HomeCybersecurityM12600Evidence
Topic/Matter Intersection

Topic:"Cybersecurity" in M12600

Matter: Nova Scotia Power - Cybersecurity Accountability IN THE MATTER OF AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED’s collection and retention of customer information, customer service and communications, billing processes and regulatory matters
498 passages 81 documents

Cybersecurity across all matters →

N-1LOCs Redacted (N-1 from M12273) 24 passages
Re: Important Notice About Your Personal Information p. p. 8
Re: Important Notice About Your Personal Information Dear Valued Customer: We are writing to provide you with information about the recent cyber incident impacting Nova Scotia Power. On April 25, 2025, Nova Scotia Power discovered that an...

AI summary This notice informs customers of a cyber incident at Nova Scotia Power, where unauthorized access occurred on March 19, 2025, potentially exposing personal information. The company has initiated response protocols, informed authorities, and provided free credit monitoring services to affected customers. A related legal matter, M12273, is referenced in an email exchange.

Sent Via Email p. p. 8
tolen in this security breach; - 2) A lawful explanation as to the communication delay between discovering the security breach on April 25, 2025, and the communication that I received on May 22, 2025; - 3) Provide comprehensive identity pr...

AI summary The text outlines a customer's concerns regarding a data breach by NS Power, requesting explanations for the delayed communication, identity protection measures, and a written acknowledgment of NS Power's responsibility for the breach, as well as an explanation for why Nova Scotians should trust NS Power again.

Contact Information p. pp. 14-108
Contact Information Name on account: Account number: \ \ \ \ \ \ \ Business contact: Account address: Address 1: \ \ \ \ \ \ \ Address 2: \ \ \ \ \ \ \ \ City: \ \ \ \ \ \ \ Province: \ \ \ \ \ \ \ Postal code: \ \ \ \ \ \ \ Country: \ \ \...

AI summary The complaint details a cyber security breach at NS Power and highlights concerns over the lack of in-house expertise and the need for regulatory approval for a $6.8M cyber security upgrade. The complainant questions why such a core service is not baseline funded and why regulatory approval is needed for a legally mandated effort.

How do they want the complaint resolved? p. pp. 14-20
How do they want the complaint resolved? I expect PROMPT action from the NS Energy Board on this ongoing cyber threat. The fact that the NS Energy Board continued to pursue a standard 90 day review period without triaging and expediting th...

AI summary The complainant is urging the NS Energy Board to take prompt action on a cybersecurity threat, criticizing the standard 90-day review period and NS Power's failure to prioritize cybersecurity. The complainant claims that NS Power's negligence led to the theft of credit information affecting 280,000 Nova Scotians. They expect the NS Energy Board to expedite the process and for NS Power to self-fund the cybersecurity effort.

Attached, you will find: p. p. 20
Attached, you will find: - 1. A formal complaint letter outlining the incident, technical analysis, and risks posed by the remedial platform; - 2. An email with evidence from Meng Cheng Yeh. (Meng Cheng Yeh is a formal privacy complaint co...

AI summary A formal complaint letter and supporting evidence from Meng Cheng Yeh, a student specializing in IT Systems Management and Security, are submitted regarding a data breach at Nova Scotia Power. The incident is said to pose ongoing cyber risks to affected individuals, and the complainant requests urgent review and additional documentation if needed.

Dear Commissioner, p. p. 20
Dear Commissioner, My name is YungYu Yeh, A victim of NS power's customer data breach. I am writing to formally file a privacy complaint regarding the recent cyber incident involving Nova Scotia Power, which has resulted in the confirmed l...

AI summary A customer of Nova Scotia Power, YungYu Yeh, reports a data breach and expresses concerns about the security of the identity protection service provided by NS Power, 'mytrueidentity.ca,' highlighting multiple vulnerabilities in its implementation.

5. Indications of Neglect: p. pp. 20-27
5. Indications of Neglect: - Outdated copyright (2019). - Use of deprecated security practices (e.g., X-XSS-Protection). - No evidence of recent updates or audits. Given these findings, I strongly believe that this "remedial" service may f...

AI summary The document highlights cybersecurity concerns related to an outdated service used by NS Power, noting outdated copyright and deprecated security practices. It requests an investigation into due diligence and alignment with privacy laws, emphasizing potential risks to Nova Scotians.

Conclusion: p. p. 27
Conclusion: mytrueidentity.ca does not meet modern web security standards for handling sensitive financial information. Until critical security policies, headers, and coding practices are addressed, entering credit card data into this site...

AI summary The document concludes that mytrueidentity.ca lacks modern web security standards for handling sensitive financial information, exposing users to cyber risks. It advises Nova Scotian residents against submitting payment or personal information on the platform.

p. p. 32
ring CSP analysis Cool des Raw : server headers Scan history Benchmark comparison Test Score Reason Recommendation Content Security Policy (CSP) -25 🗴 Content Security Policy (CSP) header not implemented Implement one, see MDN's Content Se...

AI summary The document provides a security analysis of a website, highlighting several security headers and their implementation status. Key issues include the lack of a Content Security Policy (CSP) header, absence of Subresource Integrity (SRI), and incomplete implementation of X-Content-Type-Options and X-Frame-Options headers. Recommendations are provided to improve security settings.

Section 59 p. p. 32
tionList.longestInteractionList.longestInteractionList.longestInteractionList.longestInteractionList.longestInteractionList.longestInteractionList.l longestInteractionList.sort(function(h,d){return d.latency}),longestInteractionList.splice...

AI summary The provided text is a fragment of code or technical documentation, likely related to performance monitoring or web security headers. It includes references to performance events, timing functions, and security headers such as CSP, SRI, X-Content-Type-Options, X-Frame-Options, and HSTS. The text also includes a mention of 'Security Analysis by Meng Cheng'.

\ \ EXTERNAL EMAIL / COURRIEL EXTERNE \ \ p. pp. 36-134
ay 23, 2025. While your letter acknowledged that my personal data had been stolen by an unauthorized third party, it didn't meet acceptable standards for breach notification in several important ways: - 1. Lack of Specific Information: The...

AI summary The letter criticizes Nova Scotia Power for inadequate breach notification following a data theft, citing lack of specific information, no guidance on next steps, and minimal support. It requests detailed disclosure, explanation of the delay, enhanced identity protection, clear guidance, and improved cybersecurity protocols.

Re: Important Notice About Your Personal Information p. p. 49
Re: Important Notice About Your Personal Information Dear Valued Customer We are writing to provide you with information about the recent cyber incident impacting Nova Scotia Power. On April 25, 2025, Nova Scotia Power discovered that an u...

AI summary Nova Scotia Power experienced a cyber incident on April 25, 2025, where unauthorized access was gained to parts of its network and servers. Customer information, including personal and account details, may have been accessed. As a precaution, TransUnion myTrueIdentity credit monitoring service is being offered to affected customers.

Re: Important Notice About Your Personal Information p. pp. 55-56
Re: Important Notice About Your Personal Information Dear Valued Customer: We are writing to provide you with information about the recent cyber incident impacting Nova Scotia Power. On April 25, 2025, Nova Scotia Power discovered that an...

AI summary Nova Scotia Power has informed customers of a cyber incident where unauthorized access occurred on March 19, 2025, leading to the potential exposure of personal information. The company has engaged cybersecurity experts and notified authorities. As a precaution, customers are being offered free credit monitoring through TransUnion.

Good evening, p. pp. 61-64
Good evening, As discussed today, please consider this synopsis of a potential source of the cyber breach on the NS Power corporate (non-operational) network. For your further review and further investigation. On or about 20 May 2025, I re...

AI summary The letter discusses a cyber breach on NS Power's corporate network and requests disclosure of costs related to a Security Operations Centre (SOC) and Security Information Event Monitoring (SIEM) project. The letter references documents M09301 and N-2 NSPI responses, highlighting concerns about unaccounted expenses for the SOC service provided by Service Now.

Nova Scotia Power Careers Home p. pp. 64-67
Nova Scotia Power Careers Home careers.emera.com I recommend that the NS Energy Board, in the service of its formal investigation of NS Power's cyber security breach of its corporate network infrastructure, seek out how NS Power was able t...

AI summary The text discusses a cybersecurity breach at Nova Scotia Power (NSP) involving vulnerabilities in Service Now software, which were identified on 10 July 2024. The author raises concerns about whether NSP addressed these vulnerabilities across its locations, highlighting that hackers exploited these vulnerabilities on 19 March 2025, leading to unauthorized access to customer information. The text calls for an investigation into NSP's network security practices.

READ MORE p. pp. 70-71
READ MORE These two Ivanti bugs are allowing hackers to target cloud instances - so patch now

AI summary The text highlights two Ivanti bugs that are enabling hackers to target cloud instances, emphasizing the need for immediate patching to prevent potential security breaches.

Hackers are ramping up attacks using year-old ServiceNow security bugs to target unpatched systems p. pp. 77-80
Hackers are ramping up attacks using year-old ServiceNow security bugs to target unpatched systems Carly Page 9:04 AM PDT · March 20, 2025 IMAGE CREDITS: SMITH COLLECTION/GADO / GETTY IMAGES Hackers are ramping up their attempts to exploit...

AI summary Hackers are exploiting year-old ServiceNow security vulnerabilities (CVE-2024-4879, CVE-2024-5178, CVE-2024-5217) to target unpatched systems, with a notable resurgence in attacks. Security researchers warn that these flaws can be chained for full database access, and organizations using ServiceNow for sensitive employee data are at risk.

News p. p. 81
News Jul 30, 2024 • 5 mins Data Breach Vulnerabilities The vulnerabilities have exposed sensitive information from over 105 organizations including government agencies, data centers, energy providers, and software development firms. $\labe...

AI summary A data breach involving three critical vulnerabilities in the ServiceNow IT service management platform has exposed sensitive information from over 105 organizations, including government agencies and energy providers. The vulnerabilities allow unauthenticated remote attackers to execute arbitrary code, potentially leading to data theft and disruption of business operations. Cybersecurity firms have reported active exploitation and the sale of stolen data on the dark web.

Explore related questions p. p. 81
Explore related questions - How do ServiceNow vulnerabilities impact specific industries? - Why do unpatched old vulnerabilities pose significant cybersecurity risks? - How do known vulnerabilities impact government organizations? - What a...

AI summary The text presents a list of cybersecurity-related questions focusing on the impact of ServiceNow vulnerabilities, unpatched old vulnerabilities, and misconfigured ServiceNow KB articles on specific industries, government organizations, and the risks associated with unencrypted services.

Danielle Kristine Maillet p. p. 100
Danielle Kristine Maillet NSPower Account #: To: NS Power Customer Service CC: Privacy Office, Billing Department, Legal Department Re: Data Breach, Billing Disruption, and Compensation Demand Dear NS Power, I am writing to formally expres...

AI summary Danielle Kristine Maillet is writing to NS Power to express concerns about a data breach and billing disruptions, demanding a full waiver of her current bill, a credit for an unsolicited service, and a freeze on future charges until online access is restored. She threatens to escalate the matter to regulatory bodies and seek legal consultation if unresolved.

Preamble p. pp. 117-134
We are writing in response to your request for a detailed account of what personal information of yours may have been compromised in the cyber attack that recently affected Nova Scotia Power's systems. First, we want to assure you that pro...

AI summary Nova Scotia Power informs customers that a cyber attack may have compromised personal information, including contact details, account history, and financial data. While specific details cannot be identified, the company encourages credit monitoring and other security measures to protect affected individuals.

RE: Nova Scotia Power (NSP) Cyber Breach p. pp. 126-129
RE: Nova Scotia Power (NSP) Cyber Breach Nova Scotia Power (NSP) knows, or should know, that Canada is a target for cyber criminals and hostile governments such as China, Russia, Iran, and North Korea. NSP, a critical infrastructure corpor...

AI summary The document discusses a data breach by Nova Scotia Power (NSP), highlighting the delayed response and lack of transparency. The breach, which occurred on 19 March 2025, was not detected until 25 April 2025, with customer notifications delayed further. NSP is criticized for not adhering to PIPEDA standards and for insufficient security measures such as real-time threat detection and zero-trust architecture.

Section 173 p. p. 146
DRO made decision on: May Type of complaint: Other Additional details: I am writing to have it on record that the data breach has literally RUINED us and the billing is out of control for us who live in NS. During all of this while our cre...

AI summary A Nova Scotia Power ratepayer is filing a complaint regarding the impact of a data breach on their personal and financial well-being, highlighting the stress caused by fraud and medical issues. They also request specific information requests to the Board regarding where customer data is stored and its exposure to foreign legal process.

Section 177 p. p. 146
who holds the encryption keys and in what jurisdiction; (c) any contractual restriction on onward transfer or vendor use of the data. Produce the governing data-processing agreement or transfer terms. Question 6 — Foreign legal process exp...

AI summary The questions focus on data security, privacy, and compliance, asking about encryption key management, foreign legal process exposure, privacy impact assessments, vendor environments in a 2025 cyber incident, and systems handling customer personal information in specific capital projects.

N-2NSPI (NSEB) RIR 1 to 12 - Redacted (N-2 from M12273) 53 passages
Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests p. pp. 10-56
Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests 1 Request IR-1: 2 3 Please provide a timeline of this cybersecurity incident, including: 4 5 (a) the date of the breach...

AI summary The document outlines a request for a timeline of a cybersecurity incident at Nova Scotia Power, including dates of the breach, discovery, confirmation, and public communication. The response indicates the investigation is ongoing, and the incident was discovered on April 25, 2025, when employees noticed system malfunctions due to unauthorized access.

Section 14 p. pp. 10-11
Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests

AI summary The document outlines the NSEB's inquiry into Nova Scotia Power's cybersecurity incident and includes NSPI's responses to information requests. The proceeding involves cybersecurity and regulatory oversight themes.

2 p. pp. 11-15
2 Station Contact WEST Contact W 25 1 Bridgewater: CKBW Country 100.7FM [email protected]; [email protected] Yarmouth: СЛLS [email protected] Liverpool: QCCR 99.3 FM navia@gaarfm aam [email protected] Kentville/New Minas: 89.3 Rewi...

AI summary The document lists contact information for various radio stations across Nova Scotia and references a regulatory inquiry by the Nova Scotia Energy Board (NSEB) into a cybersecurity incident at Nova Scotia Power (NSP), identified as matter number M12273.

Preamble p. pp. 11-22
2 Advertisements were also placed in approximately 15 local and provincial newspapers across the province to ensure broader reach to demographics within the province. A sample ad is provided below. 4 5 Board Inquiry into Nova Scotia Power'...

AI summary Advertisements were placed in 15 local and provincial newspapers to reach broader demographics. A sample ad is included. The document references a Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) and NSPI responses to NSEB information requests.

REDACTED p. p. 15
REDACTED July 9, 2025 CBC Nova Scotia Radio Elizabeth McMillan Chris Lanteigne, Director Customer Care Cyber incident update Billing concerns Customer support sessions in communities across NS July 11, 2025 CBC Nova Scotia – Information Mo...

AI summary The document includes media mentions related to a cybersecurity incident and customer concerns, with references to a cybersecurity incident report from the NSEB. It also includes details about customer support sessions and meter reader community sessions.

Re: Important Notice About Your Personal Information p. pp. 18-22
Re: Important Notice About Your Personal Information Dear Valued Customer: We are writing to provide you with information about the recent cyber incident impacting Nova Scotia Power. On April 25, 2025, Nova Scotia Power discovered that an...

AI summary Nova Scotia Power informed customers of a cyber incident on April 25, 2025, where unauthorized access occurred to certain parts of its Canadian network and servers. Customer information, including personal and account details, may have been accessed. As a precaution, customers are being offered a two-year credit monitoring service at no cost.

Cybersecurity Incident NSEB IR-01 Attachment 1 Page 2 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 18
Cybersecurity Incident NSEB IR-01 Attachment 1 Page 2 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED) We encourage you to remain vigilant and cautious about any unsolicited communications (such as emails, text messages, social posts or ph...

AI summary Nova Scotia Power is advising customers to be cautious of unsolicited communications, including those appearing to be from the company, and has established a dedicated hotline for inquiries. The company apologizes for a cybersecurity incident and is taking steps to improve system security.

Cybersecurity Incident NSEB IR-01 Attachment 1 Page 3 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 18
Cybersecurity Incident NSEB IR-01 Attachment 1 Page 3 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED)

AI summary This document discusses a cybersecurity incident related to Nova Scotia Power (NSP) and involves the Canadian Centre for Cybersecurity (CCCS) and the Royal Canadian Mounted Police (RCMP). The Nova Scotia Energy Board (NSEB) is mentioned in the context of the incident.

Cybersecurity Incident NSEB IR-01 Attachment 1 Page 4 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 18
Cybersecurity Incident NSEB IR-01 Attachment 1 Page 4 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED)

AI summary This document is a redacted attachment related to a cybersecurity incident under the Nova Scotia Energy Board (NSEB) IR-01 proceeding. It contains confidential information and is part of a regulatory proceeding involving cybersecurity concerns.

Cybersecurity Incident NSEB IR-01 Attachment 2 Page 2 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 22
Cybersecurity Incident NSEB IR-01 Attachment 2 Page 2 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED) We encourage you to remain vigilant and cautious about any unsolicited communications (such as emails, text messages, social posts or ph...

AI summary Nova Scotia Power has experienced a cybersecurity incident and is urging customers to remain cautious of unsolicited communications. They have provided a dedicated contact number for inquiries and are working to strengthen system security to prevent future incidents. Peter Gregg, President & CEO of Nova Scotia Power, has apologized for the incident.

Cybersecurity Incident NSEB IR-01 Attachment 2 Page 3 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 22
Cybersecurity Incident NSEB IR-01 Attachment 2 Page 3 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED)

AI summary This document is a redacted attachment related to a cybersecurity incident under the Nova Scotia Energy Board (NSEB) reference number IR-01. It contains confidential information and is part of a regulatory proceeding.

Cybersecurity Incident NSEB IR-01 Attachment 2 Page 4 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 22
Cybersecurity Incident NSEB IR-01 Attachment 2 Page 4 of 4 REDACTED (CONFIDENTIAL INFORMATION REMOVED)

AI summary This document is a redacted attachment related to a cybersecurity incident involving Nova Scotia Power and the Nova Scotia Energy Board. It contains confidential information and is part of a regulatory proceeding.

What is the dark web? p. p. 26
What is the dark web? These threat actors, and other cyber criminals, use a hidden part of the internet that is only accessible through special software—it is commonly referred to as the "dark web" and is known to be used by cyber criminal...

AI summary The text introduces the concept of the dark web, describing it as a hidden part of the internet used by cyber criminals to store and trade data. It also includes a note about technical support for myTrueIdentity® and a reference to a cybersecurity incident attachment.

Further Protection p. pp. 26-27
Further Protection Here's are some additional steps you can take to further protect your personal information: Service Canada advises individuals affected by a breach to contact both TransUnion and Equifax for file monitoring and to regula...

AI summary The text provides guidance on protecting personal information following a data breach, including contacting credit agencies, monitoring financial accounts, and signing up for fraud alerts.

Cybersecurity Incident NSEB IR-01 Attachment 4 Page 1 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 27
Cybersecurity Incident NSEB IR-01 Attachment 4 Page 1 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED) NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025)

AI summary This document provides updates from NS Power regarding a cybersecurity incident, including excerpts from their website as of September 5, 2025. The content is redacted and marked as confidential information.

CYBER INCIDENT UPDATES p. p. 27
CYBER INCIDENT UPDATES

AI summary The document provides updates on recent cyber incidents, highlighting the involvement of key organizations such as Nova Scotia Power and the Canadian Centre for Cybersecurity.

July 8, 2025 p. p. 27
July 8, 2025 Since the cyber incident discovered on April 25, power meters have continued to function and gather accurate energy usage data from homes and businesses across the province. However, due to the cyber incident, the meters have...

AI summary Following a cyber incident, Nova Scotia Power has paused and resumed billing with estimated bills until systems are restored. Meter readers are now visiting homes to collect accurate energy usage data. Customers are advised to expect meter readers wearing branded clothing and identification badges.

Cybersecurity Incident NSEB IR-01 Attachment 4 Page 2 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 27
Cybersecurity Incident NSEB IR-01 Attachment 4 Page 2 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED) NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025)

AI summary This document provides updates on a cybersecurity incident involving NS Power, with information sourced from website excerpts dated September 5, 2025. The content is redacted due to the inclusion of confidential information.

Wednesday, June 25, 2025 Update p. p. 27
Wednesday, June 25, 2025 Update A dedicated team within Nova Scotia Power, along with third-party cybersecurity experts, are continuing the investigation into the recent ransomware attack that has impacted our customers and our company. To...

AI summary Nova Scotia Power is updating customers about a ransomware attack that impacted personal data, including that of former customers. The company is offering five years of free credit monitoring to all customers and is investigating the full scope of data affected.

Cybersecurity Incident NSEB IR-01 Attachment 4 Page 3 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 27
Cybersecurity Incident NSEB IR-01 Attachment 4 Page 3 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED)

AI summary The document is a redacted attachment related to a cybersecurity incident under the Nova Scotia Energy Board (NSEB) proceeding. It contains confidential information and does not provide specific details about the incident or its implications.

NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) p. p. 27
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) We are focused on supporting our customers. We are here for regular business from 8 AM–6 PM, Monday through Friday. Please contact us at [1-800-428-6230](tel:1-800-42...

AI summary Nova Scotia Power is addressing a cyber incident by providing customer support, removing SINs from systems, and cooperating with investigations. They are also offering resources to help customers protect themselves from identity theft and are committed to restoring customer confidence.

NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) p. p. 27
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025)

AI summary This document provides updates on a recent cyber incident affecting NS Power, including actions taken by the Canadian Centre for Cybersecurity (CCCS) and the Royal Canadian Mounted Police (RCMP). It outlines the ongoing investigation and steps being taken to secure systems.

Wednesday, June 4, 2025 Update p. p. 27
Wednesday, June 4, 2025 Update Following the recent ransomware attack and its effect on our customers, we've been invited to speak with members of the Nova Scotia Public Accounts Committee at their meeting today. While recognizing that the...

AI summary Nova Scotia Power (NSP) is addressing a recent ransomware attack impacting customers and is participating in a meeting with the Nova Scotia Public Accounts Committee. NSP expressed transparency and apologized for the incident, emphasizing ongoing investigations and collaboration with cybersecurity experts and law enforcement.

NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) p. p. 27
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) The privacy commissioner of Canada stated last week that: "Data breaches have surged over the past decade, and this incident highlights the growing risks of cyberatta...

AI summary NS Power discusses a recent cyber incident, emphasizing their commitment to cybersecurity and compliance with standards. They highlight their response measures and ongoing investigation into the breach, which affected customer data. No ransom was paid to the attackers.

NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) p. p. 27
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) I am also encouraging all impacted customers to sign up for complimentary credit monitoring and identity protection services. We have updated our [website](https://ww...

AI summary Nova Scotia Power (NSP) is providing credit monitoring and identity protection services to impacted customers following a cyber incident. NSP is cooperating with the Nova Scotia Energy Board and the Office of the Privacy Commissioner of Canada in the investigation. In-person support will be available for customers who need assistance. The President & CEO, Peter Gregg, assures continued transparency and efforts to restore services.

Cybersecurity Incident NSEB IR-01 Attachment 4 Page 7 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 27
Cybersecurity Incident NSEB IR-01 Attachment 4 Page 7 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED)

AI summary This document is a redacted page from a cybersecurity incident report related to Nova Scotia Energy Board (NSEB) IR-01. It contains confidential information and is part of an attachment to the incident report.

NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) p. p. 27
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025)

AI summary This document provides updates on a cyber incident affecting NS Power, including actions taken by the Canadian Centre for Cybersecurity, RCMP, and Nova Scotia Energy Board.

Friday, May 23, 2025 Update p. p. 27
Friday, May 23, 2025 Update We wanted to provide an update on Nova Scotia Power's ongoing cyber incident. Today, we are confirming we have been the victim of a sophisticated ransomware attack. Since the incident began several weeks ago, No...

AI summary Nova Scotia Power has been the victim of a sophisticated ransomware attack. They have not paid the threat actor and are working with cybersecurity experts to restore systems and assess the impact. Affected customers have been notified and provided with free credit monitoring services.

Wednesday, May 14, 2025 Update p. p. 27
Wednesday, May 14, 2025 Update Nova Scotia Power continues to investigate a cyber incident that has impacted certain IT systems in our network. We are working with external cybersecurity experts to determine the scope of the impact and saf...

AI summary Nova Scotia Power is investigating a cyber incident that occurred on or around March 19, 2025, which resulted in unauthorized access to customer information stored on impacted servers. Notifications are being sent to affected customers, and a free two-year credit monitoring service is being provided through TransUnion. Customers are advised to be cautious of unsolicited communications.

Cybersecurity Incident NSEB IR-01 Attachment 4 Page 9 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 27
Cybersecurity Incident NSEB IR-01 Attachment 4 Page 9 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED) NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) Any customer who receives a letter in the mail from Nova Scoti...

AI summary Nova Scotia Power is providing customers who receive mail letters with a phone number to contact for questions and to activate a two-year credit monitoring subscription following a cybersecurity incident.

Cybersecurity Incident NSEB IR-01 Attachment 4 Page 10 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 27
Cybersecurity Incident NSEB IR-01 Attachment 4 Page 10 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED) NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025)

AI summary This document provides updates from NS Power regarding a cybersecurity incident, as reported on their website on September 5, 2025. The content is redacted, indicating that it contains confidential information.

Thursday, May 1, 2025 Update p. p. 27
Thursday, May 1, 2025 Update Nova Scotia Power is providing important information about the recent cyber incident affecting our company. On April 25, we detected unusual activity on our network and immediately initiated our incident respon...

AI summary Nova Scotia Power has experienced a cyber incident where unauthorized access occurred, potentially compromising customer personal information. The company has initiated an investigation with external cybersecurity experts and notified law enforcement. No disruption to operations has been reported, and customers are advised to remain cautious of unsolicited communications.

Cybersecurity Incident NSEB IR-01 Attachment 4 Page 11 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 27
Cybersecurity Incident NSEB IR-01 Attachment 4 Page 11 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED) NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025)

AI summary This document provides updates on a cybersecurity incident involving NS Power, with excerpts from their website as of September 5, 2025. It highlights the ongoing efforts and responses to the incident, though specific details are redacted due to confidentiality.

Monday, April 28, 2025 Update p. p. 27
Monday, April 28, 2025 Update Emera Inc. and Nova Scotia Power today announced on April 25, 2025 they discovered and are actively responding to a cybersecurity incident involving unauthorized access into certain parts of its Canadian netwo...

AI summary Emera Inc. and Nova Scotia Power disclosed a cybersecurity incident involving unauthorized access to parts of their Canadian network. They have activated response protocols, engaged cybersecurity experts, and isolated affected servers. Operations in Nova Scotia remain unaffected, and there is no expected material financial impact.

July 8, 2025 p. p. 27
July 8, 2025 - Power meters have continued to function and gather accurate energy usage data from homes and businesses across the province. However, due to the cyber incident, the meters have not been able to communicate that data to our s...

AI summary Nova Scotia Power has experienced a cyber incident affecting communication from power meters to their systems. Billing was paused and later resumed with estimated bills. Meter readers are now visiting homes to collect accurate energy usage data, and customers may receive estimated bills if access is hindered.

NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) p. p. 27
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) - Those who want to sign up for the credit monitoring service can use our [Customer Verification Form](https://www.nspower.ca/home cyber/customer-verification-form) t...

AI summary NS Power is offering a credit monitoring service to affected customers following a cyber incident. Customers can access the service through a verification form and will not be charged for any related costs. NS Power remains available for regular business during standard hours.

Wednesday, June 5, 2025 p. p. 27
Wednesday, June 5, 2025 - Nova Scotia Power leadership appeared before the Nova Scotia Public Accounts Committee as part of our ongoing commitment to transparency following the recent ransomware attack. - Immediately after detecting the cy...

AI summary Nova Scotia Power addressed a recent ransomware attack before the Public Accounts Committee, outlining their response, including notifying affected customers, offering credit monitoring, and cooperating with investigations. No ransom was paid, and the company is focused on rebuilding trust and enhancing cybersecurity.

Friday, May 23, 2025 p. p. 27
Friday, May 23, 2025 - Nova Scotia Power confirms we been the victim of a sophisticated ransomware attack. - No payment has been made to the threat actor. This decision reflects our careful assessment of applicable sanctions laws and align...

AI summary Nova Scotia Power has confirmed being a victim of a ransomware attack. No payment has been made to the threat actor, and the company is working with cybersecurity experts to assess the impact and restore systems safely.

NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) p. p. 27
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) and investigate the incident. We have also been working to further strengthen our systems and add additional security protections. - Notifications have been mailed to...

AI summary NS Power has been working to strengthen its systems and add additional security protections following a cyber incident. Notifications have been sent to impacted account holders, and a two-year free credit monitoring service has been provided through TransUnion. NS Power expresses regret over the incident and emphasizes the importance of protecting customer information.

Wednesday, May 14, 2025 p. p. 27
Wednesday, May 14, 2025 - Nova Scotia Power continues to investigate a cyber incident that has impacted certain IT systems in our network. - While the investigation remains ongoing, we have determined that on or around March 19, 2025, cert...

AI summary Nova Scotia Power is investigating a cyber incident that occurred on or around March 19, 2025, which led to unauthorized access to customer information. Affected customers are being notified and offered free credit monitoring services from TransUnion.

Thursday, May 1, 2025 p. p. 27
Thursday, May 1, 2025 - We are actively responding to a cyber incident that has impacted certain IT systems in our network. - While our investigation is ongoing, we have identified that certain customer personal information was accessed an...

AI summary Nova Scotia Power is responding to a cyber incident that has compromised certain IT systems, resulting in unauthorized access to customer personal information. The investigation is ongoing.

NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) p. p. 27
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) - If we determine that your data was affected, we will send you notice with further details including about the affected information, along with resources and support...

AI summary NS Power is informing customers about a potential cyber incident and advising them to be cautious of unsolicited communications requesting personal information. Customers affected will be notified with further details and resources.

Monday, April 28, 2025 p. p. 27
Monday, April 28, 2025 - Emera and Nova Scotia Power discovered and are actively responding to a cybersecurity incident involving unauthorized access into certain parts of our network and servers supporting portions of our business applica...

AI summary Emera and Nova Scotia Power have detected a cybersecurity incident involving unauthorized access to parts of their network and servers. They have taken steps to contain the breach and ensure no disruption to physical operations or customer service.

What happened? p. p. 27
What happened? Last updated: Tuesday, June 24, 2025 On April 25, we discovered and began actively responding to a cybersecurity incident involving unauthorized access into certain parts of our network and servers. Upon further investigatio...

AI summary A cybersecurity incident involving unauthorized access to Nova Scotia Power's network and servers was discovered on April 25. A ransomware attack led to the access and exfiltration of customer personal information. No ransom was paid in compliance with legal guidance, and the investigation is ongoing.

What is Nova Scotia Power doing to address this cyber incident? p. p. 27
What is Nova Scotia Power doing to address this cyber incident? Last updated: Tuesday, June 24, 2025 While our investigation remains ongoing, we have taken the following steps: - Engaged third-party cybersecurity experts to help us investi...

AI summary Nova Scotia Power is addressing a cyber incident by engaging third-party cybersecurity experts, notifying law enforcement and regulators, and conducting a detailed review of accessed data. The investigation is ongoing, and it has been confirmed that some customer personal information was taken.

Cybersecurity Incident NSEB IR-01 Attachment 4 Page 17 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 27
Cybersecurity Incident NSEB IR-01 Attachment 4 Page 17 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED)

AI summary This document is a redacted attachment from a cybersecurity incident report related to the Nova Scotia Energy Board. It contains confidential information and does not provide specific details about the incident or its implications.

Was customer information or confidential business information accessed? p. p. 27
Was customer information or confidential business information accessed? Last updated: Tuesday, June 24, 2025 While our investigation is ongoing, we have identified that certain customer personal information was accessed and taken by the th...

AI summary The investigation revealed that customer personal information was accessed and taken by a threat actor, with some data published on the dark web. Impacted customers have been notified and provided with resources and support.

Was my data impacted? p. p. 27
Was my data impacted? Last updated: Wednesday, June 25, 2025 Anyone who received a letter from us did receive information about what personal data may have been impacted in that letter. Our investigation remains ongoing. The ransomware att...

AI summary Nova Scotia Power is investigating the impact of a ransomware attack on customer data. While letters were sent to those affected, specifics remain unclear. The company is offering free credit monitoring to all customers as a precautionary measure.

NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) p. p. 27
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) Last updated: Wednesday, June 25, 2025 Our investigation is ongoing, and we sent letters to customers we determined to have been impacted in the incident. Out of an a...

AI summary NS Power is expanding its offer of five years of free credit monitoring to all current and past customers as part of ongoing efforts to address a cyber incident. The investigation is ongoing, and letters have been sent to impacted customers.

NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) p. p. 27
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) Power—past and present—regardless of whether you received a letter from us about the incident.

AI summary NS Power provides updates regarding a cyber incident, including information for customers who may have received a letter about the incident, as well as those who have not.

Cybersecurity Incident NSEB IR-01 Attachment 4 Page 20 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 27
Cybersecurity Incident NSEB IR-01 Attachment 4 Page 20 of 20 REDACTED (CONFIDENTIAL INFORMATION REMOVED) NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025)

AI summary This document provides updates from NS Power regarding a cybersecurity incident, as reported on their website on September 5, 2025. It is part of a regulatory proceeding and includes redacted confidential information.

Section 139 p. p. 56
Board Inquiry into Nova Scotia Power's Cybersecurity Incident (NSEB M12273) NSPI Responses to NSEB Information Requests

AI summary The document outlines the Nova Scotia Energy Board's inquiry into Nova Scotia Power's cybersecurity incident, along with NSP's responses to information requests from the NSEB.

BOARD CONFIDENTIAL (Attachment Only) p. p. 56
BOARD CONFIDENTIAL (Attachment Only) 1 Request IR-9: 2 3 Does the utility currently have a communication policy in place in case of a cybersecurity 4 breach? 5 6 (a) If yes, please share the policy document. 7 (b) If not, why not. 8 9 Resp...

AI summary The utility, NS Power, confirms it has a 'Cyber Incident Communication Playbook' in place to address cybersecurity breaches. The document outlining this policy is included as a confidential attachment.

N-3Incident Report - Redacted (N-3 from M12273) 10 passages
Board Inquiry into Nova Scotia Power's Cybersecurity Incident p. p. 2
Board Inquiry into Nova Scotia Power's Cybersecurity Incident Nova Scotia Power Incident Report December 22, 2025 REDACTED

AI summary The document outlines a Board Inquiry into a cybersecurity incident involving Nova Scotia Power, with the incident report dated December 22, 2025. The content is partially redacted, limiting the details available.

2025 Nova Scotia Power's Cybersecurity Incident Report REDACTED p. p. 2
2025 Nova Scotia Power's Cybersecurity Incident Report REDACTED 1 TABLE OF CONTENTS 2 3 1.0 INTRO DDUCTION 3 4 2.0 THE IN NCIDENT 7 5 3.0 AFFEC CTED SYSTEMS AND DATA 11 6 3.1 Compromised Systems 11 7 3.2 Data & Personal Information 13 8 4....

AI summary This document outlines the 2025 Nova Scotia Power's Cybersecurity Incident Report, which was requested by the Nova Scotia Energy Board following a cybersecurity incident. The report includes sections on the incident description, affected systems, response actions, impact analysis, and recommendations for improving cybersecurity measures.

Section 5 p. p. 2
26 assess its data handling practices. DATE FILED: December 22, 2025 Page 3 of 43 1 M12273, Board Inquiry into Nova Scotia Power's Cybersecurity Incident, NSEB Letter, July 14, 2025, page 1. 2 M12273, NSEB Letter, July 14, 2025, pp. 2-3. 3...

AI summary The document references a cybersecurity incident involving Nova Scotia Power and an inquiry by the Nova Scotia Energy Board. It includes citations to letters and pages from the inquiry, indicating a regulatory process focused on data handling practices.

2025 Nova Scotia Power's Cybersecurity Incident Report REDACTED p. pp. 2-41
2025 Nova Scotia Power's Cybersecurity Incident Report REDACTED 1 2. In the incident report to be filed by the end of this year, please provide a Gantt chart 2 that includes a list of all the summary tasks/rolled-up tasks currently underta...

AI summary Nova Scotia Power (NSP) is required to submit a detailed cybersecurity incident report, including Gantt charts for system restoration and impacted Board matters. The Premier of Nova Scotia has directed the NSEB to investigate NSP's billing methodology, consumer protections, and potential financial relief for affected customers.

2025 Nova Scotia Power's Cybersecurity Incident Report REDACTED p. pp. 4-39
2025 Nova Scotia Power's Cybersecurity Incident Report REDACTED 1 Matter M12273-Board Inquiry into Nova Scotia Power's Cybersecurity Incident. This would be the most efficient way to address the matter.[7](#page-5-0) 2 3 4 Accordingly, the...

AI summary This document outlines a 2025 cybersecurity incident report by Nova Scotia Power (NSP) under a Board inquiry (M12273). It references a related complaint (M12457) regarding systemic regulatory compliance issues at Blarney Stone Restaurant and a letter from the Nova Scotia Energy Board (NSEB) dated December 10, 2025.

Preamble p. p. 17
- 3 As discussed above, NS Power has been committed to transparency in its communications with - 4 customers and other stakeholders throughout the cyber response to date. This approach has focused - 5 on the importance of sharing known inf...

AI summary Nova Scotia Power has emphasized transparency in its communication with customers and stakeholders during the cyber incident, evolving its approach based on new information, customer feedback, and system restoration. The company has used various channels, including in-person sessions and radio ads, to reach customers and provide updates on billing and credit monitoring.

25 4.3 Other Stakeholders p. pp. 17-24
25 4.3 Other Stakeholders 26 - 27 NS Power employees have been a key stakeholder audience throughout the Incident, as they were - 28 impacted as employees and as customers. Employees have received ongoing communications in - 29 the form of...

AI summary This section discusses the involvement of NS Power employees as key stakeholders during a cyber incident, highlighting their dual role as employees and customers, and the communication efforts made to keep them informed.

NS Power Cyber Incident Report Appendix A Page 1 of 2 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 41
NS Power Cyber Incident Report Appendix A Page 1 of 2 REDACTED (CONFIDENTIAL INFORMATION REMOVED)

AI summary The document is a redacted appendix from a cyber incident report by NS Power, indicating that confidential information has been removed. It does not provide specific details about the incident or its implications.

PROGRAM STRUCTURE p. p. 41
PROGRAM STRUCTURE The Restoration Program is structured into five (5) key portfolios of work – focusing on restoring business capabilities. Portfolio Scope Summary Enterprise Resource Planning (ERP) Recovery and restoration of core enterpr...

AI summary The Restoration Program is structured into five portfolios: Enterprise Resource Planning, Customer, Additional Capabilities, Cybersecurity, and Technology Enablement, each aimed at restoring critical business operations and systems.

NS Power Cyber Incident Report Appendix B Page 1 of 7 p. p. 44
NS Power Cyber Incident Report Appendix B Page 1 of 7 Affected Regulatory Matters Report 2 - October 1 Report 3 - November 3 Report 4 - December 1 Latest update Forecast Restoration of Normal Activities Rates-Rela ted Matters

AI summary The document is an appendix from a cyber incident report by NS Power, outlining affected regulatory matters. It includes a table with reports dated October 1, November 3, and December 1, along with a forecast for the restoration of normal activities.

N-4NSPI (NSEB) RIR 13 to 15 (N-4 from M12273) 3 passages
Preamble
(i) Please refer to part (c). (ii) NS Power does not have readily available the specific breakdown requested; however, nearing eight months since the cyber incident, residential customers have received an average of 4 bills with half being...

AI summary NS Power does not have the specific breakdown requested but notes that residential customers have received an average of 4 bills since the cyber incident, with half being estimated. The request is referred to part (c).

Section 14
Request IR-16: Since becoming aware of the cyber incident, has NS Power deployed additional resources specifically to assist with the estimated billing process, including responses to customer complaints about estimated bills? Response IR-...

AI summary NS Power has deployed additional resources, including new hires and temporary meter reading staff, to assist with the estimated billing process and manage customer complaints following a cyber incident. They have also leveraged external contact centres and internal employees to handle increased call volumes and provide support to customers.

NON-CONFIDENTIAL
NON-CONFIDENTIAL Finally, employees in Customer Care and Billing, like many areas across NS Power, have worked extra hours to demonstrate their commitment to supporting customers since the cyber incident. Date Filed: December 23, 2025 NSPI...

AI summary NS Power employees in Customer Care and Billing have worked extra hours to support customers following a cyber incident, demonstrating commitment to service continuity. The document references a filing dated December 23, 2025, related to matter IR-16.

N-5Proof of Advertisement 6 passages
NOVA SCOTIA ENERGY BOARD NOTICE OF PUBLIC HEARING p. p. 0
NOVA SCOTIA ENERGY BOARD NOTICE OF PUBLIC HEARING S E E H O S T I N G O N A 4 IN THE MATTER OF AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer information, customer...

AI summary The Nova Scotia Energy Board is holding a public hearing to examine the impact of a cyber incident on Nova Scotia Power Incorporated's handling of customer information, billing processes, and regulatory matters. The hearing will take place from July 27 to July 29, 2026, and interested parties can participate by submitting written comments or requesting formal standing as intervenors.

NOVA SCOTIA ENERGY BOARD NOTICE OF PUBLIC HEARING p. p. 1
NOVA SCOTIA ENERGY BOARD NOTICE OF PUBLIC HEARING IN THE MATTER OF AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer information, customer service and communications,...

AI summary The Nova Scotia Energy Board is holding a public hearing to investigate the impact of a cyber incident on Nova Scotia Power Incorporated's handling of customer information, service, billing, and regulatory matters. The hearing is scheduled for July 27-29, 2026, and the public can participate by listening online, submitting written comments, or requesting intervenor status.

NOVA SCOTIA ENERGY BOARD NOTICE OF PUBLIC HEARING p. p. 2
NOVA SCOTIA ENERGY BOARD NOTICE OF PUBLIC HEARING IN THE MATTER OF AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer information, customer service and communications,...

AI summary The Nova Scotia Energy Board is conducting a public hearing to examine the impact of a cyber incident on Nova Scotia Power's handling of customer information, service, billing, and regulatory matters. The hearing will take place in July 2026, with details on participation and submission of evidence provided.

NOVA SCOTIA ENERGY BOARD NOTICE OF PUBLIC HEARING p. p. 3
NOVA SCOTIA ENERGY BOARD NOTICE OF PUBLIC HEARING IN THE MATTER OF AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer information, customer service and communications,...

AI summary The Nova Scotia Energy Board is conducting a public hearing to investigate the impact of a cyber incident on Nova Scotia Power's handling of customer data, billing processes, and regulatory matters. The hearing will take place from July 27 to 29, 2026, in Halifax, with opportunities for public participation and submission of comments.

NOVA SCOTIA ENERGY BOARD NOTICE OF PUBLIC HEARING p. p. 4
NOVA SCOTIA ENERGY BOARD NOTICE OF PUBLIC HEARING IN THE MATTER OF AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer information, customer service and communications,...

AI summary The Nova Scotia Energy Board is conducting a public hearing to investigate the impact of a cyber incident on Nova Scotia Power's handling of customer information, billing processes, and regulatory matters. The hearing will take place from July 27 to July 29, 2026, with opportunities for public participation and submission of written comments.

NOVA SCOTIA ENERGY BOARD NOTICE OF PUBLIC HEARING p. p. 5
NOVA SCOTIA ENERGY BOARD NOTICE OF PUBLIC HEARING IN THE MATTER OF AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer information, customer service and communications,...

AI summary The Nova Scotia Energy Board is holding a public hearing to investigate the impact of a cyber incident on Nova Scotia Power's handling of customer information, customer service, billing processes, and regulatory matters. The hearing will take place from July 27 to July 29, 2026, and the public is invited to participate through various means.

N-6NSPI (CA) RIR 1-11 - Redacted 5 passages
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to Consumer Advocate Information Requests
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to Consumer Advocate Information Requests 1 Request IR-1: 2 3 Cyber Security Program Effectiveness 4 5 Reference: Exhibit N-3 - 2025 Nova Scotia Power's...

AI summary The document outlines Nova Scotia Power Inc.'s (NSPI) cybersecurity training program, including mandatory quarterly training and monthly phishing simulations for all employees. It also requests data on training results and standards for the period ending March 2025, referencing Exhibit N-3 from NSPI's 2025 cybersecurity incident report.

NON-CONFIDENTIAL
NON-CONFIDENTIAL 1 (e) Please provide a summary of the number and types of cyber incidents NSPI recorded 2 in the last 5 years? What improvements have been made to systems and practices as 3 a result of these events. 4 5 Response IR-1: 6 7...

AI summary The response outlines NSPI's cybersecurity training completion rates and phishing failure rates over the past year. NSPI requires all eligible employees to complete mandatory quarterly cybersecurity training, with high completion rates observed. Phishing simulations show varying failure rates across months, with a notable increase in March 2025.

NON-CONFIDENTIAL
NON-CONFIDENTIAL 1 Request IR-3: 2 3 Customer Data Retention 4 5 Reference: Exhibit N-3 - 2025 Nova Scotia Power's Cybersecurity Incident Report, Page 40, 6 ll. 10-24 7 8 Quote: 9 10 With respect to the collection and retention of customer...

AI summary The document discusses NSPI's process of collecting and purging customer social insurance numbers (SINs). It notes that SINs were collected until 2018, but were removed from systems by 2024. The request asks NSPI to confirm that all SINs have been purged from their systems.

CONFIDENTIAL (Attachment Only)
CONFIDENTIAL (Attachment Only) 1 Request IR-6: 2 3 Treatment of Incident Costs 4 5 Reference: Exhibit N-3 - 2025 Nova Scotia Power's Cybersecurity Incident Report, Page 14, 6 ll 18-25 7 8 Quote: 9 10 11 12 13 14 15 16 17 18 Immediately fol...

AI summary The document requests Nova Scotia Power Inc. (NSPI) to quantify the costs incurred and forecast remaining costs related to a cybersecurity incident, explain how these costs are being isolated from ratepayers, and discuss the impact of staff reassignments on operations and customer service.

CONFIDENTIAL (Attachmen Only)
CONFIDENTIAL (Attachmen Only) 1 (c) When NS Power lost the ability to communicate with the Advanced Metering 2 Infrastructure (AMI) network through the cyber incident, bill estimation logic reverted to 3 a contingency CIS subroutine which...

AI summary This text discusses how NS Power estimated missing meter readings during a cyber incident using seasonal logic, and how refunds are handled for overpayments. It also notes a decrease in refund requests over recent quarters. The cybersecurity accountability document is confidential and removed.

N-7NSPI (David MacLeod) RIRs C-4 to E-2 2 passages
1 Request IR C-4: p. p. 3
1 Request IR C-4: 2 3 (a) Provide a complete timeline of NSP's notifications to regulatory and law 4 enforcement bodies following discovery of the Attack, including: 5 6 (i) notification to the NSEB / UARB; 7 8 (ii) notification to the Off...

AI summary The document requests a timeline of NSP's notifications to regulatory and law enforcement bodies following a cyber attack, and details on NSP's data inventory and retention practices. NSP responded by referencing sections of the Incident Report and existing information requests for data inventory details.

p. p. 3
1 Request IR D-2: 2 3 (a) Describe the technical and organizational controls applied to protect customer 4 personal information prior to March 19, 2025, including: 5 6 (i) encryption of personal information at rest and in transit; 7 8 (ii)...

AI summary The text outlines information requests related to cybersecurity and privacy practices of Nova Scotia Power (NSP) prior to an incident, including technical and organizational controls, responses to ransomware threats, and privacy impact assessments. It also includes requests for details on the personal information stolen in an attack and steps taken to address the breach.

N-8NSPI (DOE) RIRs 1-10 5 passages
1 Request IR-01: p. p. 9
1 Request IR-01: 2 3 4 5 6 For customers on Time-of-Use (TOU) or Net-Metering rates whose data was lost or estimated, please provide the specific methodology used to determine the "peak" versus "off-peak" consumption during the period of s...

AI summary The document outlines responses to three requests regarding billing methodologies during system unavailability, manual field interventions for demand resets, and customer-reported fraud incidents. It explains that TOU rates did not bill peak consumption during the period of system unavailability and that no costs were incurred for manual demand resets. No fraud or identity theft incidents have been reported since April 2025.

1 Request IR-05: p. p. 9
1 Request IR-05: 2 3 Please provide a table listing every regulatory filing or milestone from April 2025 to the 4 present that required an extension or was filed with "data limitations," including the specific 5 date the utility expects to...

AI summary The document includes several requests and responses related to regulatory filings, labor costs, and payment holds. It addresses data limitations, overtime costs due to a cyber incident, and payment holds related to vegetation management and grid reliability.

Why is this happening? p. pp. 10-12
Why is this happening? Our systems were impacted by the cyber incident cyber incident earlier this year and we are still working to restore them safely and securely. While meters have continued to accurately record energy use they are unab...

AI summary A cyber incident earlier this year has impacted Nova Scotia Power's systems, preventing meters from sending energy usage data to billing systems. This affects billing during peak times and has caused the MyEnergy Insights tool to be unavailable.

Why is this happening? p. p. 11
Why is this happening? Our systems were impacted by the cyber incident cyber incident earlier this year and we are still working to restore them safely and securely. While meters have continued to accurately record energy use they are unab...

AI summary A cyber incident earlier this year has impacted Nova Scotia Power's systems, preventing meters from sending energy usage data to billing systems. This affects billing during peak times and has caused the MyEnergy Insights tool to be unavailable.

Why is this happening? p. p. 14
Why is this happening? Our systems were impacted by the cyber incident earlier this year and we are still working to restore them safely and securely. While meters have continued to accurately record energy use they are unable to send that...

AI summary A cyber incident earlier this year has impacted Nova Scotia Power's systems, preventing meters from sending energy use data to billing systems. This affects billing during peak times and has caused the MyEnergy Insights tool to be unavailable.

N-9NSPI (INQ Law) RIRs 1-7 3 passages
Section 2
below). For 2025, approximately 79% of assigned training was completed, though the schedule for completion of these processes was disrupted due to the Incident. As noted above, since the Incident, NS Power has taken steps to enhance its ex...

AI summary NS Power has completed 79% of assigned privacy training for 2025, though the schedule was disrupted by an incident. Since the incident, NS Power has increased training frequency to quarterly and achieved 100% completion for the first quarter of 2026. Procedures for reporting and responding to privacy breaches and cyber incidents have been established and provided as confidential attachments.

1 Request IR-2:
1 Request IR-2: 2 3 With respect to governance and risk management processes addressing privacy risks, please 4 provide the following documentation or information, as applicable. If any of the documents 5 or information is not available, p...

AI summary The document requests information on Nova Scotia Power's privacy governance and risk management processes, including policies, procedures, and audit plans related to data collection, consent management, and privacy officers. A response indicates that relevant materials have been provided as confidential attachments.

30
30 1 (g) NS Power did not conduct a formal audit of access to personal data of customers in the 2 2 years leading up to the incident. NS Power prohibits employees from accessing personal 3 information of customers without a legitimate busi...

AI summary The document discusses NS Power's lack of a formal audit of customer data access in the two years prior to an incident. It outlines NS Power's policies on employee access to personal information and procedures for reporting unauthorized access. The request also includes inquiries about NS Power's awareness date of a cybersecurity incident.

N-10NSPI (NSEB) RIRs 1-25 - Redacted 10 passages
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to NSEB Information Requests p. pp. 3-16
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to NSEB Information Requests 1 Request IR-1: 2 3 In response to the Board's IR-13 and IR-14 (Exhibit N-4), the utility provided the following 4 response...

AI summary The document outlines the Minister of Energy's accountability process for Nova Scotia Power (NSEB M12600) and NSPI's responses to information requests regarding the CIS subroutine used during a cybersecurity incident. The focus is on how the CIS subroutine estimates energy usage when actual meter readings are unavailable and the validation and testing of the subroutine.

CONFIDENTIAL (Attachment Only) p. p. 16
CONFIDENTIAL (Attachment Only) 1 Request IR-9: 2 3 Please provide specific and detailed information addressing whether all or any part of the 4 information about current NS Power customers was available in NS Power's systems to be 5 stolen...

AI summary The document addresses a request for information regarding the availability of customer data in NS Power's systems during a cyber attack. It references NS Power's documented privacy policies aligned with PIPEDA and mentions an Incident Report filed with the NSEB on December 22, 2025.

Preamble p. p. 16
Cybersecurity Accountability NSEB IR-9 Attachment 2 has been removed due to confidentiality. Cybersecurity Accountability NSEB IR-9 Attachment 3 has been removed due to confidentiality. Cybersecurity Accountability NSEB IR-9 Attachment 4 h...

AI summary The document mentions that multiple attachments related to Cybersecurity Accountability under NSEB IR-9 have been removed due to confidentiality. These attachments are part of a regulatory proceeding involving Nova Scotia Energy Board (NSEB).

Cybersecurity Accountability NSEB IR-9 Attachment 13 Page 1 of 8 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 16
Cybersecurity Accountability NSEB IR-9 Attachment 13 Page 1 of 8 REDACTED (CONFIDENTIAL INFORMATION REMOVED)

AI summary The document is a redacted attachment related to cybersecurity accountability under the Nova Scotia Energy Board (NSEB) IR-9 proceeding. It contains confidential information and is part of a regulatory proceeding involving Nova Scotia Power Inc. (NSPI).

Cybersecurity Accountability NSEB IR-9 Attachment 13 Page 2 of 8 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 16
Cybersecurity Accountability NSEB IR-9 Attachment 13 Page 2 of 8 REDACTED (CONFIDENTIAL INFORMATION REMOVED) - 2 - When you correspond with us by email, we collect your email address, internet IP address, as well as the message included in...

AI summary The document outlines how Nova Scotia Power collects and uses personal information through email and website interactions for purposes such as providing services, managing operations, and ensuring cybersecurity. It also mentions the use of cookies for authentication and analysis.

Cybersecurity Accountability NSEB IR-9 Attachment 13 Page 5 of 8 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 16
Cybersecurity Accountability NSEB IR-9 Attachment 13 Page 5 of 8 REDACTED (CONFIDENTIAL INFORMATION REMOVED) - 5 -

AI summary This document is a redacted page from a cybersecurity accountability proceeding related to Nova Scotia Power and the Nova Scotia Energy Board. The content is confidential and has been removed.

Cybersecurity Accountability NSEB IR-9 Attachment 13 Page 6 of 8 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 16
Cybersecurity Accountability NSEB IR-9 Attachment 13 Page 6 of 8 REDACTED (CONFIDENTIAL INFORMATION REMOVED) - 6 - The information collected by these cookies is anonymous and they do not collect any information that can identify you person...

AI summary The document discusses the use of cookies on Nova Scotia Power's website, including how they collect anonymous data and respect user privacy settings. It highlights that Hotjar's recordings are used to improve site usability and are not shared outside of Nova Scotia Power.

2. Details of Complaint p. p. 16
2. Details of Complaint Please describe the events or circumstances that led to your complaint. Include details such as the names or positions of people involved in the incident, the location(s) where the incident occurred, date and time o...

AI summary The section outlines the details required for a complaint, including events, people involved, locations, dates, and information types. Several attachments related to cybersecurity accountability have been removed due to confidentiality.

NON-CONFIDENTIAL p. p. 16
NON-CONFIDENTIAL Request IR-13: 2 Please provide any memos, assessments, reports or email messages prepared on or after April 25, 2025, discussing how customers would be advised about the cybersecurity breach and the theft of their persona...

AI summary NS Power responded to a request regarding how customers would be informed about a cybersecurity breach and the theft of personal information. They referenced existing documents, including an Incident Report and a Cyber Incident Communication Playbook, outlining their approach to transparency and timely communication.

1 p. p. 16
1 Cyber Calls Handled by TransUnion Calls Offered Average Time in Queue Average Handle Time Total 10,958 0:01:29 0:06:10 May 7,018 0:02:11 0:06:16 June 3,097 0:00:10 0:05:57 July 399 0:00:24 0:06:14 August 155 0:00:26 0:05:55 September 202...

AI summary The document discusses the response by Nova Scotia Power (NSPI) to information requests regarding a cyber incident affecting former customers. NSPI determined that approximately 540,000 former customers were impacted, following a complex investigation with third-party experts.

N-11NSPI (SBA) RIRs 1-20 - Redacted 6 passages
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to Small Business Advocate Information Requests
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to Small Business Advocate Information Requests 1 Request IR-01: 2 3 Please refer to M12600, Exhibit N-3, Nova Scotia Power Incident Report - Redacted,...

AI summary The document outlines responses from Nova Scotia Power (NS Power) to information requests regarding a cyber incident discovered on April 25, 2025. NS Power confirmed prior outages but clarified they were unrelated to the cyber incident. Multiple employees reported the issue, and all IT applications except Customer Information Systems were impacted.

BOARD CONFIDENTIAL (Attachment Only)
BOARD CONFIDENTIAL (Attachment Only) 1 Request IR-08: 2 3 Please refer to the Report, Page 17, Lines 26-20: 4 5 In relation to NS Power's operational program, NS Power's core 6 energy operations are designed to comply with other industry-s...

AI summary The document discusses a request and response regarding NERC audits of NS Power's cybersecurity and IT operations. The most recent audit began in December 2024 and was extended due to a cyber-attack, with the final report issued in January 2026. The report is confidential and marked as non-public.

NON-CONFIDENTIAL
NON-CONFIDENTIAL 1 provide details and when the changes were implemented or, if not yet implemented, 2 when they are expected to be implemented. 3 4 Response IR-09: 5 6 (a) Mandatory quarterly cyber training is delivered through our cybers...

AI summary Nova Scotia Power Inc. (NSPI) provides details on its mandatory cybersecurity training program, including quarterly training, phishing simulations, and participation rates. Training is delivered through the KnowBe4 platform and includes onboarding, remedial training, and tracking of quiz results. Participation rates are consistently high, with 98-100% participation.

16 Phishing simulation failure statistics at NSPI for the past 3 years are as follows:
16 Phishing simulation failure statistics at NSPI for the past 3 years are as follows: Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec 2023 2.8% 1.3% 2.3% 1.1% 4.3% 4.9% 2.3% 1.7% 11.0% 2024 0.4% 17.7% 1.7% 3.7% 1.1% 2.5% 4.7% 0.2% 0.5% 0....

AI summary The document provides phishing simulation failure statistics for NSPI over the past three years, highlighting varying rates of failure across different months and years. The data shows fluctuations in failure percentages, with some months having significantly higher rates than others.

REDACTED
REDACTED 1 Request IR-17: 4 dated March 18, 2026 (https://www.priv.gc.ca/en/opc-actions-and 5 decisions/investigations/investigations-into-businesses/2026/2026-ns-power-ca/) (the "OPC 6 Compliance Letter"), Breach Timeline: 7 8 9 10 11 12...

AI summary The document outlines a cybersecurity incident involving Nova Scotia Power, where a threat actor gained domain administrator privileges and deployed malware between April 8 and 22, 2025. The OPC Compliance Letter and Incident Report are referenced, and questions are raised about existing protections, detection mechanisms, and steps taken to prevent future incidents.

REDACTED
REDACTED - 1 "proof" provided by the threat actor referenced in the Compliance Letter). This file tree list - 2 contained directories of data, which included customer information. - 3 On May 22, 2025, NS Power became aware that the threat...

AI summary NS Power became aware of a data breach on May 22, 2025, when a threat actor published data on the dark web. NS Power informed customers through various channels and has not found evidence of misuse of the data. The OPC Compliance Letter indicates no data has been made public or sold.

N-12NSPI (David MacLeod) RIR A-6 & RIR B-4, 1 passage
NON-CONFIDENTIAL
NON-CONFIDENTIAL 1 Request IR A-6: 2 3 (a) NSP's Chief Operating Officer filed a report titled IT – OT Cyber Security Control 4 Implementation Phase 1 with the UARB on February 27, 2025, twenty days before the 5 Attack. With respect to tha...

AI summary The document discusses a cybersecurity control implementation plan filed by NSP's Chief Operating Officer with the UARB in 2025, twenty days before a cyber attack. The plan focused on OT systems and not IT systems, customer data systems, billing platforms, or AMI infrastructure. The IT systems were covered under a separate plan started in 2021. The scope of the OT plan was defined by Deloitte LLP and approved by NS Power's Director of Information Security and Risk Management.

N-13Evidence - InterGroup, on behalf of CA - Redacted 11 passages
In the Matter of p. p. 0
In the Matter of EVIDENCE OF ED MOLLARD M12600 JUNE 23, 2026 Nova Scotia Power Incorporated (NSPI) AN INQUIRY ABOUT THE IMPACT OF THE CYBER INCIDENT ON NSPI'S COLLECTION AND RETENTION OF CUSTOMER INFORMATION, CUSTOMER SERVICE AND COMMUNICA...

AI summary This document is pre-filed testimony from Ed Mollard on behalf of the Consumer Advocate regarding the impact of a cyber incident on NSPI's customer information management, customer service, billing processes, and regulatory matters. The testimony was submitted to the Nova Scotia Energy Board.

Preamble p. p. 2
This testimony has been prepared for the Consumer Advocate ("CA") by or under the direction of Ed Mollard of InterGroup Consultants Ltd. ("InterGroup"). This report reviews the Nova Scotia Power ("NSP", "NSPI", "NS Power") Cybersecurity In...

AI summary This testimony, prepared by Ed Mollard of InterGroup Consultants Ltd. for the Consumer Advocate, reviews a cybersecurity incident at Nova Scotia Power. Mollard outlines his qualifications, the scope of his review, and his commitment to providing fair and objective evidence to the Nova Scotia Energy Board.

2.0 SUMMARY OF RECOMMENDATIONS p. pp. 2-3
2.0 SUMMARY OF RECOMMENDATIONS Based on the analysis summarized in this report, InterGroup makes the following recommendations to the Board: - Recommendation 1: InterGroup recommends NSPI be directed to update its staff training policies a...

AI summary InterGroup recommends several measures to NSP and NSPI, including updating staff training policies, enhancing privacy practices, conducting compliance audits, improving customer notifications, and managing credit monitoring services. These recommendations aim to improve cybersecurity, privacy, and customer communication following a data breach incident.

3.0 OVERVIEW OF INCIDENT p. pp. 3-7
3.0 OVERVIEW OF INCIDENT The NSPI Incident Report 1 dated December 22, 2025, states that on or around March 19, 2025 a Nova Scotia Power employee visited a website and clicked on a pop-up link which resulted in malware being downloaded and...

AI summary A cybersecurity incident occurred at Nova Scotia Power on March 19, 2025, when an employee clicked on a malicious link, leading to malware installation. The breach was discovered on April 25, 2025, and affected ERP systems, billing systems, and customer data, including personal information. The threat actor did not access operational systems, and the company has taken steps to address the incident.

4.0 CYBERSECURITY AWARENESS TRAINING p. pp. 7-10
4.0 CYBERSECURITY AWARENESS TRAINING NS Power indicates at the time of the incident, its approach to privacy compliance was documented through its privacy policies and procedures.[13](#page-8-1) We understand that NSP maintains thirteen (1...

AI summary The document discusses NSP's cybersecurity awareness training program, including its mandatory quarterly training, monthly phishing simulations, and privacy policies. NSP reports high completion rates for training and outlines its phishing failure rate targets.

5.0 COLLECTION AND RETENTION OF CUSTOMER INFORMATION p. pp. 10-11
5.0 COLLECTION AND RETENTION OF CUSTOMER INFORMATION NS Power's cybersecurity incident investigations showed that certain personal customer information for both current and former customers was exfiltrated from the system. Depending on the...

AI summary NS Power experienced a cybersecurity incident resulting in the exfiltration of personal customer information. The document discusses NS Power's data collection and retention practices, referencing PIPEDA and noting issues revealed by the incident. InterGroup highlights the requirement for clear purposes in data collection and consent for new uses.

5.2 FORMER CUSTOMER DATA p. p. 12
5.2 FORMER CUSTOMER DATA NS Power retained personal information relating to former customers within its CIS system and these were also impacted by the cybersecurity breach. NSP states approximately 540,000 former customers were affected by...

AI summary NS Power retained personal information of approximately 540,000 former customers, which were impacted by a cybersecurity breach. The company's policy on data retention and disposal is unclear, despite information requests. NSP's privacy policy mentions varying retention periods based on product/service and legal needs, but specific timelines are not provided. Emera's records management policies are referenced but lack detailed data retention timelines.

6.0 STAKEHOLDER COMMUNICATION p. pp. 14-15
6.0 STAKEHOLDER COMMUNICATION NS Power states that its incident response and business continuity processes were activated following the detection of the Cybersecurity breach.[40](#page-15-2) NS Power notified relevant law enforcement agenc...

AI summary NS Power activated its incident response and business continuity processes after a cybersecurity breach was detected. It notified law enforcement agencies and the OPC, and implemented a multi-channel communication approach, including public postings, direct notices to impacted customers, and updates through various platforms.

6.1 TIMING OF INCIDENT DETECTION AND INITIAL CUSTOMER NOTIFICATION p. pp. 15-16
6.1 TIMING OF INCIDENT DETECTION AND INITIAL CUSTOMER NOTIFICATION NS Power discovered the incident on April 25, 2025, over a month after the breach first occurred (March 19, 2025) and subsequently issued a public notice on April 28, 2025....

AI summary NS Power discovered a cybersecurity breach on April 25, 2025, over a month after it occurred on March 19, 2025, and issued a public notice 39 days later. This delay led to customer trust loss, complaints, and service disruptions. NS Power attributes the delay to limitations in its security detection systems. The NSEB is reviewing cybersecurity improvements as part of Proceeding M12273.

6.3 COMMUNICATION TO FORMER CUSTOMERS p. pp. 17-18
6.3 COMMUNICATION TO FORMER CUSTOMERS NS Power determined that personal information of former customers was also impacted by the breach and provided a public notification on June 25, 2025.[59](#page-18-1) With respect to communication to i...

AI summary NS Power notified the public about a data breach affecting former customers but did not directly contact them due to lack of updated contact information. A recommendation is made for NSP to explore ways to reach former customers who may have relocated outside the province.

9.0 INCIDENT COST TREATMENT p. pp. 23-25
9.0 INCIDENT COST TREATMENT NSP notes it activated its incident response and business continuity protocols, engaging both internal and external experts to support efforts on containment, eradication and remediation of the threat.[84](#page...

AI summary NSP has incurred costs related to a security breach and is isolating these costs through separate project codes. While some costs, such as credit monitoring, may be covered by insurance, it is unclear whether other costs will be passed on to customers. Recommendations suggest that NSP should not recover these costs from customers and isolate future insurance premium increases related to the incident.

N-14Evidence & Appendix A Resume - Tricia Ralph INQ Law/Consulting - BCC 11 passages
Preamble p. p. 2
- 1. In my opinion, the following met best practice, and were reasonable in terms of expectations for customer service and limiting the impacts of the cybersecurity attack on customers: - Aside from issues related to the personal informati...

AI summary The text evaluates Nova Scotia Power Incorporated's (NSPI) response to a cybersecurity attack, finding some actions reasonable and others unreasonable. Key points include the reasonableness of customer notification timelines and communication efforts, while the use of a PI inventory, retention of SINs, and insufficient customer notices were deemed unreasonable.

B. Introduction p. pp. 2-3
B. Introduction - 1. I have been retained by Counsel for the Nova Scotia Energy Board ("NSEB") to carry out a review of NSPI's privacy related practices in relation to the cybersecurity incident NSPI identified on April 25, 2025 (the "Inci...

AI summary This report outlines a review of NSPI's privacy practices following a cybersecurity incident identified on April 25, 2025. The reviewer was retained by the Nova Scotia Energy Board to assess the reasonableness of NSPI's actions in delivering services to its customers.

D. Methodology p. p. 3
D. Methodology 5. In order to come to my opinions, I reviewed the 2025 Nova Scotia Power's Cybersecurity Incident Report (the "Incident Report") and responses to my Information Request ("IR") to NSPI, as well as relevant information in oth...

AI summary The methodology section outlines the review of NSPI's 2025 Cybersecurity Incident Report and responses to an information request, using PIPEDA principles as a benchmark for evaluating the reasonableness of NSPI's actions without interpreting PIPEDA itself.

Privacy Training p. p. 4
Privacy Training - 20. Privacy training ensures that employees who handle PI understand their obligations and the risks associated with mishandling it. Without it, even well-designed policies are ineffective, as human error remains one of...

AI summary The document outlines NSPI's privacy training initiatives, including quarterly cybersecurity training and monthly phishing simulations. While NSPI achieved a 96% completion rate in 2024, the rate dropped to 79% in 2025, which is considered low. After the Incident, 100% of required training was completed in the first quarter of 2026.

Current Customer Notification p. p. 8
Current Customer Notification - 37. As set out in Section 4.2 of the Incident Report, on Monday April 28, 2025, three days after it discovered the Incident, NSPI informed customers that it was actively responding to a cybersecurity inciden...

AI summary NSPI informed customers of a cybersecurity incident through various channels starting on April 28, 2025, and continued updates through May 2025. Direct notifications were sent on May 13, 2025, to 277,000 affected customers. The timeline was deemed reasonable, balancing the need for accuracy with timely communication.

Former Customer Notification p. p. 8
Former Customer Notification 45. Section 4.2 of the Incident Report states that as it continued its investigation, NSPI determined that PI relating to former customers had also been impacted by the Incident. The Incident Report does not sp...

AI summary The Incident Report indicates that NSPI identified former customer data was impacted by the Incident, but did not notify them until two months after the Incident was discovered. The delay is considered unreasonable, as best practices suggest notification should occur within days, not months, unless extenuating circumstances apply, which were not indicated here.

Contents of Direct Customer Notification p. p. 8
- 50. In its notification letters, NSPI explained that the impacted data would have varied by customer, and depended, in part, on the information a customer would have provided NSPI. The types of PI that customers were notified as having p...

AI summary NSPI informed customers of a data breach affecting personal information, including names, addresses, SINs, and account details. Customers were concerned about the lack of specific information on impacted data and the difficulty in taking protective measures. NSPI could not definitively identify the data impacted on an individual basis.

Reasonableness of Type of PI Collected p. p. 14
- 65. In Section 8.5 of the Incident Report, NSPI explained that in addition to the information it collects identified above, prior to the Incident, there was also a practice of collecting social insurance numbers (SINs): - Prior to 2018,...

AI summary NSPI collected SINs from customers prior to 2018 for account authentication but stopped in 2018. In 2021, during the MyEnergy Insights program, SINs were inadvertently exported to a cloud environment and may have been exfiltrated. SINs are considered highly sensitive due to the difficulty in remediation if compromised.

Issue 6 – Third-party Service Providers p. pp. 19-21
Issue 6 – Third-party Service Providers - 90. Board counsel has asked that I provide an opinion on the reasonableness of NSPI's actions in relation to the Incident concerning security measures implemented with third -party service provider...

AI summary The Board counsel seeks an opinion on the reasonableness of NSPI's actions regarding third-party service providers in relation to a security incident. NSPI asserts the incident was caused by malware installed by an employee, not due to third-party service providers. Active oversight of third-party providers is emphasized, but since they were not involved in the incident, further opinion on this issue is not required.

Issue 10 – Communications Related to Cybersecurity Issues p. p. 21
Issue 10 – Communications Related to Cybersecurity Issues - 93. Board counsel has asked that I provide an opinion on the reasonableness of NSPI's actions concerning communications with customers about the Incident. - 94. In Section 4.2 of...

AI summary The document discusses NSPI's approach to communicating with customers and stakeholders during a cybersecurity incident, including the use of a multi-channel strategy and media outreach to ensure transparency and keep customers informed.

F. Conclusion p. pp. 21-24
F. Conclusion - 105. In conclusion, in my opinion, the following actions by NSPI met best practice, and were reasonable in terms of expectations for customer service and limiting the impacts of the cybersecurity attack on customers: - Asid...

AI summary The conclusion evaluates NSPI's actions following a cybersecurity attack, finding some measures reasonable and others not. While NSPI's privacy governance, notification timelines, and customer communication were deemed reasonable, the use of a PI inventory, retention of SINs, and lack of record-keeping were considered unreasonable.

N-15INQ Law/Consulting (CA) RIRs 1-4 3 passages
2 3 NOVA SCOTIA ENERGY BOARD 4 5 6 IN THE MATTER OF: The Public Utilities Act 7 8 – and – 9 10 IN THE MATTER OF: AN INQUIRY about the impact of the cyber in
2 3 NOVA SCOTIA ENERGY BOARD 4 5 6 IN THE MATTER OF: The Public Utilities Act 7 8 – and – 9 10 IN THE MATTER OF: AN INQUIRY about the impact of the cyber incident on NOVA 11 SCOTIA POWER INCORPORATED's collection and retention 12 of custom...

AI summary This document outlines an inquiry by the Nova Scotia Energy Board regarding the impact of a cyber incident on Nova Scotia Power Incorporated's data handling practices, customer service, billing processes, and regulatory compliance. The inquiry was initiated under the Public Utilities Act, with responses due by July 29, 2026.

Preamble
ID.IM-P8: Data processing is mapped, illustrating the data actions and associated data elements for systems/products/services, including components; roles of the component owners/operators; and interactions of individuals or third parties...

AI summary The response discusses the importance of a well-structured personal information (PI) inventory in determining specific data points affected by a cyber incident. It highlights that Nova Scotia Power's inability to identify exact data points suggests deficiencies in their PI inventory and data mapping processes.

Request IR-4:
Request IR-4: 15 In paragraph 106, page 26 of the Report, INQ Law/Consulting concludes that 8 of the 18 actions 16 of Nova Scotia Power relating to personal information that were reviewed, "did not meet best 17 practices, and were unreason...

AI summary The text discusses concerns raised about Nova Scotia Power's handling of personal information following a cyber security attack. It highlights that collecting SINs unnecessarily and retaining customer data longer than necessary were significant issues impacting customer expectations and the mitigation of the attack's effects.

N-16NSPI Refiled Formal Incident Report - Redacted (filed in M12273 as N-5 on April 27, 2026) 41 passages
Preamble
DATE FILED: December 22, 2025 Page 4 of 46 20260427 REFILE 20251222 NSPI to NSEB Cyber Incident Report PCON.docx 5 M12600, Minister of Energy – Accountability for Nova Scotia Power Inc., Minister of Energy Letter, December 3, 2025.

AI summary A cyber incident report from NSPI to NSEB was filed on December 22, 2025, referencing a ministerial letter dated December 3, 2025, concerning accountability for Nova Scotia Power Inc.

2025 Nova Scotia Power's Cybersecurity Incident Report REDACTED
2025 Nova Scotia Power's Cybersecurity Incident Report REDACTED 1 The NSEB replied to the Premier by letter on December 10, 2025, providing, in part, the following: 2 3 Upon receipt of your letter, the Board opened a new matter (M12600). G...

AI summary The NSEB opened a new matter (M12600) following a letter from the Premier, connecting it to an ongoing cybersecurity inquiry (M12273). NS Power argues that many issues raised by the Premier were already addressed in prior reports and that M12273 is the appropriate proceeding. The NSEB also requested NS Power to provide updates on a broader review related to a customer complaint (M12457).

Section 12
1 Incident, on May 28, 2025 and the Company is actively and fully cooperating with the OPC to 2 support the OPC's investigative efforts. 3 4 Incident Timeline & Attack Vector 5 6 The forensic investigation of the Incident has been complex....

AI summary This text details a cybersecurity incident at NS Power, where an employee clicked on a malicious link, leading to a sophisticated attack that compromised the company's systems starting March 19, 2025. The threat actor used persistence mechanisms and elevated privileges to move laterally and deploy ransomware on April 25, 2025.

1 Between April 8 and April 22, 2025, the threat actor leveraged this malware to access systems in
1 Between April 8 and April 22, 2025, the threat actor leveraged this malware to access systems in 2 the environment and to perform additional internal reconnaissance and credential harvesting 3 activities. 4 5 Beginning on or around April...

AI summary Between April 8 and 22, 2025, a threat actor used malware to access systems in the environment and perform reconnaissance and credential harvesting. On April 25, 2025, data was exfiltrated, ransomware was deployed, and backups were destroyed. NS Power disabled external access and isolated affected systems. The incident was contained by April 29, 2025.

2025 Nova Scotia Power's Cybersecurity Incident Report REDACTED
2025 Nova Scotia Power's Cybersecurity Incident Report REDACTED 1 4.0 RESPONSE AND RECOVERY ACTIONS 23 24 Ongoing remediation steps include: 25 26 27 28 1 2 3 4 5 6 NS Power is also advancing efforts to restore and, where necessary, rebuil...

AI summary The document outlines Nova Scotia Power's response and recovery actions following a 2025 cybersecurity incident. It details ongoing remediation efforts, including the restoration of core business systems and the establishment of a Business Restoration Process Office (RPO) to coordinate recovery. The report also mentions the company's existing cybersecurity safeguards, which are based on the NIST Cybersecurity Framework.

Section 21
1 To ensure customers were kept informed, the Company also employed a multi-platform paid media 2 strategy that includes online, as well as TV, print and radio to reach a wide variety of customer 3 demographics. In addition, NS Power activ...

AI summary NS Power implemented a multi-platform communication strategy, including paid media and social media, to keep customers informed during a cybersecurity incident. Customers were also encouraged to report suspicious activities, and support was available via customer care representatives.

Section 22
day, April 28, 2025, NS Power informed customers that it was actively 16 responding to a cybersecurity incident, and encouraged customers to report any suspicious emails 17 or phone calls. 18 11 13 19 On May 1, 2025, NS Power determined th...

AI summary NS Power informed customers on April 28, 2025, about a cybersecurity incident and encouraged them to report suspicious communications. On May 1, 2025, the company confirmed that customer information had been impacted and updated customers using a multi-channel strategy, while working to determine the full scope of the incident and initiating notification processes.

Section 34
1 them with information about the Incident. Given the nature of the cyber attack and the critical 2 infrastructure nature of the company and the North American electric utility industry, the Company 3 also notified the Federal Bureau of In...

AI summary NS Power experienced a cyber attack and notified the FBI and OPC. The company's response was deemed effective due to prior preparation, including third-party experts, updated incident-response plans, and simulation exercises.

REDACTED
REDACTED 1 In addition, the Company deployed dozens of employees to communities across the 2 province to provide hands-on support for customers who prefer assistance in person, 3 recognizing that not all customers may be comfortable regist...

AI summary NS Power deployed employees to assist customers in person and updated its website to improve access to services. The company has implemented cybersecurity standards aligned with NIST and NERC, and has completed a two-year update to its cybersecurity practices. NERC conducts periodic audits of NS Power's energy operations.

REDACTED
REDACTED 1 NS Power maintains a cybersecurity training and awareness program and conducts 2 mandatory quarterly cyber training and monthly phishing simulation testing exercises with 3 all employees to educate employees about NS Power's inf...

AI summary NS Power has implemented a cybersecurity training and awareness program, including mandatory quarterly training and monthly phishing simulations. Following a cybersecurity incident, NS Power activated its incident response protocols, engaged third-party experts, and initiated containment, eradication, and remediation efforts. Ongoing restoration and strengthening of cyber security systems are also being prioritized.

2
2 Date Media Outlet Format Reporter Member of NSP senior leadership team Topic May 23, 2025 CBC TV Amy Smith, Anchor recorded sit-down interview Peter Gregg, President and CEO Cyber incident update May 23, 2025 CBC Mainstreet Radio Jeff Do...

AI summary Nova Scotia Power (NSP) has been involved in a series of media interviews and public communications regarding a cybersecurity incident. NSP's President and CEO, Peter Gregg, and Director of Customer Care, Chris Lanteigne, have addressed the incident and related customer support efforts. The Nova Scotia Energy Board (NSEB) is conducting an inquiry into the incident under matter number M12273.

REDACTED
REDACTED July 9, 2025 CBC Nova Scotia Radio Elizabeth McMillan Chris Lanteigne, Director Customer Care Cyber incident\nupdate Billing concerns Customer support sessions in communities across NS July 11, 2025 CBC Nova Scotia – Information M...

AI summary The text includes a table with media coverage related to a cybersecurity incident and customer care sessions in Nova Scotia. It also references a cybersecurity incident report attached to NSEB IR-01.

Re: Important Notice About Your Personal Information
Re: Important Notice About Your Personal Information Dear Valued Customer: We are writing to provide you with information about the recent cyber incident impacting Nova Scotia Power. On April 25, 2025, Nova Scotia Power discovered that an...

AI summary Nova Scotia Power informed customers of a cyber incident on April 25, 2025, where unauthorized access occurred to parts of its Canadian network. Customer information, including personal and account details, was accessed. The company is offering free credit monitoring and advising customers to be cautious of unsolicited communications.

https://www.mytrueidentity.ca
https://www.mytrueidentity.ca You will be prompted to enter the following activation code: Please ensure that you redeem your activation code before 9/30/2025 to take advantage of the service. Upon completion of the online activation proce...

AI summary This document provides information about activating a service called my TrueIdentity® which offers credit monitoring, identity theft protection, and related features. It also includes a note about cybersecurity incident NSEB IR-01 Attachment 1 Page 4 of 4.

What is the dark web?
What is the dark web? These threat actors, and other cyber criminals, use a hidden part of the internet that is only accessible through special software—it is commonly referred to as the "dark web" and is known to be used by cyber criminal...

AI summary The text explains that the dark web is a hidden part of the internet accessible only through special software, often used by cyber criminals to store and trade data. It also provides contact information for technical support related to myTrueIdentity® and references a cybersecurity incident attachment.

We're Here to Help
We're Here to Help We know this has been a scary and frustrating time for our customers, and we are sincerely sorry that this has happened. To better assist you, we will be visiting communities in Nova Scotia to offer in-person support. Ou...

AI summary Nova Scotia Power is offering in-person support to customers affected by a cybersecurity incident. They are providing assistance with credit monitoring registration, estimated bills, and other customer-related inquiries. Customers are advised to be cautious of scams during the incident.

July 8, 2025
July 8, 2025 Since the cyber incident discovered on April 25, power meters have continued to function and gather accurate energy usage data from homes and businesses across the province. However, due to the cyber incident, the meters have...

AI summary A cyber incident on April 25 has caused power meters to function but not communicate data, leading to estimated billing. Meter readers are now visiting properties to collect actual usage data, with customers receiving estimated bills if access is not possible. Nova Scotia Power is addressing the issue and has provided information on adjusted billing processes.

Wednesday, June 25, 2025 Update
Wednesday, June 25, 2025 Update A dedicated team within Nova Scotia Power, along with third-party cybersecurity experts, are continuing the investigation into the recent ransomware attack that has impacted our customers and our company. To...

AI summary Nova Scotia Power is updating customers about a ransomware attack that impacted personal data of former and current customers. The company is offering five years of free credit monitoring to all customers. Personal information potentially accessed includes names, contact details, account history, and possibly bank account numbers and Social Insurance Numbers.

NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025)
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) We are focused on supporting our customers. We are here for regular business from 8 AM–6 PM, Monday through Friday. Please contact us at 1-800-428-6230 . To make it e...

AI summary Nova Scotia Power is addressing a cybersecurity incident, providing customer support, and cooperating with the Office of the Privacy Commissioner and the Nova Scotia Energy Board. They are working to delete SINs from their systems and are taking steps to prevent future incidents.

Wednesday, June 4, 2025 Update
Wednesday, June 4, 2025 Update Following the recent ransomware attack and its effect on our customers, we've been invited to speak with members of the Nova Scotia Public Accounts Committee at their meeting today. While recognizing that the...

AI summary Nova Scotia Power is addressing a recent ransomware attack affecting customers and is participating in a meeting with the Nova Scotia Public Accounts Committee. The company emphasizes its commitment to transparency and collaboration with cybersecurity experts and law enforcement.

Friday, May 23, 2025 Update
Friday, May 23, 2025 Update We wanted to provide an update on Nova Scotia Power's ongoing cyber incident. Today, we are confirming we have been the victim of a sophisticated ransomware attack. Since the incident began several weeks ago, No...

AI summary Nova Scotia Power has confirmed a ransomware attack affecting its systems. The company has been working with cybersecurity experts to restore systems and investigate the incident. No ransom has been paid, and affected customers have been notified with details on credit monitoring services. The incident is being discussed in the context of cybersecurity and regulatory oversight.

Wednesday, May 14, 2025 Update
Wednesday, May 14, 2025 Update Nova Scotia Power continues to investigate a cyber incident that has impacted certain IT systems in our network. We are working with external cybersecurity experts to determine the scope of the impact and saf...

AI summary Nova Scotia Power is investigating a cybersecurity incident that occurred on or around March 19, 2025, where unauthorized access occurred to customer information stored on impacted servers. Notifications are being sent to affected customers, and a two-year credit monitoring service is being provided at no cost.

Thursday, May 1, 2025 Update
Thursday, May 1, 2025 Update Nova Scotia Power is providing important information about the recent cyber incident affecting our company. On April 25, we detected unusual activity on our network and immediately initiated our incident respon...

AI summary Nova Scotia Power is informing customers about a recent cybersecurity incident that resulted in unauthorized access to customer personal information. The company has initiated an investigation with external experts and is working to restore systems securely. Customers are advised to be cautious of unsolicited communications. No disruption to service has been reported.

Monday, April 28, 2025 Update
Monday, April 28, 2025 Update Emera Inc. and Nova Scotia Power today announced on April 25, 2025 they discovered and are actively responding to a cybersecurity incident involving unauthorized access into certain parts of its Canadian netwo...

AI summary Emera Inc. and Nova Scotia Power disclosed a cybersecurity incident involving unauthorized access to parts of their Canadian network. The companies have activated response protocols and engaged cybersecurity experts to contain the breach. Operations in Nova Scotia remain unaffected, and there is no expected material financial impact.

Wednesday, June 25, 2025
Wednesday, June 25, 2025 - x Beginning today, we will be offering five years of free credit monitoring to all customers of Nova Scotia Power, past and present, regardless of whether you received a letter from us about the incident. Anyone...

AI summary Nova Scotia Power is offering free credit monitoring for five years to all current and former customers following a cybersecurity incident where personal information was accessed by an unauthorized third party on or around March 19, 2025.

Wednesday, June 5, 2025
Wednesday, June 5, 2025 - x Nova Scotia Power leadership appeared before the Nova Scotia Public Accounts Committee as part of our ongoing commitment to transparency following the recent ransomware attack. - x Immediately after detecting th...

AI summary Nova Scotia Power leadership appeared before the Nova Scotia Public Accounts Committee following a ransomware attack that resulted in stolen customer data. The company activated response protocols, engaged cybersecurity experts, and notified impacted customers, offering free credit monitoring and identity protection. No ransom was paid, and the company is cooperating with investigations and investing in cybersecurity.

Friday, May 23, 2025
Friday, May 23, 2025 - x Nova Scotia Power confirms we been the victim of a sophisticated ransomware attack. - x No payment has been made to the threat actor. This decision reflects our careful assessment of applicable sanctions laws and a...

AI summary Nova Scotia Power has confirmed a ransomware attack, resulting in stolen data being published by the threat actor. No ransom has been paid, and the company is working with cybersecurity experts to assess the impact and restore systems.

Wednesday, May 14, 2025
Wednesday, May 14, 2025 - x Nova Scotia Power continues to investigate a cyber incident that has impacted certain IT systems in our network. - x While the investigation remains ongoing, we have determined that on or around March 19, 2025,...

AI summary Nova Scotia Power is investigating a cyber incident that occurred around March 19, 2025, which resulted in unauthorized access to customer information stored on impacted servers. Notifications are being sent to affected customers, and a two-year credit monitoring service is being provided at no cost as a precaution.

Thursday, May 1, 2025
Thursday, May 1, 2025 - x We are actively responding to a cyber incident that has impacted certain IT systems in our network. - x While our investigation is ongoing, we have identified that certain customer personal information was accesse...

AI summary A cybersecurity incident has occurred, impacting IT systems and leading to unauthorized access of customer personal information. The investigation is ongoing, and the incident is being actively addressed.

Monday, April 28, 2025
Monday, April 28, 2025 - x Emera and Nova Scotia Power discovered and are actively responding to a cybersecurity incident involving unauthorized access into certain parts of our network and servers supporting portions of our business appli...

AI summary Emera and Nova Scotia Power are responding to a cybersecurity incident involving unauthorized access to parts of their network and servers. Incident response protocols have been activated, and no physical operations have been disrupted. Customers are advised to remain vigilant and report suspicious activity.

What happened?
What happened? Last updated: Tuesday, June 24, 2025 On April 25, we discovered and began actively responding to a cybersecurity incident involving unauthorized access into certain parts of our network and servers. Upon further investigatio...

AI summary A cybersecurity incident involving unauthorized access and a ransomware attack occurred on April 25, leading to the theft of customer personal information. No ransom was paid in compliance with sanctions laws. The investigation is ongoing, and updates are being provided through the company's website.

:KDWLV1RYD6FRWLD3RZHUGRLQJWRDGGUHVVWKLVF\EHULQFLGHQW"ௗௗ
:KDWLV1RYD6FRWLD3RZHUGRLQJWRDGGUHVVWKLVF\EHULQFLGHQW"ௗௗ Last updated: Tuesday, June 24, 2025 While our investigation remains ongoing, we have taken the following steps: - x Engaged third-party cybersecurity experts to help us investigate,...

AI summary The NSEB has engaged cybersecurity experts to investigate and remediate a recent incident where customer personal information was accessed. The investigation is ongoing, and law enforcement and regulators have been notified.

NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025)
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) - x Informed impacted customers via mail and provided a free subscription to TransUnion's credit monitoring service, my TrueIdentity®. - x Organized in-person support...

AI summary NS Power has informed impacted customers via mail and provided credit monitoring services. They have organized in-person support and resumed billing through an estimated billing approach, with customers able to access their bills through MyAccount.

Was my data impacted?
Was my data impacted? Last updated: Wednesday, June 25, 2025 Anyone who received a letter from us did receive information about what personal data may have been impacted in that letter. Our investigation remains ongoing. The ransomware att...

AI summary Nova Scotia Power is investigating the impact of a ransomware attack on customer data. While they cannot confirm specifics, they are offering free credit monitoring to all customers as a precautionary measure.

NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025)
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) Last updated: Wednesday, June 25, 2025 Our investigation is ongoing, and we sent letters to customers we determined to have been impacted in the incident. Out of an a...

AI summary NS Power is updating customers about a cyber incident, expanding free credit monitoring to all current and past customers for five years as a precautionary measure.

Why didn't you offer credit monitoring to everyone right away when this happened? Why now?
Why didn't you offer credit monitoring to everyone right away when this happened? Why now? Last updated: Wednesday, June 25, 2025 Our initial focus was on customers that were confirmed to have their personal data impacted by the breach. As...

AI summary The organization initially focused on customers confirmed to have been affected by a data breach but later expanded free credit monitoring to all customers, including former ones, due to evolving findings and a desire to provide reassurance and protection.

NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025)
NS Power – Cyber Incident Updates (Website Excerpts – September 5, 2025) Power—past and present—regardless of whether you received a letter from us about the incident.

AI summary The document provides updates on a cyber incident affecting NS Power, with information directed to both past and present power customers, regardless of whether they received a letter regarding the incident.

What services have been affected?
What services have been affected? Last updated: Tuesday, June 24, 2025 Initially, there was disruption to our internal IT and customer care systems, which affected our billing processes and access to our online customer portal, MyAccount....

AI summary The incident disrupted internal IT and customer care systems, affecting billing processes and access to the online customer portal, MyAccount. Services such as MyEnergy Insights and Efficiency Insights are currently unavailable through MyAccount. Efforts are ongoing to restore full system functionality.

A. Background Facts
A. Background Facts - 2. NS Power has been the victim of a highly sophisticated ransomware attack. While the attack did not affect NS Power's infrastructure relating to the provision of power to its customers, the incident has caused some...

AI summary NS Power suffered a ransomware attack that did not impact customer infrastructure but disrupted internal IT and customer care systems. Customer data was exfiltrated and posted on the dark web. NS Power has collaborated with cybersecurity experts to respond to the incident.

Appendix "B" \ \ \ CONFIDENTIAL \ \ \
Appendix "B" \ \ \ CONFIDENTIAL \ \ \ NS Power's Confidential Submission, particularly in respect of paragraphs 3-8, as well as the last sentence of paragraph 2, requires confidentiality protection because the information — when taken coll...

AI summary NS Power has experienced a major ransomware attack, leading to the theft and dark web posting of customer personal information. NS Power has not made any ransom payments and is seeking confidentiality protection for its submission due to the sensitive nature of the information. Cybersecurity guidelines from the Canadian Centre for Cyber Security and insights from PWC's Alison Wikoff are referenced.

N-17NS Power Rebuttal Evidence - Redacted 38 passages
Cybersecurity Accountability p. p. 2
Cybersecurity Accountability Nova Scotia Power Rebuttal August 10, 2026 REDACTED

AI summary The document is a redacted rebuttal from Nova Scotia Power regarding cybersecurity accountability, submitted on August 10, 2026.

1.0 INTRODUCTION p. p. 2
1.0 INTRODUCTION - In a letter dated December 10, 2025, the Board initiated this matter (M12600) as a separate matter - from the ongoing cybersecurity inquiry (M12273). The Board confirmed it would determine a - process to consider M12600...

AI summary The document outlines the initiation and progression of regulatory matter M12600, which was separated from the ongoing cybersecurity inquiry (M12273). The Board determined that the matter would be addressed in an oral hearing after receiving NS Power's Cybersecurity Incident Report. NS Power provided responses to information requests and submitted evidence, including rebuttal evidence from Jena Valdetero of GreenbergTraurig.

Cybersecurity Accountability REDACTED p. pp. 5-59
Cybersecurity Accountability REDACTED Customers can still access these public/media updates on NS Power's website at nspower.ca/cyber. There are "[Cyber Incident Updates](https://www.nspower.ca/home cyber)", which directs viewers to the de...

AI summary NS Power has provided impacted customers with complimentary credit monitoring services for five years, expanding eligibility to all current and former customers. The service includes credit reports, credit scores, monitoring alerts, educational resources, and identity restoration assistance.

Cybersecurity Accountability REDACTED p. pp. 5-50
Cybersecurity Accountability REDACTED • Up to $1,000,000 of expense reimbursement insurance related to identity theft. • Dark Web Monitoring, which monitors surface, social, deep, and dark websites for potentially exposed personal, identit...

AI summary NS Power is addressing the cybersecurity breach by offering credit monitoring and identity theft insurance to affected customers, including former ones. The company communicated through multiple channels to inform customers about the breach and the measures being taken.

Cybersecurity Accountability REDACTED p. p. 9
Cybersecurity Accountability REDACTED Station Contact NORTHEAST Amherst: CFTA Tantramar 107.9 FM [email protected] Truro: [email protected] CKYT Cat Country (MBS or: [email protected] Radio) & CKTO EZ Rock (MBS Radio) New Glasgow: newglas...

AI summary The document provides a list of radio stations and their contact information in Nova Scotia, including email addresses for various stations across different regions such as the Northeast, Metro, and Pictou County. The heading mentions 'Cybersecurity' and 'Accountability' but is redacted, suggesting the content may be sensitive or incomplete.

4 p. p. 9
4 Date Media Outlet Format Reporter Member of NSP senior leadership team Topic May 23, 2025 CBC TV Amy Smith, Anchor recorded sit down interview Peter Gregg, President and CEO Cyber incident update May 23, 2025 CBC Mainstreet Radio Jeff Do...

AI summary The document lists media interviews and appearances by Nova Scotia Power (NSP) senior leadership regarding a cyber incident update, with the most recent interview occurring on June 17, 2025. The information was filed on August 10, 2026, as part of a regulatory proceeding.

Cybersecurity Accountability REDACTED p. p. 9
Cybersecurity Accountability REDACTED Date Media Outlet Format Reporter Member of NSP senior leadership team Topic Customer support sessions in communities across NS June 17, 2025 CBC Information Morning Mainland (recorded to air June 18)...

AI summary The document outlines media appearances by Chris Lanteigne, Director of Customer Care at Nova Scotia Power, discussing cybersecurity incidents, billing concerns, and customer support sessions in communities across Nova Scotia.

4.0 EVIDENCE OF INTERGROUP CONSULTANTS p. pp. 9-20
4.0 EVIDENCE OF INTERGROUP CONSULTANTS The InterGroup Evidence makes 13 recommendations focused on areas where NS Power's cybersecurity, privacy, communications, customer notification, billing contingency, and governance practices could be...

AI summary The InterGroup Evidence provides 13 recommendations to NS Power to improve cybersecurity, privacy, communication, and governance practices. NS Power agrees with the need for continuous improvement and highlights existing initiatives, noting that some recommendations align with OPC guidance. Specific emphasis is placed on updating staff training policies and addressing system access restrictions for non-compliance.

Cybersecurity Accountability REDACTED p. pp. 41-42
Cybersecurity Accountability REDACTED - NS Power has had a Personal Information Inventory in place since 2018. As noted above, it has - been attached hereto as Confidential Attachment 3. - In INQ's response to CA IR-1, INQ added, when aske...

AI summary NS Power has maintained a personal information inventory since 2018. The inventory helps identify data categories but not specific records accessed during a cyber incident. Forensic evidence is needed for that. NS Power notified customers about SIN compromises and sent tailored notifications.

Preamble p. pp. 43-46
While I agree that it is important to take steps to identify whether sensitive personal data was affected in an incident and act quickly to notify as soon as feasible, a finding of unreasonableness is not sustained by the evidentiary recor...

AI summary The text discusses the reasonableness of NS Power's response to a cybersecurity incident, emphasizing the need to balance timely notification with operational challenges. It highlights that NS Power prioritized service continuity and took steps such as restoring systems, extracting documents, and engaging third parties for credit monitoring and customer communication.

Cybersecurity Accountability REDACTED p. p. 55
Cybersecurity Accountability REDACTED posted on May 14, 2025. As additional information became available and evolving expectations regarding longer-term protections emerged, the Company proactively expanded the offering to five years on Ju...

AI summary NS Power initially offered two years of credit monitoring following a data breach but later expanded it to five years. The company argues that the initial decision was reasonable given no legal requirement, historical practice, and the subsequent proactive extension. The expansion provided greater protection than industry norms and was not a reimbursement opportunity.

7.0 NS POWER'S ENHANCED PRIVACY GOVERNANCE PROGRAM p. pp. 57-59
7.0 NS POWER'S ENHANCED PRIVACY GOVERNANCE PROGRAM Beyond the circumstances of this Attack and the response to it, the Company recognizes that the privacy, cybersecurity, and related regulatory landscape is ever evolving with significant a...

AI summary NS Power is enhancing its privacy governance program in response to evolving regulatory and technological challenges, including Bill C-36 and the increasing use of AI. The company is strengthening its privacy framework, policies, and oversight mechanisms, with a dedicated Privacy Officer role being formalized and elevated in the organizational structure.

Inquiry into Nova Scotia Power Incorporated's Cybersecurity Incident p. p. 64
Inquiry into Nova Scotia Power Incorporated's Cybersecurity Incident Evidence of Jena Valdetero, Co-Chair US Data Privacy and Cybersecurity at Greenberg Traurig LLP Prepared for NS Power Inc. August 10, 2026 NON-CONFIDENTIAL

AI summary This document outlines the evidence provided by Jena Valdetero, Co-Chair of US Data Privacy and Cybersecurity at Greenberg Traurig LLP, prepared for Nova Scotia Power Inc. in an inquiry related to a cybersecurity incident.

1 1.0 SCOPE AND MANDATE p. pp. 64-67
1 1.0 SCOPE AND MANDATE - 2 I have been retained by Nova Scotia Power Incorporated ("NS Power" or "Company") in - 3 connection with the recent cybersecurity incident (the "Incident") impacting the Company to - 4 provide expert rebuttal opi...

AI summary The document outlines the scope and mandate of the expert opinion provided by the individual retained by Nova Scotia Power Incorporated in response to findings and recommendations from two expert reports regarding a recent cybersecurity incident.

Cybersecurity Accountability Rebuttal Attachment 1 Page 4 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 67
Cybersecurity Accountability Rebuttal Attachment 1 Page 4 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL - 1 questions of legal interpretation...

AI summary Jena Valdetero, an expert in data security and privacy law, provides an opinion on whether NS Power acted reasonably in response to a cybersecurity incident. She has extensive experience managing data security incidents and advising on privacy laws, including PIPEDA and similar legislation.

11 3.0 INFORMATION CONSIDERED p. pp. 67-68
11 3.0 INFORMATION CONSIDERED - 12 In preparing this Report, I have considered: - 13 The Ralph Report (M12600, Exhibit N-14, Evidence of Tricia Ralph INQ Law/Consulting, - 14 June 23, 2026); - 15 The Mollard Report (M12600, Exhibit N-13, E...

AI summary The document outlines the information considered in the inquiry into NS Power's cybersecurity incident, including reports, regulatory guidance, industry standards, and input from various stakeholders such as TransUnion, NS Power, Osler, and Emera.

12 4.0 SUMMARY OF OPINIONS p. pp. 68-69
12 4.0 SUMMARY OF OPINIONS - 13 In my opinion, NS Power's response to the Incident should be assessed in the context of a large- - 14 scale ransomware event involving extensive data exfiltration, severe operational disruption - 15 experien...

AI summary The text presents an opinion from a witness, Jena Valdetero, defending NS Power's response to a major ransomware incident. It highlights the company's actions, such as public notice, customer communication, and remedial measures, and argues that these were reasonable and timely compared to other incidents handled by the witness over the past 14 years. The opinion disagrees with conclusions in the Ralph Report and Mollard Report that NS Power's response was unreasonable.

1 5.0 KEY CHRONOLOGICAL FACTS IDENTIFIED IN THE RECORD p. pp. 69-70
1 5.0 KEY CHRONOLOGICAL FACTS IDENTIFIED IN THE RECORD - 2 Before turning to the specific findings and recommendations in the Ralph Report and Mollard - 3 Report, I set out the key chronological facts established by the evidentiary record,...

AI summary This section outlines key chronological events related to a cybersecurity incident discovered by NS Power in April 2025. The incident led to the activation of response protocols, notifications to authorities, and customer communication. NS Power informed the OPC and offered credit monitoring services to affected customers.

Cybersecurity Accountability Rebuttal Attachment 1 Page 9 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 72
Cybersecurity Accountability Rebuttal Attachment 1 Page 9 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL - 1 notice; it was a recognized notifi...

AI summary This document discusses the evidence presented by Jena Valdetero regarding NS Power's cybersecurity incident, focusing on the use of a recognized notification mechanism permitted by Canadian law to inform affected individuals.

3 Rationale p. p. 72
3 Rationale - 4 (a) The Incident Was a Complex, Large-Scale Ransomware Event, Not a Routine Breach - 5 The record establishes that this was not a routine data breach. This was a sophisticated and - 6 coordinated cyberattack in which a thre...

AI summary The document explains that the cybersecurity incident involving NS Power was a complex, large-scale ransomware attack, not a routine breach. It outlines the steps NS Power took, including engaging external legal counsel, forensic investigators, and third-party services, to manage the incident and notify affected individuals.

15 (b) Current Customer Notification Speed Does Not Establish What Was Feasible for 16 Former Customers p. p. 72
15 (b) Current Customer Notification Speed Does Not Establish What Was Feasible for 16 Former Customers 17 Based on the information in the record and information obtained from individuals directly involved 18 in the Incident response, NS P...

AI summary NS Power quickly notified current customers of a data breach by using existing customer data, but faced challenges in notifying former customers due to the lack of current contact information, which is common given the transient nature of the customer base and the presence of universities in Nova Scotia.

14 (c) Former Customer Notice Required Additional Operational Readiness p. p. 72
14 (c) Former Customer Notice Required Additional Operational Readiness - 15 Tasked with notifying former customers indirectly, NS Power sought assistance from TransUnion, - 16 who in turn connected NS Power with Sogica, an IT services com...

AI summary NS Power, in response to a cybersecurity incident, partnered with TransUnion and Sogica to notify former customers and provide credit monitoring services. Concerns about the initial two-year offer led to an upgrade to five years of service without additional action from customers. NS Power implemented a multi-channel communication strategy to ensure broad awareness of the incident.

Cybersecurity Accountability Rebuttal Attachment 1 Page 14 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 76
Cybersecurity Accountability Rebuttal Attachment 1 Page 14 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL 1 Even so, NS Power continued to cond...

AI summary NS Power conducted forensic analysis with third-party vendors to identify impacted customers following a cybersecurity incident. They mailed 97,000 letters to additional affected individuals. Ms. Ralph criticized the customer notices for being insufficient and unclear, suggesting customers should have been informed that all their data elements were impacted.

Cybersecurity Accountability Rebuttal Attachment 1 Page 16 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 79
Cybersecurity Accountability Rebuttal Attachment 1 Page 16 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL - 1 community outreach and the dedica...

AI summary Jena Valdetero testifies that NS Power acted reasonably and met or exceeded industry standards in its notification strategy following a cybersecurity incident, citing community outreach and a dedicated TransUnion call center as evidence.

Cybersecurity Accountability Rebuttal Attachment 1 Page 17 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 79
Cybersecurity Accountability Rebuttal Attachment 1 Page 17 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL known."[7](#page-81-0) 1 Thus, even t...

AI summary This document discusses the inquiry into NS Power's cybersecurity incident, referencing evidence provided by Jena Valdetero and mentioning the governing privacy law, which allows for the possibility that certain information may not be known.

3 (b) Telling Customers to Assume All Data Was Accessed Would Have Created Its Own 4 Risks p. p. 79
3 (b) Telling Customers to Assume All Data Was Accessed Would Have Created Its Own 4 Risks 5 Ms. Ralph suggests at paragraph 55 that a more cautious approach would have been to advise 6 customers to assume that all data points had been acc...

AI summary Ms. Ralph suggests advising customers to assume all data was accessed, but this approach could cause unnecessary alarm and costly actions. NS Power's approach of informing customers about the largest scope of potentially affected data while acknowledging variation by customer is considered accurate and defensible.

17 (c) Customer Confusion Does Not, By Itself, Establish Inadequate Notice p. pp. 79-81
17 (c) Customer Confusion Does Not, By Itself, Establish Inadequate Notice 18 In my experience advising on numerous large scale cyber security incidents, when communicating 19 information to a large population of individuals of varying edu...

AI summary The text discusses the adequacy of notice provided to customers following a cybersecurity incident, emphasizing that customer confusion alone does not establish inadequate notice. It highlights that the standard is whether the notice adequately informed individuals of the incident and available protective steps, not whether it was perfectly clear to each individual.

Cybersecurity Accountability Rebuttal Attachment 1 Page 19 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 81
Cybersecurity Accountability Rebuttal Attachment 1 Page 19 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL - 1 community support sessions of thi...

AI summary The text discusses NS Power's cybersecurity incident response, highlighting the extensive customer support measures taken, including community support sessions and multi-channel communication, which are noted as exceeding typical breach response practices.

19 Summary of Ms. Ralph's Finding p. pp. 81-83
19 Summary of Ms. Ralph's Finding - 20 At paragraph 89 of the Ralph Report, Ms. Ralph concludes that NS Power's initial offer of two - 21 years of credit monitoring was insufficient because SINs, which are static identifiers that cannot -...

AI summary Ms. Ralph's finding concludes that NS Power's initial offer of two years of credit monitoring was insufficient due to the persistent risk of misuse of SINs. She determined that extending the offer to five years was reasonable given the nature of the compromised information.

13 (b) Two Years Is Consistent with Standard Breach Response Practice p. p. 83
13 (b) Two Years Is Consistent with Standard Breach Response Practice - 14 In the United States, a handful of states require credit monitoring where the U.S. equivalent of - 15 SINs Social Security Numbers (SSNs) are affected in an inciden...

AI summary The text discusses the standard practice of offering credit monitoring following data breaches, noting that two years is consistent with industry norms in Canada. It references statistics from TransUnion and mentions that only a small percentage of companies offer five years of monitoring. The extension to five years was acknowledged as reasonable by Ms. Ralph.

Cybersecurity Accountability Rebuttal Attachment 1 Page 22 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 83
Cybersecurity Accountability Rebuttal Attachment 1 Page 22 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL - 1 condition. of resolution. In my e...

AI summary The text discusses the challenges of implementing a reimbursement program for a data breach, emphasizing the administrative burden on NS Power during a period of concurrent recovery efforts, including containment, remediation, and regulatory cooperation.

23 (a) The Recommendation Conflicts with Risk-Based Notification Principles p. p. 86
23 (a) The Recommendation Conflicts with Risk-Based Notification Principles - 24 The foundational principle of data breach notification reflected in PIPEDA and in analogous - 25 provincial frameworks is that notification obligations are ri...

AI summary The recommendation conflicts with risk-based notification principles, as data breach notification obligations under PIPEDA and provincial frameworks are risk-proportionate and targeted, requiring notification only when individuals are or may reasonably be affected by the breach.

Cybersecurity Accountability Rebuttal Attachment 1 Page 24 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 86
Cybersecurity Accountability Rebuttal Attachment 1 Page 24 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL - 1 individual's information was not...

AI summary Jena Valdetero disagrees with Recommendation 6, which directs NS Power to reach former customers who may have relocated outside the province. She argues that NS Power took meaningful steps to notify former customers through public channels and that practical limitations, such as lack of real-time national address databases, make this task unfeasible.

Cybersecurity Accountability Rebuttal Attachment 1 Page 26 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 86
Cybersecurity Accountability Rebuttal Attachment 1 Page 26 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL - 1 complaints and inquiries from aff...

AI summary The testimony discusses NS Power's cybersecurity incident, focusing on the challenges of notifying relocated former customers and the infeasibility of achieving comprehensive reach. It also addresses the recommendation for cost reimbursement for credit monitoring services, arguing against it as not standard practice in Canadian regulatory proceedings.

18 Burdens p. p. 86
18 Burdens - 19 A reimbursement program requires a defined claims period, a claims administration process, - 20 invoice verification, dispute resolution, and budget management. These are not trivial - 21 requirements for a utility that was...

AI summary The text discusses the complexities and administrative burdens associated with managing a reimbursement program, including claims periods, invoice verification, and dispute resolution, while also managing a major systems recovery program involving multiple business applications.

Cybersecurity Accountability Rebuttal Attachment 1 Page 29 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 86
Cybersecurity Accountability Rebuttal Attachment 1 Page 29 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL - 1 offered five years to individuals...

AI summary NS Power's response to Exhibit N-2, NSEB IR-4 states that affected individuals will retain free access to their credit information through TransUnion and other providers beyond five years, which is considered in assessing the need for a longer monitoring period.

Cybersecurity Accountability Rebuttal Attachment 1 Page 30 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 86
Cybersecurity Accountability Rebuttal Attachment 1 Page 30 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL 1 Appendix A 2 I serve as Co-Chair of...

AI summary Jena Valdetero, a U.S. data privacy and cybersecurity expert, provides evidence in the inquiry into NS Power's cybersecurity incident. She has extensive experience in handling data breaches, ransomware attacks, and advising on compliance with data privacy laws, including PIPEDA and GDPR.

Cybersecurity Accountability Rebuttal Attachment 1 Page 32 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 86
Cybersecurity Accountability Rebuttal Attachment 1 Page 32 of 32 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Inquiry into NS Power's Cybersecurity Incident – Evidence of Jena Valdetero NON-CONFIDENTIAL - 1 Member, Global Advisory Board, 20...

AI summary This document is a rebuttal related to a cybersecurity incident involving NS Power, filed on August 10, 2026. It includes evidence from Jena Valdetero, who has professional affiliations with various legal and privacy organizations. Attachments 2, 3, and 4 have been filed or removed due to confidentiality.

N-18Opening Statement - CA 1 passage
Section 2
- 8 11 15 18 20 24 28 32 36 38 40 41 42 46 45 - 3 Were Nova Scotia Power employees adequately trained to protect personal information 4 from the risks of cyber attacks? - 6 Did the customers and former customers of Nova Scotia Power receiv...

AI summary The document outlines questions raised by the Board regarding Nova Scotia Power's handling of a cyber attack, including employee training, customer notification, mitigation of identity theft risks, and privacy policy updates. Nova Scotia Power filed a rebuttal and evidence, but the Board emphasizes the need for a constructive discussion on improving preparedness and mitigating future impacts.

N-19Opening Statement - David MacLeod 1 passage
Section 1
IN THE MATTER OF: The Public Utilities Act – and – IN THE MATTER OF: AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer information, customer service and communication...

AI summary This opening statement from David MacLeod, a Public Interest Intervenor, highlights concerns about the long-term vulnerabilities faced by Nova Scotia residents with federal security clearances due to the 2025 Nova Scotia Power cyber breach. He emphasizes the unique risks posed by the exposure of Personally Identifiable Information (PII) to foreign threat actors and criminal networks.

N-21Opening Statement - NS Power 3 passages
Section 1
August 14, 2026 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12600 – Cybersecurity Accountability - Opening Statement Dear Ms. Henwood: Please see attached opening...

AI summary Nova Scotia Power presents an opening statement regarding a 2025 cyberattack that significantly impacted customers, employees, and corporate systems, leading to a loss of public confidence. The company acknowledges the breach of sensitive personal data, including SINs, and emphasizes its commitment to transparency and accountability in rebuilding trust.

Section 2
, including Social Insurance Numbers (SINs). Nothing is more important to us than regaining the trust of those we serve, and we understand that trust must be earned through our actions, not our words. This Attack was a serious criminal act...

AI summary Nova Scotia Power acknowledges a serious cybersecurity attack and emphasizes its commitment to customer trust and privacy. The company outlines its response, including containment, remediation, and ongoing enhancements to cybersecurity and privacy measures. It highlights collaboration with regulators and law enforcement, as well as efforts to restore systems and services.

Section 3
mpacted data, implementation of enhanced security controls, and restoration of customer-facing services while continuing to provide reliable electric service to more than half a million Nova Scotians. Since the Attack, our focus has been o...

AI summary Nova Scotia Power has restored major systems following a cyberattack and implemented enhanced cybersecurity measures. The company emphasizes ongoing efforts to improve security and resilience, ensuring reliable service to customers and maintaining a commitment to continuous improvement.

N-22Equifax Data Breach Settlement 1 passage
3. Iniunctive Relief.
3. Iniunctive Relief. Equifax has agreed to entry of a consent order requiring the company to spend a minimum of $1 billion for data security and related technology over five years and to comply with comprehensive data security requirement...

AI summary Equifax has agreed to a consent order requiring a $1 billion investment in data security over five years, with compliance audited by an independent assessor. Cybersecurity expert Mary Frantz supports the measures, stating they significantly reduce the likelihood of future breaches and benefit class members.

N-23M12835 Exhibit N-2 Att 3 2025 Managements Discussion AnalysisHIGHLIGHTED 7 passages
Cybersecurity Incident:
Cybersecurity Incident: On April 25, 2025, NSPI discovered a cybersecurity incident (the "Cybersecurity Incident") involving unauthorized access into certain parts of its IT network and servers supporting portions of its business applicati...

AI summary On April 25, 2025, NSPI experienced a cybersecurity incident with unauthorized access to its IT network. No physical operations were disrupted, but the company incurred $7 million in after-tax costs for the year. Business continuity processes were implemented, and the company is working with its insurer on the claims process.

Class Action Lawsuit:
Class Action Lawsuit: NSPI was named as a defendant in a claim for a class action lawsuit filed with the Supreme Court of Nova Scotia, seeking damages arising from the Cybersecurity Incident. The amount of damages has not been specified. D...

AI summary NSPI is a defendant in a class action lawsuit filed in the Supreme Court of Nova Scotia related to a Cybersecurity Incident. The damages sought are unspecified, and the legal proceedings are in a preliminary stage, making it impossible to estimate potential losses.

Highlights of the changes are summarized in the following table:
Highlights of the changes are summarized in the following table: For the Three months ended Year ended millions of dollars December 31 December 31 Net income - 2024 $ 71 $ 160 Increased operating revenues (refer to "Operating Revenues" sec...

AI summary The document summarizes net income and revenue changes for the periods ending December 31, 2024 and 2025. It highlights increased operating revenues, decreased fuel costs, and increased FAM and other deferrals. Notable factors include increased storm costs, a cybersecurity incident, and changes in income tax recovery.

Cybersecurity Risk
Cybersecurity Risk NSPI is exposed to potential risks related to cyberattacks, data breaches, cyber-extortion, and unauthorized access that could result in a Material Adverse Effect. The Company increasingly relies on IT systems, networks...

AI summary NSPI faces cybersecurity risks from potential cyberattacks, data breaches, and unauthorized access, which could cause a Material Adverse Effect. The company relies heavily on IT systems, networks, and third-party providers for managing critical energy infrastructure, making it a target for cyber threats, including those from nation-state actors.

Technology Risk
Technology Risk NSPI relies on various technology systems to manage operations, including increasing reliance on IT solutions operated by third parties, such as software as a service and third party cloud hosting. This subjects NSPI to inh...

AI summary NSPI faces technology risks due to reliance on third-party IT systems and the rapid evolution of AI. These risks include operational disruption, increased vulnerability to cyberattacks, and potential failure to integrate AI effectively, which could lead to adverse outcomes. The company's digital transformation strategy involves significant investment in emerging technologies, increasing project risks.

Q4 2025 compared to Q4 2024
Q4 2025 compared to Q4 2024 Q4 2025 net income decreased by $49 million compared to Q4 2024. The decrease is due to decreased income tax recovery and increased OM&G expenses. Income tax recovery decreased due to the utilization of tax loss...

AI summary Q4 2025 net income decreased by $49 million compared to Q4 2024 due to decreased income tax recovery and increased OM&G expenses, primarily driven by higher storm costs and costs related to the Cybersecurity Incident.

Q2 2025 compared to Q2 2024
Q2 2025 compared to Q2 2024 Q2 2025 net income decreased by $12 million compared to Q2 2024. The decrease is due to increased OM&G expenses, and increased depreciation and amortization due to increased PP&E in service. OM&G expenses increa...

AI summary Q2 2025 net income decreased by $12 million compared to Q2 2024, primarily due to increased OM&G expenses and depreciation and amortization from higher PP&E in service, with OM&G expenses rising from higher power generation costs and the Cybersecurity Incident.

N-24Undertaking Responses - NS Power - Redacted 8 passages
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to NSEB Undertakings
Minister of Energy – Accountability for Nova Scotia Power (NSEB M12600) NSPI Responses to NSEB Undertakings 1 Undertaking U-6: 2 3 To confirm that CA IR-1(e) will be addressed in Proceeding M12273. 4 5 Response U-6: 6 7 CA-IR-1(e) reads as...

AI summary Nova Scotia Power Inc. (NSPI) responds to an undertaking from the Nova Scotia Energy Board (NSEB) regarding cybersecurity incidents over the past five years. NSPI confirms there were no recorded cyber incidents and mentions a cybersecurity training program with mandatory quarterly training and monthly phishing simulations.

Section 16
- 3 To provide the actuals from 2025 for the costs associated with the cybersecurity incident, - 4 including cost categories, as well as an updated forecast for 2026. 5 6 Response U-7: 7 8 Minister of Energy – Accountability for Nova Scoti...

AI summary The document requests actual costs from 2025 related to a cybersecurity incident, including cost categories and an updated forecast for 2026. It references a response from NSPI to NSEB undertakings under matter M12600.

Q: You said that the threat actor has published my stolen data. Where has my information been shared?
Q: You said that the threat actor has published my stolen data. Where has my information been shared? A: These threat actors, and other cyber criminals, use a hidden part of the internet that is only accessible through special software—it...

AI summary The threat actor has published stolen data on the dark web, which is only accessible through special software. The organization has informed affected individuals and recommends signing up for TransUnion's credit monitoring service.

Q: What happens now that [a portion of our data] is now online? Isn't the threat to my personal data greater than before?
Q: What happens now that [a portion of our data] is now online? Isn't the threat to my personal data greater than before? A: We are actively working with cybersecurity experts to assess the nature and scope of the information that may have...

AI summary The organization is addressing concerns about data exposure by working with cybersecurity experts and advising affected customers to enroll in credit monitoring and remain cautious of unsolicited communications.

Q: What is the March 19 date I read in the letter I received?
Q: What is the March 19 date I read in the letter I received? While the investigation remains ongoing, we have determined that on or around March 19, 2025, certain customer information stored on the impacted servers was accessed and later...

AI summary The letter refers to a date in March 2025, around March 19, when customer information was accessed and taken by an unauthorized third party during an ongoing investigation.

Q: Who/What is responsible for the incident?
Q: Who/What is responsible for the incident? Our IT team is actively working with external cybersecurity experts to investigate this incident. We have also notified law enforcement and regulatory authorities. We cannot speculate or share u...

AI summary The incident is under investigation by the IT team in collaboration with external cybersecurity experts. Law enforcement and regulatory authorities have been notified. No unverified information is being shared during the ongoing investigation.

Q: What is Nova Scotia Power doing to address this cyber incident?
Q: What is Nova Scotia Power doing to address this cyber incident? Although we are still actively investigating this cyber incident, we have taken the following steps: - Engaged external cybersecurity experts to help us investigate, remedi...

AI summary Nova Scotia Power is addressing a cyber incident by engaging external cybersecurity experts, notifying law enforcement and regulators, reviewing accessed data, notifying impacted account holders, and working to restore systems while ensuring business continuity.

IMPROVING YOUR BILLING EXPERIENCE
IMPROVING YOUR BILLING EXPERIENCE The cyber incident disrupted our ability to read meters. We are working diligently to fix this:

AI summary A cyber incident has disrupted meter reading capabilities, and efforts are underway to resolve the issue and improve the billing experience.

100870Hearing Order 1 passage
HEARING ORDER
HEARING ORDER On December 3, 2025, the Honourable Tim Houston, Premier of Nova Scotia and Minister of Energy, wrote to the Nova Scotia Energy Board to express concern about the number of Nova Scotians experiencing inaccurate billing and a...

AI summary The Nova Scotia Energy Board has opened a new matter (M12600) following concerns raised by the Premier about inaccurate billing and lack of responsiveness from NS Power after a cybersecurity breach. A public hearing is scheduled for July 2026 to address the matter.

100871Notice of Public Hearing 1 passage
NOTICE OF PUBLIC HEARING p. p. 0
NOTICE OF PUBLIC HEARING _______________________________________________________________________________ IN THE MATTER OF AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of cus...

AI summary A public hearing is scheduled to examine the impact of a cyber incident on Nova Scotia Power Incorporated's data collection, customer service, billing processes, and regulatory matters. The hearing will take place from July 27 to July 29, 2026, in Halifax.

102138Board Decision Letter - Scope of IRs 4 passages
Section 1 p. p. 0
May 26, 2026 [[email protected]](mailto:[email protected]) Blake Williams VP Legal and Regulatory Nova Scotia Power Incorporated PO Box 910 1223 Lower Water Street Halifax, NS B3J 2W5 Dear Mr. Williams: M12600 – Nova Scotia...

AI summary NS Power has identified certain Information Requests (IRs) as outside the scope of the current proceeding, M12600 – Nova Scotia Power Incorporated – Cybersecurity Accountability. The matter relates to a 2025 cybersecurity attack and is connected to Matter M12273. The Board invited intervenors to respond to NS Power's objections, with Mr. MacLeod arguing that his IRs are within the scope of the proceeding.

Section 2 p. p. 0
relevant in Matter M12273. The Board invited intervenors to respond to NS Power's objections. Mr. MacLeod submitted the IRs he requested were all within the scope of the current proceeding and were: … intended to shed light on NSPI's corpo...

AI summary The proceeding discusses NS Power's objections and the need for information requests to understand NSPI's corporate culture and risk management practices, particularly in cybersecurity. The Small Business Advocate argues that evidence from Matter M12273 is relevant to the current proceeding for full regulatory context.

Section 3 p. p. 0
Business Advocate submitted that there were non-technical aspects of the questions it asked that would "add value and insight into the regulatory oversight that is clearly within the scope of M12600." The Consumer Advocate also submitted t...

AI summary The Business Advocate and Consumer Advocate argue that non-technical aspects of questions should be included in the regulatory proceeding, emphasizing their relevance to governance, risk management, and regulatory compliance. The Board acknowledges some overlap between matters but notes that its earlier comments pertained to a specific issue. The Consumer Advocate is concerned about the impact of excluding certain questions on the explanation of a cybersecurity incident.

Section 4 p. p. 0
he Board's ability to explain the cybersecurity incident to customers about NS Power in this proceeding and noted that considerations in one matter may be relevant to conclusions reached in the other. In response to the submissions from th...

AI summary The Board discussed NS Power's explanation of a cybersecurity incident and the relevance of considerations across different proceedings. NS Power emphasized the importance of procedural fairness, particularly in the context of technical and confidential matters, and clarified the focus of the current proceeding on the impact of the cyber incident on customer information, billing, and communications.

102158Board Decision Letter - Request for Pre-Approval of Intervener Costs 1 passage
Section 5 p. p. 0
ings the ability to arrange for a demonstration of its virtual platform in advance to ensure that the participants are familiar with its systems and to address any technical issues before the hearing. To conclude, the Board's experience wi...

AI summary The Board emphasizes the effectiveness of virtual processes in reducing costs and encourages participation via its virtual platform. It also addresses the adequacy of NS Power's cybersecurity policies, detection and response to a breach, and remedial measures.

102252Amended Hearing Order 1 passage
AMENDED HEARING ORDER
AMENDED HEARING ORDER On December 3, 2025, the Honourable Tim Houston, Premier of Nova Scotia and Minister of Energy, wrote to the Nova Scotia Energy Board to express concern about the number of Nova Scotians experiencing inaccurate billin...

AI summary The Nova Scotia Energy Board amended the hearing order for a proceeding concerning inaccurate billing and lack of responsiveness from NS Power following a cybersecurity breach. The Board is addressing the matter through an oral hearing, with dates set for August 2026, and has directed NS Power to respond to certain intervenor requests.

100224Letter from Peter Gregg in response to Premier Houston's letter 2 passages
Section 1 p. p. 0
December 8, 2025 Stephen McGrath, K.C.; Chair c/o Crystal Henwood; Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax NS, B3J 3P6 Re: M12273 – Nova Scotia Power's Cybersecurity Incident I write to the No...

AI summary Nova Scotia Power acknowledges a recent cybersecurity incident that has caused customer disruptions and billing concerns. The company is committed to addressing the issues and restoring customer trust. They also agree with Premier Houston's call for a review of estimated billing practices and are committed to transparency in providing information to the NSEB and customers.

Section 2 p. p. 0
estimated billing and believe the type of review suggested by the Premier is an important step forward and we are committed to transparently providing this information to the NSEB and our customers. Nova Scotia Power views the NSEB Inquiry...

AI summary Nova Scotia Power acknowledges the Premier's concerns regarding estimated billing and customer communications following a cybersecurity incident. They confirm that the NSEB Inquiry (M12273) is the appropriate process to address these issues and have provided updates in their Incident Reports. They emphasize their commitment to resolving any billing mistakes and improving customer communication.

100260Board letter re: acknowledgment and response 1 passage
M12600 – Minister of Energy – Accountability for Nova Scotia Power Incorporated p. pp. 0-1
M12600 – Minister of Energy – Accountability for Nova Scotia Power Incorporated I acknowledge receipt of your letter to the Energy Board on December 3, 2025, expressing concern about the number of Nova Scotians who are experiencing inaccur...

AI summary The Energy Board acknowledges a letter regarding NS Power's billing inaccuracies and lack of responsiveness following a cyber-attack. The Board will investigate the fairness of estimated billing, consumer protections, system restoration timelines, financial relief options, and potential penalties. It also references ongoing cybersecurity inquiries and independent assessments.

100848Board letter outlining process the NSEB intends to follow 5 passages
M12273 – Board Inquiry into Nova Scotia Power's Cybersecurity Incident and M12600 – Minister of Energy – Accountability for Nova Scotia Power p. p. 0
M12273 – Board Inquiry into Nova Scotia Power's Cybersecurity Incident and M12600 – Minister of Energy – Accountability for Nova Scotia Power This letter outlines the processes the Nova Scotia Energy Board intends to follow for Matter M122...

AI summary The Nova Scotia Energy Board outlines its approach to two matters: M12273, an inquiry into Nova Scotia Power's cybersecurity incident, and M12600, addressing the Minister of Energy's accountability for NS Power. The Board will handle these as separate proceedings, focusing on technical aspects of the cybersecurity incident and NS Power's customer relations and regulatory compliance.

M12273 – Board Inquiry into Nova Scotia Power's Cybersecurity Incident p. p. 0
M12273 – Board Inquiry into Nova Scotia Power's Cybersecurity Incident This proceeding will review technical aspects of the cybersecurity incident, including the reasonableness of the following: - a. NS Power's cybersecurity assets and sys...

AI summary The Board is conducting an inquiry into Nova Scotia Power's cybersecurity incident, focusing on the reasonableness of its cybersecurity assets, policies, training, response, recovery actions, and post-incident enhancements.

M12600 – Minister of Energy – Accountability for Nova Scotia Power p. p. 0
M12600 – Minister of Energy – Accountability for Nova Scotia Power This proceeding will review the reasonableness of NS Power's actions relating to the following: - a. Collection and retention of customer information - b. Measures implemen...

AI summary This proceeding reviews the reasonableness of NS Power's actions regarding customer information handling, fraud mitigation after a cybersecurity incident, billing accuracy, and impacts on operations and regulatory processes, including the transition to IESO Nova Scotia.

Next Steps in Matter M12273 p. p. 1
Next Steps in Matter M12273 As noted in the Board's letter dated July14, 2025, MNP Digital has been engaged to assist with this proceeding. The Board anticipates that MNP will prepare and file a report addressing NS Power's formal Incident...

AI summary The Board has engaged MNP Digital to assist with the proceeding, including preparing a report on NS Power's Incident Report. A Hearing Order will be issued once the report is filed, leading to an oral hearing.

Next Steps in Matter M12600 p. p. 1
Next Steps in Matter M12600 A Hearing Order for this proceeding is being issued at this time, leading to an oral hearing in mid- to late-summer. Pending the completion of this proceeding, NS Power is directed to file update reports at the...

AI summary The proceeding, Matter M12600, will proceed with an oral hearing in mid- to late-summer following the issuance of a Hearing Order. NS Power is required to submit monthly update reports detailing cybersecurity incident impacts, restoration progress, and vendor payments.

100852NS Power's Monthly Update #1 (M12273) 1 passage
Section 1 p. p. 0
August 20, 2025 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power's Cybersecurity Incident - Monthly Update 1 Dear Ms. Henwood: On July 14, 202...

AI summary Nova Scotia Power (NS Power) has experienced a cybersecurity incident that allowed unauthorized access to its IT infrastructure. The Nova Scotia Energy Board (NSEB) required NS Power to file monthly progress reports on its response and the preparation of an Incident Report. The incident did not affect physical operations or service reliability.

100853NS Power's Monthly Update #2 (M12273) 12 passages
Preamble p. p. 0
October 1, 2025 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power's Cybersecurity Incident – Monthly Update 2 Dear Ms. Henwood: On July 14, 202...

AI summary This document is a monthly update from Nova Scotia Power regarding its response to a cybersecurity incident. The Nova Scotia Energy Board directed the company to submit monthly progress reports until the Incident Report is filed by December 31, 2025. This update includes information on the Recovery Program Office, incident impact, regulatory matters, and timelines.

Cybersecurity p. p. 0
Cybersecurity The operation of cybersecurity capabilities is a critical aspect of recovery, ensuring that business services are restored in a secure and controlled manner. As technology services are reintroduced, the cybersecurity team val...

AI summary Cybersecurity is emphasized as essential during recovery operations to ensure secure restoration of business services. The cybersecurity team validates controls as technology services are reintroduced, with additional information provided in NS Power's response to NSEB IR-01(a) (M12273).

Technology Enablement p. p. 0
Technology Enablement The Incident disrupted foundational technology services, which created dependencies that impacted the restoration of some business functions and required employees to rely on contingency solutions. To address these ch...

AI summary The Incident disrupted foundational technology services, leading to dependencies that impacted business functions. A secure network rebuild, device re-imaging, and backup programs are underway to restore operations and ensure continuity.

Recovery Program Office p. p. 0
Recovery Program Office The RPO has continued to advance recovery activities across all major business and technology areas. The RPO was established following the incident response to coordinate recovery and restoration efforts across the...

AI summary The Recovery Program Office (RPO) was established to coordinate recovery and restoration efforts after an incident. It manages program delivery, regulatory and insurance obligations, resourcing, internal controls, cybersecurity, enterprise architecture, organizational change management, reporting, and data privacy across all major business and technology areas.

CIS Replacement Project p. pp. 5-6
CIS Replacement Project As noted by the NSEB in its letter of September 17, 2025, the CIS replacement capital project has been delayed by the Incident. NS Power said its investigation into the cybersecurity incident "could impact the direc...

AI summary The CIS replacement project has been delayed due to a cybersecurity incident, as noted by the NSEB and confirmed by NS Power. NS Power provided an updated project timeline in its compliance filing for M11884.

NS-NB Reliability Intertie p. p. 6
NS-NB Reliability Intertie In the NS-NB Reliability Intertie capital project proceeding (M12217), NS Power, on behalf of Wasoqonatl Transmission Incorporated, produced various sensitivity analyses in response to IRs. Midgard, the consultan...

AI summary In the NS-NB Reliability Intertie capital project proceeding (M12217), NS Power, on behalf of Wasoqonatl Transmission Incorporated, resubmitted sensitivity analyses after a cyber incident affected their IT systems. Despite minor differences in results, the cost variance was less than 0.5% of the System NPVRR, and the reliability intertie was confirmed as the lowest cost long-term solution for the NS electricity system.

Financial Reporting and Statements p. p. 6
Financial Reporting and Statements Automated financial reporting and statements have been affected by the cybersecurity incident. Similar to the issue noted above under Capital Budgeting/Finance Data , certain financial systems and data ar...

AI summary Automated financial reporting and statements have been affected by a cybersecurity incident, leading to the use of forecast figures for certain unregulated adjustments. NS Power expects actual figures to be available by the end of 2025, with no expected impact on customers.

Fuel Adjustment Mechanism p. p. 8
available for reporting. This was conveyed in the Q2 FAM report filed on August 18, 2025, tab Q13 footnote 2. An update to this was provided during the FAM SWG meeting on September 26, 2025, stating: The cause codes during the period were...

AI summary The Q2 FAM report highlights disruptions due to a cybersecurity event affecting dispatch processes, with Cause Code 5 and 3 being recorded. NSP Marketing resumed providing real-time dispatch schedules on August 5. The Dispatch Study Action Plan was impacted, delaying the ECC Optimization Tools project, with new implementation dates yet to be determined.

Hosting Capacity Map and Analysis p. p. 9
Hosting Capacity Map and Analysis As noted by the NSEB in its letter of September 17, 2025, the hosting capacity map and analysis has been affected by the cybersecurity incident. In its report on the Hosting Capacity Analysis Stakeholder W...

AI summary The hosting capacity map and analysis have been impacted by a cybersecurity incident, preventing updates to online maps and displays. NS Power is working offline to update data and models to ensure accurate information for distribution connection requests.

E1's Residential Behaviour Program p. p. 9
E1's Residential Behaviour Program As noted by the NSEB in its letter of September 17, 2025, the ability to provide relevant customer data to Efficiency One (E1) has been affected by the cybersecurity incident. Customer consumption data de...

AI summary The NSEB informed E1 that a cybersecurity incident has disrupted access to customer data from AMI meters and the MEI platform, impacting E1's programs. NS Power is working to restore data flows by 2026 and is discussing interim solutions with E1.

System Planning p. p. 9
System Planning In response to Natural Forces IR-1 (and Energy Storage Canada IR-5) under the 2025 Evergreen IRP Action Plan and Roadmap Update proceeding (M12247), NS Power advised of its inability to access certain historical and simulat...

AI summary NS Power informed the proceeding that it cannot access certain historical and simulated data due to a cyber incident affecting its IT systems. It provided alternative data from the NS-NB Reliability Intertie model and the 2023 Load Forecast Report, and stated that this issue is not expected to impact customers.

Miscellaneous p. pp. 9-14
Miscellaneous Nova Scotia Power Maritime Link Q2 2025 Quarterly Report As noted by the NSEB in its letter of September 17, 2025, the detailed allocation between the Maritime Link Project and sustaining capital costs is unavailable at this...

AI summary The cybersecurity incident at NS Power affected NSPML's ability to provide a detailed allocation between the Maritime Link Project and sustaining capital costs. NSPML confirmed that the incident did not impact operations but limited IT access to data. Restoration efforts are ongoing, and no O&M costs for 2026 are expected to be affected.

100854NS Power's Monthly Update #3 (M12273) 2 passages
Preamble p. p. 0
November 3, 2025 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power's Cybersecurity Incident – Monthly Update 3 Dear Ms. Henwood: On July 14, 20...

AI summary NS Power is providing its third monthly update to the Nova Scotia Energy Board regarding its response to a recent cybersecurity incident. The report outlines progress made and confirms that the Incident Report will be submitted by December 31, 2025, as directed by the Board.

Customer Notifications p. p. 0
Customer Notifications As noted in NS Power's September 5, 2025 response to IR-2 in NSEB M12273, NS Power has been actively investigating the cybersecurity incident with the assistance of leading third-party data analysis experts to determ...

AI summary NS Power is investigating a cybersecurity incident with third-party experts and is notifying affected customers. They are offering credit monitoring to impacted individuals, with five years of free monitoring available to all customers since June 2025.

100855NS Power's Monthly Update #4 (M12273) 3 passages
Preamble p. p. 0
December 1, 2025 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power's Cybersecurity Incident – Monthly Update 4 Dear Ms. Henwood: On July 14, 20...

AI summary NS Power is providing its fourth monthly update on its response to a cybersecurity incident, including progress on settling vendor dues and preparing an Incident Report by year-end. The NSEB has directed NS Power to include specific charts in the report, such as a Gantt chart and a list of impacted Board matters.

Joint-Use Agreement Proceeding p. pp. 3-6
e to formally create new tracking data for service times for power connections as effectively as before, as the links between applications used to track this information are currently unavailable. // As noted in responses to part (b) and (...

AI summary NS Power is unable to track installation timelines effectively due to a recent cyber incident that has disrupted application links. The incident has limited access to data on service times for power connections, and the first quarterly Point of Construction Settlement has not been completed as systems are being rebuilt.

Opening statement p. p. 7
Opening statement Thank you for inviting us to today's committee meeting. I'm joined today by our Director of Customer Care, Chris Lanteigne. At Nova Scotia Power, our commitment to providing reliable power to Nova Scotians has been unwave...

AI summary Nova Scotia Power acknowledges the impact of a recent cyber event on customer trust and service, committing to rectify billing inaccuracies and emphasizing the sophistication of the attack attributed to a Russia-based threat actor. The company highlights its ongoing cybersecurity investments and uninterrupted grid operations.

100856NS Power's Monthly Update #5 (M12273) 6 passages
Preamble p. pp. 0-16
February 5, 2026 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power's Cybersecurity Incident – Monthly Update 5 Dear Ms. Henwood: On July 14, 20...

AI summary Nova Scotia Power (NS Power) submitted Monthly Update 5 to the Nova Scotia Energy Board (NSEB), detailing progress on its cybersecurity incident response and Incident Report. The update includes an updated Gantt Chart (Attachment 1) and a revised table for Ongoing Regulatory Matters (Attachment 2), with plans to continue updating these documents. NS Power emphasizes transparency and ongoing compliance.

Technology Enablement p. p. 0
Technology Enablement NS Power has continued to strengthen foundational technology required to support core business operations. Key integrations across operational systems have been restored, and work to restore and further fortify networ...

AI summary NS Power has enhanced core technology infrastructure, restored system integrations, and advanced disaster recovery preparations. Efforts include replacing virtual firewalls with physical devices to improve reliability and configuring disaster recovery infrastructure to support system resiliency.

Cybersecurity p. p. 0
Cybersecurity NS Power is continuing to advance and strengthen overall cybersecurity readiness, to restore and validate critical cybersecurity control effectiveness.

AI summary NS Power is enhancing cybersecurity readiness and restoring critical control effectiveness to strengthen overall cybersecurity posture.

— PROGRAM ST DUCTIOE p. p. 0
— PROGRAM ST DUCTIOE — РКОВКА М ЗТ RUCIURE — The Restoration Program is structured into five (5) key portfolios of work – focusing on restoring business capabilities. Portfolio Scope Summary Enterprise Resource Planning (ERP) Recovery and...

AI summary The Restoration Program is divided into five key portfolios: Enterprise Resource Planning (ERP), Customer, Additional Capabilities, Cybersecurity, and Technology Enablement, each focusing on restoring critical business systems and operations.

The following projects experienced adjustments to their completion timeline. An overview of the changes and associated rationale is outlined below: p. p. 6
The following projects experienced adjustments to their completion timeline. An overview of the changes and associated rationale is outlined below: Pillar Project Summary of Change Rationale Cybersecurity MDR MDR target completion date was...

AI summary Adjustments to project completion timelines have been made due to changes in scope and the inclusion of new third-party services. The Cybersecurity pillar's MDR and VM projects have been delayed, and updates to affected regulatory matters have been reported.

b. Customer support mechanisms and communication strategies in the event of system issues. p. p. 16
b. Customer support mechanisms and communication strategies in the event of system issues. • As noted in (1), recognizing that the estimated billing process raised concerns amongst our customers, we have supported flexible options such as...

AI summary NS Power outlines customer support measures, including flexible billing options, community sessions, and communication strategies post-cyberattack. Efforts focus on reducing disconnections, improving transparency, and collaborating with regulators. Cybersecurity investments and stakeholder engagement are emphasized to address billing concerns and maintain grid reliability.

100870Hearing Order 1 passage
HEARING ORDER
HEARING ORDER On December 3, 2025, the Honourable Tim Houston, Premier of Nova Scotia and Minister of Energy, wrote to the Nova Scotia Energy Board to express concern about the number of Nova Scotians experiencing inaccurate billing and a...

AI summary The Nova Scotia Energy Board has opened a new matter (M12600) following concerns raised by the Premier about inaccurate billing and lack of responsiveness from NS Power after a cybersecurity breach. A public hearing is scheduled for July 2026 to address the issue.

100871Notice of Public Hearing 1 passage
NOTICE OF PUBLIC HEARING p. p. 0
NOTICE OF PUBLIC HEARING _______________________________________________________________________________ IN THE MATTER OF AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of cus...

AI summary A public hearing is scheduled to examine the impact of a cyber incident on Nova Scotia Power Incorporated's data collection, customer service, billing processes, and regulatory matters. The hearing will take place from July 27 to July 29, 2026, at the Office of the Board in Halifax.

101156NSPI Monthly Update Report #6 (M12273) 4 passages
Preamble p. p. 0
March 6, 2026 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power's Cybersecurity Incident – Monthly Update 6 Dear Ms. Henwood: On July 14, 2025,...

AI summary This document is a monthly update from Nova Scotia Power to the Nova Scotia Energy Board regarding the company's response to a cybersecurity incident that occurred in the spring of 2025. It includes an updated Restoration Roadmap Gantt Chart and other attachments related to ongoing regulatory matters and invoices on hold.

Technology Enablement p. p. 0
Technology Enablement Progress has continued in strengthening the technology environment that supports core business operations and resilience objectives. Disaster recovery infrastructure has been configured and deployed, with backup and c...

AI summary The document highlights ongoing progress in enhancing the technology environment to support core business operations and resilience. Key initiatives include the deployment of disaster recovery infrastructure, network and security improvements, and the establishment of a fully operational Backup and Disaster Recovery (BDR) site.

Cybersecurity p. p. 0
Cybersecurity NS Power is continuing to advance and strengthen overall cybersecurity readiness, with a focus on restoring, implementing, and validating critical cybersecurity control effectiveness. Control implementation activities are act...

AI summary NS Power is enhancing its cybersecurity readiness by focusing on restoring, implementing, and validating critical controls across various domains, with mitigation plans in place for remaining risks, aligned with regulatory and assurance expectations.

PROGRAM STRUCTURE p. p. 0
PROGRAM STRUCTURE The Restoration Program is structured into five (5) key portfolios of work – focusing on restoring business capabilities. Portfolio Scope Summary Enterprise Resource Planning (ERP) Recovery and restoration of core enterpr...

AI summary The Restoration Program is organized into five portfolios focused on restoring business capabilities: Enterprise Resource Planning (ERP), Customer, Additional Capabilities, Cybersecurity, and Technology Enablement. Each portfolio outlines specific systems and operations to be recovered and restored.

101209Preliminary Issues List 1 passage
PRELIMINARY ISSUES LIST
PRELIMINARY ISSUES LIST The following issues will be dealt with in the public hearing on Board inquiry on Matter M12600 - Minister of Energy – Accountability for Nova Scotia Power, which is set to begin Monday, July 27, 2026: - 1. Privacy...

AI summary The preliminary issues list outlines topics to be discussed in a public hearing regarding Nova Scotia Power's accountability, focusing on privacy policies, governance, cybersecurity incidents, billing accuracy, and regulatory impacts.

101317Notice of intervention - MEUs 1 passage
NOVA SCOTIA ENERGY BOARD
NOVA SCOTIA ENERGY BOARD IN THE MATTER OF: The Public Utilities Act – and – IN THE MATTER OF: An Inquiry about the impact of the cyber incident on Nova Scotia Power Incorporated's collection and retention of customer information, customer...

AI summary The Nova Scotia Energy Board is conducting an inquiry into the impact of a cyber incident on Nova Scotia Power Incorporated's handling of customer information, customer service, billing processes, and regulatory matters.

101325Participant List - Updated June 26 1 passage
IN THE MATTER OF THE PUBLIC UTILITIES ACT
IN THE MATTER OF THE PUBLIC UTILITIES ACT - and - IN THE MATTER OF AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer information, customer service and communications,...

AI summary This document concerns an inquiry into the impact of a cyber incident on Nova Scotia Power Incorporated's handling of customer information, customer service, billing processes, and regulatory matters.

101333Comments on preliminary issues list - NS Power 2 passages
Issues p. p. 0
Issues - (1) Privacy policies and procedures development, implementation, and adherence, including, but not limited to: - (i) Privacy training and percentage of staff that completed privacy training; - (ii) Policies for receiving and respo...

AI summary The issues outlined pertain to privacy policies, governance, risk management, breach response, data collection, and third-party involvement in a privacy-related incident. Key areas include training, complaint procedures, breach containment, reporting, and mitigation of fraud risks.

Issues within Scope of M12273 p. p. 0
Issues within Scope of M12273 Furthermore, with respect to Issue 3, NS Power notes that issues relating to NS Power's measures to detect a "privacy breach", and the measures implemented to contain the incident (a sophisticated ransomware a...

AI summary NS Power highlights that issues related to privacy breach detection and containment measures following a ransomware attack are being addressed in a separate proceeding (M12273), distinct from M12600. The Board has engaged MNP Digital to review these matters, and NS Power is cooperating with the Board to ensure these issues are adequately addressed.

101334Comments on preliminary issues list - CA 1 passage
Section 1 p. p. 0
Please refer to: David Roberts Email: [[email protected]](mailto:[email protected]) Assistant: Alissa Whalen Assistant's email: [[email protected]](mailto:[email protected]) March 23, 2026 VIA WEB PORTAL VIA EMAIL Cry...

AI summary The Consumer Advocate proposes adding two issues to the Preliminary Issues List for M12600: the impact of a cyber security incident on Nova Scotia Power's billing accuracy and the measures considered to maintain revenue from customer billing.

101377Board Letter re: Final Issues List 1 passage
Section 1 p. p. 0
March 25, 2026 By Email Parties M12600 Dear Parties: M12600 – Minister of Energy – Accountability for Nova Scotia Power – Final Issues List Further to the above noted matter, please find enclosed the Final Issues List for this matter. The...

AI summary The Board has revised Issue #8 in the Final Issues List for M12600 to include the impact of a cybersecurity incident on Nova Scotia Power's billing accuracy, as proposed by the Consumer Advocate, and to consider alternative billing measures and seasonal adjustment logic.

101378Final Issues List 2 passages
IN THE MATTER OF THE PUBLIC UTILITIES ACT
IN THE MATTER OF THE PUBLIC UTILITIES ACT - and - IN THE MATTER OF AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer information, customer service and communications,...

AI summary This regulatory proceeding concerns an inquiry into the impact of a cyber incident on Nova Scotia Power Incorporated's handling of customer information, customer service, billing processes, and regulatory matters.

FINAL ISSUES LIST
FINAL ISSUES LIST The following issues will be dealt with in the public hearing on Board inquiry on Matter M12600 - Minister of Energy – Accountability for Nova Scotia Power, which is set to begin Monday, July 27, 2026: - 1. Privacy polici...

AI summary The final issues list outlines key topics for a public hearing on Matter M12600, focusing on privacy policies, governance, risk management, customer data handling, cybersecurity incident impacts, billing accuracy, and regulatory implications related to Nova Scotia Power.

101404Notice of Intervention - David MacLeod 3 passages
\ \ EXTERNAL EMAIL / COURRIEL EXTERNE \ \
\ \ EXTERNAL EMAIL / COURRIEL EXTERNE \ \ Exercise caution when opening attachments or clicking on links / Faites preuve de prudence si vous ouvrez une pièce jointe ou cliquez sur un lien Good afternoon, I'm writing to inform you of my app...

AI summary The email is from a residential customer of Nova Scotia Power who is applying for Formal Intervenor Status in M12600 - Inquiry into Nova Scotia Power's Cybersecurity Incident. The applicant is concerned about the breach of their sensitive personal information and their professional background as a former Intelligence Analyst.

Request for Formal Intervenor Status
Request for Formal Intervenor Status To: Clerk of the Board, Nova Scotia Energy Board Matter: M12600 - Inquiry into Nova Scotia Power's Cybersecurity Incident Date: March 26, 2026

AI summary A request for formal intervenor status in the Inquiry into Nova Scotia Power's Cybersecurity Incident, matter number M12600, filed on March 26, 2026.

3. Issues to be Addressed
3. Issues to be Addressed I intend to address the "Reasonableness of Nova Scotia Power's Preparedness" by analyzing the gap between publicly available geopolitical threat assessments and NSP's security posture. Specifically: - a) The Forec...

AI summary The document outlines issues related to the reasonableness of Nova Scotia Power's (NSP) preparedness, focusing on gaps between threat assessments and NSP's security measures, data retention practices, and detection latency in a cyber breach.

101524David MacLeod (NSPI) IR A-1 to G-5 39 passages
Preamble
In the Matter of: THE PUBLIC UTILITIES ACT, R.S.N.S. 1989, c.380, as amended – and – In the Matter of: AN INQUIRY concerning the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer informat...

AI summary This proceeding concerns an inquiry into the impact of a cyber incident on Nova Scotia Power Incorporated's handling of customer information, customer service, billing processes, and regulatory matters.

PREAMBLE AND INSTRUCTIONS TO RESPONDENT
PREAMBLE AND INSTRUCTIONS TO RESPONDENT - 1. These Information Requests (hereinafter "IRs" or "Interrogatories") are submitted pursuant to - the Nova Scotia Energy Board Act, S.N.S. 2021, c. 3, and the Nova Scotia Energy Board Rules - of P...

AI summary The Nova Scotia Energy Board has issued Information Requests to Nova Scotia Power Inc. regarding a cybersecurity incident that occurred in March 2025. NSP is required to provide detailed, accurate, and non-evasive responses, with specific procedures for handling confidential or privileged information.

DEFINITIONS
DEFINITIONS - For the purposes of these Interrogatories, the following definitions apply: - "Advanced Persistent Threat" or "APT" means a prolonged and targeted cyber intrusion in - which an attacker establishes an undetected presence in a...

AI summary The document defines key terms related to cybersecurity, including Advanced Persistent Threats, Advanced Metering Infrastructure, and Critical Infrastructure, in the context of a ransomware attack on NSP. It references the Incident Report filed with the NSEB and mentions cybersecurity agencies like CISA and CCCS.

Nova Scotia Energy Board
Nova Scotia Energy Board - 1 "UARB" means the Utility and Review Board, predecessor to the NSEB, before which NSP - 2 filed its IT-OT Cyber Security Control Implementation Phase 1 plan on February 27, 2025.

AI summary The document references the filing of an IT-OT Cyber Security Control Implementation Phase 1 plan by NSP with the predecessor of the NSEB, the Utility and Review Board, on February 27, 2025.

EVIDENTIARY FOUNDATION AND DISCUSSION
EVIDENTIARY FOUNDATION AND DISCUSSION - A. The Published Threat Landscape (2015–2025) - The following discussion summarizes the publicly available and authoritative threat intelligence - that NSP, as a regulated critical infrastructure ope...

AI summary This section outlines the published threat landscape from 2015 to 2025, emphasizing warnings from the Canadian Centre for Cyber Security (CCCS) regarding escalating cyber threats, especially from Russian-nexus actors, to Canada's critical infrastructure, including the electricity sector.

A.3 Corporate Threat Intelligence
A.3 Corporate Threat Intelligence - Dragos OT/ICS Cybersecurity Year in Review (Dragos, Inc., 2024; 2025): Dragos, the - leading industrial cybersecurity firm, tracked 26 active OT-focused threat groups as of - 2025. Russian-nexus groups i...

AI summary The document highlights cybersecurity threats to critical infrastructure, particularly electric utilities, with a focus on OT networks. Russian-nexus threat groups like ELECTRUM, KAMACITE, and VOLTZITE are actively targeting Western infrastructure. Only 30% of OT networks have sufficient visibility to detect threats, and 56% lack visibility beyond the IT/OT boundary, a vulnerability exploited in the NSP Attack. There has also been a 44% increase in exploitation of public-facing applications and active ransomware groups.

A.4 The Ukrainian Grid Attacks as Proof of Concept
A.4 The Ukrainian Grid Attacks as Proof of Concept - The academic and technical literature establishes beyond reasonable dispute that Russian-nexus - actors demonstrated both the capability and the intent to attack electricity infrastructu...

AI summary The text discusses the Ukrainian grid attacks as proof of concept, highlighting the capability and intent of Russian-nexus actors to attack electricity infrastructure. It outlines three major cyberattacks: the 2015 BlackEnergy/Sandworm attack, the 2016 Industroyer/CRASHOVERRIDE attack, and the 2022 Industroyer2 attack, all attributed to Sandworm, a GRU-affiliated group.

B. NSP's Acknowledged Risk and Inadequate Response
B. NSP's Acknowledged Risk and Inadequate Response - The evidentiary record before the Board contains a critical and damaging admission. On - February 27, 2025 NSP's Chief Operating Officer, Dave Pickles, filed a report with the UARB - tit...

AI summary Nova Scotia Power (NSP) acknowledged the rising cybersecurity threats but failed to implement a comprehensive response. Their plan focused only on operational technology (OT) systems, ignored IT systems and customer data, and did not address specific Russian-nexus threats. The breach went undetected for 37 days, and NSP lacked a backup site, leading to long-term system impairments and data exposure.

C. The Standard of Reasonableness Applied
C. The Standard of Reasonableness Applied - The NSEB is asked to apply the standard of the reasonably prudent regulated utility operator - in assessing NSP's preparedness. This standard requires that NSP: - 1. Monitor and act upon publicly...

AI summary The NSEB is required to assess NSP's cybersecurity preparedness using the standard of a reasonably prudent regulated utility operator. This includes monitoring threat intelligence, implementing cybersecurity controls, maintaining detection capabilities, protecting customer data, ensuring business continuity, and complying with regulatory frameworks.

GROUP A — PRE-ATTACK THREAT AWARENESS AND GOVERNANCE
GROUP A — PRE-ATTACK THREAT AWARENESS AND GOVERNANCE - These Interrogatories address NSP's governance structures, threat intelligence practices, and - executive accountability for cybersecurity prior to March 19, 2025. They are grounded in...

AI summary This section outlines interrogatories related to NSP's governance, threat intelligence, and executive accountability for cybersecurity before March 19, 2025, based on the 'knew or ought to have known' standard and NSP's awareness of the threat environment.

IR A-1 — Threat Intelligence Program
IR A-1 — Threat Intelligence Program - (a) Did NSP maintain a formal threat intelligence program prior to March 19, 2025? If so, - provide a complete description of that program, including: - (i) the organizational unit responsible for thr...

AI summary The document outlines questions regarding Nova Scotia Power's (NSP) threat intelligence program, including its existence prior to March 19, 2025, its structure, threat intelligence sources, escalation processes, and efforts to collaborate with the Communications Security Establishment (CSE). It also asks whether NSP sought a Ministerial Designation for cybersecurity support.

IR A-2 — CCCS National Cyber Threat Assessments
IR A-2 — CCCS National Cyber Threat Assessments - (a) Confirm whether NSP reviewed each of the following CCCS publications prior to March - 19, 2025: (i) National Cyber Threat Assessment 2018; (ii) CCCS Cyber Threat Bulletin: The Cyber Thr...

AI summary The document requests Nova Scotia Power (NSP) to confirm whether it reviewed several cybersecurity threat assessments and advisories from the Canadian Centre for Cyber Security (CCCS) and the United States Cybersecurity and Infrastructure Security Agency (CISA). It also asks for details on the analysis conducted, any implemented cybersecurity measures, and internal documentation related to these reviews.

IR A-4 — Russian-Nexus Threat Awareness
IR A-4 — Russian-Nexus Threat Awareness - (a) Prior to March 19, 2025, did NSP's cybersecurity program specifically address the threat posed by Russian-nexus threat actors, including: - (i) GRU-affiliated groups (Sandworm/ELECTRUM, APT28);...

AI summary The proceeding document inquires whether NSP's cybersecurity program addressed Russian-nexus threat actors, including specific groups like GRU, FSB, ransomware collectives, and pro-Russia hacktivists, prior to March 19, 2025, and requests documentation of threat modeling and risk assessments conducted.

IR A-5 — Board of Directors and Executive Accountability
IR A-5 — Board of Directors and Executive Accountability - (a) Describe the governance structure for cybersecurity at NSP prior to March 19, 2025, - including: - (i) the role and responsibilities of the Chief Information Security Officer (...

AI summary The document requests details on NSP's cybersecurity governance structure prior to March 19, 2025, including the role of the CISO, cybersecurity briefings to the Board and Executive Leadership Team, and the most recent cybersecurity risk assessment. It also requests meeting minutes, presentations, and a cybersecurity risk register.

IR A-6 — The February 27, 2025 UARB Filing
IR A-6 — The February 27, 2025 UARB Filing - (a) NSP's Chief Operating Officer filed a report titled IT – OT Cyber Security Control - Implementation Phase 1 with the UARB on February 27, 2025, twenty days before the - Attack. With respect...

AI summary The document requests an explanation of NSP's cybersecurity plan focusing on OT systems and excludes IT systems, customer data systems, and billing platforms. It also asks about the review and approval of the plan's scope, existing cybersecurity controls for excluded systems, consideration of the NCTA 2025-2026 report, risk assessments for IT and customer data systems, and related documentation. Additionally, it seeks information on steps taken by NSP between February 27, 2025, and March 19, 2025, to address cybersecurity risks.

GROUP B — IT/OT ARCHITECTURE AND NETWORK SEGMENTATION
GROUP B — IT/OT ARCHITECTURE AND NETWORK SEGMENTATION - These Interrogatories address the technical architecture of NSP's IT and OT environments, the - degree of segmentation between them, and the vulnerability of NSP's systems to the atta...

AI summary This section of the document focuses on the IT/OT architecture and network segmentation of Nova Scotia Power (NSP), emphasizing the importance of proper segmentation in preventing ransomware attacks on utility systems.

IR B-1 — Network Architecture Documentation
IR B-1 — Network Architecture Documentation - (a) Produce a network architecture diagram depicting NSP's IT and OT environments as they existed on March 18, 2025 (the day before the Attack), including: - (i) the boundaries between IT and O...

AI summary The document requests a network architecture diagram of NSP's IT and OT environments as of March 18, 2025, including network segmentation, external access points, and connections to third-party systems. NSP may request confidential treatment but must provide a summary for the Board and MNP Digital to assess the architecture's adequacy.

IR B-2 — IT/OT Segmentation
IR B-2 — IT/OT Segmentation - (a) Describe the segmentation controls that existed between NSP's IT and OT networks as of March 18, 2025. - (b) NSP's Monthly Update 6 (March 2026) disclosed that post-attack remediation included "the continu...

AI summary The document requests details about IT/OT network segmentation controls at NSP as of March 2025, the replacement of virtual firewalls with physical devices post-attack, and the attack path used by the threat actor, including failed segmentation controls.

IR B-3 — Remote Access Infrastructure
IR B-3 — Remote Access Infrastructure - (a) Describe all remote access mechanisms in use at NSP as of March 18, 2025, including: - (i) VPN solutions, including vendor, version, and patch level; - (ii) Remote Desktop Protocol (RDP) exposure...

AI summary The document requests details on NSP's remote access mechanisms as of March 18, 2025, including specific technologies, security measures, and compliance with CISA advisory AA22-110A. It also asks whether a remote access mechanism was involved in a cyberattack and which one.

IR B-4 — Third-Party and Supply Chain Risk
IR B-4 — Third-Party and Supply Chain Risk (a) Identify all third-party vendors, managed service providers, and contractors with network access to NSP's IT or OT environments as of March 18, 2025. explain why. - (b) Describe NSP's third-pa...

AI summary The document outlines a regulatory inquiry into third-party and supply chain risk, specifically focusing on NSP's cybersecurity practices. It requests information on vendors, the cybersecurity risk management program prior to an attack, and whether the attack involved third-party access.

IR B-5 — AMI and Smart Meter Infrastructure
IR B-5 — AMI and Smart Meter Infrastructure - (a) Describe the cybersecurity architecture of NSP's AMI system as of March 18, 2025, - including the network connectivity between field devices, head-end systems, and billing - platforms. - (b...

AI summary The document outlines questions regarding the cybersecurity architecture of NSP's AMI system, the impact of a ransomware attack on AMI connectivity, and the measures in place for cybersecurity risk assessment and segmentation controls.

GROUP C — THREAT DETECTION AND INCIDENT RESPONSE
GROUP C — THREAT DETECTION AND INCIDENT RESPONSE - These Interrogatories address NSP's capability to detect intrusions and respond to cybersecurity - incidents. The 37-day detection gap — from initial intrusion on March 19, 2025 to NSP's -...

AI summary The text discusses NSP's capability to detect intrusions and respond to cybersecurity incidents, highlighting a 37-day detection gap from March 19, 2025, to late April 2025, which is a central issue in the proceeding.

IR C-1 — Security Monitoring and Detection Capabilities
IR C-1 — Security Monitoring and Detection Capabilities - (a) Describe NSP's security monitoring and threat detection capabilities as they existed on - March 18, 2025, including: - (i) Security Information and Event Management (SIEM) syste...

AI summary The document requests details on NSP's security monitoring and detection capabilities as of March 18, 2025, including SIEM systems, EDR solutions, OT-specific tools, and SOC capabilities. It also references a report indicating limited visibility in OT networks and asks whether NSP addressed this gap prior to an attack.

IR C-2 — The 37-Day Detection Gap
IR C-2 — The 37-Day Detection Gap - (a) Provide a detailed forensic timeline of the Attack from initial intrusion to NSP's awareness, - including: - (i) the date and method of initial access; - (ii) the lateral movement path taken by the t...

AI summary The document requests a detailed forensic timeline of a cyberattack on Nova Scotia Power (NSP), including the initial intrusion, lateral movement, data exfiltration, and ransomware deployment. It also asks for an explanation of why NSP's detection systems failed to identify the attack for 37 days and the handling of security alerts between March 19, 2025, and late April 2025.

IR C-3 — Incident Response Plan
IR C-3 — Incident Response Plan - (a) Did NSP have a formal Cybersecurity Incident Response Plan (IRP) in place prior to March - 19, 2025? If so, produce the most recent version of that plan as it existed prior to the Attack. - (b) Describ...

AI summary The document requests information about Nova Scotia Power's (NSP) incident response plan, including its existence prior to March 19, 2025, its coverage of ransomware and Russian-nexus attacks, and findings from previous drills and assessments.

IR D-2 — Data Protection Controls
IR D-2 — Data Protection Controls - (a) Describe the technical and organizational controls applied to protect customer personal information prior to March 19, 2025, including: - (i) encryption of personal information at rest and in transit...

AI summary The document outlines questions regarding data protection controls implemented by Nova Scotia Power (NSP) prior to March 19, 2025, focusing on encryption, access controls, data loss prevention, and monitoring for unauthorized access. It also asks for details on NSP's response to ransomware threats and the most recent privacy impact assessment conducted.

IR D-3 — Scope of Customer Data Compromise
IR D-3 — Scope of Customer Data Compromise - (a) Provide a complete accounting of the personal information stolen in the Attack, including: - (i) the total number of customers affected; - (ii) the categories of personal information stolen...

AI summary The document requests a detailed accounting of the personal information stolen in a data breach, including affected customers, types of data compromised, and steps taken to remove the data. It also asks NSP to explain why it was not aware of the data exfiltration until notified by a third party in late April 2025 and what detection controls were in place.

IR E-1 — Backup and Disaster Recovery Infrastructure
IR E-1 — Backup and Disaster Recovery Infrastructure - (a) Describe NSP's backup and disaster recovery infrastructure as it existed on March 18, 2025, - including: - (i) the backup solutions in use for each critical system (billing, AMI, f...

AI summary The document requests Nova Scotia Power (NSP) to describe its backup and disaster recovery infrastructure as of March 18, 2025, confirm whether it had an operational off-site BDR site prior to March 19, 2025, and produce its Business Continuity and Disaster Recovery Plans. It references cybersecurity threats, including ransomware, and industry best practices.

IR F-1 — NERC CIP Compliance
IR F-1 — NERC CIP Compliance - (a) Identify which, if any, of NSP's assets are classified as Bulk Electric System (BES) Cyber - Systems subject to mandatory NERC CIP standards. - (b) For each applicable NERC CIP standard (CIP-002 through C...

AI summary The document outlines a request for information regarding Nova Scotia Power's compliance with NERC CIP standards, specifically identifying which assets are classified as BES Cyber Systems and detailing NSP's compliance status, audit findings, and remediation actions as of March 18, 2025.

IR F-2 — NIST Cybersecurity Framework
IR F-2 — NIST Cybersecurity Framework - (a) Describe NSP's adoption of the NIST Cybersecurity Framework (CSF) or equivalent - framework prior to March 19, 2025. - (b) Produce any maturity assessments conducted against the NIST CSF or equiv...

AI summary The document requests Nova Scotia Power (NSP) to describe its adoption of the NIST Cybersecurity Framework (CSF) or equivalent prior to March 19, 2025, provide maturity assessments conducted in the three years before the Attack, and detail its self-assessed maturity levels for each of the five NIST CSF functions as of March 18, 2025, along with any identified gaps and remediation plans.

IR F-3 — Third-Party Cybersecurity Assessments
IR F-3 — Third-Party Cybersecurity Assessments - (a) Identify all third-party cybersecurity assessments, audits, penetration tests, vulnerability - assessments, or red team exercises conducted for NSP in the five years prior to the Attack,...

AI summary The document requests information on third-party cybersecurity assessments conducted for Nova Scotia Power (NSP) in the five years prior to a cyberattack, including details on the firms involved, assessment scope, findings, and NSP's responses. It also asks for unaddressed findings at the time of the attack and explanations for their non-remediation.

IR F-4 — Cybersecurity Investment and Resource Allocation
IR F-4 — Cybersecurity Investment and Resource Allocation - (a) Provide NSP's cybersecurity budget for each of the five fiscal years prior to the Attack - (2020–2024), including: - (i) total cybersecurity expenditure; - (ii) allocation bet...

AI summary The document requests details on Nova Scotia Power's cybersecurity budget from 2020 to 2024, including expenditure breakdowns, staffing levels, and capital investments. It also asks about unapproved resource requests and how NSP benchmarked its cybersecurity investments against industry standards.

GROUP G — POST-INCIDENT REMEDIATION AND FORWARD COMMITMENTS
GROUP G — POST-INCIDENT REMEDIATION AND FORWARD COMMITMENTS - These Interrogatories address NSP's post-attack remediation program, the adequacy and pace - of that program, and NSP's forward commitments to prevent recurrence. They are relev...

AI summary This section addresses NSP's post-incident remediation efforts, their adequacy and pace, and forward commitments to prevent recurrence. It is relevant to the Board's evaluation of NSP's accountability and whether ratepayers should bear remediation costs.

IR G-1 — Remediation Program Scope and Governance
IR G-1 — Remediation Program Scope and Governance - (a) Produce NSP's complete post-incident remediation roadmap, including: - (i) all remediation initiatives identified; - (ii) the status of each initiative as of the date of filing; - (ii...

AI summary The remediation program scope and governance for NSP is requested, including a roadmap of initiatives, their status, completion dates, costs, and governance structure. The process for determining the scope of the program, including a gap analysis against various cybersecurity standards and threat intelligence findings, is also required.

IR G-2 — Specific Remediation Measures
IR G-2 — Specific Remediation Measures - For each of the following remediation measures referenced in NSP's Monthly Updates or - Incident Report, provide the current status, target completion date, and estimated cost: - (a) Replacement of...

AI summary The document outlines specific remediation measures required by the Nova Scotia Energy Board, including the replacement of virtual firewalls, construction of a backup and disaster recovery site, and implementation of cybersecurity enhancements. Each measure includes a request for current status, target completion date, and estimated cost.

IR G-3 — Attribution and Threat Actor Identification
IR G-3 — Attribution and Threat Actor Identification - (a) NSP's Monthly Update 6 (March 2026) and related reporting attributed the Attack to - "Russian threat actors." Provide all information available to NSP regarding the attribution - o...

AI summary The document requests Nova Scotia Power (NSP) to provide details on the attribution of a cyberattack, including the identity of the threat actor, methodology used, and whether the threat actor is subject to sanctions. It also asks how this knowledge has informed NSP's cybersecurity strategy.

IR G-4 — Cost Recovery and Ratepayer Implications
IR G-4 — Cost Recovery and Ratepayer Implications - (a) Identify all costs associated with the Attack and its remediation that NSP intends to seek to - recover through regulated rates, including: - (i) the total quantum of costs to be soug...

AI summary The document outlines the need for Nova Scotia Power (NSP) to identify and justify the costs associated with a cyber attack and its remediation for recovery through regulated rates. It also asks NSP to explain whether ratepayers should bear these costs, considering NSP's prior knowledge of risks, gaps in cybersecurity planning, and the availability of threat intelligence. Additionally, it requests information on cybersecurity insurance held by NSP.

IR G-5 — Forward Cybersecurity Strategy
IR G-5 — Forward Cybersecurity Strategy - (a) Produce NSP's updated cybersecurity strategy, policy, and multi-year investment plan, as approved by NSP's Board of Directors following the Attack. - (b) Describe how NSP's forward cybersecurit...

AI summary The document requests Nova Scotia Power (NSP) to provide an updated cybersecurity strategy, policy, and investment plan, addressing specific threats from Russian-nexus actors as outlined in the CCCS NCTA 2025-2026. It also asks about mechanisms for reviewing threat advisories and participation in cybersecurity information sharing organizations.

REFERENCES
REFERENCES Canadian Centre for Cyber Security. (2018). National cyber threat assessment 2018 . Government of Canada. https://www.cyber.gc.ca/en/guidance/national-cyber-threat-assessment-2018 Canadian Centre for Cyber Security. (2020a). Cyb...

AI summary The document references multiple cyber threat assessments and reports from the Canadian Centre for Cyber Security and other international agencies, focusing on threats to critical infrastructure, including the electricity and oil and gas sectors, and highlighting specific malware like Industroyer.

101618INQ Law Consulting (NSPI) IR-1 to IR-7 6 passages
NOVA SCOTIA ENERGY BOARD
NOVA SCOTIA ENERGY BOARD IN THE MATTER OF: THE PUBLIC UTILITIES ACT - and - IN THE MATTER OF: AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer information, customer...

AI summary The Nova Scotia Energy Board is conducting an inquiry under the Public Utilities Act regarding the impact of a cyber incident on Nova Scotia Power Incorporated's data collection, customer service, billing processes, and regulatory compliance.

Request IR-2:
Request IR-2: - With respect to governance and risk management processes addressing privacy risks, please - provide the following documentation or information, as applicable. If any of the documents or - information is not available, pleas...

AI summary Request IR-2 seeks documentation and information related to Nova Scotia Power's privacy governance and risk management processes, including policies, procedures, and audit plans, particularly in the context of a cybersecurity incident.

Request IR-3:
Request IR-3: - With respect to reporting to regulators, notification to affected individuals, management and communication, please provide the following documentation or information, as applicable. If any of the documents or information i...

AI summary Request IR-3 seeks information related to a cybersecurity incident involving Nova Scotia Power, including dates of awareness, notifications to regulators and affected individuals, and templates of notification letters.

Request IR-5:
Request IR-5: - With respect to measures implemented to mitigate risk to customers from fraud and identity theft - following the cybersecurity incident, please provide the following documentation or information, - as applicable. If any of...

AI summary Request IR-5 seeks information from Nova Scotia Power regarding measures taken to mitigate fraud and identity theft risks following a cybersecurity incident, as well as any complaints received from affected individuals and how they were addressed.

Request IR-6:
Request IR-6: - With respect to whether any third-party service providers were involved in the breach and if yes, whether there were data sharing agreements in place with them. Please provide the following documentation or information, as...

AI summary The document requests information about third-party service providers involved in a cybersecurity incident, including data sharing agreements, privacy policies, contracts, breach notification dates, and audit history by Nova Scotia Power.

Request IR-7:
Request IR-7: - With respect to communications with customers relating to cybersecurity related issues, please provide the following documentation or information, as applicable. If any of the documents or information is not available, plea...

AI summary Request IR-7 asks for documentation and information related to customer communications concerning cybersecurity incidents, including access to information requests, response times, and privacy complaints.

101623NSPI Monthly Update Report #7 (M12273) 5 passages
Preamble p. p. 0
April 9, 2026 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power's Cybersecurity Incident – Monthly Update 7 Dear Ms. Henwood: On July 14, 2025,...

AI summary This document is a monthly update from Nova Scotia Power regarding its response to a cybersecurity incident. It includes an updated Restoration Roadmap Gantt Chart, an updated Ongoing Regulatory Matters table, and the status of invoices on hold. The report is part of a series of monthly updates required by the Nova Scotia Energy Board following the incident in spring 2025.

Cybersecurity p. p. 0
Cybersecurity NS Power continued to advance cybersecurity restoration activities across multiple capability areas during the reporting period. Progress continued across identity and access management, vulnerability management, and detectio...

AI summary NS Power continued to advance cybersecurity restoration activities during the reporting period, focusing on identity and access management, vulnerability management, and detection and response capabilities. Supporting processes, including governance and documentation, also matured, with preparations progressing for broader operational adoption.

Resolution of the Investigation of the Office of the Privacy Commissioner of Canada p. p. 0
Resolution of the Investigation of the Office of the Privacy Commissioner of Canada On March 25, 2026, the Office of the Privacy Commissioner of Canada (OPC) publicly announced that it would discontinue its investigation of the cyberattack...

AI summary The Office of the Privacy Commissioner of Canada (OPC) has decided to discontinue its investigation into the 2025 cyberattack on NS Power's systems, pending the completion of commitments outlined in a Compliance Letter to the OPC.

PROGRAM STRUCTURE p. p. 0
PROGRAM STRUCTURE The Restoration Program is structured into five (5) key portfolios of work – focusing on restoring business capabilities. Portfolio Scope Summary Enterprise Resource Planning (ERP) Recovery and restoration of core enterpr...

AI summary The Restoration Program is organized into five key portfolios: Enterprise Resource Planning, Customer, Additional Capabilities, Cybersecurity, and Technology Enablement, each focusing on restoring critical systems and operations.

The following projects experienced adjustments to their completion timeline. An overview of the changes and associated rationale is outlined below: p. p. 6
The following projects experienced adjustments to their completion timeline. An overview of the changes and associated rationale is outlined below: Pillar Project Summary of Change Rationale Customer OpenView / ActiVu Project end date adju...

AI summary Two projects have had their completion dates adjusted. OpenView/ActiVu's end date was moved from March 16, 2026, to May 14, 2026, due to vendor availability. The IAM project's end date was moved from September 30, 2026, to July 31, 2026, to align with the Identity recovery scope completion.

101692CA (NSPI) IR-1 to IR-11 12 passages
1 M12600
1 M12600 2 3 4 NOVA SCOTIA ENERGY BOARD 5 6 7 IN THE MATTER OF: The Public Utilities Act 8 9 – and – 10 IN THE MATTER OF: AN INQUIRY about the impact of the cyber incident on NOVA 11 SCOTIA POWER INCORPORATED's collection and retention 12...

AI summary The Nova Scotia Energy Board has issued an information request to Nova Scotia Power Inc. regarding the impact of a cyber incident on customer information management, customer service, billing processes, and regulatory matters. Responses are due by May 6, 2026.

1 Request IR-1: Cyber Security Program Effectiveness
1 Request IR-1: Cyber Security Program Effectiveness 2

AI summary The document introduces Request IR-1, which focuses on evaluating the effectiveness of the Cyber Security Program. However, the content is limited to the heading and a page number, providing no substantive discussion or analysis of the program's effectiveness.

3 Reference: Exhibit N-3 - 2025 Nova Scotia Power's Cybersecurity Incident Report, Page 18, 4 ll 1-4
3 Reference: Exhibit N-3 - 2025 Nova Scotia Power's Cybersecurity Incident Report, Page 18, 4 ll 1-4 5

AI summary The text references a 2025 Nova Scotia Power's Cybersecurity Incident Report, specifically Page 18, lines 1-4, but does not provide additional details about the incident or its implications.

6 Quote:
6 Quote: 7 NS Power maintains a cybersecurity training and awareness program and conducts mandatory 8 quarterly cyber training and monthly phishing simulation testing exercises with all employees to 9 educate employees about NS Power's inf...

AI summary NS Power implements a cybersecurity training program with mandatory quarterly training and monthly phishing simulations for all employees to educate them on information security policies and responsibilities.

12 Question
12 Question 13 14 a. For the twelve-month period ending March 2025, please provide the results of the 15 quarterly cyber training and monthly phishing simulation testing. 16 17 b. Please describe NSPI's training standards for cybersecurity...

AI summary The questions focus on NSPI's cybersecurity measures, including training standards, testing frequency, employee training completion rates, cybersecurity readiness targets, and a summary of past cyber incidents and improvements made.

42 Question
42 Question 43 44 a. Please provide the retention standards referenced in the above quote. 45 1 b. Please confirm that these standards are compliant with the Personal Information 2 Protection and Electronic Documents Act (PIPEDA). 3 4 5 Re...

AI summary The text requests confirmation on the retention and purging of customer social insurance numbers (SINs) by NSPI, compliance with PIPEDA, and the number of closed accounts with retained SINs. It references a 2025 cybersecurity incident report and quotes from Peter Gregg's statement regarding SIN collection and removal.

42 43
42 43 1 Request IR-4: Data Retention Policy Compliance with Legislation 2 3 4 Reference: Exhibit N-3 - 2025 Nova Scotia Power's Cybersecurity Incident Report, Page 40, ll 3-5 5 6 7 8 9 Quote: At the time of the Incident, NS Power had forma...

AI summary The document contains a series of requests related to data retention policies and customer account collections by NSPI. It references a cybersecurity incident and asks about NSPI's compliance with privacy and security policies, as well as actions taken in response to the incident and its impact on customer billing.

18 Reference: Exhibit N-3 - 2025 Nova Scotia Power's Cybersecurity Incident Report, Page 14, 19 ll 18-25
18 Reference: Exhibit N-3 - 2025 Nova Scotia Power's Cybersecurity Incident Report, Page 14, 19 ll 18-25 20

AI summary The text references a cybersecurity incident report by Nova Scotia Power from 2025, specifically page 14 of Exhibit N-3. It does not provide further details about the incident or its implications.

21 Quote:
21 Quote: 22 Immediately following detection of unauthorized access, NS Power activated its incident response 23 and business continuity protocols, engaged leading third-party cybersecurity experts, and took 24 actions to contain and isola...

AI summary NS Power responded to a cybersecurity incident by activating its incident response protocols, engaging third-party experts, and taking steps to contain and isolate affected servers. The company prioritized containment, eradication, and remediation of the threat, as well as analyzing the full scope of the incident.

45 46
45 46 1 Request IR-7: Cybersecurity Risk Management 2 3 Reference: Exhibit N-3 - 2025 Nova Scotia Power's Cybersecurity Incident Report, Page 17, 4 ll 11-24 5 6 Quote: 7 NS Power's cybersecurity framework (which applies to its information...

AI summary The document discusses cybersecurity risk management and customer risk mitigation measures taken by Nova Scotia Power Inc. (NSPI) following a cybersecurity incident. It references a 2025 cybersecurity incident report and outlines NSPI's cybersecurity framework aligned with NIST's Core Functions. The request also includes inquiries about insurance coverage, the unauthorized access event, and measures to prevent future breaches. Customer mitigation steps such as credit monitoring were provided.

12 Request IR-9: Data Breach Mitigation
12 Request IR-9: Data Breach Mitigation 13

AI summary The document outlines Request IR-9, which focuses on data breach mitigation. It highlights the need for measures to protect personal information, referencing the PIPEDA and the role of NSP and the CA in addressing data security concerns.

14 Reference: Exhibit N-3 - 2025 Nova Scotia Power's Cybersecurity Incident Report, Page 15 38, ll 25-28
14 Reference: Exhibit N-3 - 2025 Nova Scotia Power's Cybersecurity Incident Report, Page 15 38, ll 25-28 16

AI summary The document references Exhibit N-3 from Nova Scotia Power's 2025 Cybersecurity Incident Report, specifically Page 38, lines 25-28. It does not provide detailed content about the incident or its implications.

101693DOE (NSPI) IR-1 to IR-10 2 passages
1 2026 M12600
1 2026 M12600 2 3 NOVA SCOTIA ENERGY BOARD 4 5 IN THE MATTER OF: The Public Utilities Act, RSNS 1989, c 380 as 6 amended 7 8 - and - 9 10 11 12 13 14 15 IN THE MATTER OF: AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POW...

AI summary The Nova Scotia Energy Board is conducting an inquiry regarding the impact of a cyber incident on Nova Scotia Power Incorporated's data handling, customer service, billing processes, and regulatory matters. The Department of Energy has requested information from Nova Scotia Power by May 6, 2026.

Third-Party and Vendor Management
Third-Party and Vendor Management IR-7. Regarding the Invoices on Hold report, identify any specific vendors or projects related to Vegetation Management or Grid Reliability that have had payments withheld for more than 90 days due to Admi...

AI summary The document includes two inquiries related to third-party and vendor management. IR-7 asks about payments withheld for over 90 days for vendors or projects related to Vegetation Management or Grid Reliability. IR-8 inquires about the number of invoice disputes linked to suppliers' non-compliance with new cybersecurity protocols.

101694NSEB (NSPI) IR-1 to IR-25 10 passages
NOVA SCOTIA ENERGY BOARD
NOVA SCOTIA ENERGY BOARD IN THE MATTER OF: THE PUBLIC UTILITIES ACT - and - IN THE MATTER OF: AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer information, customer...

AI summary The Nova Scotia Energy Board is conducting an inquiry under the Public Utilities Act regarding the impact of a cyber incident on Nova Scotia Power Incorporated's handling of customer information, customer service, billing processes, and regulatory matters.

Request IR-1:
Request IR-1: - In response to the Board's IR-13 and IR-14 (Exhibit N-4), the utility provided the following response: - (d) …When NS Power lost the ability to communicate with that network through the cyber incident, the estimation logic...

AI summary The document outlines a request for information regarding the CIS subroutine used by NS Power during a cybersecurity incident. The request includes details about how the subroutine estimates energy usage, its validation, and performance metrics. It also asks for specific data, including energy bills and validation reports.

Request IR-2:
Request IR-2: - a) How does the CIS subroutine work for a customer with net-metering? - b) Why did the utility not consider providing estimated credits for customers with net metering? - c) How many net-metering customers does the utility...

AI summary Request IR-2 contains a series of questions regarding the CIS subroutine, net-metering credits, reconciliation of bills, and customer validation of energy usage data. The questions focus on operational procedures, customer billing, and cybersecurity impacts.

Request IR-3:
Request IR-3: - Please refer to the Net Metering 2025 Annual Report (Matter M12783) - At pages 7-8, the Report states: Please note that, due to the cyber incident, NS Power is still in - the process of recovering information on changes (e....

AI summary The document outlines a request (IR-3) for clarification regarding the accuracy and availability of data in the Net Metering 2025 Annual Report, including questions about whether data is actual or estimated, how estimates were made, and when lost data from 2020-2024 might be recovered due to a cyber incident.

Request IR-9:
Request IR-9: - Please provide specific and detailed information addressing whether all or any part of the information about current NS Power customers was available in NS Power's systems to be stolen in the cyber attack in circumstances w...

AI summary Request IR-9 asks NS Power to provide detailed information on whether customer data was available for theft during a cyber attack, considering data collection policies, data destruction requirements, and compliance with provincial and federal laws.

Request IR-10:
Request IR-10: - Please provide specific and detailed information addressing whether all or any part of the information about former NS Power customers was available in NS Power's systems to be stolen in the cyber attack in circumstances w...

AI summary Request IR-10 seeks detailed information on whether former NS Power customer data was accessible during a cyber attack, questioning if the data was collected or retained in violation of NS Power's policies or provincial/federal laws, and whether it should have been destroyed.

Request IR-12:
Request IR-12: - Please confirm that, at all material times relating to the cyber attack, NS Power was fully compliant with all its internal policies relating to the collection and retention of personal information of customers. - a) If no...

AI summary The request asks NS Power to confirm compliance with internal policies on customer personal information collection and retention during a cyber attack. If non-compliance occurred, the request seeks details on the policies violated, reasons for non-compliance, and corrective actions.

Request IR-13:
Request IR-13: Please provide any memos, assessments, reports or email messages prepared on or after April 25, 2025, discussing how customers would be advised about the cybersecurity breach and the theft of their personal information, and...

AI summary Request IR-13 asks for documents from April 25, 2025 onwards that discuss how customers would be informed about a cybersecurity breach and the theft of their personal information, including the details to be communicated.

Request IR-16:
Request IR-16: - Please provide any memos, assessments, reports or email messages prepared by NS Power or - on its behalf about the difficulties that customers experienced contacting NS Power's Customer - Care Centre and TransUnion in the...

AI summary Request IR-16 asks NS Power to provide memos, assessments, reports, and emails regarding customer difficulties contacting NS Power's Customer Care Centre and TransUnion after a cybersecurity breach and data theft. It also seeks detailed call statistics related to the incident from April 25, 2025, to October 31, 2025.

Request IR-20:
Request IR-20: - Please provide any memos, assessments, reports or email messages prepared by NS Power or - on its behalf about its initial pause to customer billing after the cyber attack and its resumption of - billing, including any dis...

AI summary Request IR-20 seeks information from NS Power regarding its handling of customer billing following a cyber attack, including memos, assessments, and discussions on estimating bills and manually reading meters during the system outage.

101697SBA (NSPI) IR-1 to IR-20 13 passages
1 M12600
1 M12600 2 3 NOVA SCOTIA ENERGY BOARD 4 5 IN THE MATTER OF: The Public Utilities Act, R.S.N.S. 1989, c.380, as amended 6 7 8 9 IN THE MATTER OF: AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collecti...

AI summary The Nova Scotia Energy Board is conducting an inquiry regarding the impact of a cyber incident on Nova Scotia Power Incorporated's collection and retention of customer information, customer service, billing processes, and regulatory matters. A response is requested from Blake Williams, Vice President, Legal and Regulatory at Nova Scotia Power Incorporated.

Request IR-2:
Request IR-2: Please refer to the Report, Page 8, Lines 1-3: Immediately following detection of the Incident, NS Power activated its established incident response and business continuity protocols, engaging Osler, and through Osler, Mandia...

AI summary Request IR-2 seeks information about NS Power's incident response and business continuity protocols, including their development, updates, research basis, and Osler's role in responding to an incident.

Request IR-3:
Request IR-3: Please refer to the Report, Page 8, Line 19-22: NS Power notified law enforcement of the Incident. More specifically, NS Power notified the Canadian Centre for Cybersecurity (CCCS), the Royal Canadian Mounted Police (RCMP), a...

AI summary NS Power notified law enforcement on April 27, 2025, about an incident, but there was a two-day gap between when they first became aware of the issue on April 25, 2025, and the notification. Questions are raised about the delay, notification of the FBI, discussions on timing, and whether protocols existed for notifications.

Request IR-6:
Request IR-6: Please refer to the Report, Page 17, Lines 3-6: At the time of the Incident, NS Power had implemented a common set of cybersecurity standards and policies that are informed, in part, by the National Institute of Standards and...

AI summary The text contains a request (IR-6) asking for clarification on NS Power's cybersecurity standards, their relationship to other protocols, the sources of guidance used, the meaning and timing of regulatory reviews, and whether NS Power receives updates from other organizations like NERC and E-ISAC.

Request IR-7:
Request IR-7: Please refer to the Report, Page 17, Lines 19-20: Detect – Establishes the appropriate activities to identify the occurrence of a cybersecurity event. a) Did the 'Detect' part of the Cybersecurity Framework operate as expecte...

AI summary The text from Request IR-7 asks whether the 'Detect' part of the Cybersecurity Framework operated as expected, inquires about delays in becoming aware of a breach, and seeks confirmation on why the framework may not have functioned properly if it did not operate as intended.

Request IR-8:
Request IR-8: Please refer to the Report, Page 17, Lines 26-20: In relation to NS Power's operational program, NS Power's core energy operations are designed to comply with other industry-specific rules and standards relating to cybersecur...

AI summary The document requests information about NS Power's last NERC audit related to cybersecurity and IT, and whether NERC provides audit reports on these matters.

Request IR-9:
Request IR-9: Please refer to the Report, Page 18, Lines 1-4: NS Power maintains a cybersecurity training and awareness program and conducts mandatory quarterly cyber training and monthly phishing simulation testing exercises with all empl...

AI summary The document requests detailed information about NS Power's cybersecurity training and phishing simulation exercises, including content, evaluation methods, participation rates, and any changes made post-incident. It focuses on the effectiveness and tracking of these programs.

Request IR-10:
Request IR-10: Please refer to the Report, Page 18, Lines 19-29: NS Power implemented a previously developed and tested consistent multi-channel approach throughout the response efforts for all public communications. For each update, the t...

AI summary NS Power used a multi-channel approach for public communications during a cybersecurity incident, including a dedicated landing page, social media, local media, and direct communications with stakeholders. A paid media strategy was also employed to ensure visibility. The incident was first reported on April 25, 2025, with customer notification on April 28, 2025.

Request IR-13: Please refer to the Report, Page 37, Lines 15-16:
Request IR-13: Please refer to the Report, Page 37, Lines 15-16: …In connection with these efforts, NS Power has recently completed an extensive two- year update to its cybersecurity practices to comply with current policies and anticipate...

AI summary NS Power completed a two-year update to its cybersecurity practices to align with current policies and anticipated changes in standards communicated by NIST. The question asks when this update was completed.

Request IR-14: Refer to M12600, Exhibit N-1, Nova Scotia Energy Board (NESB) IR 4(a):
Request IR-14: Refer to M12600, Exhibit N-1, Nova Scotia Energy Board (NESB) IR 4(a): As noted above, NS Power extended the offer of credit monitoring by three additional years beyond the two-year industry standard, providing additional pr...

AI summary The text discusses NS Power's extension of credit monitoring for customers affected by a security breach, raising questions about the definition of the 'industry standard,' how it was determined, and whether any customers have suffered identity breaches or damages.

Request IR-17:
Request IR-17: Refer to M12600, Exhibit N-1, NSEB IR 12, Page 2-3, Lines 8-9: …Also, the Company has not applied late charges, or penalties on any outstanding balances since the incident. NS Power will communicate directly with customers b...

AI summary The document references NS Power's handling of late fees and a cybersecurity incident. It asks about the reinstatement of late fees, their financial impact, and cybersecurity measures in place during a breach. It also cites a compliance letter to the OPC regarding a data breach in 2025.

Request IR-19:
Request IR-19: Refer to Compliance Letter to the Office of the Privacy Commissioner of Canada ("OPC") dated March 18, 2026 [(https://www.priv.gc.ca/en/opc-actions-and-](https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/inv...

AI summary The document refers to a compliance letter from the Office of the Privacy Commissioner of Canada dated March 18, 2026, concerning a cybersecurity breach at NS Power. It asks whether NS Power maintained other backups beyond those destroyed by a threat actor on April 25, 2025.

1 evidence has yet emerged that this sensitive data has been made public or sold. After its
1 evidence has yet emerged that this sensitive data has been made public or sold. After its 2 assessment of applicable sanctions laws and alignment with law enforcement guidance, 3 Nova Scotia Power did not pay a ransom to the threat actor...

AI summary The text discusses Nova Scotia Power's response to a cyber threat, noting that no ransom was paid and that evidence has not yet emerged showing sensitive customer data was made public or sold. It also raises a question about when NS Power first obtained proof that the threat actor had obtained sensitive customer information.

101749Letter NSPI re: Information requests not within scope of M21600 (refiled on May 8 to correct typo) 3 passages
Section 1 p. p. 0
April 27, 2026 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12600 – Minister of Energy – Accountability for Nova Scotia Power Dear Ms. Henwood: Nova Scotia Power In...

AI summary Nova Scotia Power Inc. (NS Power) is responding to information requests related to privacy policies, governance, and cybersecurity measures under matter M12600. The issues include privacy training, breach response, data collection, and fraud mitigation following a cybersecurity incident.

Section 2 p. p. 0
ncluding what type of personal information was collected, for what purpose). - 5. Measures implemented to mitigate risk to customers from fraud and identity theft following the cybersecurity incident. - 6. Whether any third-party service p...

AI summary The document outlines a series of questions related to a cybersecurity incident at Nova Scotia Power, focusing on data collection, fraud mitigation, third-party involvement, billing accuracy, and regulatory impacts. It also references a regulatory proceeding (M12273) and the Board's correspondence from February 6, 2026.

Section 3 p. p. 0
ng and transition to IESO Nova Scotia Conversely, the issues to be addressed in M12273 are set out in the Board's February 6, 2026 correspondence in relation to that matter and include the following: - a. NS Power's cybersecurity assets an...

AI summary The document discusses the scope of M12600 and M12273, focusing on NS Power's cybersecurity measures before and after a cyberattack. It identifies which issues fall under M12600 and which are better addressed in M12273, where MNP Digital is assisting the Board. Only specific IRs are deemed relevant to M12600.

101762Letter David MacLeod re: Response to NSPI's letter 1 passage
Section 1
David T. MacLeod 2026-04-28 Cry tal Henwood Clerk of the Board ova cotia En rgy Board 1601 Lower Water treet, 3rd Floor Halifax, N B3J 3 3 RE: M12600 - Min ter of Energy - Accountability for Nova cotia Power Ms. Henwood, I am writing in re...

AI summary The letter from David T. MacLeod responds to Nova Scotia Power's objection to answering Information Requests related to the 2025 cyber breach. The requests are tied to governance, data collection, risk mitigation, third-party involvement, and customer communications, with a focus on privacy risks for ratepayers, especially those with federal security clearances.

101810Letter CA re: Comments on NS Power's letter about scope of IRs 1 passage
Re: M12600 - Minister of Energy - Accountability for Nova Scotia Power p. p. 0
Re: M12600 - Minister of Energy - Accountability for Nova Scotia Power This is further to the Board's request for comments on the objections Nova Scotia Power has raised over the scope of some of the information requests that have been fil...

AI summary Nova Scotia Power objects to certain information requests in M12600, arguing they are more relevant to M12273. The Consumer Advocate and others argue that the overlap between the two matters is inevitable and that separating technical and non-technical aspects could hinder transparency. The Board has acknowledged the potential overlap and the importance of addressing both technical and governance-related issues in M12600.

101820Letter SBA re: Comments on NS Power's letter about scope of IRs 2 passages
Section 1 p. p. 0
April 30, 2026 VIA EMAIL Ms. Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax NS B3J 3 S3 Dear Ms. Henwood, Re: M12600 -Minister of Energy-Accountability for Nova Scotia Power The SBA a...

AI summary The SBA responds to NS Power's objections regarding Information Requests related to a cybersecurity incident. The SBA argues that while M12273 focuses on technical aspects, M12600 should also consider customer and regulatory impacts, allowing for some overlap in evidence.

Section 2 p. p. 0
evidence between the two matters is contemplated and potentially necessary in order to understand the full context of the cybersecurity incident and NS Power's response within the regulatory context. In its March 25, 2026 letter to the Par...

AI summary The Small Business Advocate (SBA) argues that evidence from two regulatory matters, M12600 and M12273, should be considered together to provide a more comprehensive understanding of NS Power's cybersecurity incident and response. The SBA emphasizes the value of clarifying non-technical aspects of cybersecurity standards and policies in M12600.

101894Email NSEB re: NSPI to provide letter and Confidential undertaking 2 passages
Preamble p. p. 0
From: [Henwood, Crystal D](mailto:[email protected]) To: [Blake Williams](mailto:[email protected]) Cc: [Alissa Whalen](mailto:[email protected]); [Andrew McLaren](mailto:[email protected]); [Annie Beth Sampson]...

AI summary The email is a communication between Henwood, Crystal D and Blake Williams regarding M12600 - NSPI to NSEB Cybersecurity Accountability IR Responses. It includes a list of recipients from various organizations, suggesting a regulatory or compliance-related proceeding involving cybersecurity accountability.

Statement of Confidentiality p. p. 0
Statement of Confidentiality This message (including any attachments) may contain private or protected information meant for a specific person or organization. If you received this by mistake, please let the sender know, do not communicate...

AI summary This email from Sofia Reiner of Nova Scotia Power to Crystal Henwood of the Nova Scotia Department of Energy relates to matter M12600, concerning NSPI's cybersecurity accountability IR responses. It is part of a regulatory proceeding and includes a list of recipients involved.

101927Letter NSPI re: IR Scope Letter - Refile 3 passages
Section 1 p. p. 0
May 8, 2026 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12600 – Minister of Energy – Accountability for Nova Scotia Power Dear Ms. Henwood: Nova Scotia Power Inc....

AI summary NS Power is responding to information requests related to privacy policies, governance, and risk management processes, as outlined in the Final Issues List for M12600. The issues include privacy training, breach response, data retention, and measures to mitigate fraud risks following a cybersecurity incident.

Section 2 p. p. 0
ncluding what type of personal information was collected, for what purpose). - 5. Measures implemented to mitigate risk to customers from fraud and identity theft following the cybersecurity incident. - 6. Whether any third-party service p...

AI summary The text outlines a series of questions and issues related to a cybersecurity incident at Nova Scotia Power, focusing on data collection, risk mitigation, third-party involvement, billing accuracy, and regulatory impacts. It also references a regulatory proceeding (M12273) and related correspondence.

Section 3 p. p. 0
ng and transition to IESO Nova Scotia Conversely, the issues to be addressed in M12273 are set out in the Board's February 6, 2026 correspondence in relation to that matter and include the following: - a. NS Power's cybersecurity assets an...

AI summary This document discusses the scope of M12600 and the relevance of Mr. MacLeod's IRs to the proceeding. NS Power argues that most of the IRs are not relevant to M12600 and should instead be addressed in M12273, which is currently under review by MNP Digital. Only specific IRs are considered relevant to M12600.

101928Letter NSPI re: Confidentiality Undertaking for IRs filed by NSPI 2 passages
Section 1 p. p. 0
May 8, 2026 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12600 – Cybersecurity Accountability Dear Ms. Henwood: Enclosed is the Confidentiality Undertaking for the...

AI summary NS Power is requesting confidential treatment for specific information in its responses to information requests in matter M12600, citing reasons such as protecting customer privacy, financial details, and internal procedures from potential threat actors.

Section 2 p. p. 0
ancial information related to customer fees. - NSPI (SBA) IR-20 contains information about the attack and the threat actor. Additionally, NS Power seeks Board Confidential treatment of the following: - NSPI (NSEB) IR-9 Attachment 8 which i...

AI summary NS Power requests confidential treatment for documents related to a cyber attack and cybersecurity measures, citing potential risks to information security if disclosed. The documents include internal cybersecurity strategies and a confidential audit report from the Northeast Power Coordinating Council.

102002NSPI Monthly Update Report #8 (M12273) 6 passages
Preamble p. p. 0
May 14, 2026 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power's Cybersecurity Incident – Monthly Update 8 Dear Ms. Henwood: On July 14, 2025,...

AI summary This document is a monthly update from Nova Scotia Power regarding its response to a cybersecurity incident. It includes an updated Restoration Roadmap Gantt Chart and an updated Ongoing Regulatory Matters table. The report is filed in accordance with a directive from the Nova Scotia Energy Board.

Technology Enablement p. p. 0
Technology Enablement Underlying technology capabilities that support business operations and cybersecurity recovery continued to mature under formal governance. Several foundational components have progressed through readiness milestones,...

AI summary The technology enablement section discusses the maturation of underlying technology capabilities supporting business operations and cybersecurity recovery. It emphasizes resilience, repeatability, and alignment with enterprise standards, with careful sequencing of foundational enablement to reduce rework risk and ensure stability.

Cybersecurity p. p. 0
Cybersecurity Cybersecurity recovery remains focused on governance and control validation, rather than individual technologies or tools. Enterprise frameworks for security monitoring, risk management, incident response, and recovery contin...

AI summary The focus of cybersecurity recovery is on governance and control validation, with enterprise frameworks for security monitoring, risk management, incident response, and recovery advancing through documented procedures and structured review cycles. Mitigation actions and oversight mechanisms support continued progress.

Resolution of the Investigation of the Office of the Privacy Commissioner of Canada p. p. 0
Resolution of the Investigation of the Office of the Privacy Commissioner of Canada As indicated in Monthly Update 7 the Office of the Privacy Commissioner of Canada (OPC) has announced that it would discontinue its investigation of the cy...

AI summary The Office of the Privacy Commissioner of Canada (OPC) has decided to discontinue its investigation into the cyberattack on NS Power's systems, pending NS Power's fulfillment of commitments outlined in a Compliance Letter. NS Power is actively working to meet these commitments and is keeping the OPC informed of its progress.

PROGRAM STRUCTURE p. p. 0
PROGRAM STRUCTURE The Restoration Program is structured into five (5) key portfolios of work – focusing on restoring business capabilities. Portfolio Scope Summary Enterprise Resource Planning (ERP) Recovery and restoration of core enterpr...

AI summary The Restoration Program is divided into five key portfolios focusing on restoring business capabilities: Enterprise Resource Planning, Customer, Additional Capabilities, Cybersecurity, and Technology Enablement. Each portfolio outlines specific systems and operations to be recovered and restored.

Cybersecurity Incident - Monthly Update 8 Attachment 2 Page 1 of 5 p. p. 5
Cybersecurity Incident - Monthly Update 8 Attachment 2 Page 1 of 5 Affected Regulatory Matters Report 2 - October 1 Report 3 - November 3 Report 4 - December 1 Report 5 - February 4 Report 6 - March 4 Report 7 - March 31 Report 8 - May 11...

AI summary This document provides a monthly update on a cybersecurity incident affecting customer billing and renewable to retail information. It outlines the timeline of updates, actions taken by NS Power, and the restoration of normal operations by March 31, 2026.

102037Board letter re: Confidential Undertaking form approved 1 passage
Section 1 p. p. 0
May 19, 2026 [[email protected]](mailto:[email protected]) Blake Williams VP Legal and Regulatory Nova Scotia Power Inc. PO Box 910 Halifax, NS B3J 2W5 Dear Mr. Williams: M12600 – Nova Scotia Power Inc. – Cybersecurity Acco...

AI summary The Board panel has approved the form of the Confidential Undertaking filed by Nova Scotia Power Inc. regarding M12600 – Cybersecurity Accountability. The Board is continuing to assess the confidential treatment of the identified information and will provide its determinations once the review is complete.

102111Reply Comments - David MacLeod 8 passages
D. 1 Satisfy All Three Prongs of Section 9(a) p. p. 0
D. 1 Satisfy All Three Prongs of Section 9(a) I qualify under all three prongs of Section 9(a): Section 9(a)(i): l am a Nova Scotia Power ratepayer. My participation concerns the adequacy of NS P's cybersecurity preparedness. Such matters...

AI summary The intervenor qualifies under all three prongs of Section 9(a) by being a Nova Scotia Power ratepayer, representing a public interest perspective on cybersecurity, and having a direct personal interest due to a data breach. They also satisfy Section 9(b) criteria by having limited financial resources and contributing a unique perspective on cybersecurity.

B. The Consumer Advocate's Mandate ls Different from My Perspective p. p. 0
B. The Consumer Advocate's Mandate ls Different from My Perspective The Consumer Advocate represents the general economic interests of ratepayers: rates, reliability, billing practices, service quality, and cost recovery. The Consumer Advo...

AI summary The speaker argues that the Consumer Advocate's role is limited to economic and service-related concerns, while they focus on national and personal security aspects of NSP's cybersecurity. They highlight the need to align NSP's cybersecurity with the 2025-2026 National Cyber Threat Assessment due to persistent threats from Russian state-sponsored actors.

E. Issue 3: Detection Latency p. p. 0
E. Issue 3: Detection Latency My third issue concerns the 37-day detection latency between the initial breach on March 19. 2025, and NSP's detection of the breach on April 25, 2025. A 37-day detection latency is significant. During this pe...

AI summary The third issue focuses on the 37-day detection latency between a breach on March 19, 2025, and NSP's discovery on April 25, 2025. The delay allowed the threat actor to conduct reconnaissance, lateral movement, privilege escalation, and data exfiltration. The author argues that this is a threat-detection and incident-response issue, not a reliability or service-quality concern, and claims expertise in this area.

F. My Perspective ls Unique, Substantive, and Dtrectly Relevant p. p. 0
F. My Perspective ls Unique, Substantive, and Dtrectly Relevant The three issues I propose to address are not duplicative of the Consumer Advocate's mandate. They are: - (a) Unique: No other party in this proceeding is offering an intellig...

AI summary The author argues that their perspective on NSP's cybersecurity posture is unique, substantive, and directly relevant to the Board's mandate. They highlight that no other party is providing an intelligence-community-informed analysis of NSP's cybersecurity in light of NCTA threat warnings, and that their input addresses material questions about NSP's preparedness and response.

3. SCOPE OF ISSUES IN MATTER 12600 p. p. 0
3. SCOPE OF ISSUES IN MATTER 12600

AI summary This section outlines the scope of issues in Matter 12600, which involves regulatory proceedings related to Nova Scotia Power and cybersecurity considerations, as referenced by the National Cyber Threat Assessment.

A. NSP's Position p. p. 0
A. NSP's Position NSP submits that the three issues [ propose to address fall outside the scope of Matter 12600. B. Matter 12600 Concerns NSP's Cybersecurity Preparedness and Breach Response Matter 12600 is a proceeding concerning NSP's cy...

AI summary NSP argues that three issues fall within the scope of Matter 12600, which concerns its cybersecurity preparedness and breach response following a March 2025 data breach. The issues relate to NCTA alignment, SIN retention, and detection latency, all of which are central to assessing NSP's cybersecurity policies and practices.

C. NSP's Argument lmproperlv Narrows the Scope of the Proceeding p. p. 0
C. NSP's Argument lmproperlv Narrows the Scope of the Proceeding NSP's argument appears to rest on an improperly narrow construction of the proceeding's scope. If followed, it would limit the Board's inquiry to technical compliance with mi...

AI summary NSP's argument is criticized for narrowly defining the proceeding's scope, which would limit the Board's inquiry to technical compliance rather than a holistic assessment of NSP's cybersecurity posture. This approach is deemed inconsistent with the Board's mandate and the public interest in ensuring reasonable cybersecurity practices.

D. Conclusion on Scope p. p. 0
D. Conclusion on Scope NSP's argument that my issues fal I outside the scope of Matter 12600 is without merit. Each issue is directly relevant to the Board's assessment ofNSP's cybersecuriry preparedness and breacb response. 1 respectfully...

AI summary The text concludes that NSP's argument that the issues are outside the scope of Matter 12600 is without merit, as each issue is directly relevant to the Board's assessment of NSP's cybersecurity preparedness and breach response.

102138Board Decision Letter - Scope of IRs 3 passages
Section 1 p. p. 0
May 26, 2026 [[email protected]](mailto:[email protected]) Blake Williams VP Legal and Regulatory Nova Scotia Power Incorporated PO Box 910 1223 Lower Water Street Halifax, NS B3J 2W5 Dear Mr. Williams: M12600 – Nova Scotia...

AI summary NS Power informed the Board that some Information Requests (IRs) from David MacLeod, the Small Business Advocate, and the Consumer Advocate are outside the scope of the current proceeding, M12600, which relates to cybersecurity accountability. The Board invited intervenors to respond to NS Power's objections, with Mr. MacLeod arguing that his IRs are within the proceeding's scope.

Section 2 p. p. 0
relevant in Matter M12273. The Board invited intervenors to respond to NS Power's objections. Mr. MacLeod submitted the IRs he requested were all within the scope of the current proceeding and were: … intended to shed light on NSPI's corpo...

AI summary The document discusses the relevance of Matter M12273 in the current proceeding, with NS Power objecting to the scope of intervenor requests. Mr. MacLeod argues that the requested information is within the proceeding's scope and relates to NSPI's corporate culture and risk management. The Small Business Advocate notes some overlap between the current proceeding and M12273 to fully understand the cybersecurity incident and NS Power's response within the regulatory context.

Section 4 p. p. 0
he Board's ability to explain the cybersecurity incident to customers about NS Power in this proceeding and noted that considerations in one matter may be relevant to conclusions reached in the other. In response to the submissions from th...

AI summary NS Power emphasized the importance of procedural fairness and confidentiality in the cybersecurity incident proceeding, noting that the scope of the current matter is distinct from Matter M12273. It argued that the Board's ruling supports a clear separation between the two proceedings.

102158Board Decision Letter - Request for Pre-Approval of Intervener Costs 2 passages
Section 5 p. p. 0
ings the ability to arrange for a demonstration of its virtual platform in advance to ensure that the participants are familiar with its systems and to address any technical issues before the hearing. To conclude, the Board's experience wi...

AI summary The Board emphasizes the effectiveness of virtual processes in reducing costs and encourages participation via its virtual platform. It also notes that electronic submissions are preferred to avoid printing and courier costs. The Board addresses the adequacy of NS Power's cybersecurity policies, detection and response to a breach, and its remedial measures.

Section 6 p. p. 0
ices and controls prior to the breach: - b. The reasonableness of NS Power's detection and response to the breach; and - c. The appropriateness of NS Power's remedial measures and future preparedness. Those issues are intended to be addres...

AI summary The document outlines issues related to NS Power's cybersecurity incident, including the reasonableness of detection and response, and the appropriateness of remedial measures. It refers to Matter M12273 and notes that some issues are better addressed in that proceeding.

102252Amended Hearing Order 1 passage
AMENDED HEARING ORDER
AMENDED HEARING ORDER On December 3, 2025, the Honourable Tim Houston, Premier of Nova Scotia and Minister of Energy, wrote to the Nova Scotia Energy Board to express concern about the number of Nova Scotians experiencing inaccurate billin...

AI summary The Nova Scotia Energy Board has amended the hearing order for a matter concerning inaccurate billing and lack of responsiveness from NS Power following a cybersecurity breach. The Board has opened a new matter (M12600) and will consider NS Power's Cybersecurity Incident Report before deciding on a process. A public hearing is scheduled for August 2026.

102321Letter NSPI re: RIRs 1 passage
Section 1 p. p. 0
June 9, 2026 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: Subject - M12600 – Nova Scotia Power Incorporated – Cybersecurity Accountability – Responses to IRs in Scop...

AI summary Nova Scotia Power Inc. submitted responses to information requests related to cybersecurity accountability as directed by the Nova Scotia Energy Board. The responses cover specific IRs, with some previously submitted in an earlier filing.

102373NSPI Monthly Update Report #9 (M12273) 4 passages
Preamble p. p. 0
June 12, 2026 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power's Cybersecurity Incident – Monthly Update 9 Dear Ms. Henwood: On July 14, 2025,...

AI summary This document is the ninth monthly update from Nova Scotia Power regarding its response to a cybersecurity incident that occurred in the spring of 2025. It includes an updated Restoration Roadmap Gantt Chart and other attachments related to ongoing regulatory matters and invoices on hold.

Cybersecurity p. p. 0
Cybersecurity Cybersecurity capabilities continue to mature through structured governance, validation, and readiness activities. Foundational identity and access controls have been strengthened, enabling greater consistency and reliability...

AI summary The document highlights the maturation of cybersecurity capabilities through structured governance and validation. Identity and access controls have been strengthened, and cybersecurity workstreams are progressing under an enhancement roadmap with effective oversight and stakeholder coordination.

Resolution of the Investigation of the Office of the Privacy Commissioner of Canada p. p. 0
Resolution of the Investigation of the Office of the Privacy Commissioner of Canada As indicated in Monthly Update 8, the Office of the Privacy Commissioner of Canada (OPC) has announced that it would discontinue its investigation of the c...

AI summary The Office of the Privacy Commissioner of Canada (OPC) has paused its investigation into a cyberattack on NS Power's systems pending NS Power's fulfillment of commitments outlined in a Compliance Letter. NS Power is actively working to meet these commitments and keeping the OPC informed of its progress.

PROGRAM STRUCTURE p. p. 0
PROGRAM STRUCTURE The Restoration Program is structured into five (5) key portfolios of work – focusing on restoring business capabilities. Portfolio Scope Summary Enterprise Resource Planning (ERP) Recovery and restoration of core enterpr...

AI summary The Restoration Program is organized into five portfolios focusing on restoring business capabilities: Enterprise Resource Planning, Customer, Additional Capabilities, Cybersecurity, and Technology Enablement. Each portfolio outlines specific systems and operations to be recovered and restored.

102481Letter SBA re: Not filing evidence 1 passage
Section 1 p. p. 0
June 23, 2026 VIA EMAIL Ms. Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax NS B3J 3S3 Dear Ms. Henwood: Re: M12600 -Nova Scotia Power Incorporated - Cybersecurity Accountability The S...

AI summary The Small Business Advocate (SBA) has reviewed the application and responses to Information Requests in M12600 - Nova Scotia Power Incorporated - Cybersecurity Accountability. The SBA will not file evidence but will participate in the hearing.

102676CA (INQ Law/Consulting) IR-1 to IR-4 4 passages
1 M12600
1 M12600 2 3 4 NOVA SCOTIA ENERGY BOARD 5 6 7 IN THE MATTER OF: The Public Utilities Act 8 – and – 9 10 IN THE MATTER OF: AN INQUIRY about the impact of the cyber incident on NOVA 11 SCOTIA POWER INCORPORATED's collection and retention 12...

AI summary The Nova Scotia Energy Board has issued an information request to INQ Law/Consulting regarding a cyber incident affecting Nova Scotia Power's data handling, customer service, billing, and regulatory matters. Responses are due by July 29, 2026, and the request is part of an inquiry under the Public Utilities Act.

Section 2
1 Request IR-1: 2 With regard to paragraph 13, page 6 of the Report of INQ Law/Consulting: 3 4 A. What are the industry standards for organizations such as Nova Scotia Power regarding the 5 content of a Personal Information Inventory? 6 7...

AI summary This document contains three information requests related to a cyber incident involving Nova Scotia Power. The requests focus on personal information inventory standards, the effectiveness of a PI inventory in identifying impacted data points, and the adequacy of credit monitoring offered as a remedial measure following the breach.

Section 3
osure. However, in my opinion, the extension of credit monitoring to five 30 years brought the remedial offering to a level that was reasonable given the nature of the 31 information compromised." 32 33 A. What factors, including but not l...

AI summary The text discusses the conclusion that five years of credit monitoring is a reasonable mitigation for customer risk following a cybersecurity incident. It also requests references or examples used to assess the reasonableness of this measure and criticizes eight actions by Nova Scotia Power for not meeting best practices.

Date Filed: July 8, 2026 CA (BCC) Page 2 of 3
Date Filed: July 8, 2026 CA (BCC) Page 2 of 3 1 2 Which of the actions listed in paragraph 106 were the most significant: 3 A. 4 When viewed in light of the reasonable expectations of customers, and; 5 B. 6 In failing to limit the impact o...

AI summary The document presents a question regarding the most significant actions listed in paragraph 106, focusing on customer expectations and the impact of a cyber security attack.

102711NSPI Monthly Update Report #10 (M12273) 5 passages
Preamble p. p. 0
July 10, 2026 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power's Cybersecurity Incident – Monthly Update 10 Dear Ms. Henwood: On July 14, 2025...

AI summary This monthly update from NS Power to the Nova Scotia Energy Board provides an overview of progress in responding to a cybersecurity incident that occurred in the spring of 2025. The report includes an updated Restoration Roadmap Gantt Chart and other attachments related to ongoing regulatory matters and invoices on hold.

Cybersecurity p. p. 0
Cybersecurity Cybersecurity capabilities are established and operating effectively across the environment, providing a strong foundation for the organization's ongoing operations and recovery objectives. Key security controls, including id...

AI summary The organization's cybersecurity capabilities are functioning effectively, with strong identity and access management controls in place. Current efforts focus on sustaining and evolving these capabilities through governance and readiness activities, ensuring long-term operational effectiveness and compliance.

Recovery Timeline p. p. 0
Recovery Timeline The program has now delivered the majority of its recovery objectives, with key business and technology capabilities fully operational and supporting organizational needs. Service continuity remained stable throughout the...

AI summary The program has largely met its recovery objectives, with key systems operational and service continuity stable. NS Power is addressing commitments from the OPC regarding a cyberattack investigation, which will be resolved upon completion of these commitments.

PROGRAM STRUCTURE p. p. 0
PROGRAM STRUCTURE The Restoration Program is structured into five (5) key portfolios of work – focusing on restoring business capabilities. Portfolio Scope Summary Enterprise Resource Planning (ERP) Recovery and restoration of core enterpr...

AI summary The Restoration Program is organized into five key portfolios: Enterprise Resource Planning (ERP), Customer, Additional Capabilities, Cybersecurity, and Technology Enablement. Each portfolio focuses on restoring critical systems and capabilities to ensure business continuity and operational resilience.

The following projects experienced adjustments to their completion timeline. An overview of the changes and associated rationale is outlined below: p. p. 5
The following projects experienced adjustments to their completion timeline. An overview of the changes and associated rationale is outlined below: Pillar Project Summary of Change Rationale Fuel Adjustment Mechanism General NA Updated Upd...

AI summary The document outlines timeline adjustments for several projects, including the Fuel Adjustment Mechanism, Maritime Link Benefits Report, FAM Quarterly, and Dispatch Study Action Plan Quarterly Update. Changes are accompanied by rationales such as project go-live dates and conclusion of impacted areas related to a Cybersecurity Incident.

102803Board letter re: Hearing Logistics 1 passage
Section 1 p. p. 0
July 16, 2026 Dear Parties: M12600 – Nova Scotia Power Inc- Cybersecurity Accountability – Hearing Logistics The Board is requesting the following information for the upcoming hearing: - 1. That all parties identify for the Board and the o...

AI summary The Board is requesting information regarding witness appearances for the upcoming cybersecurity accountability hearing involving Nova Scotia Power Inc. Parties must confirm by specific dates whether they will request virtual appearances or object to virtual testimony, with NS Power required to submit its witness panel by August 5, 2026.

102814Email DOE re: do not object to CA virtual appearance of witness 2 passages
Preamble p. p. 0
From: [Kayter, Thomas J](mailto:[email protected]) To: [Alissa Whalen](mailto:[email protected]); [Painting-MacLean, Kimberly](mailto:[email protected]) Subject: RE: M12600 - Nova Scotia Power - Cyberse...

AI summary An email from Thomas J. Kayter to Alissa Whalen and Kimberly Painting-MacLean regarding a cybersecurity accountability letter from the Canadian Association (CA) in the context of the M12600 proceeding involving Nova Scotia Power.

Dear Ms Painting-MacLean, p. p. 0
Dear Ms Painting-MacLean, The Department of Energy does not object to the Consumer Advocate's request for the virtual appearance of its witness, Ed Mollard. Yours very truly, Thomas Kayter Lawyer/avocat Legal Services Division/ Division de...

AI summary The Department of Energy does not object to the Consumer Advocate's request for the virtual appearance of Ed Mollard as a witness. The email is part of a regulatory proceeding related to cybersecurity accountability involving Nova Scotia Power.

102885Email NSEB re: Extension for NSPI to advise of witnesses to appear virtually 2 passages
Preamble p. p. 0
From: [Henwood, Crystal D](mailto:[email protected]) To: [Jennifer Power](mailto:[email protected]) Cc: [Alissa Whalen](mailto:[email protected]); [Andrew McLaren](mailto:[email protected]); [Annie Beth Sampson]...

AI summary This email concerns the logistics for the cybersecurity accountability hearing (M12600) involving Nova Scotia Power. It is a communication among various stakeholders, including representatives from Nova Scotia Power, the Department of Energy, and legal counsel, regarding the upcoming proceeding.

\ \ EXTERNAL EMAIL / COURRIEL EXTERNE \ \ p. pp. 0-2
\ \ EXTERNAL EMAIL / COURRIEL EXTERNE \ \ Exercise caution when opening attachments or clicking on links / Faites preuve de prudence si vous ouvrez une pièce jointe ou cliquez sur un lien Hi Kimberley, Apologies. Regarding Question 1, as N...

AI summary This email exchange discusses the submission of rebuttal evidence by NS Power in a cybersecurity accountability proceeding, with Jenn indicating that a final determination on expert support is pending. Kimberley requests clarification on the specific part of the letter requiring additional time to respond.

103176NSEB email re: order of evidence at hearing 1 passage
Statement of Confidentiality
Statement of Confidentiality This message (including any attachments) may contain private or protected information meant for a specific person or organization. If you received this by mistake, please let the sender know, do not communicate...

AI summary This email from Crystal Henwood of the Nova Scotia government to multiple recipients informs them of a regulatory proceeding (M12600) related to Nova Scotia Power's cybersecurity accountability. The message is marked as confidential and includes instructions on handling it if received by mistake.

103205NSPI Monthly Update Report #11 (M12273) 4 passages
Preamble
August 13, 2026 Crystal Henwood Clerk of the Board Nova Scotia Energy Board 1601 Lower Water Street, 3rd Floor Halifax, NS B3J 3S3 Re: M12273 – Nova Scotia Power's Cybersecurity Incident – Monthly Update 11 Dear Ms. Henwood: On July 14, 20...

AI summary Nova Scotia Power is providing an update on its response to a cybersecurity incident that occurred in the spring of 2025. The company submitted its 11th monthly report to the Nova Scotia Energy Board, including an updated Restoration Roadmap Gantt Chart and status updates on regulatory matters and invoices on hold.

Cybersecurity
Cybersecurity Cybersecurity capabilities continue to operate effectively, supporting the organization's operational and recovery objectives. Key security controls, including identity and access management capabilities, are fully implemente...

AI summary The document outlines the current state of cybersecurity capabilities, emphasizing their effectiveness in supporting operational and recovery objectives. Key security controls are fully implemented, and efforts are focused on sustaining and maturing these capabilities through governance and compliance.

Recovery Timeline
Recovery Timeline The program continued to advance during the reporting period, with additional recovery objectives completed and further capabilities transitioning into operational service. Most business and technology restoration activit...

AI summary The recovery program has made significant progress, with most restoration activities completed and a focus now on long-term operational management. NS Power is addressing commitments from the OPC regarding a cyberattack investigation, with timelines detailed in Attachment 1.

PROGRAM STRUCTURE
PROGRAM STRUCTURE The Restoration Program is structured into five (5) key portfolios of work – focusing on restoring business capabilities. Portfolio Scope Summary Enterprise Resource Planning (ERP) Recovery and restoration of core enterpr...

AI summary The Restoration Program is organized into five portfolios: Enterprise Resource Planning, Customer, Additional Capabilities, Cybersecurity, and Technology Enablement. Each portfolio focuses on restoring critical systems and operations to ensure business continuity and service delivery.

103319Undertaking List 2 passages
MATTER NAME: Nova Scotia Power - Cybersecurity Accountability MATTER #: M12600
MATTER NAME: Nova Scotia Power - Cybersecurity Accountability MATTER #: M12600 DATE: UND# DESCRIPTION REQUESTED OF BY DATE DUE August 18, 2026 U-1 To provide information that demonstrates what the Equifax tool uses to confirm identity. NSP...

AI summary This regulatory proceeding, Matter M12600, involves Nova Scotia Power being asked to provide detailed information regarding cybersecurity measures, data breaches, and associated costs. The request includes details on data volumes, identity verification processes, and phishing failure rates.

CONTINUED M12600
CONTINUED M12600 DATE UND# DESCRIPTION REQUESTED OF FOR DUE DATE forecast for 2026 and 2027 and beyond if possible. August 18, 2026 U-8 Provide a more granular breakdown of the cost categories and actual and forecast costs related to the c...

AI summary The document outlines several requests related to cybersecurity incidents and data management practices by NSPI, including cost breakdowns, tracking of carrying costs, and documentation related to SIN elimination and customer service protocols.

20260818-1Hearing Transcript — 08/18/2026 (Chris Lanteigne, Lia MacDonald, Glen MacLeod, Blake Williams) 19 passages
NOVA SCOTIA ENERGY BOARD
NOVA SCOTIA ENERGY BOARD IN THE MATTER OF: THE PUBLIC UTILITIES ACT - and - IN THE MATTER OF: AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer information, customer...

AI summary The Nova Scotia Energy Board is conducting an inquiry under the Public Utilities Act regarding the impact of a cyber incident on Nova Scotia Power Incorporated's handling of customer information, customer service, billing processes, and regulatory matters.

LIST OF UNDERTAKINGS
LIST OF UNDERTAKINGS NO. PAGE NO. 11 reliability screening or clearance. This demographic 12 includes public service employees, retirees, veterans, 13 military personnel, research staff, and those working in 14 the manufacturing of militar...

AI summary The text discusses the vulnerabilities faced by individuals with security clearances due to a 2025 cyber breach by Nova Scotia Power. It highlights the risks of data breaches for this group, including exposure to foreign threat actors and criminal networks, which can be used for social engineering and blackmail.

Section 32
held by Nova Scotia Power was actually affected by the attack? A. (Williams) That's correct. We cannot definitively say what was taken by the threat actor. Q. And why is that? A. (Williams) Well, the nature of the systems and what was done...

AI summary The testimony discusses the difficulty in determining the exact data affected by a cyberattack on Nova Scotia Power's systems. While the volume and origin of removed data can be identified, the specific contents of the affected data remain unknown, likened to being unable to determine which books were viewed in a box that was opened.

BY MR. ROBERTS:
BY MR. ROBERTS: Q. And I apologize again if this sounds like a simplistic question, but was any of the data personal information that you gathered from your customers retained in such a way that there would not be access to it from the int...

AI summary Mr. Roberts asks if customer personal data is retained in a way that prevents internet access. Williams responds that the systems in question are not directly linked to the internet and suggests discussing cybersecurity aspects in the appropriate section of the process.

NOVA SCOTIA POWER PANEL 83 Cr-ex, (Roberts)
NOVA SCOTIA POWER PANEL 83 Cr-ex, (Roberts) 1 still Social Insurance Numbers customer Social 2 Insurance Numbers in the system that would have been 3 accessed, or potentially accessed? 4 A. (Williams) So I just want to make 5 sure we're (i...

AI summary The discussion revolves around the removal of Social Insurance Numbers (SINs) from the Customer Information System (CIS) in 2024 and the potential presence of SINs in the Data Lake at the time of a cyberattack in 2021. The witness, Williams, confirms the purge was completed but does not know the number of SINs in the Data Lake and cannot definitively say if it is obtainable.

NOVA SCOTIA POWER PANEL 135 Cr-ex, (Roberts)
NOVA SCOTIA POWER PANEL 135 Cr-ex, (Roberts) 1 failure rate among employees in their monthly phishing 18 employees. So there's items in there that really try to 19 trick employees. 1 And I actually think, like reviewing 2 this, that's it's...

AI summary The discussion focuses on Nova Scotia Power's cybersecurity training program, specifically their monthly phishing simulations. In November 2024, 14.3% of employees failed the test, prompting a response involving senior management updates and mandatory additional training for those who failed.

Preamble
failures. And if an employee fails multiple times, you know, obviously the severity of any discussions that is –– are had with that employee would increase. And maybe I'll pass it on to Mr. Williams just to elaborate a little bit on that,...

AI summary The discussion outlines Nova Scotia Power's approach to cybersecurity training, including financial consequences for repeated phishing test failures and the emphasis on addressing these issues through senior leadership meetings. The failure rate of 14.3% and its context in early 2025 are highlighted.

NOVA SCOTIA POWER PANEL 141 Cr-ex, (Roberts)
NOVA SCOTIA POWER PANEL 141 Cr-ex, (Roberts) 6.4 percent and 3.3 percent. Are those numbers concerning? A. (Williams) I would suggest, sir, that anything above zero is concerning, given what we know can happen. But as Mr. Lanteigne has poi...

AI summary The discussion addresses concerns about cybersecurity testing results, with a response indicating that while the numbers are concerning, there have been efforts to address issues through training and follow-up. The witness also clarifies that the incident involved more than just a phishing attempt and defers further technical details to another proceeding.

NOVA SCOTIA POWER PANEL 143 Cr-ex, (Roberts)
NOVA SCOTIA POWER PANEL 143 Cr-ex, (Roberts) Not up here; I mean at the next proceeding. Q. I'm in the hands of the Board on this. I mean, I would expect that you might be able to characterize, if not answer in any technical details, at le...

AI summary The discussion revolves around cybersecurity training and cultural changes at Nova Scotia Power Inc. following a phishing attack. The witness explains that training remains monthly but there has been a significant cultural shift in understanding the importance of cybersecurity after experiencing a breach.

to date?
to date? 1 (Williams) We can provide that. A. 2 MS. MacADAM: If I could have that as 3 an undertaking? 4 THE CHAIR: It'll be Undertaking U-5. 5 UNDERTAKING U-5 - To provide an 6 updated phishing failure rate for 7 the period of April 2025...

AI summary The discussion revolves around the provision of an updated phishing failure rate for April 2025 to date and a request for information on cyber incidents recorded by NSPI over the last five years. The participants are discussing the appropriate handling of undertakings and commitments related to cybersecurity.

NOVA SCOTIA POWER PANEL 209 Cr-ex, (Rudderham)
NOVA SCOTIA POWER PANEL 209 Cr-ex, (Rudderham) I just said, it would be anything in the future would be up to this Board to make a determination as to whether it was prudent or imprudent. Q. Okay. So that's not –– the assurance doesn't go...

AI summary The discussion centers on the costs associated with cybersecurity restoration efforts by Nova Scotia Power Inc. (NSPI), with the assurance that the Board will determine the prudence of future costs, while current restoration costs incurred in 2025 and 2026 are being accounted for by the utility and ultimately the shareholder.

Section 122
1 that it's necessarily going to match up. And that's, I 2 guess, why I cautioned you when we first began this 3 discussion about this document, that there's no-one up 4 here prepared to speak to this document from a different 5 proceeding...

AI summary The discussion revolves around the confidentiality of a document related to a cybersecurity incident, with the witness explaining that detailed breakdowns and forecasts are kept confidential, while some figures may be made public.

Section 132
1 capital". So I had said, "Okay. Well, then, is capital 2 not included or" I'm just I can't quite understand 3 what I'm looking at, what's actually being tracked, what's 4 actually being recorded. 5 I just want to understand what I'm 6 lo...

AI summary The discussion revolves around the transparency of cybersecurity incident costs, with a concern about what is being tracked and recorded. The Chair asks whether the issue stems from confidentiality or if there are other factors, and the speaker responds that some costs are actuals and should be on the public record.

NOVA SCOTIA POWER PANEL 233 Cr-ex, (Rudderham)
NOVA SCOTIA POWER PANEL 233 Cr-ex, (Rudderham) 1 because it's reported in one proceeding, not reported 15 it's they're tracking using specific codes similar to, 16 you know, the storm costs. So in the storm cost 17 proceedings, all those c...

AI summary The discussion revolves around the handling of cybersecurity incident costs in regulated statements and the concern over the confidentiality of forecast numbers, particularly for 2025. The witness notes that specific codes are used to track such costs, similar to those used in storm cost proceedings, but they are not included in the current record.

Section 144
INTERNATIONAL REPORTING INC. CERTIFIED COURT REPORTERS 1 and the impacts of the attack. 2 Q. So costs from, like, all those 3 lawyers, I think you said, KPMG, LevelBlue, those types of 4 costs is what you're describing, or...? 5 A. (Willia...

AI summary The text discusses cybersecurity-related costs, including those from external firms like Mandiant and KPMG, as well as customer-related restoration activities such as account recovery and AMI system restoration.

NOVA SCOTIA POWER PANEL 273 Cr-ex, (Rudderham)
NOVA SCOTIA POWER PANEL 273 Cr-ex, (Rudderham) 1 it subject to check, yes. 2 Okay. And at least some of those Q. 3 projects in 2025 would have been deferred because of the 4 cyberattack or the activities that came afterwards, 5 decreased s...

AI summary The discussion focuses on the impact of a cyberattack on Nova Scotia Power Inc.'s projects, particularly the delay of the Customer Care Modernization Project in 2025. The witness explains that the project was paused after the attack and resumed in June, with implementation eventually taking place in March.

NOVA SCOTIA POWER PANEL 275 Cr-ex, (Rudderham)
NOVA SCOTIA POWER PANEL 275 Cr-ex, (Rudderham) 1 to be June of last year. So despite the fact that that 2 project came in nine months later, we did come in under 3 the budget for that still. So it's an example where the 4 investment had be...

AI summary The discussion centers on the impact of a cybersecurity attack on capital projects, with NSPI stating that while delays occurred, the financial impact has not been analyzed or quantified on a general level due to the unique nature of each project.

Section 158
1 approved by the Board, and so any to the extent that 2 there is any costs associated with a delay, and that that 3 delay is determined to be imprudent, then those costs 4 would be dealt with by the Board in the normal course. 5 Q. And on...

AI summary The discussion focuses on the Board's handling of costs associated with delays, particularly in the context of a cybersecurity incident. The witness explains that any costs resulting from delays, including those caused by the incident, are identified and explained in capital plans.

NOVA SCOTIA POWER PANEL 279 Cr-ex, (Rudderham)
NOVA SCOTIA POWER PANEL 279 Cr-ex, (Rudderham) 1 where I'm meant to be looking. 18 MR. CLARKE: Excuse me for a second. 19 Mr. Chair, I was just wondering about INTERNATIONAL REPORTING INC. CERTIFIED COURT REPORTERS 1 the mid-afternoon brea...

AI summary The discussion revolves around the impact of a cybersecurity incident on capital project schedules, with a focus on whether other factors may have influenced project timelines. The panel is questioning the completeness of the information provided and considering the possibility that some projects may no longer be delayed.

20260819-1Hearing Transcript — 08/19/2026 (Chris Lanteigne, Lia MacDonald, Glen MacLeod, Blake Williams) 14 passages
NOVA SCOTIA ENERGY BOARD
NOVA SCOTIA ENERGY BOARD IN THE MATTER OF: THE PUBLIC UTILITIES ACT - and - IN THE MATTER OF: AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer information, customer...

AI summary The Nova Scotia Energy Board is conducting an inquiry under the Public Utilities Act regarding the impact of a cyber incident on Nova Scotia Power Incorporated's handling of customer information, customer service, billing processes, and regulatory matters.

I N D E X O F P R O C E E D I N G S
I N D E X O F P R O C E E D I N G S August 18, 2026 PAGE NO. Hearing opens 1 Preliminary matters 1 Opening Statement by Consumer Advocate 8 Opening Statement by Small Business Advocate 12 Opening Statement by Mr. David MacLeod 14 NOVA SCOT...

AI summary The document outlines the proceedings of a regulatory hearing involving Nova Scotia Power, including opening statements by various advocates, cross-examinations, and the submission of exhibits. Key topics include the Equifax data breach settlement and the 2025 financial statements.

NOVA SCOTIA POWER PANEL 407 Questions, (Melanson)
NOVA SCOTIA POWER PANEL 407 Questions, (Melanson) 1 been notification to the senior leadership of the 1 And interestingly enough, Mr. Williams 2 talked yesterday kind of about the cultural changes that 3 we've seen at Nova Scotia Power wit...

AI summary The text discusses Nova Scotia Power's approach to cybersecurity, including employee training for phishing attacks and the validation of successful phishing tests. It also addresses the company's rebuttal to recommendations regarding computer access controls, emphasizing the balance between risk and employee needs.

1 So I'm just wondering, what's the
NOVA SCOTIA POWER PANEL 469 Questions, (Deveau) 1 So I'm just wondering, what's the INTERNATIONAL REPORTING INC. CERTIFIED COURT REPORTERS a page. Sorry; can you search in there Rob, can you do a quick search for me, just search for the wo...

AI summary The discussion focuses on the security measures taken by Nova Scotia Power Inc. regarding the MyEnergy Insights Program, specifically the encryption of data in the Azure environment and the breach that allowed unauthorized access despite these protections.

Preamble
1 would move on and the assumption would be you've dealt 2 within the 14 days. 3 Q. Okay. 4 A. (Williams) Any data that hasn't 5 been touched would remain for 90 days with the assumption 6 that we may still need it, we just haven't gotten...

AI summary The discussion revolves around data retention policies and security risks associated with storing data in a Data Lake and CIS system. It highlights that data not accessed within 90 days is lost, and there are concerns about unauthorized access to data stored in these systems.

NOVA SCOTIA POWER PANEL 475 Questions, (Deveau)
NOVA SCOTIA POWER PANEL 475 Questions, (Deveau) 1 you're expanding it to other platforms or well, the SIN 2 numbers probably wouldn't make it to MyEnergy, but when 3 you're copying it from the CIS system to the Azure system, 4 it's just an...

AI summary The discussion revolves around data security and migration from the CIS system to the Azure system, with concerns raised about potential unauthorized access and data manipulation. The response highlights the use of automated destruction tools and secure environments to mitigate risks.

NOVA SCOTIA POWER PANEL 483 Questions, (Deveau)
NOVA SCOTIA POWER PANEL 483 Questions, (Deveau) 1 [11:50:29] So obviously it's the paragraph Q. 2 at the top of page 22 of 30 there, and it's the reference 3 highlighted it's a reference to the Company maintaining 4 cyber insurance coverag...

AI summary The text discusses Nova Scotia Power's cybersecurity insurance coverage, noting that the company's coverage may be exhausted due to a sophisticated cyberattack or multiple events, and that there is no guarantee of renewal on acceptable terms. This is linked to the company's experience over the past year and a half.

NOVA SCOTIA POWER PANEL 493 Questions, (Deveau)
NOVA SCOTIA POWER PANEL 493 Questions, (Deveau) 1 Okay. Q. 2 A. (Williams) So I certainly take 3 you –– take your word for that, sir. 4 Q. Yeah. Okay. 5 I'll take you to the rebuttal, N-17, 6 page 10 and 11. And I think it's the same sente...

AI summary The text discusses cybersecurity standards and policies at Nova Scotia Power, referencing a two-year update to practices in alignment with the NIST Cybersecurity Framework. It clarifies that while practices were updated, the 13 core policies remained unchanged.

Section 91
INTERNATIONAL REPORTING INC. CERTIFIED COURT REPORTERS page 43. BY VICE CHAIR DEVEAU: Q. That one, I do not see I didn't see a date on it when it was last updated. A. (Williams) I'm not aware of a date on here, sir. And the reason for that...

AI summary The discussion revolves around the lack of a specific date on a document related to Nova Scotia Power's data protection measures and the clarification regarding the company's audit program. The document is described as a screenshot from a web page and not updated in recent years. An information protection audit was conducted in December 2024 as part of the company's annual audit program.

NOVA SCOTIA POWER PANEL 531 Questions, (Chair)
NOVA SCOTIA POWER PANEL 531 Questions, (Chair) 1 that has files and folders, is the technical difficulty 14 documentation would be included. 15 And were either SharePoint or Q. 16 OneDrive impacted by the cyberattack? 17 (Williams) No, the...

AI summary The discussion revolves around the use of SharePoint by Nova Scotia Power, specifically the impact of a cyberattack on its on-premises version. The company has used SharePoint for several years, but the online version was not affected, while the on-premises version had functional limitations post-attack.

NOVA SCOTIA POWER PANEL 611 Questions, (Chair)
NOVA SCOTIA POWER PANEL 611 Questions, (Chair) 1 levels in terms of invoice payments? 2 A. (Williams) I don't have a 3 specific date, sir, but as referenced in the body of the 4 report, that it's indicated that those numbers are 5 expected...

AI summary The discussion centers on the expected reduction in invoice payment levels over time due to operational familiarity with a new system, and the commitment by Nova Scotia Power to not pass on cyber incident costs to customers, excluding overearnings scenarios.

In-ch, (Clarke)
In-ch, (Clarke) 1 JENA VALDETERO, Solemnly affirmed: 2 THE CHAIR: Go ahead, Mr. Clarke. 3 MR. CLARKE: Thank you, Mr. Chair. 4 EXAMINATION ON QUALIFICATIONS BY MR. CLARKE 5 Q. Ms. Valdetero, can you please 6 confirm you filed evidence in th...

AI summary The examination of Jena Valdetero by Mr. Clarke confirms her submission of evidence and qualifications, including her role as a practising attorney and co-chair of the U.S. Data Privacy and Cybersecurity Practice at Greenberg Traurig. She has extensive experience in data breach investigations and incident response, including work with vendors similar to those retained by Nova Scotia Power.

Section 165
me, Ms. Valdetero, are any of those utilities that you mentioned, are they similar to Nova Scotia Power in that they're vertically integrated single providers within the jurisdiction they operate? A. Yes. The energy company is. Q. Okay. An...

AI summary The discussion centers on the scope of an expert's retainer in a regulatory proceeding, with questions about data minimization and best practices. The expert clarifies that her retainer was related to responding to a cyberattack and not to data minimization practices. Counsel and the Chair discuss the relevance of the expert's qualifications and the scope of her involvement.

Section 175
Questions, (Melanson) 1 of having a real experienced understanding of exactly what 2 happens in these incidents and how difficult it is to get 3 it right. 4 I have what's becoming kind of a tired 5 saying, but I always say in a large incid...

AI summary The text discusses the challenges faced by a company during a large incident, emphasizing the difficulty of making decisions with no perfect options. It highlights Nova Scotia Power's response, noting their efforts to raise awareness about encryption and service issues, as well as the potential impact on customer information.

20260820-1Hearing Transcript — 08/20/2026 (Jena Valdetero, Ed Mollard, Tricia Ralph) 5 passages
NOVA SCOTIA ENERGY BOARD
NOVA SCOTIA ENERGY BOARD IN THE MATTER OF: THE PUBLIC UTILITIES ACT - and - IN THE MATTER OF: AN INQUIRY about the impact of the cyber incident on NOVA SCOTIA POWER INCORPORATED's collection and retention of customer information, customer...

AI summary The Nova Scotia Energy Board is conducting an inquiry under the Public Utilities Act regarding the impact of a cyber incident on Nova Scotia Power Incorporated's handling of customer information, customer service, billing processes, and regulatory matters.

Chair.
Chair. 1 CROSS-EXAMINATION BY MS. RUDDERHAM 1 revenue requirement based on what they say are their all 2 in costs for this event. 3 Q. So when you say, "All in costs," 4 are you saying that the only costs associated are in 5 relation to ge...

AI summary The proceeding involves cross-examination regarding the definition of 'all in costs' associated with a cybersecurity incident, including the distinction between direct and indirect costs. The witness acknowledges a lack of sufficient information to determine indirect costs and confirms attendance at prior proceedings, including the Industrial Group's cross-examination of the NSPI panel.

RALPH 743
RALPH 743 1 MS. RUDDERHAM: No questions, Mr. 11 enforcement and necessary government entities and 12 regulators? 13 A. Yes. It's not always required to 14 engage with law enforcement, but in a cyberattack, there 15 likely is. 16 Q. And the...

AI summary The text discusses the need for Nova Scotia Power (NSP) to engage with law enforcement and regulators during a cyberattack and the importance of continuing operations to serve customers. It also references an Incident Report that mentions an update being provided promptly, but without a specific date, raising questions about the timing.

1 And would you agree that you also Q.
INTERNATIONAL REPORTING INC. CERTIFIED COURT REPORTERS A. Yeah, that was my understanding. Q. Okay. And would you agree with me that the steps that were taken with respect to TransUnion and Sogica, that would have taken some time? A. Yes....

AI summary The testimony discusses Nova Scotia Power's efforts to notify former customers of a data breach, including collaboration with TransUnion and Sogica, and acknowledges the challenges in identifying current addresses for former customers.

1 suggesting.
practitioners disagree, and I think for me, again, back to the customer perspective, it was clear from my reading of the information from the letters and emails and whatnot, from I guess it was mostly emails, but from customers, it was con...

AI summary The text discusses customer confusion and communication issues following a cybersecurity incident, with a focus on transparency and reasonable steps taken by Nova Scotia Power. The discussion includes customer reactions, the need for clearer communication, and the reasonable expectations of affected customers.

Disclaimer: These summaries were generated by AI from the filings they describe. We take care to make them accurate, but errors are possible - and they aren't advice. Only the filings themselves are the record: if you're relying on something here, confirm it against the source documents or the Nova Scotia Energy Board's own record. Full disclaimer →