025 cybersecurity incident report details a sophisticated breach discovered on April 25, 2025, following system outages. The NSEB directed inclusion of breach discovery, attack vectors, timeline, evidence, vulnerabilities, and breach causation. The incident involved unauthorized access to IT systems supporting business applications.

Section 12
etter, July 14, 2025, p. 2. DATE FILED: December 22, 2025 Page 7 of 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSP) was filed on December 22, 2025, as part of a regulatory proceeding. The document details a cybersecurity incident, though specific information has been confidentially removed.

Section 13
f 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSP) is referenced, indicating confidential information related to a cybersecurity event involving NSP. The document's content is not disclosed due to confidentiality.

Section 14
1 Immediately following detection of the Incident, NS Power activated its established incident 2 response and business continuity protocols, engaging Osler, and through Osler, Mandiant’s 3 cybersecurity and incident response team. 4 5 Unde...

AI summary NS Power responded to a cybersecurity incident by activating protocols and engaging Osler and Mandiant for containment and remediation. The breach, believed to have occurred in March-April 2025, involved data exfiltration, including customer information. NS Power notified law enforcement, cybersecurity agencies, and the Office of the Privacy Commissioner of Canada.

Section 15
ny also notified the Federal Bureau 25 of Investigation (FBI). 26 27 NS Power also reported the Incident to the Office of the Privacy Commissioner of Canada (OPC) 28 on May 1, 2025, with an update on May 14, 2025. The OPC initiated an inve...

AI summary NS Power reported a cybersecurity incident to the FBI and OPC, with the OPC initiating an investigation. The incident began on March 19, 2025, and NS Power isolated affected systems on April 25, 2025. No operational disruptions were caused, and the company is cooperating with the OPC.

Section 16
customers in Nova Scotia. DATE FILED: December 22, 2025 Page 10 of 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 3.0 AFFECTED SYSTEMS AND DATA 2 3 In its letter of July 14,...

AI summary NS Power's 2025 cybersecurity incident report details compromised systems including ERP platforms (PeopleSoft, PowerPlan, Oracle E-Business Suite) and customer billing systems (MyAccount, Advanced Metering Infrastructure Head End System). The report follows NSEB directives to disclose affected systems and data, referencing a July 2025 NSEB letter (M12273).

Section 17
3 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 • Additional systems: 2 o Aligne Fuels/Plant Information (PI) 3 o Geospatial Information System 4 o Adept Restoration 5 o Certa...

AI summary The document is a 2025 cybersecurity incident report by Nova Scotia Power, listing affected systems and tools, including additional systems, cybersecurity technologies, and data center infrastructure. It references Appendix A for detailed restoration timelines.

Section 18
3 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 3.2 Data & Personal Information 2 3 The process to 4 identify the customers who were directly impacted has been extremely compl...

AI summary NS Power's 2025 cybersecurity incident report details the complexity of identifying impacted customers and the types of personal data accessed, including names, contact information, account history, and sensitive identifiers like SIN. The company issued notifications to affected customers, clarifying the scope of data exposure.

Section 19
cted by the Incident. DATE FILED: December 22, 2025 Page 13 of 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 4.0 RESPONSE AND RECOVERY ACTIONS 2 3 In its letter of July 14,...

AI summary NS Power outlines its response to a 2025 cybersecurity incident, including containment measures, engagement with third-party experts, stakeholder communication, and analysis of response effectiveness. The NSEB directed inclusion of these actions in the report.

Section 20
g a thorough analysis to 25 understand the full scope and nature of the Incident. 26 27 Immediate remediation actions were taken: 28 12 M12273, NSEB Letter, July 14, 2025, p. 2. DATE FILED: December 22, 2025 Page 14 of 43 REDACTED (CONFIDE...

AI summary NS Power is addressing a 2025 cybersecurity incident through immediate remediation, system restoration, and enhanced security protocols. A Recovery Process Office (RPO) was established to coordinate efforts, focusing on restoring core business systems and strengthening cybersecurity infrastructure.

Section 21
21 22 23 24 25 26 27 28 29 30 DATE FILED: December 22, 2025 Page 16 of 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A redacted cybersecurity incident report by Nova Scotia Power (NSP) was filed on December 22, 2025. The document is marked as confidential, with sensitive information removed. The proceeding appears to involve NSP's disclosure of a cybersecurity incident to regulatory authorities.

Section 22
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power (NSP) is referenced, though specific details are confidential. The document pertains to cybersecurity measures and incidents within the organization.

Section 23
1 Existing Safeguards 2 3 At the time of the Incident, NS Power had implemented a common set of cybersecurity standards 4 and policies that are informed, in part, by the National Institute of Standards and Technology’s 5 (NIST) Cybersecuri...

AI summary NS Power implemented cybersecurity standards aligned with NIST and NERC, including five core functions: Identify, Protect, Detect, Respond, and Recover. The company updated its practices over two years to comply with evolving guidelines and industry-specific rules.

Section 24
and IT 28 including, but not limited to, those mandated by the North American Electric Reliability 29 Corporation (NERC). NERC conducts extensive periodic audits (including security) of the 30 Company’s Energy Operations to ensure effectiv...

AI summary The text references North American Electric Reliability Corporation (NERC) audits of Nova Scotia Power's Energy Operations for compliance, including cybersecurity. A redacted 2025 cybersecurity incident report is mentioned, though details are confidential.

Section 25
f 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSP) is referenced, indicating confidential information related to a cybersecurity event involving NSP. The document's content is not disclosed due to confidentiality.

Section 26
1 NS Power maintains a cybersecurity training and awareness program and conducts mandatory 2 quarterly cyber training and monthly phishing simulation testing exercises with all employees to 3 educate employees about NS Power’s information...

AI summary NS Power implements mandatory cybersecurity training and phishing simulations for employees. It also employs multi-channel communication strategies to inform customers about data breaches, emphasizing transparency and customer-centric support through various media platforms.

Section 27
rch strategy throughout the Incident to 28 ensure that the NS Power website and information appeared as the top search result when 29 customers used search engines (i.e. Google) to find information about the Incident. This paid 30 search s...

AI summary NS Power implemented a paid search strategy to ensure its website was the top search result for customers querying the Incident, aiming to mitigate fraud risks. The approach focused on maintaining visibility and controlling information dissemination during the cybersecurity incident.

Section 28
3 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 official Nova Scotia Power website. Social media accounts have been regularly updated and 2 monitored, and where appropriate, t...

AI summary Nova Scotia Power (NSP) reported a 2025 cybersecurity incident, notifying customers via multi-channel communication starting April 28, 2025. On May 13, 2025, NSP directly informed ~277,000 affected customers, detailing impacted personal information and initiating third-party assistance for notifications.

Section 29
28 29 On May 13, 2025, NS Power sent direct notices to approximately 277,000 current customers whose 30 personal information the Company was able to determine had been impacted in this incident. DATE FILED: December 22, 2025 Page 19 of 43...

AI summary NS Power notified 277,000 customers on May 13, 2025, about a cybersecurity incident impacting their personal information. The report was filed confidentially on December 22, 2025, as part of a regulatory proceeding.

Section 30
43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 Nova Scotia Power cybersecurity incident report is redacted, with confidential information removed. The document outlines a cybersecurity incident but provides no further details due to redaction.

Section 31
1 The following morning (May 14, 2025), the Company also issued a press release, provided a 2 detailed update on its website, and updated its various social media accounts, which received 3 widespread coverage in the local and national med...

AI summary NS Power informed customers about an incident through media and provided credit monitoring services via TransUnion to mitigate risks like fraud. They offered two years of complimentary services, including credit reports and alerts.

Section 32
d provide them with additional reassurance. 26 27 • Access to online educational resources concerning credit management, fraud victim 28 assistance and identity theft prevention. 29 DATE FILED: December 22, 2025 Page 20 of 43 REDACTED (CON...

AI summary The document references a 2025 cybersecurity incident report by Nova Scotia Power, though the content is redacted. It includes a date filed (December 22, 2025) and mentions access to online resources for credit management and fraud prevention, though these details are not elaborated.

Section 33
43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 Nova Scotia Power cybersecurity incident report is redacted, with confidential information removed. The document outlines a cybersecurity incident but provides no further details due to redaction.

Section 34
1 • Access to Identity Restoration agents who are available to assist individuals with questions 2 about identity theft. In the unlikely event that an individual becomes a victim of fraud, a 3 personal restoration specialist will help to r...

AI summary NS Power provided identity theft assistance, $1M expense reimbursement insurance, and dark web monitoring to customers affected by a 2025 cyber incident. Updates were shared via website and media, and credit monitoring was extended to former customers. The company proactively mitigated risks through these measures.

Section 35
dit monitoring offer to five years 28 for all current and former customers. Customers who had already registered for credit monitoring 29 had their monitoring timeframe automatically extended. 30 DATE FILED: December 22, 2025 Page 21 of 43...

AI summary Nova Scotia Power extended credit monitoring for five years for all current and former customers, with existing registrants automatically extended. A 2025 cybersecurity incident report is mentioned but redacted.

Section 36
43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 Nova Scotia Power cybersecurity incident report is redacted, with confidential information removed. The document outlines a cybersecurity incident but provides no further details due to redaction.

Section 38
is standard in incidents of this nature, to ensure that the call centre had sufficient capacity to 30 handle the volume of calls and allow NS Power’s customer service team to focus on a subset of DATE FILED: December 22, 2025 Page 22 of 43...

AI summary The document references a 2025 Nova Scotia Power cybersecurity incident report, noting redacted details. It highlights efforts to ensure call center capacity to manage call volumes, allowing NS Power's customer service team to focus on specific tasks.

Section 39
43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 Nova Scotia Power cybersecurity incident report is redacted, with confidential information removed. The document outlines a cybersecurity incident but provides no further details due to redaction.

Section 41
age with customers on reliability 23 and other customer topics of interest. 24 25 In addition, the NS Power website was updated with additional tips and tools to help customers 26 navigate support services and a fact sheet was created with...

AI summary NS Power has implemented customer outreach initiatives to improve reliability and provide guidance on identity theft protection. A cybersecurity incident report was filed in December 2025, though the details are redacted.

Section 42
43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 Nova Scotia Power cybersecurity incident report is redacted, with confidential information removed. The document outlines a cybersecurity incident but provides no further details due to redaction.

Section 44
omepage of the company’s website. In December 2025, 25 sessions have been held in Yarmouth, Port Hawkesbury and Truro, helping dozens of customers 26 with their bills. Additional sessions, originally scheduled for December but postponed du...

AI summary Nova Scotia Power Inc. has held customer billing sessions in multiple locations, with additional sessions planned for January 2026. A cybersecurity incident report for 2025 has been filed, though its contents are redacted.

Section 45
f 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSP) is referenced, indicating confidential information related to a cybersecurity event involving NSP. The document's content is not disclosed due to confidentiality.

Section 47
o this incident will 23 include a review of lessons learned, including a review of communications with customers. 24 25 4.3 Other Stakeholders 26 27 NS Power employees have been a key stakeholder audience throughout the Incident, as they w...

AI summary The incident review includes examining lessons learned and customer communications. NS Power employees, as both employees and customers, received ongoing updates via emails and in-person briefings from leadership and supervisors during the response and restoration efforts.

Section 48
f 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSP) is referenced, indicating confidential information related to a cybersecurity event involving NSP. The document's content is not disclosed due to confidentiality.

Section 49
1 investigation, employees were made aware of the latest information and what to expect in terms 2 of public information, increased media coverage, and senior officials appearing before various 3 provincial government committees. Where app...

AI summary NS Power communicated with employees and stakeholders during a cyber incident, providing updates on the response, payroll restoration, and establishing a new SharePoint site for information. Key stakeholders, including Efficiency Nova Scotia and NERC, were also informed.

Section 50
unities. 22 NS Power also notified NERC, the Electricity Information Sharing and Analysis Center (E-ISAC), 23 and the Northeast Power Coordinating Council, and provided them with information about the 24 Incident. 25 26 As noted above, NS...

AI summary NS Power reported a cybersecurity incident to multiple organizations, including NERC, E-ISAC, and law enforcement agencies such as RCMP and CSIS, highlighting the severity and critical nature of the attack.

Section 51
43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 Nova Scotia Power cybersecurity incident report is redacted, with confidential information removed. The document outlines a cybersecurity incident but provides no further details due to redaction.

Section 52
1 infrastructure nature of the company and the North American electric utility industry, the Company 2 also notified the Federal Bureau of Investigation (FBI). 3 4 NS Power also reported the Incident to the Office of the Privacy Commission...

AI summary NS Power reported a cybersecurity incident to the FBI and OPC, and described its response as effective due to prior preparedness, including third-party expertise, updated incident-response plans, and simulation exercises.

Section 53
-makers were 29 engaged from the outset. This facilitated timely escalation, prioritization of actions, and 30 coordinated decision-making. Internal communication and coordination among executive DATE FILED: December 22, 2025 Page 27 of 43...

AI summary Nova Scotia Power (NSP) acknowledges the effectiveness of its incident response during a cybersecurity incident, while recognizing the need for continuous improvement. The company plans to refine its incident-response plans, incorporate real-world lessons, and enhance documentation to improve future preparedness and resilience.

Section 54
institutional knowledge for future responses. 19 20 The Company considers this continuous improvement approach to be an essential component of 21 responsible cybersecurity governance. DATE FILED: December 22, 2025 Page 28 of 43 REDACTED (C...

AI summary Nova Scotia Power Inc. emphasizes a continuous improvement approach as essential to responsible cybersecurity governance. The document is a redacted 2025 cybersecurity incident report filed by the company.

Section 55
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 5.0 COLLECTION AND RETENTION OF PERSONAL INFORMATION 2 3 In its letter of July 14, 2025, the NSEB directed the following be inclu...

AI summary The document outlines NS Power's policies and practices for collecting and retaining personal information following a cybersecurity incident. It mentions that NS Power had established privacy policies and procedures, and it is now enhancing its privacy governance framework in response to the incident.

Section 56
s are encouraged to escalate and report privacy issues and there are clear 23 reporting processes in place. 24 25 13 M12273, NSEB Letter, July 14, 2025, p. 2. DATE FILED: December 22, 2025 Page 29 of 43 REDACTED (CONFIDENTIAL INFORMATION R...

AI summary The document references a 2025 Nova Scotia Power cybersecurity incident report, which has been redacted. It also mentions a letter from the Nova Scotia Energy Board dated July 14, 2025, and outlines processes for reporting privacy issues.

Section 57
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 6.0 IMPACT ANALYSIS 2 3 In its letter of July 14, 2025, the NSEB directed the following be included in the Report regarding 4 the...

AI summary The 2025 Nova Scotia Power Cybersecurity Incident Report discusses the impact analysis of a cybersecurity breach, including financial, operational, and reputational effects. The report notes no evidence of grid or energy delivery system compromise, and NS Power is committed to restoring customer trust. A reference is made to a letter from the NSEB dated July 14, 2025.

Section 58
ssed this in his opening statement to the 27 Standing Committee on Natural Resources and Economic Development on November 25, 2025: 28 14 M12273, NSEB Letter, July 14, 2025, p. 2. DATE FILED: December 22, 2025 Page 30 of 43 REDACTED (CONFI...

AI summary This document references a cybersecurity incident report submitted by Nova Scotia Power in 2025, as noted in a letter from the Nova Scotia Energy Board dated July 14, 2025. The report was presented to the Standing Committee on Natural Resources and Economic Development on November 25, 2025.

Section 59
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power (NSP) is referenced, though specific details are confidential. The document pertains to cybersecurity measures and incidents within the organization.

Section 60
1 At Nova Scotia Power, our commitment to providing reliable power to Nova 2 Scotians has been unwavering for over 100 years. We recognize that the recent 3 cyber event has affected the trust we have built with our customers, and I want to...

AI summary Nova Scotia Power acknowledges the impact of a recent cyber event on customer trust and service, including billing disruptions. The company is taking steps to resolve issues such as overestimated bills, payment delays, and longer wait times, while also removing social insurance numbers from systems and working to reconnect customer meters by the end of March.

Section 62
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power (NSP) is referenced, though specific details are confidential. The document pertains to cybersecurity measures and incidents within the organization.

Section 63
1 6.2 Assessment of Potential Harm 2 3 As outlined above, NS Power determined through its investigation that certain customer 4 information stored on the impacted servers was accessed and taken by an unauthorized third party. 5 However, wh...

AI summary NS Power acknowledges a data breach impacting customer information but has no evidence of misuse or financial harm. The company emphasizes transparency and customer support, and confirms no disruption to service or billing operations. Concerns about billing processes are being addressed seriously.

Section 64
concern and disruption it has caused customers. NS Power has never 25 intentionally overbilled its customers and has been steadfast and consistent in its commitment to 26 customers that it is actively trying to address the issues and, wher...

AI summary NS Power acknowledges concerns and disruptions caused by cybersecurity incidents and emphasizes its commitment to addressing issues and fixing mistakes. The company offers flexible billing options to affected customers. The NSEB directed NS Power to address outcomes from M12457, as outlined in Appendix C.

Section 65
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 8.0 RECOMMENDATIONS 2 3 In its letter of July 14, 2025, the NSEB directed the following be included in the Report regarding 4 the...

AI summary The NSEB directed the inclusion of recommendations in Nova Scotia Power’s 2025 Cybersecurity Incident Report, focusing on enhancing security measures, conducting audits, policy updates, employee training, improving customer communication, and addressing gaps in personal information management.

Section 66
14 15 16 17 18 19 20 21 22 23 24 25 26 27 DATE FILED: December 22, 2025 Page 36 of 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary The document is a redacted cybersecurity incident report filed by Nova Scotia Power Inc. on December 22, 2025, and is part of a regulatory proceeding. It contains confidential information that has been removed.

Section 67
f 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSP) is referenced, indicating confidential information related to a cybersecurity event involving NSP. The document's content is not disclosed due to confidentiality.

Section 68
1 8.2 Additional Security Audits, Policy Updates, and Employee Training 2 Section 4.1 addressed additional security audits, policy updates, and employee training as 3 summarized below. 4 5 Regarding security audits, NERC conducts extensive...

AI summary The document discusses NS Power's efforts to enhance cybersecurity through additional security audits, policy updates, and employee training. It mentions NERC audits, the OPC's ongoing investigation, and NS Power's alignment with the NIST Cybersecurity Framework. Employee training includes quarterly sessions and phishing simulations.

Section 69
their information security responsibilities. 23 24 8.3 New Strategies and Proactive Measures 25 26 With respect to new strategies and proactive measures, please refer to section 8.1 above. 27 DATE FILED: December 22, 2025 Page 37 of 43 RED...

AI summary The document discusses NS Power's approach to customer communications following a cybersecurity incident, emphasizing transparency, timely communication, and a customer-centric focus. Actions included multi-channel public communications, paid media strategies, and social media engagement.

Section 70
gle) to find information about the Incident. 18 • Updated and monitored social media accounts and, where appropriate, provided answers 19 to related customer questions online. 20 • Provided customers the ability to speak directly with NS P...

AI summary The document outlines the measures taken by NS Power following a cybersecurity incident, including customer communication through social media, direct contact options, notification of affected individuals, and provision of complimentary credit monitoring services for up to five years.

Section 71
could receive more information about 5 the Incident, and support for credit monitoring sign-ups, whose number was included in 6 the notice letters and made available to customers. 7 • Staffed this call centre with TransUnion employees who...

AI summary Nova Scotia Power has taken several measures to assist customers affected by a cybersecurity incident, including providing credit monitoring sign-ups, staffing a call centre with TransUnion employees, distributing fact sheets, and deploying employees to communities for hands-on support. Approximately 375,000 customers were directly notified.

Section 72
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power (NSP) is referenced, though specific details are confidential. The document pertains to cybersecurity measures and incidents within the organization.

Section 74
26 In limited circumstances, NS Power continued to collect SINs from customers where there was a 27 legal requirement to do so. SINs continued to be collected for tax reporting purposes where NS 17 Peter Gregg, President & CEO, Nova Scotia...

AI summary NS Power collected SINs for tax reporting in limited circumstances due to legal requirements. A cybersecurity incident report was filed in 2025, though the details are redacted. Peter Gregg, President & CEO of Nova Scotia Power, gave an opening statement to the Standing Committee on Natural Resources and Economic Development in November 2025.

Section 75
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 Power was required to issue a T5 in connection with interest over $50 earned in a year on a 2 customer deposit. 3 4 In 2021, Nova...

AI summary Nova Scotia Power reported a cybersecurity incident in 2021 involving the potential exfiltration of SINs from customer data exported for the MyEnergy Insights program. The company has since taken steps to lock down affected systems and permanently delete SINs from its records, with completion expected by March 2026.

Section 76
required for tax reporting purposes, any such information identified will be securely deleted. NS 21 Power anticipates obtaining confirmation of its completion of this process by March 31, 2026. DATE FILED: December 22, 2025 Page 41 of 43...

AI summary Nova Scotia Power is expected to complete a process related to tax reporting by March 31, 2026. A redacted cybersecurity incident report was filed on December 22, 2025.

Section 77
f 43 REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A redacted 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSP) is referenced, indicating confidential information related to a cybersecurity event involving NSP. The document's content is not disclosed due to confidentiality.

Section 78
1 9.0 CONCLUSION 2 3 NS Power trusts that the foregoing addresses the NSEB’s direction with respect to the information 4 requested in its letters of July 14, 2025 and November 7, 2025. 5 6 NS Power experienced a sophisticated cyberattack d...

AI summary NS Power responded to the NSEB's information requests regarding a cyberattack in 2025. The attack led to data exfiltration and system disruption, but no operational systems were affected. NS Power activated response protocols, engaged Mandiant, and notified multiple agencies. Customer notifications, credit monitoring, and recovery efforts are ongoing.

Section 79
rking to reconnect customer meters to 27 billing systems; ongoing progress, system restoration timelines, and Board‑related matters are 28 tracked in the appended charts and monthly updates. 29 DATE FILED: December 22, 2025 Page 42 of 43 R...

AI summary NS Power discusses ongoing efforts to restore customer billing systems and business capabilities following a cybersecurity incident. They note that many of the Premier's requests have been or will be addressed through materials provided in the proceeding.

Section 80
terprise resource planning systems—PeopleSoft Payroll, Resource PowerPlan, and Oracle Fusion—to ensure continuity of payroll, financial, and asset Planning (ERP) management operations. Customer Recovery and restoration of advanced metering...

AI summary The document outlines a restoration roadmap for critical systems following a cyber incident at NS Power, including enterprise resource planning systems, customer-facing platforms, and cybersecurity controls, with specific project timelines and completion percentages.

Section 81
31-Oct-25 N/A PowerPlan 31-Jul-26 55% Oracle Fusion 31-Jul-26 25% CUSTOMER MyAccount 25-Sep-26 25% AMI HES 31-Mar-26 50% ADMS Resiliency 17-Apr-26 50% MV90 07-Jul-26 40% ADDITIONAL CAPABILITIES Aligne Fuels/PI 31-Dec-25 90% Adept Restorati...

AI summary The text presents a Gantt chart outlining the planned schedule for the Restoration Program Office (RPO) initiatives, including various projects with their completion percentages and dates. It notes that these timelines are subject to change due to evolving priorities and unforeseen dependencies. The chart includes sections such as PowerPlan, AMI HES, and Cybersecurity initiatives.

Section 82
NS Power Cyber Incident Report Appendix B Page 1 of 7 Report 2 - Report 3 - Report 4 - Forecast Restoration of Affected Regulatory Matters Latest update October 1 November 3 December 1 Normal Activities Rates-Related Matters

AI summary This document outlines a cyber incident report for NS Power, including affected regulatory matters related to rates. It lists several reports with dates and a forecast for the restoration of normal activities, though details are limited.

Section 89
NS Power Cyber Incident Report Appendix B Page 2 of 7 Report 2 - Report 3 - Report 4 - Forecast Restoration of Affected Regulatory Matters Latest update October 1 November 3 December 1 Normal Activities Customer Billing

AI summary The document provides an overview of affected regulatory matters related to a cyber incident at NS Power, with a focus on customer billing and the forecast for the restoration of normal activities.

Section 94
ction to the website content. NS Power will continue to revise this content to reflect the current customer experience. In addition to the foregoing, in a recent bill insert, NS Power also informed customers of the improvements made to the...

AI summary The text discusses NS Power's ongoing efforts to update website content to reflect the current customer experience, including improvements to the online customer portal (My Account) such as new features and updated login screens for better security and user experience. It also references a redacted cyber incident report and mentions affected regulatory matters, including the Capital and Ace Plan.

Section 97
As noted in the October October 1 (abridged): "As noted by the NSEB in its letter of September 17, 2025, the CIS replacement capital project has been delayed by the Incident. NS monthly update, an application Power said its investigation i...

AI summary The CIS replacement capital project has been delayed due to a cybersecurity incident, according to NS Power. The company mentioned that its investigation into the incident could impact the project's direction and timeline. An updated timeline was provided in a compliance filing (M11884) submitted to the NSEB on September 23, 2025.

Section 98
be submitted to the NSEB in as shown below: ... Please refer to NS Power’s compliance filing in M11884 for further information." 2026. October 1: "In the NS-NB Reliability Intertie capital project proceeding (M12217), NS Power, on behalf o...

AI summary The document references compliance filings and a capital project proceeding related to the NS-NB Reliability Intertie. It mentions NS Power's submission of sensitivity analyses and cybersecurity implications discussed by Midgard, a consultant for Board counsel.

Section 99
ltant for Board counsel, commented on this and the cybersecurity implications in its evidence of July 18, 2025:

AI summary Board counsel provided evidence on July 18, 2025, regarding cybersecurity implications in the proceeding.

Section 100
"Due to an ongoing cyber incident affecting portions of NS Power’s Information Technology (“IT”) systems, WTI regenerated the sensitivity analyses using the same assumptions and modeling approach. While the outputs differ slightly from tho...

AI summary Due to a cyber incident affecting NS Power’s IT systems, WTI regenerated sensitivity analyses using the same assumptions and modeling approach. The results are similar to the original but not identical, with variances attributed to rerunning the Plexos optimization engine for a complex, multivariable, 22-year problem. The NS – NB Reliability Intertie Project has been approved by the NSEB.

Section 101
been transferred to the IESO- NS. Despite these differences, WTI emphasized that “the cost variance in each case is <0.5% of the System NPVRR,” which it cited as confirming that the Reliability Intertie “enables the lowest cost long-term s...

AI summary The document discusses the impact of a cybersecurity incident on financial reporting and statements, noting that automated systems were affected. It also mentions that cost variances in the NS electricity system are considered negligible and do not indicate flaws in the modeling approach.

Section 102
ements Update: Automated financial reporting and statements have been affected by the cybersecurity incident. Similar to the issue noted above under Capital Budgeting/Finance Data, certain financial systems and data are unavailable as a re...

AI summary NS Power's automated financial reporting and statements have been affected by a cybersecurity incident, leading to the use of forecast figures for unregulated adjustments in the Q1 2026 Regulated Financial Statements. Actual figures are expected to be available for the Q4 2025 Regulated Financial Statements.

Section 105
December 1: "As identified in the Second Monthly Update Report, Fuel Adjustment Mechanism (FAM) related matters have been affected by the Incident. The Company has commenced preparations for the 2024/2025 FAM Audit. Significant progress wa...

AI summary The document discusses the impact of an incident on Fuel Adjustment Mechanism (FAM) related matters and the progress made in preparing for the 2024/2025 FAM Audit. The Company has made progress in recovering systems and data, including enabling cloud installation of PortOps dispatch optimization software and restoring some historical network drive information.

Section 108
2025 report including the period from April 25, 2025. Once all systems are back online, any discrepancies will be trued up in future reports. Dispatch Study Action Plan Quarterly Update: "In its Dispatch Study Action Plan Quarterly Update...

AI summary The text mentions a 2025 report covering April 25, 2025, and a Dispatch Study Action Plan Quarterly Update dated December 15, 2025, which includes progress updates on the ECC Optimization Tools Project with final implementation expected by the end of March 2026. A redacted section of a cyber incident report is also referenced.

Section 109
NS Power Cyber Incident Report Appendix B Page 5 of 7 Report 2 - Report 3 - Report 4 - Forecast Restoration of Affected Regulatory Matters Latest update October 1 November 3 December 1 Normal Activities Performance Standards

AI summary This document text refers to a cyber incident report by NS Power and mentions 'Performance Standards' in the context of affected regulatory matters. It includes dates and a forecast for the restoration of normal activities.

Section 115
October 1: "As noted by the NSEB in its letter of September 17, 2025, the hosting capacity map and analysis has been affected by the cybersecurity incident. In Dependent on the GIS its report on the Hosting Capacity Analysis Stakeholder Wo...

AI summary The hosting capacity map and analysis for the Commercial Net Metering Program have been affected by a cybersecurity incident, causing delays in updating the map and planned 2026 enhancements. The incident impacted GIS applications, preventing updates to online maps and integration with CYME.

Section 119
minimize impact, and recreating work made unavailable due to the Incident. To date, NS Power Return to normal processes for has maintained its obligations under the SGIP and DGIP with respect to timelines and processing of Interconnection...

AI summary The text discusses NS Power's efforts to maintain obligations under the SGIP and DGIP despite a cyber incident, highlighting the dependency of DGIP modelling on PI data and GIS, with an estimated ETA of March 2026.

Section 122
The Residential Behaviour October 1: "As noted by the NSEB in its letter of September 17, 2025, the ability to provide relevant customer data to EfficiencyOne (E1) has been affected by program will require a the cybersecurity incident. Cus...

AI summary The NSEB noted that a cybersecurity incident has disrupted data flows from NS Power to EfficiencyOne (E1), affecting the Residential Behaviour Program. This has limited E1's access to customer consumption data from AMI meters and the My Energy Insights platform. NS Power is working to restore data flows and is meeting with E1 to discuss interim solutions.

Section 127
Reliability Intertie model." to the IESO-NS Relatedly, as referenced above under NS-NB Reliability Intertie, historical PLEXOS models were unretrievable as a result of the Incident. However, as noted above, NS Power was able to recreate th...

AI summary The document discusses the impact of a cyber incident on NS Power's ability to retrieve historical PLEXOS models related to the NS-NB Reliability Intertie. NS Power was able to recreate the models temporarily, allowing continued system planning activities, with no expected impact on customers.

Section 128
NS Power Cyber Incident Report Appendix B Page 7 of 7 Report 2 - Report 3 - Report 4 - Forecast Restoration of Affected Regulatory Matters Latest update October 1 November 3 December 1 Normal Activities Miscellaneous

AI summary This document is a page from a cyber incident report by NS Power, specifically Appendix B, which lists affected regulatory matters and includes reports dated October 1, November 3, and December 1. It mentions the forecast for the restoration of normal activities but provides no further details.

N-4NSPI (NSEB) RIR 13 to 15 14 passages
Section 1
Board Inquiry into Nova Scotia Power’s Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL

AI summary The Nova Scotia Energy Board (NSEB) is investigating a cybersecurity incident involving Nova Scotia Power (NSPI). NSPI has submitted responses to NSEB's information requests as part of the inquiry (NSEB M12273). The proceeding focuses on cybersecurity measures and compliance with regulatory disclosure requirements.

Section 2
Inquiry into Nova Scotia Power’s Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL

AI summary The document outlines an inquiry into a cybersecurity incident involving Nova Scotia Power Inc. (NSPI), focusing on NSPI's responses to information requests from the Nova Scotia Energy Board (NSEB). The text is marked as non-confidential and pertains to regulatory proceedings.

Section 4
e season. 30 31 (e) The CIS subroutine for estimating seasonal usage considers two seasons, ‘warm’ and 32 ‘cold’. Historically, bills in May through October are considered as warm and the Date Filed: December 23, 2025 NSPI (NSEB) IR-13 Pag...

AI summary NSPI explains its use of the CIS subroutine for seasonal billing adjustments, noting historical warm/cold season divisions and challenges with transitional months. NSPI reverted to warm billing in November 2025 after initial cold billing led to higher estimates, proactively contacting affected customers and adjusting billing procedures.

Section 5
NS Power has access to historical billing data, including the true meter reads used for those 17 bills. The CIS system uses this data to inform the estimation subroutine described above. Date Filed: December 23, 2025 NSPI (NSEB) IR-13 Page...

AI summary NS Power has access to historical billing data used by the CIS system for estimation. The document relates to NSPI's responses in a Board Inquiry regarding a cybersecurity incident (NSEB M12273).

Section 6
d Inquiry into Nova Scotia Power’s Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL 1 Request IR-14: 2 3 On page 2 of the Monthly Update 4, NS Power noted that customer meters have continued...

AI summary Inquiry into NSPI's cybersecurity incident (NSEB M12273) addresses meter reconnection progress, risks to timelines, meter reading methods, and billing data post-incident. NSPI reports 75% of customers have received readings since the incident, with full reconnection expected by March 2026.

Section 7
NSPI (NSEB) IR-14 Page 1 of 4 Board Inquiry into Nova Scotia Power’s Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL

AI summary The Nova Scotia Energy Board (NSEB) is conducting an inquiry into a cybersecurity incident involving Nova Scotia Power Inc. (NSPI), with NSPI providing responses to information requests related to the incident.

Section 8
Inquiry into Nova Scotia Power’s Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL

AI summary The document outlines an inquiry into a cybersecurity incident involving Nova Scotia Power Inc. (NSPI), focusing on NSPI's responses to information requests from the Nova Scotia Energy Board (NSEB). The text is marked as non-confidential and pertains to regulatory proceedings.

Section 9
1 (ii) For those bills that were estimated, please provide a breakdown based on the 2 number of months since the meters associated with those bills were actually 3 read. 4 5 (e) Were the bills all based on the same number of estimated mont...

AI summary The text includes questions about billing practices, cybersecurity impacts on meter readings, and overpayment policies, followed by a response detailing the status of smart meter reconnection (70% completed) and risks like weather events and tech delays. Key themes involve billing procedures, cybersecurity, and advanced metering infrastructure.

Section 10
rces. 28 29 • Unforeseen delays in the restoration or availability of supporting 30 technologies such as integration platforms or user access management Date Filed: December 23, 2025 NSPI (NSEB) IR-14 Page 2 of 4 Board Inquiry into Nova Sc...

AI summary NSPI discusses cybersecurity incident response delays due to integration platform and user access management challenges, meter reading processes involving service orders and estimated billing, and references a table detailing monthly estimated bill counts.

Section 11
availability. 13 14 (c) Monthly breakdown of the total number of bills generated based on estimates is set out in 15 the table below. All other bills would be based on true reads. 16 17 (d) 18 19 (i) Please refer to part (c). 20 21 (ii) NS...

AI summary NSPI explains billing practices post-cyber incident, including estimated reads based on seasonal history and photo read usage. Residential customers received ~4 bills(avg), half estimated. Photo reads (80% usable) help adjust bills, with resubmission options for poor-quality images.

Section 13
quiry into Nova Scotia Power’s Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL

AI summary The document outlines Nova Scotia Power Inc.'s (NSPI) responses to information requests related to a cybersecurity incident investigated by the Nova Scotia Energy Board (NSEB) under matter number NSEB M12273. The text is marked as non-confidential.

Section 15
e variance attributable to averaging. 30 31 (b) Estimates are only generated when meter readings are missing. Understanding the 32 accuracy of these estimates relative to true readings at the same time at that property isn’t 33 possible. H...

AI summary Nova Scotia Power Inc. (NSPI) addresses the Nova Scotia Energy Board's (NSEB) inquiry into a cybersecurity incident, noting that 48% of November bills used actual meter reads. NSPI implemented online photo meter submission to improve accuracy of estimated readings, acknowledging challenges in assessing estimate accuracy due to missing data.

Section 16
Inquiry into Nova Scotia Power’s Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL 1 Request IR-16: 2 3 Since becoming aware of the cyber incident, has NS Power deployed additional resources...

AI summary NSPI deployed 40 new customer service resources, utilized TransUnion for call management, and mobilized internal staff to address billing process challenges and customer inquiries following a cybersecurity incident. Additional support included community outreach sessions to explain billing options.

Section 17
r communities across the province to answer questions and help our customers 27 understand the options related to their bills. A list of upcoming dates can be 28 found at nspower.ca/billing. 29 Date Filed: December 23, 2025 NSPI (NSEB) IR-...

AI summary NSPI acknowledges a cybersecurity incident and highlights employee efforts in Customer Care and Billing to support customers. The document pertains to a Board Inquiry (NSEB M12273) into the incident and NSPI's responses to NSEB information requests.

N-5Refiled Incident Report - NSPI - Redacted 163 passages
Section 1
REDACTED (CONFIDENTIAL INFORMATION REMOVED) Nova Scotia Energy Board IN THE MATTER OF The Public Utilities Act, R.S.N.S. 1989, c.380, as amended M12273 Board Inquiry into Nova Scotia Power’s Cybersecurity Incident Nova Scotia Power Inciden...

AI summary Nova Scotia Power's cybersecurity incident report, part of a regulatory inquiry under the Public Utilities Act, details the incident, affected systems, and response actions. The report is submitted as part of a regulatory proceeding (M12273) to address the incident's implications.

Section 3
Preventing Future Breaches ....................................... 38 20 8.2 Additional Security Audits, Policy Updates, and Employee Training.............................. 40 21 8.3 New Strategies and Proactive Measures .....................

AI summary The document outlines Nova Scotia Power's cybersecurity incident report, detailing measures to prevent future breaches through audits, policy updates, employee training, customer communication, and data retention policies.

Section 4
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 1.0 INTRODUCTION 2 3 In its July 14, 2025 letter regarding the cybersecurity incident (Incident) experienced by Nova 4 Scotia Powe...

AI summary Nova Scotia Power Inc. (NSP) is required by the Nova Scotia Energy Board (NSEB) to submit a cybersecurity incident report detailing the 2025 incident, including affected systems, root causes, and response actions. The NSEB also directed NSP to settle vendor dues and engage MNP to investigate data handling practices following a financial technology data compromise.

Section 5
Board will also refer this matter to MNP to further 25 investigate causes of the NS Power’s financial technology data compromise and 26 assess its data handling practices. 1 M12273, Board Inquiry into Nova Scotia Power’s Cybersecurity Inci...

AI summary The Board will refer the matter to MNP to investigate the causes of Nova Scotia Power’s financial technology data compromise and assess its data handling practices. The incident report must include a Gantt chart detailing recovery tasks, timelines, and progress.

Section 7
M12273, NSEB Letter, November 7, 2025, p. 2. 5 M12600, Minister of Energy – Accountability for Nova Scotia Power Inc., Minister of Energy Letter, December 3, 2025. DATE FILED: December 22, 2025 Page 4 of 46 20260427 REFILE 20251222 NSPI to...

AI summary A redacted cybersecurity incident report from Nova Scotia Power Inc. (NSPI) to the Nova Scotia Energy Board (NSEB) is referenced in regulatory proceeding M12273, alongside a December 2025 letter from the Minister of Energy regarding NSPI accountability. The document's confidentiality and lack of details limit further analysis.

Section 8
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.

Section 9
1 The NSEB replied to the Premier by letter on December 10, 2025, providing, in part, the following: 2 3 Upon receipt of your letter, the Board opened a new matter (M12600). Given the 4 connection between these issues and the Board’s ongoi...

AI summary The NSEB opened a new matter (M12600) related to issues raised by the Premier, considering whether they should be addressed in the ongoing cybersecurity inquiry (M12273). NS Power argues that many issues were already addressed in prior reports and that the second set of Information Requests (IRs) under M12273 specifically handle customer billing concerns, making M12273 the appropriate proceeding.

Section 10
ceeding in which to address the issues raised by the Premier without the need for a 24 new matter. 25 26 On December 10, 2025, the NSEB provided additional direction by letter stemming from a 27 customer complaint (M12457). In its letter,...

AI summary The document references a cybersecurity incident report by Nova Scotia Power Inc. (NSPI) and a board inquiry (M12273) into the incident. It also mentions a customer complaint (M12457) leading to a directive for NSPI to report on a broader regulatory review, with updates to be included in a separate process from the initial complaint.

Section 11
Page 6 of 46 20260427 REFILE 20251222 NSPI to NSEB Cyber Incident Report PCON.docx REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 2.0 THE INCIDENT 2 3 In its letter of July 14,...

AI summary Nova Scotia Power Inc. (NSPI) reported a sophisticated cyberattack discovered on April 25, 2025, when employees noticed non-functional applications. Investigation revealed unauthorized access to IT systems by a threat actor, with the NSEB requiring detailed incident reporting including discovery, attack vector, timeline, and vulnerabilities exploited.

Section 12
became evident that a threat actor had gained unauthorized access into certain parts of NS Power’s 26 information technology network and servers which support portions of its business applications. 8 M12273, NSEB Letter, July 14, 2025, p....

AI summary A threat actor gained unauthorized access to parts of Nova Scotia Power’s IT network and servers supporting business applications. The document references a July 2025 NSEB letter and a December 2025 cyber incident report submitted by NSPI to NSEB.

Section 13
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.

Section 14
1 Immediately following detection of the Incident, NS Power activated its established incident 2 response and business continuity protocols, engaging Osler, and through Osler, Mandiant’s 3 cybersecurity and incident response team. 4 5 Unde...

AI summary NS Power responded to a cybersecurity incident by engaging Osler and Mandiant, containing the breach, and notifying law enforcement and regulatory bodies. The incident, detected in March 2025, involved data exfiltration starting in April 2025. No operational systems were accessed, and notifications were sent to RCMP, CSIS, FBI, and OPC.

Section 15
ny also notified the Federal Bureau 25 of Investigation (FBI). 26 27 NS Power also reported the Incident to the Office of the Privacy Commissioner of Canada (OPC) 28 on May 1, 2025, with an update on May 14, 2025. The OPC initiated an inve...

AI summary Nova Scotia Power Inc. (NSPI) notified the Federal Bureau of Investigation (FBI) and the Office of the Privacy Commissioner of Canada (OPC) about a cybersecurity incident. The OPC initiated an investigation into the matter following reports on May 1, 2025, and an update on May 14, 2025.

Section 16
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 Incident, on May 28, 2025 and the Company is actively and fully cooperating with the OPC to 2 support the OPC’s investigative effo...

AI summary Nova Scotia Power Inc. (NSP) experienced a cybersecurity incident starting March 19, 2025, via a phishing attack leading to malware installation. The attack evolved into ransomware deployment on April 25, 2025. NSP is cooperating with the OPC investigation.

Section 17
25, the threat actor began to move laterally to systems in the environment using 28 accounts with elevated privileges. The threat actor then deployed additional malware in additional 29 systems. DATE FILED: December 22, 2025 Page 9 of 46 2...

AI summary A cybersecurity incident involving lateral movement and malware deployment by a threat actor is reported by Nova Scotia Power Inc. to the Nova Scotia Energy Board, with details redacted. The incident is part of a regulatory proceeding.

Section 18
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 Between April 8 and April 22, 2025, the threat actor leveraged this malware to access systems in 2 the environment and to perform...

AI summary In April 2025, NS Power experienced a cybersecurity incident involving malware deployment, data exfiltration, and ransomware. The threat actor used sophisticated methods to evade detection. NS Power contained the incident by April 29, 2025, and no further activity was detected. Mandiant confirmed containment, and NS Power provided details to the Board’s consultant.

Section 19
Page 10 of 46 20260427 REFILE 20251222 NSPI to NSEB Cyber Incident Report PCON.docx REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 The Incident has not caused any disruption to...

AI summary Nova Scotia Power Inc. (NSPI) reported a 2025 cybersecurity incident to the Nova Scotia Energy Board (NSEB), confirming no disruption to physical operations or electricity reliability in Nova Scotia. The incident did not affect NSPI's ability to provide safe, reliable service to customers.

Section 20
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 3.0 AFFECTED SYSTEMS AND DATA 2 3 In its letter of July 14, 2025, the NSEB directed the following be included in the Report regard...

AI summary NSPI's 2025 cybersecurity incident report details compromised systems including ERP platforms (PeopleSoft, PowerPlan) and customer billing systems (MyAccount, AMI Head End System) as directed by the NSEB. The report references a July 14, 2025 NSEB letter (M12273) requiring specific disclosure of affected systems and data exposure.

Section 21
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 • Additional systems: 2 • Aligne Fuels/Plant Information (PI) 3 • Geospatial Information System 4 • Adept Restoration 5 • Certain...

AI summary Nova Scotia Power Inc. (NSPI) submitted a 2025 cybersecurity incident report to the Nova Scotia Energy Board (NSEB), detailing affected systems including Aligne Fuels/Plant Information, Geospatial Information Systems, and cybersecurity tools like Active Directory and Data Loss Prevention Tools. Appendix A provides technical details and restoration timelines.

Section 22
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 3.2 Data & Personal Information 2 3 . The process to 4 identify the customers who were directly impacted has been extremely comple...

AI summary Nova Scotia Power (NSP) reported a 2025 cybersecurity incident where unauthorized access exposed customer data, including names, contact details, SINs, and account history. Identifying impacted customers was complex, and two notification letters were issued, with one highlighting potential SIN exposure. The breach included bank account numbers for some customers.

Section 23
etters were substantively identical, except that one version 19 advised the customer that based on the investigation, their social insurance number may have been 20 affected by the Incident. 21 DATE FILED: December 22, 2025 Page 14 of 46 2...

AI summary Nova Scotia Power Inc. (NSPI) submitted a cybersecurity incident report to the Nova Scotia Energy Board (NSEB), disclosing customer notifications regarding potential social insurance number breaches. The report, filed December 22, 2025, details substantively identical letters sent to affected customers.

Section 24
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 4.0 RESPONSE AND RECOVERY ACTIONS 2 3 In its letter of July 14, 2025, the NSEB directed the following be included in the Report re...

AI summary Nova Scotia Power Inc. (NSP) reported on its response to a 2025 cybersecurity incident, including containment, threat eradication, stakeholder communication, and lessons learned. The NSEB directed the inclusion of these actions in the report, referencing Board Order M12273.

Section 25
ion and remediation of the threat, and conducting a thorough analysis to 25 understand the full scope and nature of the Incident. 26 12 M12273, NSEB Letter, July 14, 2025, p. 2. DATE FILED: December 22, 2025 Page 15 of 46 20260427 REFILE 2...

AI summary Nova Scotia Power Inc. (NSPI) submitted a cybersecurity incident report to the Nova Scotia Energy Board (NSEB), outlining immediate, intermediate, and ongoing remediation actions. The document references a prior NSEB letter (M12273) and emphasizes incident analysis and threat remediation, though specific details are redacted.

Section 26
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 2 3 4 5 6 NS Power is also advancing efforts to restore and, where necessary, rebuild core business 7 applications and infrastruct...

AI summary NS Power is restoring core business applications and infrastructure following a cybersecurity incident, leveraging secure backups and reestablishing security protocols. A Business Restoration Process Office (RPO) has been established, with a strategic partner assisting in recovery efforts focused on business continuity and customer stability.

Section 27
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 2 3 4 5 6 Existing Safeguards 7 8 At the time of the Incident, NS Power had implemented a common set of cybersecurity standards 9...

AI summary Nova Scotia Power (NSP) outlines its cybersecurity safeguards aligned with NIST's framework, including Identify, Protect, Detect, Respond, and Recover functions. The company completed a two-year update to ensure compliance with evolving standards and maintains continuous improvement in cybersecurity programs.

Section 28
Recover – Establishes the appropriate activities to maintain plans for resilience and to 29 restore any capabilities or services that were impaired due to a cybersecurity event. DATE FILED: December 22, 2025 Page 18 of 46 20260427 REFILE 2...

AI summary Nova Scotia Power Inc. (NSPI) submitted a cybersecurity incident report to the Nova Scotia Energy Board (NSEB), detailing measures to restore capabilities impaired by a cyber event and establish resilience planning activities.

Section 29
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.

Section 30
1 In relation to NS Power’s operational program, NS Power’s core energy operations are designed 2 to comply with other industry-specific rules and standards relating to cybersecurity and IT 3 including, but not limited to, those mandated b...

AI summary NS Power outlines its cybersecurity compliance with NERC standards, including audits and employee training. It emphasizes transparency and multi-channel communication strategies for customer notifications following an incident, focusing on accountability and trust-building.

Section 31
website and 27 social media channels, notice to all local media, and communications directly to key 28 account/business customers, government and other stakeholders in addition to employees. 29 DATE FILED: December 22, 2025 Page 19 of 46 2...

AI summary Nova Scotia Power Inc. (NSPI) submitted a confidential cybersecurity incident report to the Nova Scotia Energy Board (NSEB) on December 22, 2025, detailing a cyber incident. The report includes redacted information and was filed as part of a regulatory proceeding.

Section 32
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.

Section 33
1 To ensure customers were kept informed, the Company also employed a multi-platform paid media 2 strategy that includes online, as well as TV, print and radio to reach a wide variety of customer 3 demographics. In addition, NS Power activ...

AI summary NS Power informed customers about a cybersecurity incident through multi-platform communication strategies, including paid media, social media, and direct customer service. Notifications began on April 28, 2025, with updates on May 1, 2025, detailing impacted customer data and scam prevention measures.

Section 34
ere working 24 urgently to determine the full nature and scope of the data that may have been affected. The 25 Company also initiated the process of notifying affected individuals, including retaining third- 26 party service providers to a...

AI summary Nova Scotia Power Inc. (NSPI) is investigating the scope of a cybersecurity incident and notifying affected individuals, with third-party assistance. The report, filed on December 22, 2025, details NSPI's response to the incident and efforts to mitigate impacts.

Section 35
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 2 3 4 5 6 On May 13, 2025, NS Power sent direct notices to approximately 277,000 current customers whose 7 personal information th...

AI summary NS Power notified 277,000 customers of a cybersecurity incident in 2025, offering two years of free credit monitoring via TransUnion. The company issued press releases, engaged with media, and provided guidance to mitigate fraud risks. The response included daily credit report access and identity theft protections.

Section 36
d is one of the primary tools 25 leveraged for determining credit-related identity theft or fraud. 26 27 • Unlimited online access to their credit score, updated daily. 28 DATE FILED: December 22, 2025 Page 21 of 46 20260427 REFILE 2025122...

AI summary A redacted cybersecurity incident report by Nova Scotia Power Inc. (NSPI) to the Nova Scotia Energy Board (NSEB) was filed on December 22, 2025. The document details a cyber incident but contains confidential information removed for redaction.

Section 37
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 • Credit monitoring, which provides individuals with email notifications to key changes on 2 an individual’s TransUnion Canada cre...

AI summary Nova Scotia Power Inc. (NSP) implemented measures to assist customers affected by a 2025 cybersecurity incident, including credit monitoring, identity theft protection, educational resources, and dark web monitoring. NSP also provided updates through its website and media channels after threat actors published data on the dark web.

Section 38
to customers through the same channels as previous 24 updates, including updating the company’s website and social media channels, notifying local 25 media, and conducting media interviews. 26 DATE FILED: December 22, 2025 Page 22 of 46 20...

AI summary Nova Scotia Power Inc. (NSPI) submitted a redacted cybersecurity incident report to the Nova Scotia Energy Board (NSEB), detailing a 2025 incident. The report outlines communication channels used to inform customers, including website updates, social media, local media, and interviews.

Section 39
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.

Section 40
1 Former Customers 2 3 As the Company continued its investigation of the impacted data, NS Power determined that 4 personal information relating to former customers had also been impacted by the Incident. 5 6 On June 25, 2025, NS Power not...

AI summary NS Power identified former customers affected by a data incident, extended credit monitoring to five years, and notified them through media and advertising due to lack of contact info. Additional 97,000 customers were later identified, with direct notices sent on October 31, 2025, offering credit monitoring.

Section 41
Power sent direct notices to these 28 individuals on October 31, 2025, and offered them an additional opportunity to sign up for credit 29 monitoring, to the extent they have not already done so. DATE FILED: December 22, 2025 Page 23 of 46...

AI summary Nova Scotia Power has sent direct notifications to approximately 375,000 customers impacted by a cybersecurity incident, and also sent direct notices to 28 individuals offering credit monitoring.

Section 42
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.

Section 44
pany deployed dozens 26 of employees to communities across the province to provide hands-on support for customers who 27 prefer assistance in person, recognizing that not all customers may be comfortable registering 28 online, and to ensur...

AI summary Nova Scotia Power Inc. (NSP) deployed employees across the province to assist customers in person, ensuring access to services for those uncomfortable with online registration. Over 30 community sessions were held, assisting more than 700 customers. A cybersecurity incident report was filed with the Nova Scotia Energy Board (NSEB) on December 22, 2025.

Section 45
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.

Section 48
Page 27 of 46 20260427 REFILE 20251222 NSPI to NSEB Cyber Incident Report PCON.docx REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary This document is a redacted cybersecurity incident report submitted by Nova Scotia Power Inc. (NSPI) to the Nova Scotia Energy Board (NSEB) in 2025, detailing a cyber incident. The content has been redacted due to confidentiality.

Section 49
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.

Section 51
o this incident will 23 include a review of lessons learned, including a review of communications with customers. 24 25 4.3 Other Stakeholders 26 27 NS Power employees have been a key stakeholder audience throughout the Incident, as they w...

AI summary The document outlines a review of a cybersecurity incident involving Nova Scotia Power, including lessons learned and communication with stakeholders, particularly employees who were impacted both as employees and customers. The report was filed on December 22, 2025.

Section 52
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.

Section 53
1 throughout the response and restoration to date. Ahead of each public update related to the cyber 2 investigation, employees were made aware of the latest information and what to expect in terms 3 of public information, increased media c...

AI summary NS Power kept employees and stakeholders informed throughout the cyber incident response, providing regular updates, FAQs, and a new SharePoint site for information. Key stakeholders, including Efficiency Nova Scotia and the Independent Energy System Operator, were also kept informed of progress.

Section 54
esentatives of the 22 Affordable Energy Coalition, and key contacts within Nova Scotia’s Mi’kmaw communities. 23 NS Power also notified NERC, the Electricity Information Sharing and Analysis Center (E-ISAC), 24 and the Northeast Power Coor...

AI summary Nova Scotia Power (NSP) reported a cybersecurity incident to multiple entities, including NERC, E-ISAC, the Northeast Power Coordinating Council, and law enforcement agencies such as CCCS, RCMP, and CSIS. This incident was also reported to Nova Scotia’s Mi’kmaw communities and the Affordable Energy Coalition.

Section 55
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.

Section 56
1 them with information about the Incident. Given the nature of the cyber attack and the critical 2 infrastructure nature of the company and the North American electric utility industry, the Company 3 also notified the Federal Bureau of In...

AI summary Nova Scotia Power Inc. (NSP) reported a cyber attack to the FBI and OPC, and considers its response effective due to prior preparedness measures, including third-party expertise, updated plans, and simulation exercises.

Section 57
. 27 28 During the Incident response, governance structures and workstreams were clearly established, 29 and appropriately experienced and skilled subject-matter experts and decision-makers were DATE FILED: December 22, 2025 Page 30 of 46...

AI summary The document outlines the response to a cybersecurity incident by Nova Scotia Power, highlighting the establishment of governance structures and the involvement of experienced experts during the incident response.

Section 58
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 engaged from the outset. This facilitated timely escalation, prioritization of actions, and 2 coordinated decision-making. Interna...

AI summary NSP acknowledges the effectiveness of its incident response during the 2025 cybersecurity incident but emphasizes the need for continuous improvement, including updating response plans and enhancing documentation to improve future preparedness and resilience.

Section 59
institutional knowledge for future responses. 21 22 The Company considers this continuous improvement approach to be an essential component of 23 responsible cybersecurity governance. 24 DATE FILED: December 22, 2025 Page 31 of 46 20260427...

AI summary The document outlines Nova Scotia Power's cybersecurity incident report, highlighting the company's commitment to continuous improvement in cybersecurity governance as a key component of responsible management.

Section 60
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 5.0 COLLECTION AND RETENTION OF PERSONAL INFORMATION 2 3 In its letter of July 14, 2025, the NSEB directed the following be includ...

AI summary The NSEB directed NS Power to review its policies and practices for collecting, using, and retaining personal information following a cybersecurity incident. NS Power has since taken steps to enhance its privacy governance framework and improve its privacy program, including enhancing employee training and promoting a culture of privacy.

Section 61
are encouraged to escalate and report privacy issues and there are clear 26 reporting processes in place. 27 13 M12273, NSEB Letter, July 14, 2025, p. 2. DATE FILED: December 22, 2025 Page 32 of 46 20260427 REFILE 20251222 NSPI to NSEB Cyb...

AI summary The document references a cybersecurity incident report submitted by Nova Scotia Power Inc. (NSPI) to the Nova Scotia Energy Board (NSEB), highlighting the importance of privacy reporting processes. A specific reference to a letter (M12273) dated July 14, 2025, is included.

Section 62
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED 1 6.0 IMPACT ANALYSIS 2 3 In its letter of July 14, 2025, the NSEB directed the following be included in the Report regarding 4 the...

AI summary This section of the 2025 Nova Scotia Power Cybersecurity Incident Report discusses the impact analysis of a breach, including financial, operational, and reputational effects. It confirms that no operational technology or energy delivery systems were accessed, and the grid remained uninterrupted. NS Power is committed to restoring customer trust, as noted by Peter Gregg in a public statement.

Section 63
ddressed this in his opening statement to the 28 Standing Committee on Natural Resources and Economic Development on November 25, 2025: 14 M12273, NSEB Letter, July 14, 2025, p. 2. DATE FILED: December 22, 2025 Page 33 of 46 20260427 REFIL...

AI summary This document is a redacted version of Nova Scotia Power’s 2025 cybersecurity incident report, filed with the Nova Scotia Energy Board on December 22, 2025. It references a prior letter from the NSEB dated July 14, 2025, and was addressed by a representative to the Standing Committee on Natural Resources and Economic Development on November 25, 2025.

Section 64
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.

Section 65
1 At Nova Scotia Power, our commitment to providing reliable power to Nova 2 Scotians has been unwavering for over 100 years. We recognize that the recent 3 cyber event has affected the trust we have built with our customers, and I want to...

AI summary Nova Scotia Power acknowledges the impact of a recent cyber event on customer trust and service, including billing disruptions. The company is working to restore systems, address overestimated bills, and implement flexible billing options. They are also removing social insurance numbers from systems and plan to reconnect customer meters by the end of March.

Section 67
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.

Section 68
1 6.2 Assessment of Potential Harm 2 3 As outlined above, NS Power determined through its investigation that certain customer 4 information stored on the impacted servers was accessed and taken by an unauthorized third party. 5 However, wh...

AI summary NS Power acknowledges a data breach where customer information was accessed by an unauthorized third party but has no evidence of misuse or financial harm. The company committed to transparency, timely communication, and customer support. The incident did not disrupt physical operations but affected billing systems, prompting concerns about billing processes and late fees.

Section 69
the concern and disruption it has caused customers. NS Power has never 25 intentionally overbilled its customers and has been steadfast and consistent in its commitment to 26 customers that it is actively trying to address the issues and,...

AI summary NS Power is addressing a cybersecurity incident that has caused customer concerns and disruptions. The company has committed to fixing any billing errors and is offering flexible payment options to affected customers. The NSEB has directed NS Power to address broader review outcomes from M12457, with responses provided in Appendix C.

Section 70
N 2 3 As noted in the introduction, the NSEB directed NS Power to address the broader review outcomes 4 arising from M12457. Each of the Board’s questions are addressed in turn in Appendix C. 5 DATE FILED: December 22, 2025 Page 37 of 46 2...

AI summary The NSEB directed NS Power to address outcomes from M12457, with recommendations including enhancing security measures, conducting audits, updating policies, and improving customer communication following a cybersecurity incident.

Section 71
taken the following steps to enhance its cybersecurity environment to facilitate the 22 prevention of future breaches: 23 24 25 26 27 16 M12273, NSEB Letter, July 14, 2025, p. 2. DATE FILED: December 22, 2025 Page 38 of 46 20260427 REFILE...

AI summary The document outlines ongoing steps taken by Nova Scotia Power to enhance its cybersecurity environment following a cyber incident, though specific details are redacted. It references a report filed with the Nova Scotia Energy Board.

Section 72
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.

Section 73
1 8.2 Additional Security Audits, Policy Updates, and Employee Training 2 3 Section 4.1 addressed additional security audits, policy updates, and employee training as 4 summarized below. 5 6 Regarding security audits, NERC conducts extensi...

AI summary The text discusses NS Power's efforts in cybersecurity, including security audits conducted by NERC, an ongoing investigation by the OPC, updates to cybersecurity policies informed by NIST, and mandatory employee training programs to ensure compliance and awareness.

Section 74
r information security responsibilities. 24 25 8.3 New Strategies and Proactive Measures 26 27 With respect to new strategies and proactive measures, please refer to section 8.1 above. 28 DATE FILED: December 22, 2025 Page 40 of 46 2026042...

AI summary The document outlines NS Power's approach to customer communications following a cybersecurity incident, emphasizing transparency, timely communication, and a customer-centric strategy. Actions include multi-channel public communications, paid media strategies, and social media engagement.

Section 75
e) to find information about the Incident. 18 • Updated and monitored social media accounts and, where appropriate, provided answers 19 to related customer questions online. 20 • Provided customers the ability to speak directly with NS Pow...

AI summary The document outlines Nova Scotia Power's response to a cybersecurity incident, including customer communication, provision of credit monitoring services, and establishment of a dedicated call centre to support affected individuals.

Section 77
Page 42 of 46 20260427 REFILE 20251222 NSPI to NSEB Cyber Incident Report PCON.docx REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary This document is a confidential cybersecurity incident report submitted by Nova Scotia Power Inc. to the Nova Scotia Energy Board, related to a cyber incident that occurred in 2025. The content has been redacted, and key details are not disclosed.

Section 78
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.

Section 80
26 In limited circumstances, NS Power continued to collect SINs from customers where there was a 27 legal requirement to do so. SINs continued to be collected for tax reporting purposes where NS 17 Peter Gregg, President & CEO, Nova Scotia...

AI summary The document references a 2025 cybersecurity incident report submitted by Nova Scotia Power to the Nova Scotia Energy Board, which includes redacted confidential information. It also mentions the collection of Social Insurance Numbers (SINs) by NS Power in limited circumstances for tax reporting purposes.

Section 81
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.

Section 83
quired for tax reporting purposes, any such information identified will be securely deleted. NS 21 Power anticipates obtaining confirmation of its completion of this process by March 31, 2026. 22 DATE FILED: December 22, 2025 Page 44 of 46...

AI summary This document is a redacted cybersecurity incident report submitted by Nova Scotia Power to the Nova Scotia Energy Board, filed on December 22, 2025. It outlines a cybersecurity incident and includes sensitive information that has been removed for confidentiality.

Section 84
EDACTED (CONFIDENTIAL INFORMATION REMOVED) 2025 Nova Scotia Power’s Cybersecurity Incident Report REDACTED

AI summary A 2025 cybersecurity incident report by Nova Scotia Power Inc. (NSPI/NSP) has been filed, though the document is redacted and confidential information has been removed. The report likely details cybersecurity measures, incidents, or vulnerabilities related to NSPI's operations.

Section 85
1 9.0 CONCLUSION 2 3 NS Power trusts that the foregoing addresses the NSEB’s direction with respect to the information 4 requested in its letters of July 14, 2025 and November 7, 2025. 5 6 NS Power experienced a sophisticated cyberattack d...

AI summary NS Power responded to a cyberattack in 2025, addressing the NSEB's information requests. The attack affected customer data and internal systems, but not operational systems. NS Power activated incident response protocols, notified multiple agencies, and implemented customer support and recovery measures.

Section 86
orking to reconnect customer meters to 27 billing systems; ongoing progress, system restoration timelines, and Board‑related matters are 28 tracked in the appended charts and monthly updates. 29 DATE FILED: December 22, 2025 Page 45 of 46...

AI summary NS Power indicates that many of the Premier’s requests to the NSEB have been addressed through materials provided in the proceeding or will be addressed in future deliverables. Billing concerns related to the cybersecurity incident are being considered as part of the process.

Section 87
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED 1 Request IR-1: 2 3 Please provide a timeline of this cybersecurity incident, including: 4 5 (a) the date of the breach; 6 7 (b) the date suspicious...

AI summary NSPI is responding to NSEB's information request regarding a cybersecurity incident. The incident was discovered on April 25, 2025, and involves a sophisticated cyberattack on NSPI's IT systems. The investigation is ongoing, and the timeline of the incident is being provided as part of the response.

Section 88
NSPI (NSEB) IR-1 Page 1 of 21 20260427 REFILE M12273 Cybersecurity Incident NSEB IR-01 PCONF.docx REDACTED (CONFIDENTIAL INFORMATION REMOVED) Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSE...

AI summary This document outlines NSPI's responses to the NSEB's information requests regarding a cybersecurity incident. The inquiry is part of a regulatory proceeding, and the responses include redacted confidential information.

Section 89
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary This document outlines NSPI's responses to NSEB information requests related to a cybersecurity incident, with details redacted.

Section 90
1 certain parts of NS Power’s information technology network and servers which support 2 portions of its business applications. 3 4 Immediately following detection of the Incident, NS Power activated its established 5 incident response and...

AI summary NS Power detected a cyber incident involving unauthorized access to its IT network and servers, leading to data exfiltration. The company activated incident response protocols, engaged cybersecurity experts, and notified law enforcement agencies including CCCS, RCMP, and CSIS. No operational technology systems were compromised.

Section 91
an Security Intelligence Service (CSIS) on April 27, 2025 and 24 provided them with information about the Incident. Given the nature of the cyber attack 25 and the critical infrastructure nature of the company and the North American electr...

AI summary Nova Scotia Power Inc. (NSP) reported a cybersecurity incident to multiple federal and international agencies, including CSIS, FBI, and OPC, due to the critical infrastructure nature of the company and the North American electric utility industry. The incident was reported on April 27, 2025, and May 1, 2025, with an update on May 14, 2025.

Section 92
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary This document relates to a cybersecurity incident and NSPI's responses to information requests from the NSEB. The content has been redacted and does not include specific details about the incident or the responses.

Section 94
ns directly to key account/business customers, government and 25 other stakeholders in addition to employees. 26 27 The Company also employed a multi-platform advertising strategy that includes online 28 media, as well as TV, print and rad...

AI summary NS Power implemented a multi-platform advertising strategy, including online media, TV, print, and radio, to communicate directly with key customers, government stakeholders, and employees during a cybersecurity incident. A paid search strategy was also activated to ensure broad reach.

Section 95
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary This document outlines NSPI's responses to information requests from the NSEB regarding a cybersecurity incident, with the content redacted.

Section 96
1 the NS Power website and information appeared as the top search result when customers 2 used search engines (i.e. Google) to find information about the Incident. Social media 3 accounts have been regularly monitored, and where appropriat...

AI summary NS Power informed customers about a cybersecurity incident, providing updates on the impact of the incident and encouraging vigilance against scams. Notifications were sent to affected customers, and third-party service providers were engaged to assist with the process.

Section 97
ders to assist with this effort. 23 24 On May 13, 2025, NS Power sent notices to approximately 277,000 current customers 25 whose personal information the Company was able to determine had been impacted in this 26 incident. 27 28 The follo...

AI summary NS Power notified approximately 277,000 customers on May 13, 2025, about a cybersecurity incident affecting their personal information. The company also issued a press release and detailed updates on its website and social media the following day.

Section 98
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary This document pertains to a cybersecurity incident and includes NSPI's responses to NSEB information requests. The content has been redacted, limiting the availability of specific details.

Section 100
indicates that based on the investigation, the 22 customer’s social insurance number may have been impacted in the Incident. 23 24 NS Power’s notice to impacted customers also included guidance for steps they could take 25 to reduce any ri...

AI summary The text discusses a cybersecurity incident that may have impacted customers' social insurance numbers. NS Power informed affected customers and offered complimentary credit monitoring services, later extended to five years. The document is part of a regulatory inquiry into the incident.

Section 101
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary This document outlines NSPI's responses to information requests related to a cybersecurity incident, as part of the NSEB M12273 proceeding. The content is redacted and does not provide specific details about the incident or responses.

Section 103
identity theft. 25 26 • Dark Web Monitoring, which monitors surface, social, deep, and dark websites for 27 potentially exposed personal, identity and financial information and helps protect 28 individuals against identity theft. 29 Date F...

AI summary The document outlines NSPI's response to the NSEB's inquiry regarding a cybersecurity incident involving the exposure of customer data on the dark web. NSPI provided updates to customers through established communication channels following the discovery of the breach.

Section 104
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The document outlines NSPI's responses to information requests from the NSEB regarding a cybersecurity incident, with details redacted.

Section 106
available to customers. 26 27 As is standard in incidents of this nature, to ensure that the call centre had sufficient 28 capacity to handle the volume of calls and allow NS Power’s customer service team to 29 focus on a subset of escalat...

AI summary The document outlines NSPI's responses to the NSEB's information requests regarding a cybersecurity incident. It mentions that a call centre was staffed by TransUnion to manage the high volume of calls during the incident, allowing NS Power's customer service team to focus on escalated queries.

Section 107
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The document outlines NSPI's responses to information requests from the NSEB related to a cybersecurity incident, with the content of the responses redacted.

Section 109
of paper copies were distributed and available to customers across the province 24 through customer support sessions at community locations. In addition, the fact sheet was 25 available at NS Power local depots and provided to MLAs and loc...

AI summary NS Power distributed paper copies of a fact sheet across the province, made it available at local depots, and encouraged customers and employees to spread awareness. The document relates to a cybersecurity incident inquiry by the NSEB and NSPI's responses to information requests.

Section 110
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The document outlines NSPI's responses to NSEB information requests related to a cybersecurity incident, with portions redacted.

Section 111
1 In addition, the Company deployed dozens of employees to communities across the 2 province to provide hands-on support for customers who prefer assistance in person, 3 recognizing that not all customers may be comfortable registering onl...

AI summary NS Power has deployed employees to assist customers in person and updated its website to improve service access. The company has implemented cybersecurity standards based on NIST guidelines and completed a two-year update to its cybersecurity practices.

Section 112
ations are 24 designed to comply with other industry-specific rules and standards relating to 25 cybersecurity and IT including, but not limited to, those mandated by the North American 26 Electric Reliability Corporation (NERC). NERC cond...

AI summary The document discusses Nova Scotia Power's (NSPI) cybersecurity measures, including mandatory training and phishing simulations, in response to a cybersecurity incident inquiry by the Nova Scotia Energy Board (NSEB). It mentions compliance with NERC standards and audits.

Section 113
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED 1 Incident Response and Remediation: 2 3 Immediately following detection of unauthorized access, NS Power activated its incident 4 response and busin...

AI summary NSPI responded to the NSEB's information requests regarding a cybersecurity incident, activating incident response protocols, engaging third-party experts, and taking immediate remediation actions to contain and isolate affected servers.

Section 114
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED 1 2 3 4 Ongoing remediation steps include: 5 6 7 8 9 10 11 12 13 14 NS Power is also advancing efforts to restore and, where necessary, rebuild core...

AI summary NSPI is responding to NSEB information requests regarding a cybersecurity incident. Ongoing remediation includes restoring core business systems and strengthening cybersecurity protocols. A business restoration process office has been established, and a strategic partner has been retained to assist in the recovery.

Section 115
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 (e) NS Power initially notified customers of the Incident on Monday, April 28, 2025 as noted...

AI summary This document outlines NSPI's responses to the NSEB's information requests regarding a cybersecurity incident. NSPI notified customers on April 28, 2025, and provided ongoing updates during the response period. The matter is under inquiry by the NSEB as part of proceeding M12273.

Section 116
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The document outlines NSPI's responses to NSEB information requests regarding a cybersecurity incident, with sensitive details redacted.

Section 118
streamed session. Following this two-hour session with elected officials, Peter Gregg made 26 himself available and spoke to media gathered outside the legislative chamber. 27 Date Filed: September 5, 2025 NSPI (NSEB) IR-1 Page 15 of 21 20...

AI summary This document outlines NSPI's responses to the NSEB's information requests regarding a cybersecurity incident. It includes actions taken, such as proactive notifications to media and customer support sessions for credit monitoring.

Section 119
Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary This document pertains to a cybersecurity incident and includes NSPI's responses to information requests from the NSEB. The content has been redacted.

Section 121
ainland (noted in chart below), as well as information being shared with 28 AllNovaScotia.com, Global Halifax, MBS Radio, Halifax Examiner and the Chronicle 29 Herald. 30 Date Filed: September 5, 2025 NSPI (NSEB) IR-1 Page 17 of 21 2026042...

AI summary Nova Scotia Power Inc. (NSPI) has been involved in a cybersecurity incident, leading to an inquiry by the Nova Scotia Energy Board (NSEB). NSPI has taken proactive steps to inform customers through outreach to local radio stations.

Section 123
Ken Kingston, News Director [email protected] Port Hawkesbury: 101.5FM Sydney: The Coast 89.7FM Radio [email protected] - (CKOA) [email protected] MBS Radio [email protected] New Country 103.5FM NORTHEAST Amherst: CFTA Tantram...

AI summary The document outlines a Board Inquiry into a cybersecurity incident involving Nova Scotia Power, with responses provided by NSPI to NSEB information requests. The filing date is September 5, 2025, and the matter number is M12273. The document is marked as confidential with redacted information.

Section 124
REDACTED Station Contact & CKTO EZ Rock (MBS Radio) New Glasgow: [email protected] CKEZ 97.9FM Pictou County: [email protected] CKEC 94.1FM The Breeze METRO Halifax: Surge 105FM (CKHY) & Hot [email protected] (both newsroo...

AI summary The document outlines Nova Scotia Power Inc.'s (NSPI) responses to information requests from the Nova Scotia Energy Board (NSEB) regarding a cybersecurity incident. Advertisements were placed in local and provincial newspapers to reach a broader audience, though specific details are redacted.

Section 125
's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED

AI summary The document discusses a cybersecurity incident involving Nova Scotia Power Inc. (NSPI) and its responses to information requests from the Nova Scotia Energy Board (NSEB). The incident is referenced by the matter number M12273.

Section 126
1 (f) Please see the following table for details on public interviews provided: 2 Member of NSP senior Date Media Outlet Format Reporter Topic leadership team Amy Smith, Peter Gregg, Anchor Cyber incident May 23, 2025 CBC TV President and...

AI summary The text lists public interviews conducted by NSP senior leadership regarding a cyber incident update. The interviews were conducted on May 23, 2025, with CBC TV and CBC Mainstreet Radio, featuring Peter Gregg, President and CEO, and Jeff Douglas as the reporter.

Section 127
Radio Douglas President and Mainstreet update (live/on air) CEO Peter Gregg, Gillian Cyber incident May 23, 2025 allnovascotia.ca Print/Online President and Cormier update CEO Peter Gregg, Mike Cyber incident May 29, 2025 Canadian Press Pr...

AI summary This text lists media coverage and updates related to a cyber incident involving Nova Scotia Power Inc. (NSPI), with updates provided by Peter Gregg, President and CEO, and other officials.

Section 128
update CEO Peter Gregg, CBC Info Portia Cyber incident May 30, 2025 Radio President and Morning Clarke update CEO Cyber incident update Chris Customer Ryan Lanteigne, June 17, 2025 CTV TV support MacDonald Director sessions in Customer Car...

AI summary The text provides updates on cyber incidents from Nova Scotia Power Inc. (NSPI), with statements from Peter Gregg, CEO, and Portia Clarke, President and CEO. It also mentions a customer support initiative led by Ryan Lanteigne, Director of Customer Care, involving community sessions across Nova Scotia.

Section 129
communities across NS CBC Chris Billing/custom Information Lanteigne, er support June 17, Morning Radio Director sessions for 2025 Mainland Customer Care credit (recorded to air monitoring June 18) Date Filed: September 5, 2025 NSPI (NSEB)...

AI summary This document outlines a board inquiry into a cybersecurity incident involving Nova Scotia Power, with responses provided by NSPI to the Nova Scotia Energy Board. The incident is referenced as NSEB M12273, and the filing date is September 5, 2025.

Section 130
s Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests REDACTED Cyber incident update Billing Chris concerns CBC Nova Elizabeth Lanteigne, July 9, 2025 Radio Customer Scotia McMillan Director support Customer Ca...

AI summary The document discusses a cybersecurity incident related to Nova Scotia Power Inc. (NSPI) and their responses to information requests from the Nova Scotia Energy Board (NSEB). It also mentions customer concerns and outreach efforts by NSPI.

Section 131
communities across NS CBC Nova Scotia – Chris Meter Readers Information Lanteigne, & Community Taryn July 11, 2025 Morning Radio Director Sessions (also Grant Mainland Customer Care asked about (to air Monday, cyber incident) July 13) 1 Da...

AI summary This document is a confidential report related to a cybersecurity incident filed by Nova Scotia Power Inc. (NSPI) with the Nova Scotia Energy Board (NSEB), referencing matter number M12273. The report includes attachments and is part of a regulatory proceeding.

Section 132
ttachment 1 Page 1 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Cybersecurity Incident NSEB IR-01 Attachment 1 Page 2 of 4 We encourage you to remain vigilant and cautious about any unsolicited communications (such as emails, text mess...

AI summary Nova Scotia Power Inc. (NSPI) has experienced a cybersecurity incident and is advising customers to be cautious of unsolicited communications. They have partnered with TransUnion Canada to provide a 24-month subscription to myTrueIdentity® for credit monitoring and identity restoration at no cost to affected customers.

Section 136
hat the creditor contact you prior to establishing any accounts in your name. To place a fraud alert on your credit report, contact TransUnion Canada and Equifax Canada using the information above. 4/4 REDACTED (CONFIDENTIAL INFORMATION RE...

AI summary Nova Scotia Power has experienced a cybersecurity incident and is advising customers to be cautious of unsolicited communications requesting personal information. The company has established a dedicated contact number for customer inquiries and is taking steps to enhance system security.

Section 137
Cybersecurity Incident NSEB IR-01 Attachment 2 Page 3 of 4 Services Description We have retained the assistance of Trans Union of Canada, Inc. (“TransUnion Canada”), one of Canada’s leading consumer reporting agencies and arranged a 24-mon...

AI summary The document outlines a cybersecurity incident and describes a service provided to affected individuals, including a 24-month subscription to myTrueIdentity® for credit monitoring and identity restoration, with instructions on how to activate the service using an activation code.

Section 141
hat the creditor contact you prior to establishing any accounts in your name. To place a fraud alert on your credit report, contact TransUnion Canada and Equifax Canada using the information above. 4/4 REDACTED (CONFIDENTIAL INFORMATION RE...

AI summary This text discusses steps customers affected by a cybersecurity incident involving Nova Scotia Power should take, including signing up for credit monitoring services and using an activation code provided in a letter.

Section 143
cess cannot be paused or resumed after periods of inactivity. If you aren’t able to complete the enrolment process in one session, you will have to call TransUnion to complete the process. Dark Web Monitoring: Once you’ve signed up, What i...

AI summary The text outlines steps for individuals to take following a cybersecurity incident, including enrolling in dark web monitoring, contacting TransUnion for technical support, and taking further protective measures such as contacting credit reporting agencies and reviewing financial statements.

Section 144
ments. If you notice any suspicious activity related to your Social Insurance Number, report it to the police and contact the Canadian Anti-Fraud Centre at 1-888-495-8501. 2 Sign up for Equifax’s fraud alerts and security freezes through t...

AI summary The document provides guidance to customers affected by a cybersecurity incident involving Nova Scotia Power, advising them to report suspicious activity, sign up for fraud alerts, and contact their financial institutions. It also outlines support measures being taken by Nova Scotia Power, including in-person assistance and customer care resources.

Section 145
REMOVED) Cybersecurity Incident NSEB IR-01 Attachment 4 Page 1 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) CYBER INCIDENT UPDATES NEWS July 8, 2025 Since the cyber incident discovered on April 25, power m...

AI summary Following a cyber incident discovered on April 25, NS Power has paused and resumed customer billing due to communication issues with power meters. Meter readers are now visiting homes to collect accurate energy usage data to provide actual bills until systems are restored.

Section 146
REMOVED) Cybersecurity Incident NSEB IR-01 Attachment 4 Page 2 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) Wednesday, June 25, 2025 Update A dedicated team within Nova Scotia Power, along with third-party...

AI summary Nova Scotia Power is updating customers about a ransomware attack that impacted personal data, including that of former customers. The company is offering five years of free credit monitoring to all customers and is investigating the full scope of data affected.

Section 147
and customer correspondence), and driver’s license number. For some of our former customers, bank account numbers (for pre-authorized payment) and Social Insurance Numbers may also have been impacted. We intend to do everything we can to s...

AI summary Nova Scotia Power Inc. (NSPI) is informing customers of a cybersecurity incident that may have exposed personal information, including bank account numbers and Social Insurance Numbers. The company is offering expanded credit monitoring and providing resources to help customers protect themselves from identity theft.

Section 148
to be from Nova Scotia Power asking you to provide your personal information. Please avoid clicking on suspicious links or downloading attachments without confirming they are from a legitimate source. We have heard concerns about SINs, whi...

AI summary Nova Scotia Power is addressing a cybersecurity incident involving the collection of SINs and is cooperating with the Office of the Privacy Commissioner of Canada and the Nova Scotia Energy Board. They are committed to transparency and have been invited to speak with the Nova Scotia Public Accounts Committee.

Section 149
on and response efforts remain ongoing, we have committed to be as open and transparent as possible. This meeting today is a part of that transparency. Opening remarks by Peter Gregg, President & CEO On behalf of our entire team at Nova Sc...

AI summary Nova Scotia Power Inc. (NSPI) is addressing a cybersecurity incident affecting its systems and customers. The company has apologized for the impact and is working to resolve the issue while maintaining transparency. Cybersecurity experts and law enforcement are involved in the ongoing investigation.

Section 150
N REMOVED) Cybersecurity Incident NSEB IR-01 Attachment 4 Page 5 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) The privacy commissioner of Canada stated last week that: “Data breaches have surged over the p...

AI summary Nova Scotia Power Inc. (NSPI) discusses a recent cybersecurity incident, emphasizing its commitment to cybersecurity and compliance with standards set by NIST and NERC. The company assured that no payments were made to the attackers and highlighted its response protocols, including engaging third-party experts and isolating affected systems.

Section 151
ng swift actions to contain and isolate the affected systems to prevent further intrusion. Our cybersecurity program ensured that our operations systems and electric grid continue to perform as usual. As you know, the criminals stole data,...

AI summary Nova Scotia Power Inc. (NSPI) has taken steps to isolate affected systems following a cybersecurity incident and is providing credit monitoring services to impacted customers. Investigations are ongoing, with cooperation from the Nova Scotia Energy Board (NSEB) and the Office of the Privacy Commissioner of Canada.

Section 152
ns of the incident have been initiated by both the Nova Scotia Energy Board and the Office of the Privacy Commissioner of Canada. Nova Scotia Power will fully cooperate with both of these proceedings. You have my commitment that our team i...

AI summary Nova Scotia Power has been the victim of a ransomware attack and is working with cybersecurity experts to restore systems and investigate the incident. No ransom has been paid, and the threat actor has published stolen data. The company is committed to transparency and cooperation with the Nova Scotia Energy Board and the Office of the Privacy Commissioner of Canada.

Section 153
the threat actor has published data that was stolen from our systems. We are actively working with cybersecurity experts to assess the nature and scope of the information that may have been impacted. Notifications have been mailed to impac...

AI summary Nova Scotia Power is addressing a cybersecurity incident that affected IT systems, working with experts to assess the impact and restore systems. Affected customers have been notified and provided with free credit monitoring services. The company emphasizes the importance of vigilance against phishing and unsolicited communications.

Section 154
as impacted certain IT systems in our network. We are working with external cybersecurity experts to determine the scope of the impact and safely and securely restore and rebuild our impacted systems. While the investigation remains ongoin...

AI summary Nova Scotia Power Inc. experienced a cybersecurity incident where customer information was accessed by an unauthorized third party around March 19, 2025. Customers are being notified, and a free credit monitoring service is being provided. The affected information includes personal and account details, and customers are advised to be cautious of unsolicited communications.

Section 155
be from Nova Scotia Power asking you to provide your personal information. Please avoid clicking on suspicious links or downloading attachments without confirming they are from a legitimate source. 8 REDACTED (CONFIDENTIAL INFORMATION REMO...

AI summary Nova Scotia Power detected unusual network activity on April 25, 2025, and initiated an incident response plan. The company confirmed that personal customer information was accessed by an unauthorized third party. They are working with external cybersecurity experts and law enforcement to investigate and restore affected systems.

Section 156
very seriously. The security of your information is our top priority. We are working urgently to determine the full nature and scope of the data that may have been affected, and individuals impacted. If we determine that your data was affe...

AI summary Nova Scotia Power and Emera Inc. discovered a cybersecurity incident involving unauthorized access into parts of their Canadian network and servers. The incident does not impact generation, transmission, or distribution facilities, nor does it affect customer service. The company is working to determine the full scope of the breach and will notify affected individuals.

Section 157
iscovered and are actively responding to a cybersecurity incident involving unauthorized access into certain parts of its Canadian network and servers supporting portions of its business applications. Immediately following detection of the...

AI summary Nova Scotia Power Inc. is responding to a cybersecurity incident involving unauthorized access to its Canadian network and servers. The incident has not disrupted physical operations or impacted customer service in Nova Scotia. The company is working with cybersecurity experts to restore affected systems.

Section 158
curity Incident NSEB IR-01 Attachment 4 Page 12 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) LATEST UPDATES July 8, 2025 • Power meters have continued to function and gather accurate energy usage data from...

AI summary Nova Scotia Power Inc. (NSPI) is experiencing a cyber incident that has disrupted communication between power meters and their systems. While meters continue to collect data, billing has been paused and later resumed with estimated bills. Meter readers are now being deployed to gather actual usage data to provide more accurate bills.

Section 159
etation, pets, fencing, etc., you will receive an estimated bill based on an average of the previous energy used at your property during a similar time of year. Wednesday, June 25, 2025 • Beginning today, we will be offering five years of...

AI summary Nova Scotia Power is offering free credit monitoring to current and former customers following a cybersecurity incident where personal information was accessed by an unauthorized third party. The company is providing expanded support and covering all costs related to the credit monitoring service.

Section 160
• We are focused on supporting our customers. We are here for regular business from 8 AM–6 PM, Monday through Friday. Please contact us at 1-800-428-6230. Wednesday, June 5, 2025 • Nova Scotia Power leadership appeared before the Nova Scot...

AI summary Nova Scotia Power Inc. confirmed a ransomware attack that led to stolen customer data. The company did not make a ransom payment and is working with cybersecurity experts and law enforcement to restore systems and support affected customers with credit monitoring and identity protection.

Section 161
been impacted. • Since the incident began several weeks ago, we have been actively working with the assistance of third-party cyber security experts to restore our systems safely 13 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Cybersecurity...

AI summary Nova Scotia Power has been dealing with a cybersecurity incident, working with third-party experts to restore systems and strengthen security. Affected customers have been notified and offered free credit monitoring. The company expresses regret over the incident and emphasizes the importance of data security.

Section 162
ely sorry that this issue has occurred. Protecting the privacy and security of information held by Nova Scotia Power is something we take very seriously. Wednesday, May 14, 2025 • Nova Scotia Power continues to investigate a cyber incident...

AI summary Nova Scotia Power is investigating a cyber incident that led to unauthorized access and exfiltration of customer information. Affected customers are being notified and offered free credit monitoring services. The company emphasizes the seriousness of protecting customer privacy and security.

Section 163
systems in our network. • While our investigation is ongoing, we have identified that certain customer personal information was accessed and taken by an unauthorized third party. 14 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Cybersecurity...

AI summary Nova Scotia Power Inc. (NSPI) has identified a cybersecurity incident where customer personal information was accessed by an unauthorized third party. NSPI is investigating and will notify affected customers with further details and resources. Customers are advised to be cautious of unsolicited communications requesting personal information.

Section 164
ou to provide your personal information. Please avoid clicking on suspicious links or downloading attachments without confirming they are from a legitimate source. Monday, April 28, 2025 • Emera and Nova Scotia Power discovered and are act...

AI summary Emera and Nova Scotia Power have discovered a cybersecurity incident involving unauthorized access to parts of their network and servers. They have activated response protocols, engaged cybersecurity experts, and isolated affected systems. Operations remain unaffected, and customers are advised to remain vigilant against suspicious communications.

Section 165
4 Page 16 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) FAQS What happened? Last updated: Tuesday, June 24, 2025 On April 25, we discovered and began actively responding to a cybersecurity incident involvin...

AI summary Nova Scotia Power Inc. (NSPI) experienced a ransomware attack on April 25, 2025, leading to unauthorized access to customer personal information. No ransom was paid due to legal restrictions. NSPI is working with cybersecurity experts and law enforcement to investigate and remediate the breach.

Section 166
ION REMOVED) Cybersecurity Incident NSEB IR-01 Attachment 4 Page 17 of 20 NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) • Informed impacted customers via mail and provided a free subscription to TransUnion’s cred...

AI summary Nova Scotia Power informed impacted customers about a cybersecurity incident where personal information was accessed and published on the dark web. The company provided credit monitoring services and organized in-person support. They are expanding free credit monitoring to all customers, regardless of whether they received a letter.

Section 167
s of Nova Scotia Power—past and present—regardless of whether you received a letter from us about the incident. I’m a current customer, but I did not get a letter. Does that mean I was not affected? 17 REDACTED (CONFIDENTIAL INFORMATION RE...

AI summary Nova Scotia Power is offering free credit monitoring to all current and past customers, regardless of whether they received a letter about a cybersecurity incident. The offer was expanded from two years to five years. Customers who already signed up will be automatically extended to five years. The expansion is part of ongoing efforts to protect customers.

Section 168
a code and already signed up for two years of monitoring, you will be automatically extended to five years. Why didn’t you offer credit monitoring to everyone right away when this happened? Why now? Last updated: Wednesday, June 25, 2025 O...

AI summary Nova Scotia Power Inc. (NSPI) is expanding free credit monitoring to all past and present customers following a cybersecurity incident. Initially, it was offered only to those confirmed to have been impacted. The company is now reaching out to former customers through various channels to ensure they are informed.

Section 169
as broadly as possible. We are actively sharing this information with media, on social media, with stakeholders, and through paid advertising to reach as many current and former customers as possible. We strongly encourage anyone who is co...

AI summary Nova Scotia Power Inc. (NSPI) is informing customers of a cybersecurity incident that disrupted internal IT systems, billing processes, and access to the MyAccount portal. The company is offering free credit monitoring and encourages customers to share information with former customers. NSPI is working to restore systems and provide estimated bills.

Section 170
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL 1 Request IR-3: 2 3 NS Power, in its Thursday, May 14, 2025, cybersecurity update letter stated: 4 5 Beginni...

AI summary The Nova Scotia Energy Board (NSEB) is inquiring into Nova Scotia Power's (NSPI) cybersecurity incident, focusing on the determination of no misuse of customer data, notice procedures, communication strategies, and the selection of credit monitoring services. NSPI has committed to providing five years of free credit monitoring to affected customers.

Section 171
TransUnion myTrueIdentity® services? 31 Date Filed: September 5, 2025 NSPI (NSEB) IR-3 Page 1 of 7 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NS...

AI summary The document outlines NSPI's responses to the NSEB's information requests regarding a cybersecurity incident. The inquiry is part of a regulatory proceeding, and the responses are non-confidential.

Section 172
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL 1 (i) Please list the components of this service and provide comment of their 2 appropriateness. 3 4 (ii) Wh...

AI summary Nova Scotia Power Inc. (NSPI) responded to inquiries regarding a cybersecurity incident, detailing their investigation and credit monitoring measures. They mentioned enhanced dark web monitoring and indicated no misuse of data. NSPI also began notifying affected customers.

Section 173
’s personal information 26 has been misused in a manner that is directly connected to this Incident. 27 28 (b) NS Power began mailing letters to impacted customers on May 13, 2025. 29 Date Filed: September 5, 2025 NSPI (NSEB) IR-3 Page 2 o...

AI summary Nova Scotia Power Inc. (NSPI) is responding to an inquiry by the Nova Scotia Energy Board (NSEB) regarding a cybersecurity incident. Personal information of customers was misused, and NSPI began mailing letters to impacted customers on May 13, 2025.

Section 174
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL

AI summary This document outlines Nova Scotia Power's responses to information requests from the Nova Scotia Energy Board regarding a cybersecurity incident. The inquiry focuses on NSPI's handling of the incident and its implications.

Section 176
set out above, the Company’s approach to transparent communications about the impact 26 of the Incident on NS Power customers principally consisted of direct notifications to active 27 impacted customers, and public postings to the Company...

AI summary The Company communicated the impact of a cybersecurity incident to NS Power customers through direct notifications and public postings on the Company website, supported by media outreach and social media engagement. Samples of notification letters are attached as Attachments 1 and 2 to IR-1.

Section 177
nquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL

AI summary This document relates to an inquiry into a cybersecurity incident at Nova Scotia Power and includes their responses to information requests from the Nova Scotia Energy Board. It is marked as non-confidential.

Section 179
ailable to assist individuals with 26 questions about identity theft. In the unlikely event that an individual becomes a 27 victim of fraud, a personal restoration specialist will help to resolve any identity 28 theft. 29 30 • Up to $1,000...

AI summary The document outlines identity theft protection services offered by Nova Scotia Power Inc., including assistance with fraud resolution and up to $1,000,000 in expense reimbursement insurance. It is part of NSPI's responses to the NSEB regarding a cybersecurity incident inquiry.

Section 180
Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL

AI summary This document outlines Nova Scotia Power's responses to the Nova Scotia Energy Board's information requests regarding a cybersecurity incident. The inquiry is part of a regulatory proceeding to assess the incident and its implications.

Section 182
ubscription to TransUnion’s myTrueIdentity® service, as a two-year time period for a 25 credit monitoring service has become a well-established, common practice for 26 organizations across industries (financial services, healthcare, retail...

AI summary The document discusses Nova Scotia Power's cybersecurity incident and their responses to information requests from the Nova Scotia Energy Board (NSEB). It references a subscription to TransUnion’s myTrueIdentity® service for credit monitoring following a data breach.

Section 183
nquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL

AI summary This document outlines Nova Scotia Power's responses to information requests from the Nova Scotia Energy Board regarding a cybersecurity incident. The inquiry is referenced as NSEB M12273, and the responses are marked as non-confidential.

Section 185
dit management, fraud victim 26 assistance and identity theft prevention. 27 28 • Access to Identity Restoration agents who are available to assist individuals with 29 questions about identity theft. In the unlikely event that an individua...

AI summary The document outlines measures for identity theft prevention and restoration assistance, including access to Identity Restoration agents and personal restoration specialists. It is related to a cybersecurity incident inquiry by the Nova Scotia Energy Board (NSEB) into Nova Scotia Power Inc. (NSPI).

Section 186
nquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests NON-CONFIDENTIAL 1 • Up to $1,000,000 of expense reimbursement insurance related to identity theft. 2 3 • Dark Web Monitoring,...

AI summary The document outlines NSPI's responses to the NSEB's information requests regarding a cybersecurity incident, including measures such as expense reimbursement insurance, dark web monitoring, and communication strategies with impacted individuals.

Section 187
IR-3 Page 7 of 7 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Osler, Hoskin & Harcourt LLP Box 50, 1 First Canadian Place Toronto, Ontario, Canada M5X 1B8 416.362.2111 MAIN 416.862.6666 FACSIMILE August 8, 2025 Adam Kardash Direct Dial: 416...

AI summary NS Power has been the victim of a sophisticated ransomware attack that did not impact customer power infrastructure but affected internal IT and customer care systems. The threat actor exfiltrated customer data and posted it on the dark web. NS Power seeks a procedural order to keep its confidential submissions restricted to the Inquiry panel, the Clerk of the Board, and the Board's counsel.

Section 188
o exfiltrated certain data, including customer information. Consistent with the aggressive tactics of ransomware attackers, the threat actors have already posted certain NS Power data on the dark web. 3. In line with recognized best practi...

AI summary NS Power has experienced a ransomware attack leading to data exfiltration and public posting of data on the dark web. NS Power is collaborating with cybersecurity experts and intends to provide sensitive information to the Board regarding the incident, emphasizing the need for confidentiality due to the unique nature of the cybersecurity inquiry.

Section 189
ive nature of privacy or cybersecurity investigations. REDACTED (CONFIDENTIAL INFORMATION REMOVED) Page 3 9. Should the Board require further information regarding these special circumstances (including the detailed basis for the credible...

AI summary The letter requests the Board to convene an in-camera meeting with NS Power to discuss special circumstances and credible risks related to privacy or cybersecurity investigations. The request is made by Adam Kardash and his team, representing NS Power.

Section 190
tia B3J 3P6 Attention: Crystal Henwood, Clerk of the Board Dear Ms. Henwood: M12273 – Inquiry of the Nova Scotia Energy Board (the Board) into Cybersecurity Incident of Nova Scotia Power (NS Power) Thank you for your correspondence dated A...

AI summary NS Power is responding to the Nova Scotia Energy Board's inquiry into a cybersecurity incident. They emphasize their commitment to cooperation while requesting strict confidentiality for sensitive information. They reference privacy regulatory authorities' procedures as a model for handling such investigations.

Section 191
en privacy regulatory authorities’ extensive experience investigating cybersecurity incidents, we view their investigative procedures as being helpful and informative to the Board as it determines the 1 Sherman Estate v. Donovan, 2021 SCC...

AI summary The document discusses NS Power's expectations regarding the Board's handling of confidentiality claims during the Inquiry, emphasizing the need for scrutiny and the opportunity to explain the necessity of keeping certain information confidential, potentially through an oral hearing with cybersecurity experts.

Section 196
us peine des sanctions prévues à l’article 413-10 du code pénal et, sous réserve de ce qui est nécessaire à l’établissement du rapport annuel, à l’article 226- 13 du même code. Unofficial Translation Art II The commission’s agents are boun...

AI summary NS Power has faced a sophisticated ransomware attack, leading to the theft and potential dark web posting of customer personal information. Despite extortion tactics, NS Power has decided not to pay the ransom, aligning with law enforcement guidance and applicable sanctions laws.

100161NSPI Monthly Update Report #4 7 passages
Section 1
December 1, 2025 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power’s Cybersecurity Incident – Monthly Update 4 Dear Ms. Henwood: On July 14, 20...

AI summary The Nova Scotia Energy Board (NSEB) directed Nova Scotia Power (NS Power) to submit monthly updates on its response to a cybersecurity incident. NS Power is on track to deliver its Incident Report by December 31, 2025. The NSEB mandated resolving vendor dues, providing a Gantt chart in the report, and engaging MNP to investigate data handling practices.

Section 3
nd Project Accounting was re- established resulting in a resumption of automated end-to-end project lifecycle tracking and data supporting decision-making on property, plant and equipment investments. A cross-functional team of employees a...

AI summary NS Power addresses billing disruptions from a cybersecurity incident by implementing manual meter readings, waiving late fees, and planning system reconnection. A cross-functional team works to restore normal payment processes, with full meter reconnection expected by March 2026. The NSEB is referenced in a related inquiry.

Section 9
ata for the FAM report was able to be created through different processes, with a high degree of confidence that the data is accurate. Once systems are back online, any discrepancies will be trued up. Dispatch Study Action Plan Quarterly U...

AI summary The document discusses updates on the FAM report data accuracy, delays in the ECC Optimization Tools Project until March 2026, resolution of Maritime Link Project cost allocation issues, and the impact of a cybersecurity incident on the Joint-Use Agreement Proceeding. NS Power also addressed capital costs for poles under the JUA.

Section 11
ent, an analysis cannot be completed at this time. 3 NS Power’s response to CA IR-3 parts (b), (d) and (e), submitted to the Board on August 20, 2025, provided the following, respectively: Prior to the cyber incident, NS Power maintained l...

AI summary NS Power explains that a cyber incident disrupted its ability to track customer installation timelines and service times for power connections. Pre-incident processes involved Bell Aliant, but post-incident application links are unavailable, limiting data access and new tracking capabilities. Clarity on historical data may emerge by fall.

Section 12
wer and Bell poles, as the links between applications used for tracking are currently unavailable. 4 NS Power’s response to SBA IR-1 parts (b) and (c) provided the following, respectively: Since the signing of the LOI, approximately 175 wo...

AI summary NS Power's response to the Joint-Use Agreement Proceeding (M12149) highlights delays caused by a recent cyber incident, which has disrupted access to critical systems like GIS, preventing the finalization of agreements with Bell and affecting the Point of Construction Settlement process.

Section 15
ver 100 years. We recognize that the recent cyber event has affected the trust we have built with our customers, and I want to acknowledge and apologize for the concern and disruption this has caused. Over the past 215 days, our team has w...

AI summary Nova Scotia Power acknowledges a sophisticated cyberattack linked to a Russia-based group, impacting customer trust and billing accuracy. The company committed to rectifying overestimations, enhancing cybersecurity measures, and restoring systems while ensuring grid stability. Recovery efforts include IT upgrades, secure communication systems, and financial process improvements.

Section 17
power poles across the province and clearing trees from 1,500 kilometers of power lines. We continue to make essential investments to meet our customers’ energy needs and strengthen future resilience. In September, we submitted a General R...

AI summary Nova Scotia Power submitted a General Rate Application, emphasizing reliability investments and affordability balance with customer advocates. They commit to correcting billing errors and cooperate with regulatory and cybersecurity investigations by NSEB and OPC.

97660Board Letter re: Inquiry 2 passages
Section 1
May 14, 2025 [email protected] Judith Ferguson Executive Vice President, Regulatory, Legal and Business Planning Nova Scotia Power Incorporated P.O. Box 910, 1223 Lower Water Street Halifax, NS B3J 3S8 Dear Ms. Ferguson: M12273 -...

AI summary Nova Scotia Power disclosed a cybersecurity incident involving unauthorized access to customer data, including personal information and account details. The breach, discovered in March 2025, caused delays in regulatory proceedings. The Board expressed concern over the impact on IT systems and the timeline of the incident.

Section 2
otes that customer information was accessed on March 19, 2025, which is more than a month before the date NS Power discovered and responded to the cyber incident as noted in its initial press release. The Board has opened a proceeding and...

AI summary The Board has initiated an inquiry into a cybersecurity incident involving NS Power, where customer data was accessed before the company's public response. The Board will engage cybersecurity experts and require NS Power to submit a report, emphasizing regulatory oversight while allowing NS Power to focus on recovery efforts.

98507Board Letter re: Reports required 3 passages
Section 1
July 14, 2025 [email protected] Judith Ferguson Executive Vice President, Regulatory, Legal and Business Planning Nova Scotia Power Incorporated P.O. Box 910, 1223 Lower Water Street Halifax, Nova Scotia B3J 3S8 Dear Ms. Ferguson:...

AI summary The Nova Scotia Utility and Review Board is conducting an inquiry into Nova Scotia Power’s cybersecurity incident (M12273), requesting a detailed report on the breach’s discovery, attack vector, timeline, affected systems, data exposure, and indicators of compromise. MNP Digital is assisting with the investigation.

Section 3
Root Cause Analysis • A description of how the breach occurred. • An identification of vulnerabilities or security gaps that were exploited. Impact Analysis • Assessment of the breach's impact on NS Power, including financial, operational...

AI summary The document outlines a cybersecurity breach at NS Power, detailing root causes, vulnerabilities, operational and reputational impacts, response actions, and recommendations for improved security measures. It emphasizes the need for enhanced safeguards, audits, and stakeholder communication.

Section 4
breaches. o additional security audits, policy updates, and employee training. o implementing new strategies and proactive measures to strengthen NS Power’s cybersecurity defenses. o improving communications and responsiveness to the conce...

AI summary The document addresses NS Power's response to cybersecurity breaches, including security audits, policy updates, and improved customer communication. The Board emphasizes public transparency in its inquiry, even when sensitive information cannot be disclosed. NS Power is required to file an incident report, after which the Board will review its response and planning.

98677NSEB (NSPI) IR 1 to 12 9 passages
Section 1
M12273 NOVA SCOTIA ENERGY BOARD IN THE MATTER OF: THE PUBLIC UTILITIES ACT - and - IN THE MATTER OF: BOARD INQUIRY INTO NOVA SCOTIA POWER'S CYBERSECURITY INCIDENT INFORMATION REQUESTS To: Nova Scotia Power Incorporated Judith Ferguson Exec...

AI summary The Nova Scotia Energy Board issued an information request to Nova Scotia Power regarding a cybersecurity incident under the Public Utilities Act, seeking responses by August 15, 2025. The request was sent to Judith Ferguson, Executive Vice President of Nova Scotia Power, with copies to the Board's Senior Advisor, Somesh Singh, and Clerk of the Board, Crystal Henwood.

Section 3
Document: 322181 Date Filed: 24 July 2025 Page 1 1 Request IR-1: 2 Please provide a timeline of this cybersecurity incident, including: 3 a) the date of the breach; 4 b) the date suspicious activity was discovered; 5 c) the date the cyber...

AI summary The document contains two information requests (IR-1 and IR-2) related to a cybersecurity incident involving Nova Scotia Power (NSP). IR-1 seeks a detailed timeline of the breach, including dates for discovery, confirmation, and public disclosure. IR-2 asks for confirmation of affected customers, including former customers, and details about data access by unauthorized parties.

Section 4
not, please explain. 29 c) Please confirm whether the number of former customers impacted is included in the 30 numbers provided by the utility in subsections a) – c) of this Information Request. 31 32 Request IR-3: 33 NS Power, in its Thu...

AI summary The text includes two information requests: one seeking clarification on whether former customers are included in impact numbers, and another referencing NS Power's cybersecurity update involving TransUnion. The latter mentions no evidence of personal data misuse but notes arrangements with TransUnion for affected individuals.

Section 6
Document: 322181 Date Filed: 24 July 2025 Page 2 1 year subscription to a comprehensive credit monitoring service (TransUnion 2 myTrueIdentity®) at no cost. 3 4 [Cyber Nova Scotia Power: Wednesday, May 14, 2025 Update] 5 6 NS Power, in its...

AI summary Nova Scotia Power (NSP) offers free credit monitoring to customers following a data breach. The document includes questions about NSP's breach response, including determination of no misuse, notice timelines, communication methods, and selection of TransUnion's service.

Section 8
ease explain. 34 j) After the five-year credit monitoring expires, how can the utility determine that this breach 35 will not lead to unauthorized activity beyond that period? 36

AI summary The text raises concerns about assessing ongoing risks of unauthorized activity after a five-year credit monitoring period expires, questioning how utilities can ensure breaches do not lead to future unauthorized access.

Section 9
Document: 322181 Date Filed: 24 July 2025 Page 3 1 Request IR-4: 2 a) Please provide the utility’s comments to complaints received by the Board and filed as 3 Letters of Comment that request at least 10 years of credit monitoring Identity...

AI summary The document includes three requests (IR-4 to IR-6) related to customer complaints about credit monitoring services and a cybersecurity breach. It seeks Nova Scotia Power's comments on complaints regarding credit monitoring coverage, compensation for declined services, and details about compromised personal data. The breach involved sensitive information like names, addresses, and financial data.

Section 10
24 [Cyber Nova Scotia Power: Wednesday, May 14, 2025 Update] 25 26 a) If a customer requests it, could the utility provide details about the compromised 27 information relating specifically to that customer? 28 i. If yes, please explain th...

AI summary The text raises questions about Nova Scotia Power's (NSP) handling of a data breach, including customer access to compromised information, communication practices, and the functionality of a dedicated support line. Complaints note the support line incorrectly routes to TransUnion instead of NSP representatives.

Section 12
Document: 322181 Date Filed: 24 July 2025 Page 4 1 i. Please confirm whether the dedicated number belongs to NS Power’s support 2 team or TransUnion. 3 ii. If TransUnion, please explain why it is operated by a third-party and comment on 4...

AI summary The document contains requests (IR-1 to IR-10) directed at Nova Scotia Power (NSP) regarding cybersecurity breach management, customer support resources, credit monitoring issues, and communication policies. Questions focus on third-party involvement, customer guidance, service impacts, and policy documentation.

Section 13
and new connection service 32 requests, that have been impacted by this breach due to the shifting of resources away 33 from these activities to support NS Power’s cybersecurity response. In addition, provide a 34 status update on the esti...

AI summary The text outlines requests related to a cybersecurity breach impacting NS Power's services, including delays in connection requests, billing issues, and customer communication. It seeks information on actions taken, service restoration timelines, and billing resolutions.

98825Letter NSPI re: Filing time 1 passage
Section 1
August 1, 2025 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Board Inquiry into Nova Scotia Power’s Cybersecurity Incident Dear Ms. Henwood: In response to t...

AI summary Nova Scotia Power Incorporated requests an extension to file monthly reports in M12273, citing the need for process clarification regarding the Board's inquiry into a cybersecurity incident. The request follows discussions with the Board's counsel.

98826Board Letter re: Filing / Timelines 1 passage
Section 1
August 1, 2025 [email protected] Judith Ferguson Executive Vice President, Regulatory, Legal and Business Planning Nova Scotia Power Incorporated P.O. Box 910, 1223 Lower Water Street Halifax, Nova Scotia B3J 3S8 Dear Ms. Ferguson...

AI summary The Board acknowledges Nova Scotia Power's request to delay filing monthly reports on a cybersecurity incident (M12273), citing sensitivity of information. It permits a delay until August 15, 2025, requiring NS Power to submit confidentiality requests by that date. Interested parties are invited to intervene by August 14.

98827Notice of Intervention - IG 1 passage
Section 1
2025 M12273 NOVA SCOTIA ENERGY BOARD IN THE MATTER OF: The Public Utilities Act - and - IN THE MATTER OF: Board Inquiry into Nova Scotia Power’s Cybersecurity Incident NOTICE OF INTERVENTION OF: K + S Windsor Salt Ltd. CKF Inc. Crown Fibre...

AI summary The Industrial Group (comprising multiple large/medium industrial companies) seeks intervention in a proceeding related to Nova Scotia Power’s cybersecurity incident, arguing their costs and rates will be affected by the outcome. The matter is under the Public Utilities Act.

98857Notice of Intervention - SBA 1 passage
Section 1
Matter No. M12273 NOVA SCOTIA ENERGY BOARD IN THE MATTER OF: The Public Utilities Act - and - IN THE MATTER OF: Board inquiry into Nova Scotia Power’s Cybersecurity Incident NOTICE OF INTERVENTION OF: SMALL BUSINESS ADVOCATE TAKE NOTICE th...

AI summary The Small Business Advocate intervenes in a proceeding under the Public Utilities Act regarding Nova Scotia Power’s cybersecurity incident, representing three classes of small businesses. The intervention highlights potential impacts on small business interests and seeks to ensure their concerns are addressed in the regulatory process.

98858Notice of Intervention - DOE 1 passage
Section 1
2025 M12273 NOVA SCOTIA ENERGY BOARD IN THE MATTER OF: The Public Utilities Act, RSNS 1989, c 380 as amended - and – IN THE MATTER OF: Board Inquiry into Nova Scotia Power’s Cybersecurity Incident - and – NOTICE OF INTERVENTION OF: HIS MAJ...

AI summary The Nova Scotia Department of Energy intervenes in a proceeding concerning Nova Scotia Power’s cybersecurity incident, asserting authority over energy matters and requesting information distribution through the Minister of Energy.

98860Notice of Intervention - CA 1 passage
Section 1
M12273 NOVA SCOTIA ENERGY BOARD IN THE MATTER OF: The PUBLIC UTILITIES ACT -and- IN THE MATTER OF: A Board Inquiry into NOVA SCOTIA POWER’s Cybersecurity Incident NOTICE OF INTERVENTION OF: CONSUMER ADVOCATE TAKE NOTICE that the Consumer A...

AI summary The Consumer Advocate intervenes in a proceeding under the Public Utilities Act regarding Nova Scotia Power's cybersecurity incident, representing residential ratepayers. The Advocate will address issues raised by the Energy Board and participate in the inquiry.

98887Notice of Intervention - E1 1 passage
Section 1
M12273 NOVA SCOTIA ENERGY BOARD IN THE MATTER OF THE PUBLIC UTILITIES ACT -and- IN THE MATTER OF a Board Inquiry into NOVA SCOTIA POWER’s Cyber Security Incident EFFICIENCYONE NOTICE OF INTERVENTION TAKE NOTICE that EfficiencyOne hereby in...

AI summary EfficiencyOne intervenes in a proceeding related to Nova Scotia Power's cyber security incident under the Public Utilities Act. As the electricity and conservation franchise holder, EfficiencyOne asserts a direct interest in the matter and intends to participate in the hearing, providing contact details for their legal counsel.

98901Letter NSPI re: Application for Procedural Order and Request for Confidentiality 3 passages
Section 1
Osler, Hoskin & Harcourt LLP Box 50, 1 First Canadian Place Toronto, Ontario, Canada M5X 1B8 416.362.2111 MAIN 416.862.6666 FACSIMILE August 8, 2025 Adam Kardash Direct Dial: 416.862.4703 [email protected] Our Matter Number: 1268459 Sent...

AI summary NS Power seeks a procedural order and confidentiality for submissions related to a 2025 ransomware attack inquiry. The request emphasizes the sensitive nature of cybersecurity incident details, limiting access to panel members, the Clerk, and Board counsel.

Section 2
further background facts are outlined in the Confidential Submissions. Page 2 B. Procedural Order Sought 4. Pursuant to Rules 5(2) and 5(3) of the Board Regulatory Rules, NS Power respectfully requests that the Board issue procedural order...

AI summary NS Power requests procedural orders to dispense with the Board's regulatory rules and adopt privacy regulator standards for a cybersecurity-related inquiry, citing public interest and collaboration needs. Confidential submissions detail the rationale, with emphasis on aligning with international privacy practices.

Section 5
are circumstances where non-parties with a relevant interest may, at the Page 4 regulator’s discretion, be asked to provide information or respond to the regulator’s questions, but such “interested persons” are similarly never granted acce...

AI summary NS Power commits to providing a detailed report on a cybersecurity incident to the Board by October 31, 2025, emphasizing cooperation in privacy investigations. The procedural order outlines terms for the Inquiry, including submission deadlines and non-adversarial process principles.

98924Board letter re additional information required 5 passages
Section 1
August 12, 2025 [email protected] Adam Kardash, Partner & Co-Chair Privacy and Data Management Osler, Hoskin & Harcourt LLP Box 50, 1 First Canadian Place Toronto, ON M5X 1B8 Dear Mr. Kardash: M12273 – Board Inquiry into Nova Scotia Power...

AI summary This document references a Board Inquiry (M12273) into Nova Scotia Power’s cybersecurity incident, addressed to Adam Kardash of Osler, Hoskin & Harcourt LLP. The inquiry pertains to regulatory oversight of cybersecurity measures in the energy sector.

Section 2
Privacy and Data Management Osler, Hoskin & Harcourt LLP Box 50, 1 First Canadian Place Toronto, ON M5X 1B8 Dear Mr. Kardash: M12273 – Board Inquiry into Nova Scotia Power’s Cybersecurity Incident

AI summary A letter from Osler, Hoskin & Harcourt LLP to Mr. Kardash regarding Board Inquiry M12273 into Nova Scotia Power’s cybersecurity incident. The inquiry examines the incident's implications and potential regulatory actions.

Section 3
This is further to your public and “Board Confidential” letters sent to the Nova Scotia Energy Board on August 8, 2025. The Board panel considering this matter is Stephen T. McGrath, K.C., Chair, Roland A. Deveau, K.C., Vice Chair, and Ric...

AI summary The Nova Scotia Energy Board investigates a utility's cybersecurity practices following a breach, assessing prudence, infrastructure impact, customer service, and data handling. The Board asserts authority under the Public Utilities Act to examine compliance and determine cost recovery reasonableness.

Section 4
Public Inquiries Act (Energy and Regulatory Boards Act, SNS 2024, c. 2, Sch. A, s. 24). More specifically, the Board may allow or disallow the recovery of costs by a public utility from its customers. NS Power has incurred capital and oper...

AI summary The document discusses the Board's authority under the Public Inquiries Act to assess whether NS Power's cybersecurity costs are appropriately invested and whether sufficient investment has been made in cyber protection. It raises concerns about potential imprudence in cost recovery from ratepayers.

Section 5
(and, if not, whether it has incurred or will incur expenses as a result that could be considered to have resulted from imprudence). Document: 323519 -2- Moreover, your client has a broadly stated mandate “to furnish service and facilities...

AI summary The Board raises concerns about NS Power's prudent investment in cybersecurity following a recent incident, questioning the adequacy of its operational technology protections and data handling practices. It challenges the confidentiality terms in the proposed procedural order, emphasizing the 'open courts' principle and referencing past proceedings (Matter M11181).

98954Notice of Intervention - PHP 1 passage
Section 1
Matter No. M12273 NOVA SCOTIA ENERGY BOARD IN THE MATTER OF: The Public Utilities Act – and – IN THE MATTER OF: A Board Inquiry into Nova Scotia Power’s Cyber Security Incident NOTICE OF INTERVENTION TO: The Nova Scotia Energy Board (“Boar...

AI summary Port Hawkesbury Paper LP (PHP) seeks intervenor status in a Nova Scotia Energy Board inquiry into Nova Scotia Power’s cybersecurity incident, citing its reliance on power purchased under the ELIADC Tariff. PHP argues its interest in the proceeding due to its significant energy procurement from NSPI.

98958Letter from NS Power requesting extension to filing IR responses 1 passage
Section 1
Osler, Hoskin & Harcourt LLP Box 50, 1 First Canadian Place Toronto, Ontario, Canada M5X 1B8 416.362.2111 MAIN 416.862.6666 FACSIMILE Toronto August 14, 2025 Adam Kardash Direct Dial: 416.862.4703 Montréal [email protected] Calgary Sent b...

AI summary Nova Scotia Power Inc. (NS Power) requests an extension until September 5, 2025, to respond to the Nova Scotia Energy Board’s inquiry regarding a cybersecurity incident. NS Power cites ongoing investigations and work related to the cybersecurity matter as the reason for needing additional time.

98960Participant List 1 passage
Section 1
M12273 NOVA SCOTIA ENERGY BOARD Board Inquiry into Nova Scotia Power's Cybersecurity Incident LIST OF PARTICIPANTS NOVA SCOTIA POWER INC. (NS Power) Adam Kardash 1223 Lower Water Street Counsel PO Box 910 [email protected] Halifax, NS B3J...

AI summary The Nova Scotia Energy Board is conducting an inquiry into a cybersecurity incident involving Nova Scotia Power Inc. (NS Power). Key participants include NS Power's legal counsel, executive vice president, board counsel, and a cybersecurity consultant from MNP Digital LLP. The proceeding is referenced as Matter M12273.

98963Board Letter approving NS Power's extension request to filing IR responses 1 passage
Section 1
August 15, 2025 [email protected] Adam Kardash, Partner & Co-Chair Privacy and Data Management Osler, Hoskin & Harcourt LLP Box 50, 1 First Canadian Place Toronto, ON M5X 1B8 Dear Mr. Kardash: M12273 – Board Inquiry into Nova Scotia Power...

AI summary The Board grants NS Power's request to extend the deadline for responding to cybersecurity incident inquiries but emphasizes the need for timely responses to customer concerns regarding data compromise and credit monitoring.

99040Letter on behalf of NS Power re confidentiality - Redacted 3 passages
Section 1
Osler, Hoskin & Harcourt LLP Box 50, 1 First Canadian Place Toronto, Ontario, Canada M5X 1B8 416.362.2111 MAIN 416.862.6666 FACSIMILE August 20, 2025 Adam Kardash Direct Dial: 416.862.4703 [email protected] Our Matter Number: 1268459 Sent...

AI summary Osler, Hoskin & Harcourt LLP responds to the Nova Scotia Energy Board's inquiry into a cybersecurity incident involving Nova Scotia Power (NS Power), reiterating NS Power's commitment to cooperation while emphasizing the need for confidentiality protections due to the sensitive nature of the information involved.

Section 2
changed in this matter will be quite sensitive and require particularly strict confidentiality protection, and may warrant that it be provided only to the Board and no other parties in the proceeding. Investigations into cybersecurity inci...

AI summary The text emphasizes the need for strict confidentiality in the proceeding, citing cybersecurity investigations as a justification. It references Sherman Estate v. Donovan and highlights NS Power's expectation that the Board will scrutinize confidentiality claims, with a request for an oral hearing involving cybersecurity experts.

Section 3
ity to further explain to the Board why it is necessary to hold the designated information in confidence, including, if necessary, through an oral hearing with the assistance of cybersecurity experts. NS Power appreciates the Board will wo...

AI summary NS Power emphasizes the need for confidentiality in cybersecurity-related information shared with the Board, requesting justification for strict confidentiality measures and assurances on data protection. It acknowledges the Board's extension for responding to information requests and intends to prioritize early responses. NS Power assumes advisors and intervenors will comply with confidentiality undertakings.

99043NSPI Monthly Update Report #1 2 passages
Section 1
August 20, 2025 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power’s Cybersecurity Incident - Monthly Update 1 Dear Ms. Henwood: On July 14, 202...

AI summary Nova Scotia Power (NS Power) reported a cybersecurity incident detected on April 25, 2025, leading to unauthorized access. NS Power initiated containment and remediation efforts, engaging cybersecurity experts and law enforcement. The Incident Report preparation was delayed, but no physical operations or customer service disruptions were caused.

Section 2
to physical operations at NS Power’s generation, transmission and distribution facilities, and the Incident has not impacted the Company’s ability to safely or reliably serve customers in Nova Scotia. However, the Incident impacted some bu...

AI summary NS Power's incident affected data center systems but not customer service. A Recovery Program Office was established to restore systems and enhance security. The OPC is investigating, and NS Power is cooperating.

99240Letter NSPI re: RIRs 1 passage
Section 1
Osler, Hoskin & Harcourt LLP Box 50, 1 First Canadian Place Toronto, Ontario, Canada M5X 1B8 416.362.2111 MAIN 416.862.6666 FACSIMILE September 5, 2025 Adam Kardash Direct Dial: 416.862.4703 [email protected] REDACTED Our Matter Number: 1...

AI summary Nova Scotia Power Inc. (NS Power) submitted responses to information requests regarding a cybersecurity incident, seeking confidential treatment for specific details under Rule 12(2) of the Board Regulatory Rules. The confidential information is restricted to panel members, the Clerk of the Board, and advisors.

99375Board Letter re: Response to Monthly Update #1 and confidentiality 8 passages
Section 1
September 17, 2025 Judith Ferguson [email protected] Executive Vice President, Regulatory, Legal and Government Relations Nova Scotia Power Incorporated P.O. Box 910, 1223 Lower Water Street Halifax, Nova Scotia B3J 3S8 Adam Karda...

AI summary Nova Scotia Power Inc. (NSP) submitted its first monthly update on a cybersecurity incident to the Board, following a July 14, 2025 directive. NSP requested an extension for its initial filing due to confidentiality concerns, which the Board granted but required confidentiality-related requests to be submitted by August 15, 2025. The inquiry involves Board members Stephen T. McGrath, Roland A. Deveau, and Richard J. Melanson.

Section 3
• On April 25, 2025, NS Power identified a cybersecurity incident resulting from unauthorized access to its information technology (IT) infrastructure. The Company immediately started containment, remediation and investigation efforts, eng...

AI summary NS Power reported a 2025 cybersecurity incident involving unauthorized IT access, with no disruption to critical infrastructure. The company initiated containment, engaged experts, and notified authorities. Business systems like billing and energy trading were affected, prompting a Recovery Program Office for restoration. Cooperation with the Privacy Commissioner of Canada is ongoing. The Board criticized the update for lacking new information.

Section 4
e’s content was underwhelming. It repeated information that generally was already provided in prior correspondence, and in the public domain. The Board would have expected more information about the Recovery Program Office, who is involved...

AI summary The Board criticized the Recovery Program Office's lack of transparency, customer concerns over data misuse, and delayed responses to Information Requests (IRs) related to cybersecurity. The Monthly Update failed to detail cybersecurity impacts on business systems or regulatory matters, with updates shared haphazardly through other filings.

Section 5
-3- involved in matters before the Board, have learned about the impact of the cybersecurity incident in a haphazard manner through filings on various other matters, including:

AI summary Stakeholders involved in matters before the Board have learned about the impact of a cybersecurity incident in a disorganized manner through filings on various other matters.

Section 6
• M12351 – The Company’s Dispatch Study Action Plan Quarterly Update dated June 30, 2025, advised that the incident impacted the project’s expected progress and implementation date and that the ECC Optimization Tools project schedule recov...

AI summary NS Power requested an indefinite extension to submit its 2024/25 Time-Varying Pricing (TVP) and EM&V reports due to a cybersecurity incident disrupting Advanced Metering Infrastructure (AMI) data access. The incident also impacts the upcoming TVP Season and requires stakeholder consultation for revised TVP tariffs, with Matter M11822 referenced for prior TVP rate applications.

Section 7
hampered by the unavailability of data; • M11626 – In its report on the Hosting Capacity Analysis Stakeholder Workshop related to the Commercial Net Metering Program, NS Power stated that the cybersecurity incident impacted some of its bus...

AI summary A cybersecurity incident disrupted data availability for NS Power, delaying updates to the Commercial Net Metering Program's hosting capacity map and halting EfficiencyOne's Residential Behaviour Program. NS Power lacks a timeline for data restoration, impacting program performance and evaluations.

Section 10
• M12330 - In its Q2 2025 Quarterly Report, NSPML advised that due to the cybersecurity incident, the detailed allocation between the Maritime Link Project and sustaining capital costs is unavailable at this time. It added that an update w...

AI summary A cybersecurity incident disrupted NS Power's IT systems, delaying filings, causing billing errors via manual smart meter readings, and pausing CIS replacement. The Board received complaints about inflated demand charges and requested updates on system restoration. NS Power cited the incident as the cause for filing extensions and paused CIS upgrades, which were part of the 2025 ACE Plan.

Section 11
. NS Power stated that Capital Work Order C0021835 - IT - CIS Replacement was listed in the 2025 ACE Plan (M12012) as a project for subsequent submittal and that approximately $1.6 million had been spent on the project, with a projected sp...

AI summary NS Power disclosed that a cybersecurity incident may impact the timeline and direction of the CIS Replacement project in the 2025 ACE Plan (M12012), which has a high-risk rating. The Board criticized the lack of coordinated communication about these impacts and directed NS Power to include them in the Monthly Update, with the next update due October 1, 2025.

99535NSPI Monthly Update Report #2 16 passages
Section 1
October 1, 2025 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power’s Cybersecurity Incident – Monthly Update 2 Dear Ms. Henwood: On July 14, 202...

AI summary Nova Scotia Power (NS Power) is providing monthly updates to the Nova Scotia Energy Board (NSEB) on its response to a cybersecurity incident and progress on the Incident Report, due by December 31, 2025. The Board directed monthly reports following the incident, with expanded guidance provided in September 2025.

Section 2
As new information becomes available regarding any of the foregoing, and additional progress is made in the Company’s recovery efforts, it will be reflected in these monthly update reports. 1 NSEB Letter re: M12273 – Board Inquiry into Nova...

AI summary NS Power's cybersecurity incident did not affect power delivery but disrupted internal operations. The company implemented manual processes for continuity and focused on recovery through the RPO. Cybersecurity validation was critical during restoration, with ongoing controls checks.

Section 9
er and any adjustments arising from schedule variances if required. NS Power shall endeavor to submit this report no later than 60 days after the end of a tariff year. PHP will be entitled to a credit equal to 25 percent of the cost differ...

AI summary NS Power's systems for calculating cost-to-customer metrics under ELIADC and RTP tariffs were disrupted by a cyber incident, impacting ADC evaluations and PHP's CBL cost calculations. NS Power aims to file a new PHP-specific tariff by 2025, pending NSEB approval, and will reassess costs once systems are restored.

Section 12
reducing estimated billing going forward. In acknowledging that customers’ billing experience was impacted by the Incident, NS Power has waived all late fees and paused collections activity since the Incident. Capital and ACE Plan Capital...

AI summary NS Power has waived late fees and paused collections due to billing impacts from an Incident. Capital budgeting and the 2025 ACE Plan face data challenges, with mitigation via spreadsheets. The CIS replacement project is delayed due to the Incident, noted by the NSEB.

Section 13
f September 17, 2025, the CIS replacement capital project has been delayed by the Incident. NS Power said its investigation into the cybersecurity incident “could impact the direction and timeline” of the project. The Company provided an u...

AI summary A cybersecurity incident has delayed the CIS replacement capital project, with NS Power stating it may affect the project's timeline. NS Power provided an updated timeline in compliance filing M11884. The NS-NB Reliability Intertie project (M12217) also faced rerun sensitivity analyses due to the incident, with Midgard noting minor output variances from the original models.

Section 15
Despite these differences, WTI emphasized that “the cost variance in each case is <0.5% of the System NPVRR,” which it cited as confirming that the Reliability Intertie “enables the lowest cost long-term solution for the NS electricity syste...

AI summary The cybersecurity incident affected financial reporting and the Fuel Adjustment Mechanism (FAM), with WTI emphasizing minimal cost variance (<0.5% of System NPVRR) and Midgard dismissing re-run variances as non-material. Data unavailability from the incident impacted the Maritime Link Benefits Report, though NS Power expects full recovery by 2025.

Section 18
In the Q2 FAM report covering letter of August 18, 2025, the Company provided the following: The Fuel Reports that are submitted as part of the Quarterly FAM report in tabs 1-30 are derived from an enterprise resource system which NS Power...

AI summary NS Power manually produced Fuel Reports for Q2 2025 due to an inaccessible enterprise resource system and plans to reconcile them once the system is restored. A cybersecurity event disrupted Cause Code reporting under ELIADC, affecting dispatch instructions and leading to specific Cause Code unavailability.

Section 22
e Company relied on estimated bills. Notwithstanding these impacts, NS Power has implemented manual meter reading, limiting the number of estimated bills. The following metrics were not impacted: SAIDI, SAIFI, CKAIDI, CKAIFI, ETR Updates,...

AI summary NS Power implemented manual meter reading to reduce estimated bills, with metrics like SAIDI and SAIFI remaining unaffected. The Affiliate Code of Conduct (ACOC) processes were impacted by a cybersecurity incident, leading to estimated billing for affiliate time, with a true-up process planned. Annual ACOC training remains mandatory.

Section 25
s. Demand Side Management E1’s Residential Behaviour Program As noted by the NSEB in its letter of September 17, 2025, the ability to provide relevant customer data to Efficiency One (E1) has been affected by the cybersecurity incident. Custo...

AI summary NS Power faces data access challenges due to a cybersecurity incident, impacting E1's Residential Behaviour Program and the Evergreen IRP proceeding. Data from AMI meters and MEI is unavailable, with recovery expected into 2026. NS Power is seeking interim solutions and referencing historical data from the 2023 Load Forecast Report.

Section 26
online. However, please see Attachment 1 for the requested data for 2024 (for the peak hour) and the requested data for 2030 and 2035 pulled from the NS-NB Reliability Intertie model.8 Relatedly, as referenced above under NS-NB Reliability...

AI summary The document discusses challenges in retrieving historical PLEXOS models due to a cybersecurity incident, with NS Power temporarily recreating models for planning. It also highlights NSPML's inability to detail cost allocations between the Maritime Link Project and sustaining capital due to IT system outages, prompting NSEB to request IT service restoration.

Section 27
s and the effect of the cybersecurity incident: a) The cybersecurity incident experienced in the Spring of 2025 by NS Power did not affect the operations of NSPML’s assets. However, with 8 Natural Forces IR-1, NS Power 2025 Evergreen IRP Upd...

AI summary The cybersecurity incident experienced by NS Power in Spring 2025 did not impact NSPML’s operations. The text references two documents: Natural Forces IR-1 (M12247) and NSEB Letter M12273 regarding the Board’s inquiry into the incident.

Section 28
2025. 9 NSEB Letter M12273 - Board Inquiry into NS Power Inc.’s Cybersecurity Incident - Monthly Update #1 and Confidentiality, September 17, 2025, p.4. Page 13 of 16 October 1, 2025 C. Henwood

AI summary The NSEB's September 2025 letter (M12273) details a monthly update on its inquiry into NS Power Inc.'s cybersecurity incident, emphasizing confidentiality protocols. The document references ongoing regulatory scrutiny of cybersecurity practices within the energy sector.

Section 29
respect to information technology, much of NSPML’s data was not accessible for a period. Some data has since been made accessible and NSPML continues to work with the corporate Emera team to complete accessibility efforts. b) There are no...

AI summary NSPML faced data accessibility issues due to a cybersecurity incident, impacting the Joint-Use Agreement Proceeding (M12149). NS Power could not analyze O&M costs for poles under the JUA or access historical installation data, citing the incident as the cause. No customer impact or 2026 O&M costs are proposed.

Section 30
he cyber incident, NS Power is currently unable to access this historical data, as the application used for tracking is unavailable. Greater clarity on the availability of this data may be possible by the fall. // Since the cyber incident,...

AI summary NS Power reports a cyber incident disrupting access to historical data and new tracking data creation for power connection service times. Data availability clarity may emerge by fall. References to regulatory matters M12394 and M12149 are included.

Section 32
As noted in responses to part (b) and (d), NS Power had the capability to track installation timelines more effectively prior to the cyber incident. However, the incident has temporarily impacted the Company’s ability to access and generate...

AI summary A cyber incident has disrupted NS Power's ability to track installation timelines and access data for pole settlements with Bell. Key systems like GIS are unavailable, delaying processes such as Point of Construction Settlement and hindering agreement finalization with Bell. NS Power estimates 175 work orders under a new process but cannot validate actual installations.

Section 33
t with Bell has not yet been finalized or signed.14 While some of the GIS services have been restored, the integrations required for the Joint Use tracking and reporting remain unavailable. NS Power has no further updates on the JUA progres...

AI summary A cybersecurity incident disrupted NS Power's GIS services, Joint Use Agreement (JUA) tracking, and Customer Energy Management (CEM) EM&V reporting. The JUA proceeding remains open before the NSEB. NS Power's 2024 CEM EM&V report was unaffected, but 2025 data is limited to March 2025. Recovery efforts focus on restoring critical systems like billing and energy trading.

99874NSPI Monthly Update Report #3 2 passages
Section 1
November 3, 2025 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power’s Cybersecurity Incident – Monthly Update 3 Dear Ms. Henwood: On July 14, 20...

AI summary Nova Scotia Power (NS Power) provides its third monthly update to the Nova Scotia Energy Board (NSEB) on progress addressing a cybersecurity incident. Key updates include restoring ERP system functionality for General Ledger operations and implementing measures to resume normal invoice payment processes, with the Incident Report due by December 31, 2025.

Section 2
hat this disruption has had an impact on many vendors and suppliers, and it has put several measures in place to return to normal invoice payment processes and timelines. November 3, 2025 C. Henwood The IT and Finance teams have been worki...

AI summary NS Power reports a cybersecurity incident disrupting invoice payments and regulatory processes, with efforts underway to restore systems and notify affected customers. The incident has impacted ongoing regulatory matters, including rates-related proceedings, with updates provided in NSEB M12273.

99920Board Letter re: Directives 3 passages
Section 1
November 7, 2025 [email protected] Judith Ferguson Executive Vice President, Regulatory, Legal and Government Relations Nova Scotia Power Incorporated P.O. Box 920, 1223 Lower Water Street Halifax, NS B3J 3S8 Dear Ms. Ferguson: M1...

AI summary This letter from Judith Ferguson of Nova Scotia Power Incorporated provides a third monthly update on the Board's inquiry into NS Power's cybersecurity incident. The update was filed on November 3, 2025, and is being reviewed by a three-member Board panel.

Section 3
s investigation into the incident remains ongoing. Monthly Update # 3 also stated that NS Power remains on schedule to provide the Incident Report to the Board on or before December 31, 2025. There is still uncertainty about what tasks and...

AI summary The Board highlights ongoing delays in NS Power's incident report submission, lack of progress on recovery efforts (e.g., manual meter reading), and concerns over unpaid vendor invoices. It directs NS Power to resolve outstanding payments and provide detailed financial updates, while referring the cybersecurity incident to MNP for investigation.

Section 4
eyond 30 days. The Board will also refer this matter to MNP to further investigate causes of the NS Power’s financial technology data compromise and assess its data handling practices. 2. In the incident report to be filed by the end of th...

AI summary The Board refers NS Power's financial technology data compromise to MNP for investigation and assessment of data handling practices. An incident report with Gantt charts detailing recovery tasks and impacted matters is required, including timelines and progress updates.

100161NSPI Monthly Update Report #4 7 passages
Section 3
nd Project Accounting was re- established resulting in a resumption of automated end-to-end project lifecycle tracking and data supporting decision-making on property, plant and equipment investments. A cross-functional team of employees a...

AI summary NS Power has re-established Project Accounting for tracking investments in property, plant, and equipment. Efforts are ongoing to resolve outstanding supplier payments and return to normal billing processes. A manual meter reading process has been implemented due to a cybersecurity incident, with 75% of customers having received at least one meter reading. Late fees have been waived, and reconnection of meters to billing systems is expected by March 2026.

Section 9
ata for the FAM report was able to be created through different processes, with a high degree of confidence that the data is accurate. Once systems are back online, any discrepancies will be trued up. Dispatch Study Action Plan Quarterly U...

AI summary The document outlines updates on the ECC Optimization Tools Project's revised timeline, resolution of Maritime Link Project cost allocation, and cybersecurity impacts on the Joint-Use Agreement Proceeding. NS Power notes capital costs for poles under the JUA and highlights data accuracy in the FAM report. The NSEB emphasized IT system restoration for accurate filings.

Section 11
ent, an analysis cannot be completed at this time. 3 NS Power’s response to CA IR-3 parts (b), (d) and (e), submitted to the Board on August 20, 2025, provided the following, respectively: Prior to the cyber incident, NS Power maintained l...

AI summary NS Power explains that a cyber incident has disrupted their ability to track customer installation data and create new tracking data for power connections, impacting service timelines. They note that pre-incident processes involved delays with Bell Aliant, but current data access is unavailable due to the incident.

Section 12
wer and Bell poles, as the links between applications used for tracking are currently unavailable. 4 NS Power’s response to SBA IR-1 parts (b) and (c) provided the following, respectively: Since the signing of the LOI, approximately 175 wo...

AI summary NS Power reports delays in joint-use agreement processes due to a cyber incident disrupting access to critical systems like GIS, which tracks pole ownership. This has hindered progress on the Point of Construction Settlement and prevented finalizing agreements with Bell, as data validation and system access remain unavailable.

Section 14
oint-Use Agreement Proceeding (M12149), June 16, 2025. 6 SBA IR-2, Joint-Use Agreement Proceeding (M12149), June 16, 2025. Page 8 of 9 December 1, 2025 C. Henwood Update on OPC Investigation As noted in previous reports, the Office of the...

AI summary The document details ongoing OPC investigation into a cyber incident, Nova Scotia Power's cooperation, and a committee appearance by executives. The company apologized for customer disruption and emphasized commitment to resolving the investigation. The Standing Committee on Natural Resources and Economic Development was briefed on the incident.

Section 15
ver 100 years. We recognize that the recent cyber event has affected the trust we have built with our customers, and I want to acknowledge and apologize for the concern and disruption this has caused. Over the past 215 days, our team has w...

AI summary The company acknowledges a cyber incident impacting customer trust and billing accuracy, committing to rectify overestimations and improve cybersecurity. Despite significant investments, sophisticated threats persist, though core operations remained uninterrupted. Recovery efforts include IT security upgrades, a secure cloud communication system, and financial process improvements.

Section 17
power poles across the province and clearing trees from 1,500 kilometers of power lines. We continue to make essential investments to meet our customers’ energy needs and strengthen future resilience. In September, we submitted a General R...

AI summary NS Power submitted a General Rate Application to the Nova Scotia Energy Board, emphasizing the need for reliability investments while balancing affordability. They collaborated with customer advocates and committed to addressing billing errors. Ongoing cyber investigations by NSEB and OPC are noted, along with a focus on transparency and trust-building.

100185NSEB (NSPI) IR 13 to 16 3 passages
Section 1
M12273 NOVA SCOTIA ENERGY BOARD IN THE MATTER OF: THE PUBLIC UTILITIES ACT - and - IN THE MATTER OF: BOARD INQUIRY INTO NOVA SCOTIA POWER'S CYBERSECURITY INCIDENT SECOND SET - INFORMATION REQUESTS To: Nova Scotia Power Incorporated Judith...

AI summary The Nova Scotia Energy Board has issued an information request to Nova Scotia Power regarding a cybersecurity incident, seeking detailed responses by December 23, 2025. The inquiry is part of a proceeding under the Public Utilities Act, focusing on the incident's implications and required corrective measures.

Section 5
ii. For those bills that were estimated, please provide a breakdown based on the 34 number of months since the meters associated with those bills were actually read. Document: 326189 Date Filed: 3 December 2025 Page 2 1 e) Were the bills a...

AI summary The document requests detailed breakdowns of estimated billing practices, including the number of months used for estimates and the impact of a cybersecurity incident on photo meter reads. It also inquires about overpayment refunds and references a statement by Mr. Lanteigne regarding billing discrepancies and meter read accuracy.

Section 6
ably the last month or so, 16 the meter readings have been fairly close. That said, they’re estimates. There are always 17 going to be customers who are on the extremes of those. 18 a) Please explain why half of NS Power’s bills in Novembe...

AI summary The text includes questions about NS Power's billing accuracy, specifically discrepancies between estimated and actual meter readings, and whether cybersecurity measures post-incident impacted billing processes. It requests data on overestimation rates and resource allocation for billing improvements.

100429Letter NSPI re: confidentiality of report 2 passages
Section 1
PO Box 910 Halifax, Nova Scotia Canada B3J 2W5 December 22, 2025 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 3rd Floor, 1601 Lower Water Street Halifax, Nova Scotia B3J 3P6 Dear Ms. Henwood: M12273 – Inquiry of the Nova Sco...

AI summary Nova Scotia Power Inc. (NS Power) submitted a cybersecurity incident report to the Nova Scotia Energy Board, requesting confidential treatment for sections detailing the incident timeline, affected systems, and response actions. The report references Rule 12(2) of the Board's Regulatory Rules to justify confidentiality.

Section 2
ustomer Notification Timeline – information about data obtained and communicated by the threat actor Page 1 of 2 Crystal Henwood December 22, 2025 • Section 8.0 Recommendations o 8.1 Enhancing Security Measures and Preventing Future Breach...

AI summary NS Power submitted a confidential report to the Board detailing cybersecurity remediation efforts and resilience strategies following a breach. The report's confidentiality was justified as previously outlined, with NS Power reaffirming its commitment to collaboration with the Board during the Inquiry.

100676Notice of Intervention - MacGillivray Law - WITHDRAWN 1 passage
Section 1
2025 M12273 NOVA SCOTIA ENERGY BOARD IN THE MATTER OF: The Public Utilities Act, R.S.N.S. 1989, c. 380, as amended, and IN THE MATTER OF: A Board Inquiry into Nova Scotia Power’s Cybersecurity Incident NOTICE OF INTERVENTION Danielle Frase...

AI summary A Notice of Intervention is filed by Danielle Fraser, represented by MacGillivray Law Office, seeking intervenor status in a proceeding related to Nova Scotia Power’s 2025 cybersecurity incident. The notice highlights the relevance of findings from this proceeding (M12273) to a proposed class action concerning data breaches and billing issues, with over 12,563 affected customers.

100677Affidavit - MacGillivray Law 8 passages
Section 1
2025 M12273 NOVA SCOTIA ENERGY BOARD IN THE MATTER OF: The Public Utilities Act, R.S.N.S. 1989, c. 380, as amended and IN THE MATTER OF: A Board Inquiry into Nova Scotia Power's Cybersecurity Incident

AI summary The Nova Scotia Energy Board is conducting an inquiry under the Public Utilities Act regarding a cybersecurity incident involving Nova Scotia Power. The proceeding is identified as Matter M12273, dated 2025.

Section 2
The Public Utilities Act, R.S.N.S. 1989, c. 380, as amended and IN THE MATTER OF: A Board Inquiry into Nova Scotia Power's Cybersecurity Incident

AI summary The document references a regulatory inquiry under the Public Utilities Act regarding Nova Scotia Power's cybersecurity incident. The proceeding examines the incident's implications and compliance with regulatory standards.

Section 6
hat changes in household energy usage, including switching to alternative heating sources, were not reflected in estimated billing, which they understood to be based on prior years' usage. LIMITATIONS OF MY ROLE 17. I did not: a. assess th...

AI summary An affidavit outlines the limited role of Elisa Akcakiryan in organizing communications related to Nova Scotia Power's cybersecurity incident. It clarifies she did not assess individual bills or calculate damages, but provided context for the Nova Scotia Energy Board regarding intervenor status requests. The document is part of a regulatory inquiry under the Public Utilities Act.

Section 10
-4- STATEMENT OF CLAIM Class Proceeding Pursuant to the Class Proceedings Act, S.N.S. 2007, c.28 I. OVERVIEW 1. Utilities occupy a position of trust in Canadian society. The majority of Nova Scotia citizens and consumers have little choice...

AI summary A class proceeding alleges Nova Scotia Power Inc. (NSP) failed in statutory and common law obligations following a 2025 cyberattack, causing systemic data breaches, billing inaccuracies, and prioritizing corporate interests over consumer protection, shifting financial and logistical burdens to customers.

Section 11
rioritized corporate convenience and interest over consumer protection. Furthermore, NSP shifted the financial, emotional, and logistical burden of its multiple failures onto its customers. 4. The Data Breach caused both a mass personal in...

AI summary The Plaintiff alleges that NSP prioritized corporate interests over consumer protection, causing a data breach and billing integrity failures. These failures exposed customer information and led to inaccurate billing. The action seeks relief under the Class Proceedings Act for negligence, breach of contract, and statutory violations, including privacy and consumer protection laws.

Section 12
va Scotia (the "Plaintiff"). Further to the Data Breach, the Plaintiff suffered a personal information compromise and was also subject to a billing integrity failure (described herein). 8. The Defendant, Nova Scotia Power Incorporated ("NS...

AI summary The Plaintiff alleges a data breach by Nova Scotia Power (NSP) leading to personal information compromise and billing integrity failures. NSP, as the monopoly electricity provider, collects customer data as a service condition. The class action includes customers affected by the April 2025 data breach and billing errors.

Section 13
e Plaintiff includes reference to the Class, as appropriate. -6- IV. FACTUAL BACKGROUND (A) PERSONAL INFORMATION COMPROMISE 12. The Data Breach resulted in unauthorized access to NSP's customers' personal information, including (but not ne...

AI summary The document details a data breach at Nova Scotia Power (NSP) that exposed customer personal information and disrupted billing systems, leading to inaccurate bills, customer distress, and inadequate relief measures by NSP. The breach also compromised metering and billing processes, resulting in inflated estimates and threats of disconnection.

Section 15
s standard by permitting unauthorized actors to access customers' personal information and by maintaining inadequate administrative, physical and technical safeguards. 26. NS P's offer of free credit monitoring constitutes an acknowledgmen...

AI summary The document outlines a data breach by Nova Scotia Power (NSP) leading to unauthorized access to customer personal information. NSP's failure to implement adequate cybersecurity measures resulted in significant harm, including anxiety and financial risks for customers. The Plaintiff alleges negligence in safeguarding data and non-compliance with statutory obligations under PIPEDA.

100678Board e-mail re: Any objections to NOI from MacGillivray Law 1 passage
Section 1
From: Henwood, Crystal D To: Adam Kardash; Alissa Whalen; Annie Beth Sampson; Bill Mahody; Blake Williams; Brianne Rudderham; Bryce Everist; Carly Currie; Caroline Jonah; Carvery, Kim; Cavanaugh, Marina; Charlene MacMullin; Chris Law; Chri...

AI summary Notice of intervention in Board Inquiry M12273 regarding Nova Scotia Power's cybersecurity incident, with MacGillivray Law referenced as the intervenor. The email is from Henwood to multiple recipients, including legal and regulatory stakeholders.

100731Letter CA re: factors in exercising discretion to late Notice of Intervention request 2 passages
Section 1
Please refer to: David Roberts Email: [email protected] Assistant: Alissa Whalen Assistant’s email: [email protected] January 27, 2026 VIA EMAIL VIA WEB PORTAL Crystal Henwood, Clerk of the Board Nova Scotia Energy Board 1601 Lo...

AI summary The Consumer Advocate submits comments on Danielle Fraser's request for intervenor status in M12273, emphasizing the relevance of the Board's inquiry findings to a proposed class action against Nova Scotia Power over a cyber security incident. The Advocate urges the Board to consider factors under Rule 11 when granting intervenor status.

Section 2
ervenor status is a discretionary exercise of the authority of the Board. The Consumer Advocate submits the Board should consider the following factors in exercising that discretion. 1. The proposed Intervenor is requesting Intervenor stat...

AI summary The Consumer Advocate argues that granting Intervenor status to a party seeking to advance claims in a civil court proceeding would conflict with the Board's objective of reviewing Nova Scotia Power's compliance with statutory obligations following a cyber security incident. The proposed Intervenor represents affected customers but has differing objectives.

100751Letter MacGillivray Law re: Withdrawal of Notice of intervention 1 passage
Section 1
January 28, 2026 Jamie MacGillivray, CEO [email protected] Via NSEB Web Portal MacGillivray Law - New Glasgow 134 Provost Street PO Box 753 New Glasgow, NS B2H 2P7 Crystal Henwood Ph: 902-755-0398 Fax: 902-755-2813 Regulatory Af...

AI summary The letter withdraws Danielle Fraser's intervention in M12273, citing jurisdictional limits of the Nova Scotia Energy Board regarding NSP's cybersecurity breach. The client argues the matter requires judicial remedies beyond regulatory proceedings, emphasizing concerns outside the Board's mandate.

100840NSPI Monthly Update Report #5 18 passages
Section 1
PO Box 910 Halifax, Nova Scotia Canada B3J 2W5 February 5, 2026 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power’s Cybersecurity Incident – Mo...

AI summary Nova Scotia Power (NS Power) submitted its fifth monthly update to the Nova Scotia Energy Board (NSEB) regarding its response to a 2025 cybersecurity incident. The report includes an updated Gantt chart and table for tracking regulatory matters, with plans to provide future updates. The Incident Report was filed in December 2025.

Section 6
the plant information systems and onboarding users for access. Connections have now been established for several generating assets, improving the visibility of plant output and operational oversight. Reporting and analytics restoration has...

AI summary NS Power reports progress in restoring IT systems, including plant information systems, reporting, analytics, and cybersecurity measures. Critical business functions are being stabilized through infrastructure rebuilding, with ongoing efforts in asset management, data integration, and cybersecurity validation.

Section 7
een made in strengthening foundational platforms such as reporting, data integration, network infrastructure and system access, all of which underpin core operational and customer-facing capabilities. Meaningful advancement has occurred ac...

AI summary NS Power outlines progress in restoring technology infrastructure, including system enhancements and collaboration with the Office of the Privacy Commissioner of Canada (OPC) regarding an ongoing investigation. Efforts focus on operational resilience, stakeholder transparency, and alignment with long-term business goals through the Recovery Program Office.

Section 8
Yours truly, Blake Williams Senior Director Regulatory Page 5 of 5 Monthly Cybersecurity Update 5 Attachment 1 Page 1 of 3 Executive Summary The following page outlines the key initiatives that are currently in flight to support our recove...

AI summary The document outlines a restoration program structured into five portfolios aimed at restoring business capabilities, with progress indicated by percentage completion. Key initiatives are highlighted as part of ongoing recovery efforts.

Section 9
o inform our progress on our restoration journey. PROGRAM STRUCTURE The Restoration Program is structured into five (5) key portfolios of work – focusing on restoring business capabilities. Portfolio Scope Summary Enterprise Recovery and r...

AI summary The Restoration Program is organized into five portfolios focusing on restoring enterprise systems, customer platforms, supporting capabilities, cybersecurity, and technology infrastructure to ensure business continuity and secure operations.

Section 10
reliable operation of business systems. Monthly Cybersecurity Update 5 Attachment 1 Page 2 of 3 Restoration Roadmap 2025 2026 Completion %Complete Project Oct Nov Dec Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec Date (Dec 16) ERP Payrol...

AI summary A cybersecurity restoration roadmap outlines project timelines and completion statuses for various IT and grid systems, including ERP, customer platforms, grid management tools, and cybersecurity initiatives like OT hardening and vulnerability management, with progress percentages and completion dates through 2026.

Section 11
ECHNOLOGY ENABLEMENT Network 27-May-26 30% Data Centre Computer 13-Feb-26 60% Hardware Backup & Disaster 13-Feb-26 40% Recovery (DR) The dates shown in this Gantt chart represent the current planned Complete schedule for the Restoration Pr...

AI summary The text presents a Gantt chart outlining the Restoration Program Office's (RPO) initiative timelines, noting subjectivity to change due to priorities and dependencies. It also references a 'Monthly Cybersecurity Update' document, highlighting cybersecurity as a relevant theme.

Section 14
foundational capabilities. Additional to 31-Mar-26. scope has been approved through a Change Request (CR) to return to business-as-usual operations. Additional Self-Serve Target completion date Project team completed remaining Capabilities...

AI summary The document outlines updates to cybersecurity project timelines, including approved Change Requests (CRs) for additional scope and third-party engagement. Target completion dates for Self-Serve Analytics & BI, MDR, and VM initiatives have been revised, with Observo engaged for MDR logging and monitoring.

Section 15
Monthly Cybersecurity Update 5 Attachment 2 Page 1 of 7 Report 2 - Report 3 - Report 4 - Report 5 - Affected Regulatory Matters October 1 November 3 December 1 February 4 Forecast Restoration of Normal Latest update Jan 31, 2026 Activities...

AI summary A cybersecurity update report references affected regulatory matters, including 'Rates-Related Matters,' with updates dated January 31, 2026, and mentions ongoing activities related to forecasted restoration of normal operations.

Section 22
prior Reports. Monthly Cybersecurity Update 5 Attachment 2 Page 2 of 7 Report 2 - Report 3 - Report 4 - Report 5 - Affected Regulatory Matters October 1 November 3 December 1 February 4 Forecast Restoration of Normal Latest update Jan 31,...

AI summary The text references a monthly cybersecurity update and associated regulatory matters, including dates and reports related to 'Rates-Related Matters' and 'Customer Billing.' However, no detailed discussion of cybersecurity measures, regulatory actions, or specific issues is provided in the excerpt.

Section 32
Monthly Cybersecurity Update 5 Attachment 2 Page 3 of 7 Report 2 - Report 3 - Report 4 - Report 5 - Affected Regulatory Matters October 1 November 3 December 1 February 4 Forecast Restoration of Normal Latest update Jan 31, 2026 Activities...

AI summary The text outlines a cybersecurity update related to regulatory matters, with a focus on rates-related issues. It includes headings for monthly reports and mentions a forecast restoration date, but provides no detailed discussion of cybersecurity measures or regulatory proceedings.

Section 34
the IESO-NS. Financial Reporting and Statements Q2 2026 (for completion of Q4 Financial Reporting and Statements Introduced NA NA Updated The Q4 Annual Regulated Finanical Statements are on track to file April 15, 2026. 2025 Regulated Fina...

AI summary The document outlines progress on Q4 Annual Regulated Financial Statements, targeting April 15, 2026 filing, and references cybersecurity updates and fuel rates-related matters, including the adjustment mechanism. Key themes include financial reporting timelines and cybersecurity measures.

Section 35
Activities Updated Jan 31, 2026 FuelRates-Related Matters Adjustment Mechanism Updated General NA Updated NA NA Q1 2026 Maritime Link Benefits Report Introduced NA NA NA NA Q1 2026 FAM Quarterly Introduced NA Updated NA NA Q1/Q2 2026 Dispa...

AI summary The document outlines updates to fuel rate-related matters, including the adjustment mechanism, and mentions cybersecurity activities. It references reports and updates related to Maritime Link benefits, FAM quarterly updates, and a dispatch study action plan, with activity updates dated January 31, 2026.

Section 39
and GIS. ETA for this is March 2026. Demand Side Management Monthly Cybersecurity Update 5 Attachment 2 Page 6 of 7 Report 2 - Report 3 - Report 4 - Report 5 - Affected Regulatory Matters October 1 November 3 December 1 February 4 Forecast...

AI summary The text references a 'Monthly Cybersecurity Update' with an ETA of March 2026 and mentions 'Demand Side Management' in the context of regulatory matters. It also lists reports and dates related to affected regulatory matters, including a 'Rates-Related Matters' section.

Section 41
restoration is by end of Q3 2026. Data flows to evaluate Demand Response will be restored in Q3 2026, ahead of the 26/27 Season E1's Demand Response Programming NA Introduced NA NA No Update beginning on Dec 1, 2026, pending successful res...

AI summary The document mentions the restoration of data flows for Demand Response by Q3 2026, with Demand Response Programming beginning on Dec 1, 2026, pending the successful restoration of AMI and relevant systems. It also references a Monthly Cybersecurity Update.

Section 42
Monthly Cybersecurity Update 5 Attachment 2 Page 7 of 7 Report 2 - Report 3 - Report 4 - Report 5 - Affected Regulatory Matters October 1 November 3 December 1 February 4 Forecast Restoration of Normal Latest update Jan 31, 2026 Activities...

AI summary The document provides a monthly cybersecurity update with information on affected regulatory matters, including rates-related matters and system planning. It includes reports and a forecast for the restoration of normal activities.

Section 50
1067 14% 66 4% 90+ Days 983 34% 3776 48% 148 9% Total 2870 7869 1690 Hold Reason 36-60 days Administrative 52 7% 141 12% 26 15% Procurement 171 23% 186 16% 63 37% Receiving 512 70% 823 72% 81 48% Total 735 1150 170 Hold Reasons 61-90 days...

AI summary The document provides a summary of hold reasons for different time periods, including administrative, procurement, and receiving reasons, with percentages and totals for each category. It also includes a letter from Nova Scotia Power to the Nova Scotia Standing Committee on Natural Resources and Economic Development regarding a request for further information.

Section 58
holding community engagement sessions throughout 2026 to answer customer questions directly, and our Customer Care Centre is able to support customers who have questions over the phone. • NS Power will actively encourage customers to take...

AI summary NS Power is engaging with customers through community sessions and phone support, promoting payment arrangements like Equal Billing to reduce disconnections. They acknowledge a recent cyberattack but emphasize grid security and ongoing cooperation with regulatory bodies.

100849Board letter outlining process the NSEB intends to follow 6 passages
Section 1
February 6, 2026 By Email M12273 Parties Dear Parties: M12273 – Board Inquiry into Nova Scotia Power’s Cybersecurity Incident and M12600 – Minister of Energy – Accountability for Nova Scotia Power

AI summary The Board is conducting an inquiry into Nova Scotia Power’s cybersecurity incident (M12273) and the Minister of Energy’s accountability (M12600). The email notifies parties of these proceedings, highlighting concerns over cybersecurity risks and regulatory oversight.

Section 2
ebruary 6, 2026 By Email M12273 Parties Dear Parties: M12273 – Board Inquiry into Nova Scotia Power’s Cybersecurity Incident and M12600 – Minister of Energy – Accountability for Nova Scotia Power

AI summary The email references two matters: M12273, a Board Inquiry into Nova Scotia Power’s cybersecurity incident, and M12600, concerning the Minister of Energy’s accountability. It notifies parties of these proceedings and their associated regulatory focus areas.

Section 3
This letter outlines the processes the Nova Scotia Energy Board intends to follow for Matter M12273 – Board Inquiry into Nova Scotia Power’s Cybersecurity Incident and Matter M12600 – Minister of Energy – Accountability for Nova Scotia Pow...

AI summary The Nova Scotia Energy Board outlines its approach to two matters: M12273 (cybersecurity incident inquiry) and M12600 (accountability for Nova Scotia Power). The Board proposes separating technical cybersecurity issues from customer relations, billing practices, and regulatory impacts, arguing this minimizes duplication. NS Power asserts prior reports addressed the Premier’s concerns, but the Board maintains a dual-inquiry approach.

Section 6
the proceedings. A preliminary scoping of the issues to be addressed in each proceeding is set out below. M12273 – Board Inquiry into Nova Scotia Power’s Cybersecurity Incident This proceeding will review technical aspects of the cybersecu...

AI summary The document outlines two regulatory proceedings: M12273, reviewing Nova Scotia Power's (NS Power) cybersecurity incident response and measures, and M12600, examining NS Power's accountability for customer data handling, billing accuracy, and communication post-incident. Both proceedings assess the reasonableness of NS Power's actions.

Section 7
nd reset feature for demand billing customers e. Communications with customers relating to these issues and about the cybersecurity incident f. Business and regulatory impacts, including: i. Continuing impacts of day-to-day operations ii....

AI summary The document outlines topics including cybersecurity incidents, customer communications, and business/regulatory impacts, including transition planning to IESO Nova Scotia. It references existing exhibits from Matter M12273, which address overlapping issues in regulatory proceedings.

Section 9
to Matter M12600, so that information included in them that is within the scope of that proceeding is included in the matter. Intervenors Intervenors in Matter M12273 will be deemed to be intervenors in Matter M12600 without the need to fi...

AI summary The document outlines procedural steps for Matters M12273 and M12600, including automatic intervenor status, MNP Digital's role in reviewing a cybersecurity incident, and NS Power's obligation to file monthly updates. A hearing is scheduled for mid- to late-summer 2025.

101155NSPI Monthly Update Report #6 14 passages
Section 1
PO Box 910 Halifax, Nova Scotia Canada B3J 2W5 March 6, 2026 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power’s Cybersecurity Incident – Month...

AI summary Nova Scotia Power provides Monthly Update 6 on its response to a 2025 cybersecurity incident, including attachments on restoration progress, regulatory matters, and invoice status. The report notes ongoing efforts to restore financial systems and reduce post-incident invoice backlogs.

Section 4
nistrative capabilities has advanced from foundational rebuild into active execution and operational enablement, with several workstreams reaching material milestones since the prior reporting period. Access to real-time operational data h...

AI summary NS Power reports progress in restoring operational systems, achieving 84% recovery of priority reports, and advancing cybersecurity measures. Recovery efforts focus on system reliability, disaster resilience, and minimizing operational risks, with activities expected to continue through 2026.

Section 5
rform reliably under normal operating conditions, strengthening disaster recovery and resilience capabilities, sequencing remaining restoration work to minimize operational, customer and control risk. The Recovery Program Office continues...

AI summary The document outlines NS Power's recovery program management, emphasizing interdependency handling, governance, and regulatory compliance. It mentions formal project oversight mechanisms and updates on the OPC investigation, with NS Power committed to cooperating fully. Cybersecurity initiatives and restoration progress are highlighted.

Section 6
ed to inform our progress on our restoration journey. PROGRAM STRUCTURE The Restoration Program is structured into five (5) key portfolios of work – focusing on restoring business capabilities. Portfolio Scope Summary Enterprise Recovery a...

AI summary The Restoration Program is organized into five portfolios: Enterprise Resource Planning (ERP), Customer, Additional Capabilities, Cybersecurity, and Technology Enablement. The roadmap outlines restoration efforts for 2025 and 2026, focusing on recovering core systems, cybersecurity controls, and technology infrastructure to ensure operational continuity.

Section 7
ect Oct Nov Dec Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec Date (Dec 16) ERP Payroll 31-Oct-25 100% PowerPlan 31-Aug-26 80% Oracle Fusion 31-Jul-26 68% CUSTOMER MyAccount 31-Jul-26 53% AMI HES 30-Apr-26 85% ADMS Resiliency 30-Apr-26 5...

AI summary The document presents a timeline of project milestones and completion percentages for various initiatives under ERP, customer systems, cybersecurity, and technology enablement. Key areas include cybersecurity measures (e.g., OT Hardening, MDR) and technology infrastructure (e.g., Data Centre planning, Network upgrades). Progress ranges from 5% to 100% completion, with some projects in planning stages.

Section 12
reflected interim release milestones, and Technology Backup & Completion dates are now final sequencing is being confirmed Enablement Disaster reported as TBD. through governance to ensure accurate Recovery and reliable reporting; minimum...

AI summary The text outlines updates on technology enablement milestones, noting that completion dates for backup and disaster recovery (DR) systems are now 'TBD.' Final sequencing is being confirmed through governance to ensure accurate reporting, with minimum operational capability maintained.

Section 22
Monthly Cybersecurity Update 6 Attachment 2 Page 2 of 6 Report 2 - Report 3 - Report 4 - Report 5 - Report 6 - Forecast Restoration of Normal Affected Regulatory Matters October 1 November 3 December 1 February 4 March 4 Activities Latest...

AI summary The document outlines a cybersecurity update related to regulatory matters, including customer billing and rates-related issues. It references updates dated February 28, 2026, and lists affected matters under 'Rates-Related Matters' and 'Customer Billing'.

Section 30
NSEB in 2026. The Reliability Tie project has been approved by the NSEB. Modelling NS – NB Reliability Intertie Project Introduced NA NA NA NA No new update of this nature has been transferred to the IESO-NS. Monthly Cybersecurity Update 6...

AI summary The NSEB approved the Reliability Tie project in 2026. The NS–NB Reliability Intertie Project was introduced but has no new updates. A cybersecurity update document (Attachment 2, Page 3 of 6) is referenced.

Section 31
Monthly Cybersecurity Update 6 Attachment 2 Page 3 of 6 Report 2 - Report 3 - Report 4 - Report 5 - Report 6 - Forecast Restoration of Normal Affected Regulatory Matters October 1 November 3 December 1 February 4 March 4 Activities Latest...

AI summary The document outlines a monthly cybersecurity update with attached reports detailing affected regulatory matters, including dates for report submissions and updates on financial reporting and fuel adjustment mechanisms. Key topics include cybersecurity, financial reporting, and fuel cost adjustments.

Section 32
Statements) Fuel Adjustment Mechanism Updated General NA Updated NA NA No new update Q1 2026 Maritime Link Benefits Report Introduced NA NA NA NA No new update Q1 2026 FAM Quarterly Introduced NA Updated NA NA No new update Q1/Q2 2026 Disp...

AI summary The text lists updates to regulatory mechanisms and reports, including the Fuel Adjustment Mechanism, Maritime Link Benefits Report, FAM Quarterly, and Dispatch Study Action Plan, with statuses like 'Introduced,' 'Updated,' and 'No new update' through Q1/Q2 2026. A cybersecurity update (Attachment 2, Page 4 of 6) is also noted.

Section 33
Monthly Cybersecurity Update 6 Attachment 2 Page 4 of 6 Report 2 - Report 3 - Report 4 - Report 5 - Report 6 - Forecast Restoration of Normal Affected Regulatory Matters October 1 November 3 December 1 February 4 March 4 Activities Latest...

AI summary A cybersecurity update report outlines affected regulatory matters, including dates for reports and forecasted restoration activities. It references 'Rates-Related Standards' and 'Performance Matters' as key areas under review, though no specific details on cybersecurity measures or regulatory decisions are provided.

Section 41
relevant systems. System Planning IRP Modelling has transitioned to System Planning Introduced NA NA NA NA NA the IESO-NS Monthly Cybersecurity Update 6 Attachment 2 Page 6 of 6

AI summary The text discusses the transition of IRP Modelling to the IESO-NS and mentions a Monthly Cybersecurity Update, though no detailed discussion of themes is provided.

Section 42
Monthly Cybersecurity Update 6 Attachment 2 Page 6 of 6 Report 2 - Report 3 - Report 4 - Report 5 - Report 6 - Forecast Restoration of Normal Affected Regulatory Matters October 1 November 3 December 1 February 4 March 4 Activities Latest...

AI summary The text mentions a monthly cybersecurity update and outlines affected regulatory matters, including rates-related matters and miscellaneous issues. It includes forecasted restoration dates and an update date of February 28, 2026.

Section 48
NA Updated Updated datasets are being prepared for the 2025 CEM EM&V in accordance with Econoler’s proposed plan and the evaluation; however, additional time is required to compile and share the data with with the NSEB. Verification (EM&V)...

AI summary Datasets for the 2025 CEM EM&V are being prepared according to Econoler's plan, but additional time is needed to compile and share them with the NSEB. An extension request will be filed. Restoration of My Energy Insights (MEI) systems is expected by the end of Q3 2026. A monthly cybersecurity update is also included.

101499Board letter re: updated documents 2 passages
Section 1
April 7, 2026 [email protected] Blake Williams Senior Director, Regulatory Nova Scotia Power Inc. P.O. Box 910 1223 Lower Water Street Halifax, NS B3J 3S8 Dear Mr. Williams: M12273 – Board Inquiry into Nova Scotia Power Incorporate...

AI summary The Nova Scotia Energy Board directed Nova Scotia Power Inc. to refile redacted documents related to a cybersecurity incident, citing public disclosure of previously confidential information. The Board emphasized transparency, requiring removal of redactions consistent with recently released data from the Office of the Privacy Commissioner of Canada.

Section 2
xhibit N-2(C)); and • NS Power’s Cybersecurity Incident Report dated December 22, 2025 (Exhibit N- 3(C)). Document: 329295 -2- NS Power is directed to file updated documents no later than Monday, April 20, 2026. Yours very truly, Crystal H...

AI summary The document references NS Power's cybersecurity incident report (Exhibit N-3(C)) and directs the company to submit updated filings by April 20, 2026. It includes a directive from the Board's clerk and references to board counsel and matter numbers.

101537NSPI Monthly Update Report #7 13 passages
Section 1
PO Box 910 Halifax, Nova Scotia Canada B3J 2W5 April 9, 2026 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power’s Cybersecurity Incident – Month...

AI summary NS Power submitted Monthly Update 7 to the Nova Scotia Energy Board regarding progress in restoring financial enterprise resource planning capabilities post-cybersecurity incident. The report highlights reduced aged receivables and backlog reduction, with attachments detailing restoration timelines, regulatory matters, and invoice status. Updates align with the Board's July 2025 directive for monthly progress reporting.

Section 2
vels since the cyber incident. As can be seen in Attachment 3, the backlog, which peaked on November 5, 2025, has been substantially addressed and the overall trend continues toward pre-cyber levels. As discussed in its Monthly Update 6, N...

AI summary The document outlines NSP's progress in addressing a cyber incident's aftermath, including backlog reduction, restored billing systems, and technology recovery efforts. Meter connections and billing have returned to normal, with estimated bills at pre-incident levels. Technology restoration is ongoing across infrastructure domains, with timelines detailed in attachments.

Section 4
ative functions advanced through delivery and testing phases, with infrastructure established, data restoration underway, and configuration activities progressing under internal and vendor governance. Restoration of remaining capabilities,...

AI summary NS Power advanced infrastructure restoration, data recovery, and cybersecurity measures, transitioning from recovery efforts to stable operations. Cybersecurity initiatives included identity management, vulnerability assessments, and process refinement, aligning with planned recovery timelines.

Section 5
ybersecurity restoration toward more stable, repeatable security operations, as planned. Remaining work continues to be sequenced to manage risk and align with recovery priorities. Recovery Timeline Recovery execution continued under estab...

AI summary NS Power's cybersecurity recovery efforts focus on stable operations, risk management, and completing system restorations by 2026. The OPC investigation into the 2025 cyberattack was suspended pending NS Power's fulfillment of commitments outlined in a Compliance Letter.

Section 7
nterprise resource planning systems—PeopleSoft Payroll, Resource PowerPlan, and Oracle Fusion—to support continuity of payroll, financial, and asset Planning (ERP) management operations. Customer Recovery and restoration of advanced meteri...

AI summary The document outlines a restoration roadmap for enterprise resource planning (ERP) systems, customer-facing platforms, and cybersecurity infrastructure from 2025 to 2026. Key projects include PeopleSoft Payroll, Oracle Fusion, MyAccount, and AMI HES, with completion dates and progress percentages provided for each initiative.

Section 8
31-Jul-26 72% CUSTOMER MyAccount 31-Jul-26 56% AMI HES 31-Mar-26 100% ADMS Resiliency 30-Apr-26 71% MV90 30-Jul-26 67% Grid Model Mgmt. 30-Jun-26 55% (ArcGIS/ArcFM) OpenView / ActiVu 14-May-26 80% ADDITIONAL CAPABILITIES Aligne Fuels/PI 26...

AI summary The document outlines a Gantt chart tracking progress on various initiatives under the Restoration Program Office (RPO), including grid modernization, cybersecurity, and technology enablement projects. Most projects show partial completion, with timelines subject to change due to evolving priorities and resource availability. A summary of changes to project timelines is noted, though specific details are not provided.

Section 10
Pillar Project Summary of Change Rationale Customer OpenView / Project end date adjusted Vendor is required on-site to support the ActiVu from 16-Mar-2026 to 14- implementation. The date represents May-2026, resulting in a 2- their current...

AI summary Project end dates for initiatives under the 'Customer' and 'Cybersecurity' pillars have been adjusted due to vendor availability and testing requirements. Adjustments include extending the OpenView/ActiVu project by two months and aligning the IAM project with identity recovery timelines. Testing delays for Aligne Fuels/Pi required a three-week schedule extension.

Section 11
onboarding by approximately three weeks, but these access issues have now been fully resolved. Completion of Aligne is dependent upon PI. Additional Adept Project end date adjusted Vendor is required on-site to support Capabilities from 31...

AI summary The text discusses project adjustments, including an extended deadline for the Adept Project due to vendor availability, resolved access issues, and cybersecurity updates. It also references forecasted restoration activities with an update date of March 31, 2026.

Section 18
Monthly Cybersecurity Update 7 Attachment 2 Page 2 of 5 Report 2 - Report 3 - Report 4 - Report 5 - Report 6 - Report 7 - Forecast Restoration of Normal Affected Regulatory Matters October 1 November 3 December 1 February 4 March 4 March 3...

AI summary The document outlines a cybersecurity update affecting regulatory matters, including rates-related issues and the Capital and Ace Plan. It notes the restoration of the PowerPlan is expected in Q2 2026, with updates provided through multiple reports dated up to March 31, 2026.

Section 22
Updated NA NA NA No new update Q1 2026 Maritime Link Benefits Report Introduced NA NA NA NA NA No new update Q2 2026 FAM Quarterly Introduced NA Updated NA NA NA No new update Q1/Q2 2026 Integration issues due to Vendor environment & netwo...

AI summary The document outlines updates to reports and projects, including integration issues caused by vendor environment changes and a NS Power cyber event, leading to protocol adjustments and a revised project go-live date of June 16, 2026.

Section 23
Schedule impacted. Project Go Live date changed from Q1 to Q2, to June 16, 2026 Performance Standards Meters have been restored to normal operations and customer billing is Performance Standards Introduced NA NA NA NA Updated Meter connect...

AI summary A project's Go Live date was delayed from Q1 to June 16, 2026. Meter operations and customer billing were restored to normal by March 31, 2026, with a cybersecurity update referenced in Attachment 2, Page 4 of 5.

Section 31
relevant systems. Monthly Cybersecurity Update 7 Attachment 2 Page 5 of 5 Report 2 - Report 3 - Report 4 - Report 5 - Report 6 - Report 7 - Forecast Restoration of Normal Affected Regulatory Matters October 1 November 3 December 1 February...

AI summary The document includes a cybersecurity update and references affected regulatory matters, specifically 'Rates-Related Matters' and 'System Planning', with updates dated March 31, 2026. No detailed arguments or specific entities are explicitly discussed in the provided text.

Section 39
ine. Restoration of My Energy Insights (MEI) systems are expected by the end of Q3 2026. Monthly Cybersecurity Update 7 Attachment 3 Page 1 of 2 Invoices on Hold March 26, 2026 Monthly Cybersecurity Update 7 Attachment 3 Page 2 of 2 Invoic...

AI summary The document outlines the expected restoration of My Energy Insights (MEI) systems by Q3 2026 and details administrative holds on invoices, including reasons such as credit approvals, disputes, tax form requirements, and project cost holdbacks.

101657Board letter approving NS Power's extension 1 passage
Section 1
April 20, 2026 [email protected] Blake Williams VP, Legal and Regulatory Nova Scotia Power Inc. P.O. Box 910 1223 Lower Water Street Halifax, NS B3J 3S8 Dear Mr. Williams: M12273 – Board Inquiry into Nova Scotia Power Incorporated’...

AI summary Nova Scotia Power Inc. (NS Power) requested an extension to refile documents related to a cybersecurity incident and confidentiality claims, which the Board approved until April 27, 2026. The documents include submissions, letters, and reports previously filed under confidentiality.

101752Letter NSPI re: Refiling document as requested 1 passage
Section 1
PO Box 910 Halifax, Nova Scotia Canada B3J 2W5 April 27, 2026 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 Board Inquiry into NS Power Cybersecurity Incident...

AI summary Nova Scotia Power Inc. (NS Power) is resubmitting documents to the Nova Scotia Energy Board with updated redactions following the Board's request to align with publicly disclosed information related to a cybersecurity incident inquiry (M12273).

102001NSPI Monthly Update Report #8 15 passages
Section 1
PO Box 910 Halifax, Nova Scotia Canada B3J 2W5 May 14, 2026 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power’s Cybersecurity Incident – Monthl...

AI summary Nova Scotia Power (NS Power) provides an update to the Nova Scotia Energy Board (NSEB) on its response to a 2025 cybersecurity incident, including attachments with a revised restoration roadmap, ongoing regulatory matters, and invoice status. Recovery efforts remain focused on controlled, staged operations with governance oversight.

Section 3
ore favorably each month. Please refer to Attachment 3, as the backlog has been substantially addressed and the overall trend continues toward pre-cyber levels. Customer Billing and Customer Systems Customer-facing services are now substan...

AI summary NS Power reports substantial restoration of customer-facing services, system stability, and progress in cybersecurity recovery. Meter connections and billing accuracy have improved, with focus on closing residual gaps and ensuring operational integrity. Technology enablement efforts are ongoing under formal governance.

Section 4
y continued to mature under formal governance. Several foundational components have progressed through readiness milestones, while others remain subject to staged validation and dependency resolution. The recovery strategy in this area emp...

AI summary The text outlines ongoing recovery efforts emphasizing governance, cybersecurity, and alignment with enterprise standards. Cybersecurity recovery focuses on validation and structured processes, while formal oversight ensures stable operations. The resolution of an investigation by the Office of the Privacy Commissioner of Canada is noted as a key matter.

Section 5
ation available for this reporting period, no new material impacts were identified beyond those already documented. Resolution of the Investigation of the Office of the Privacy Commissioner of Canada As indicated in Monthly Update 7 the Of...

AI summary NS Power is addressing the Office of the Privacy Commissioner of Canada's (OPC) investigation into a cyberattack by fulfilling commitments outlined in a Compliance Letter. Progress on restoration efforts includes five portfolios focusing on enterprise systems and customer-facing platforms. Blake Williams, NS Power's VP, Legal and Regulatory, confirms ongoing compliance efforts.

Section 6
and customer-facing platforms (such as contact centre and online account services) to support accurate billing, service delivery, and accessible customer support. Additional Recovery and restoration of critical supporting capabilities, inc...

AI summary The document outlines a restoration roadmap for critical systems and capabilities, including ERP, customer platforms, cybersecurity, and technology infrastructure, with project completion dates and progress percentages. It is part of a cybersecurity incident update.

Section 7
IS/ArcFM) OpenView / ActiVu 14-May-26 90% ADDITIONAL CAPABILITIES Aligne Fuels/PI 26-May-26 85% Adept Restoration 22-May-26 75% PC Replacement 14-Nov-25 100% Self-Serve BI & 31-Aug-26 65% Analytics Inventory Mgmt. – 28-Nov-25 100% Maximo P...

AI summary The text presents a Gantt chart outlining project timelines and completion statuses for the Restoration Program Office (RPO) initiatives, including cybersecurity and technology enablement projects. Timelines are subject to change based on priorities and resources. A cybersecurity incident monthly update is referenced as an attachment.

Section 8
Cybersecurity Incident - Monthly Update 8 Attachment 2 Page 1 of 5 Report 2 - Report 3 - Report 4 - Report 5 - Report 6 - Report 7 - Report 8 - Forecast Restoration of Normal Affected Regulatory Matters October 1 November 3 December 1 Febr...

AI summary The document outlines a cybersecurity incident update impacting regulatory matters, including 'Rates-Related Matters' under ongoing proceedings. It references monthly reports and a forecast for restoring normal activities, with the latest update dated May 11, 2026.

Section 14
2, 2026. Customer Billing Updated - Pulled up under the NS Power restored meter connections in March, and in April achieved the performance standard for estimated billing. NS Power's focus Meters have been restored to Customer Billing Intr...

AI summary NS Power restored meter connections in March 2026 and met estimated billing performance standards in April. The utility prioritizes assisting customers with outstanding balances through flexible repayment options, while addressing cybersecurity incident updates in a monthly report.

Section 15
Cybersecurity Incident - Monthly Update 8 Attachment 2 Page 2 of 5 Report 2 - Report 3 - Report 4 - Report 5 - Report 6 - Report 7 - Report 8 - Forecast Restoration of Normal Affected Regulatory Matters October 1 November 3 December 1 Febr...

AI summary The document provides a cybersecurity incident monthly update, detailing the Capital and Ace Plan with updates on Capital Budgeting/Finance Data and the expected restoration of the PowerPlan in Q2 2026.

Section 17
NSEB in 2026. The Reliability Tie project has been NS – NB Reliability Intertie Project Introduced NA NA NA NA NA NA No new update approved by the NSEB. Financial Reporting and Statements Q2 2026 (for completion of Q4 Financial Reporting a...

AI summary The NS–NB Reliability Intertie Project was approved by the NSEB in 2026. Financial reporting updates for Q2 2026 (related to Q4 2025 Regulated Financial Statements) were introduced, with no new updates. A cybersecurity incident monthly update (Attachment 2, Page 3 of 5) was also referenced.

Section 18
Cybersecurity Incident - Monthly Update 8 Attachment 2 Page 3 of 5 Report 2 - Report 3 - Report 4 - Report 5 - Report 6 - Report 7 - Report 8 - Forecast Restoration of Normal Affected Regulatory Matters October 1 November 3 December 1 Febr...

AI summary The document provides a monthly cybersecurity incident update, tracking the status of regulatory matters including the Fuel Adjustment Mechanism and Maritime Link Benefits Report. Updates are noted for specific reports with statuses like 'Introduced' and 'Updated,' alongside forecasted restoration timelines for affected activities.

Section 19
Introduced NA Updated NA NA Updated NA No new update Q2 2026 Update Performance Standards Meters have been restored to normal operations and customer Performance Standards Introduced NA NA NA NA Updated NA No new update. billing is returni...

AI summary Performance standards have been updated, with meters restored to normal operations and customer billing resuming as of March 31, 2026. A cybersecurity incident is documented in Attachment 2, Page 4 of 5, with a monthly update provided.

Section 23
end of Q3 2026. Data flows to evaluate Demand Response will be restored in Q3 2026, ahead of the 26/27 Season E1's Demand Response Programming NA Introduced NA NA NA NA NA No new update beginning on Dec 1, 2026, pending successful restorat...

AI summary The text outlines plans to restore Demand Response programming by Q3 2026, contingent on AMI system restoration, and references a cybersecurity incident monthly update. No new updates to E1's Demand Response Programming are introduced.

Section 24
Cybersecurity Incident - Monthly Update 8 Attachment 2 Page 5 of 5 Report 2 - Report 3 - Report 4 - Report 5 - Report 6 - Report 7 - Report 8 - Forecast Restoration of Normal Affected Regulatory Matters October 1 November 3 December 1 Febr...

AI summary The document outlines a cybersecurity incident with monthly updates, including reports on affected regulatory matters and a forecast for restoring normal activities. Updates span from October 2025 to May 2026, with a focus on system planning and incident management timelines.

Section 31
(MEI) systems are expected by the end of Q3 2026. Cybersecurity Incident - Monthly Update 8 Attachment 3 Page 1 of 2 Invoices on Hold May 11, 2026 Cybersecurity Incident - Monthly Update 8 Attachment 3 Page 2 of 2 Invoices on Hold May 11,...

AI summary The document includes a cybersecurity incident monthly update and details about invoices on hold, with administrative and procurement-related reasons such as approval requirements, disputes, and tax form approvals.

102372NSPI Monthly Update Report #9 3 passages
Preamble p. p. 0
June 12, 2026 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power's Cybersecurity Incident – Monthly Update 9 Dear Ms. Henwood: On July 14, 2025,...

AI summary Nova Scotia Power (NS Power) submitted Monthly Update 9 to the Nova Scotia Energy Board (NSEB) regarding its response to a 2025 cybersecurity incident. The report includes an updated Restoration Roadmap, Ongoing Regulatory Matters table, and invoice status, as required by the Board's July 2025 directive. This update supersedes prior reports and outlines ongoing recovery efforts.

Cybersecurity p. p. 0
Cybersecurity Cybersecurity capabilities continue to mature through structured governance, validation, and readiness activities. Foundational identity and access controls have been strengthened, enabling greater consistency and reliability...

AI summary Cybersecurity capabilities have matured through structured governance and validation, with strengthened identity and access controls. Ongoing workstreams focus on coordination, documentation, and stakeholder engagement, ensuring secure operations via oversight and mitigation strategies.

PROGRAM STRUCTURE p. p. 0
PROGRAM STRUCTURE The Restoration Program is structured into five (5) key portfolios of work – focusing on restoring business capabilities. Portfolio Scope Summary Enterprise Resource Planning (ERP) Recovery and restoration of core enterpr...

AI summary The Restoration Program is organized into five key portfolios: Enterprise Resource Planning, Customer, Additional Capabilities, Cybersecurity, and Technology Enablement, each focusing on restoring critical systems and operations.

102710NSPI Monthly Update Report #10 5 passages
Preamble p. p. 0
July 10, 2026 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power's Cybersecurity Incident – Monthly Update 10 Dear Ms. Henwood: On July 14, 2025...

AI summary This document is a monthly update from Nova Scotia Power regarding its response to a cybersecurity incident that occurred in the spring of 2025. It includes an updated Restoration Roadmap Gantt Chart and other attachments. The report is part of a series of monthly progress reports required by the Nova Scotia Energy Board.

Cybersecurity p. p. 0
Cybersecurity Cybersecurity capabilities are established and operating effectively across the environment, providing a strong foundation for the organization's ongoing operations and recovery objectives. Key security controls, including id...

AI summary The organization's cybersecurity framework is robust and effective, with key controls such as identity and access management in place. Current efforts focus on governance, control validation, and readiness to ensure long-term operational effectiveness and compliance with requirements.

Recovery Timeline p. p. 0
Recovery Timeline The program has now delivered the majority of its recovery objectives, with key business and technology capabilities fully operational and supporting organizational needs. Service continuity remained stable throughout the...

AI summary The program has achieved most of its recovery goals, with key systems operational and service continuity maintained. NS Power is addressing commitments from the OPC regarding a cyberattack investigation, which will be resolved upon completion of these commitments.

PROGRAM STRUCTURE p. p. 0
PROGRAM STRUCTURE The Restoration Program is structured into five (5) key portfolios of work – focusing on restoring business capabilities. Portfolio Scope Summary Enterprise Resource Planning (ERP) Recovery and restoration of core enterpr...

AI summary The Restoration Program is structured into five key portfolios: Enterprise Resource Planning, Customer, Additional Capabilities, Cybersecurity, and Technology Enablement. Each portfolio focuses on restoring critical systems and capabilities to ensure business continuity and resilience.

The following projects experienced adjustments to their completion timeline. An overview of the changes and associated rationale is outlined below: p. p. 5
The following projects experienced adjustments to their completion timeline. An overview of the changes and associated rationale is outlined below: Pillar Project Summary of Change Rationale Fuel Adjustment Mechanism General NA Updated Upd...

AI summary Several projects have had their completion timelines adjusted. The Fuel Adjustment Mechanism was updated, and the Maritime Link Benefits Report was introduced. The Dispatch Study Action Plan Quarterly Update is scheduled to go live in July 2024, after which no further updates related to the Cybersecurity Incident will be needed.

103204NSPI Monthly Update Report #11 3 passages
Preamble
August 13, 2026 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power's Cybersecurity Incident – Monthly Update 11 Dear Ms. Henwood: On July 14, 20...

AI summary This document is the 11th monthly update from Nova Scotia Power regarding its response to a cybersecurity incident that occurred in the spring of 2025. It includes an updated Restoration Roadmap Gantt Chart and tables related to ongoing regulatory matters and invoices on hold.

Cybersecurity
Cybersecurity Cybersecurity capabilities continue to operate effectively, supporting the organization's operational and recovery objectives. Key security controls, including identity and access management capabilities, are fully implemente...

AI summary The organization's cybersecurity capabilities are functioning effectively, with key security controls fully implemented. Current efforts focus on sustaining and improving these capabilities through governance, compliance, and stakeholder coordination. The cybersecurity environment remains stable and aligned with organizational requirements.

Recovery Timeline
Recovery Timeline The program continued to advance during the reporting period, with additional recovery objectives completed and further capabilities transitioning into operational service. Most business and technology restoration activit...

AI summary The recovery program is progressing with most restoration activities completed and focus shifting to long-term operations. NS Power is addressing commitments from the OPC regarding a cyberattack investigation, with the OPC pausing its investigation pending completion of these commitments.

Disclaimer: These summaries were generated by AI from the filings they describe. We take care to make them accurate, but errors are possible - and they aren't advice. Only the filings themselves are the record: if you're relying on something here, confirm it against the source documents or the Nova Scotia Energy Board's own record. Full disclaimer →