HomeCybersecurityM12588Evidence
Topic/Matter Intersection

Topic:"Cybersecurity" in M12588

Matter: Nova Scotia Power Inc. - CI C0053699 – Renewable to Retail Implementation - $5,644,468
17 passages 9 documents

Cybersecurity across all matters →

N-3NSPI (NSEB) RIR 1 to 15 - Redacted 2 passages
CI C0053699 Renewable to Retail Implementation (NSEB M12588) NSPI Responses to NSEB Information Requests p. p. 7
CI C0053699 Renewable to Retail Implementation (NSEB M12588) NSPI Responses to NSEB Information Requests 1 Request IR-2: 2 3 Please compare the project estimate of $5,644,468 to the $6.4 million estimate for the total 4 required for renewa...

AI summary NSPI responds to NSEB information requests regarding the Renewable to Retail (RtR) implementation project. It explains the difference between the current project estimate and a previous estimate from Matter M11874, and confirms that the cybersecurity breach did not affect any work done to date on the RtR market.

Active Submissions p. p. 23
Active Submissions Total A - Technical Evaluation A-1 - Adherence to RFP requirements A-2 - Ongoing support availability and service levels A-3 - Speed and efficiency of implementation (or project) plan, availability, and delivery the indu...

AI summary The document discusses technical evaluation criteria for submissions, including adherence to RFP requirements, implementation plans, industry expertise, and corporate risk factors such as cybersecurity and insurance. Specific references to the CIS and MDMS systems and the involvement of a Load and Revenue forecasting subject matter expert are noted.

N-4NSPI (REI) RIR 1 to 22 4 passages
p. p. 36
Request IR-10: Reference: N-1, C0053699 Renewable to Retail Implementation Project, pages 2-3 of 6. The increase of the estimated $581,816 from the 2025 ACE Plan subsequent submittal estimate of $5,062,652 is primarily due to increased Adm...

AI summary The text requests clarification on the cost increases in the 2025 ACE Plan, specifically whether they were influenced by a cybersecurity incident. It asks for supporting documentation, explanations on how the breach impacted project timelines, cost tracking methodologies, and relevant cybersecurity reports.

Section 52 p. p. 36
17 Response IR-11: 18 20 24 19 (a) Please refer to SBA IR-1. 21 (b) Due to the cyber incident, NS Power does not have access to the original estimate details 22 to provide a comparison table, and does not expect to recover this data. Pleas...

AI summary NS Power is unable to provide a comparison table of original estimate details due to a cyber incident, and instead provides tables for the calculation of overheads for the current estimate, referring to SBA IR-1 for further information.

- 6 As mentioned in part (b), NS Power does not have access to the original estimate details. p. p. 36
- 6 As mentioned in part (b), NS Power does not have access to the original estimate details. 1 Request IR-12: 15 collection/aggregation functionality dependent on MDMS/MDM systems, please 16 provide: 17 18 (i) The current meter reading on...

AI summary NS Power does not have access to original estimate details, and there are requests regarding the current meter reading onboarding timeline and operational capability for interval data collection. The response includes details on software systems impacted by the implementation and mentions cybersecurity incident remediation efforts.

2.2 Assumptions & Constraints p. p. 56
2.2 Assumptions & Constraints - 1. The project will leverage existing solutions already in place at NSP. - 2. Both the input of the request and the output of the customer data to the LRS must be secure. - 3. The customer must consent to th...

AI summary The assumptions and constraints for the project include leveraging existing solutions at NSP, ensuring secure data handling, obtaining customer consent for data sharing, and transmitting data in flat file format via secure FTP to the LRS.

102536Decision 2 passages
3.2.3 Cybersecurity Breach Impacts p. pp. 23-25
3.2.3 Cybersecurity Breach Impacts [71] Renewall submitted that NS Power should be required to demonstrate with evidence that no cyber-recovery costs were charged to this capital project. Renewall also said "it requires confirmation that t...

AI summary Renewall requested evidence that NS Power did not incur cyber-recovery costs on a capital project and that project work was not corrupted by a cyber incident. NS Power stated that no cyber-recovery costs were charged to the project, the project scope was unaffected, and project work was preserved and moved to a dormant state in its production environment.

3.2.3.1 Findings p. pp. 25-26
3.2.3.1 Findings [74] Renewall's concern about cyber-recovery costs is understandable, but speculative. Given NS Power's standard use of project codes, the Board is satisfied that the capital costs for this project do not relate to other w...

AI summary The Board acknowledges Renewall's concerns about cyber-recovery costs but finds them speculative. It is satisfied that NS Power's capital costs for the project are not related to other work and that the project was not impacted by the cyberattack. However, the Board will address any incremental costs from rework due to the cyberattack if they arise.

100718NSEB (NSPI) IR 1 to 15 - Word 1 passage
Section 2
4 million estimate for the total required for renewable to retail market development, inclusive of costs to date, forecasted costs, and deferred amounts in Matter M11874 (Letter of Credit proceeding). Please advise whether any work done to...

AI summary The document discusses the estimated $4 million required for renewable to retail market development, including costs to date, forecasted costs, and deferred amounts in Matter M11874. It also raises concerns about whether NS Power's cybersecurity breach affected work done to implement the Renewable to Retail (RtR) market and if redoing affected work has been included in the project amount. NS Power mentions that its Customer Information System (CIS) is outdated and requires modernization to support new tariff designs and programs.

100720REI (NSPI) IR 1 to 22 - PDF 1 passage
1 RtR implementation scope and cost estimate;
23 Please confirm whether NSPI is seeking recovery of its own regulatory hearing costs (internal and 24 external legal, consulting, expert witness costs) associated with this RtR capital application and 25 other RtR applications? 1 RtR imp...

AI summary The text includes questions regarding the recovery of regulatory hearing costs by NSPI for the RtR capital application and other RtR applications, as well as inquiries about the impact of a 2025 cybersecurity incident on the RtR implementation project's cost and scope.

100721REI (NSPI) IR 1 to 22 - Word 2 passages
Section 8
ses, risk registers, and scope/interface management protocols, particularly following the cybersecurity incident. Reference : N-1, C0053699 Renewable to Retail Implementation Project, page 2 of 6. Implementation began in 2023… based on… CO...

AI summary The text discusses the Renewable to Retail Implementation Project, highlighting delays in the COD (Completion of Development) and the associated rework and cost increases. It references the 2025 ACE Plan and the need for NSPI to re-baseline scope and spend to minimize costs recoverable from the LRS.

Section 9
COD dates and to a lesser extent, an increase in technical requirements for data integration of forecasted generation data as well as additional testing complexity that was previously not considered. 1. Please identify whether any of these...

AI summary The text requests clarification on whether cost increases related to the 2025 cybersecurity incident influenced the RtR project, including documentation on impacted costs, cost tracking methodologies, and technical requirement changes. It also asks for cybersecurity incident reports and their impact on project scope and costs.

101270Submission - REI 2 passages
1) Delay Costs Appear Inflated and NSPI Has Not Shown They Were Prudently Incurred p. p. 2
/span>[ 10 ](#page-2-5) N-5, NSPI (SBA) RIR-1; and N-4, NSPI (REI) RIR-11. [ 11 ](#page-2-7) N-5, NSPI (SBA) RIR-1. March 17, 2026 Page 4 Crystal Henwood NSPI should be required to satisfy the Board with evidence that no cyber-recovery cos...

AI summary The document discusses concerns regarding inflated delay costs and the prudence of their incurrence by Nova Scotia Power Inc. (NSPI). It highlights the need for NSPI to provide evidence that cyber-recovery costs were not improperly charged to a specific capital item and that existing software code and configurations have not been compromised.

CONCLUSION AND RELIEF SOUGHT p. p. 6
CONCLUSION AND RELIEF SOUGHT REI respectfully submits that the Board: - 1. Disallow or reduce delay related costs where NSPI has failed to demonstrate that such costs were prudent, unavoidable, or attributable to REI. - 2. Direct NSPI to p...

AI summary REI requests the Board to disallow or reduce various costs incurred by NSPI, including delay-related, cyber-recovery, and software development costs, and to impose conditions on cost recovery and data readiness. REI also seeks a CIS Replacement ring fence and a true-up mechanism to prevent misallocation of costs.

101449NS Power's Reply to Intervenor Submissions 1 passage
Confirmation of Cyber Incident Cost Segregation and RtR System Integrity p. p. 3
Confirmation of Cyber Incident Cost Segregation and RtR System Integrity REI submits that the absence of the original detailed ACE Plan estimate, which NS Power advises cannot be recovered due to the cyber incident, limits the Board's abil...

AI summary REI is concerned that the absence of original detailed ACE Plan estimates due to a 2025 cyber incident limits the Board's ability to assess prudence. REI requests confirmation that cyber incident costs were segregated from the RtR project and that the system's integrity remains intact. NS Power confirms that the cyber incident did not impact the project's scope or costs and that costs were segregated using a dedicated project code.

102536Decision 2 passages
3.2.3 Cybersecurity Breach Impacts p. pp. 23-25
3.2.3 Cybersecurity Breach Impacts [71] Renewall submitted that NS Power should be required to demonstrate with evidence that no cyber-recovery costs were charged to this capital project. Renewall also said "it requires confirmation that t...

AI summary Renewall requested evidence that no cyber-recovery costs were charged to the capital project and that the software code was not affected by the cyber incident. NS Power responded that the cyber incident did not impact the project scope or costs, and that project work was preserved and segregated using a dedicated project code.

3.2.3.1 Findings p. pp. 25-26
3.2.3.1 Findings [74] Renewall's concern about cyber-recovery costs is understandable, but speculative. Given NS Power's standard use of project codes, the Board is satisfied that the capital costs for this project do not relate to other w...

AI summary The Board acknowledges Renewall's concerns about cyber-recovery costs but finds them speculative. It is satisfied that NS Power's capital costs are not related to other work and that the cyberattack did not impact the work developed. Any incremental costs from rework will be addressed if necessary.

Disclaimer: These summaries were generated by AI from the filings they describe. We take care to make them accurate, but errors are possible - and they aren't advice. Only the filings themselves are the record: if you're relying on something here, confirm it against the source documents or the Nova Scotia Energy Board's own record. Full disclaimer →