N-1Application - Redacted
7 passages
dentity & Access Management 2,561,279 4,324,589 This project will enhance NS Power's security infrastructure by transitioning the Company’s existing Access Management, Privileged Access Management (PAM) and Identity and Access Management (...
AI summary The text outlines several IT projects undertaken by Nova Scotia Power, including enhancing security infrastructure, replacing the Customer Information System, and implementing cloud integration solutions. These projects aim to improve efficiency, security, and service delivery.
REDACTED (CONFIDENTIAL INFORMATION REMOVED) 2026 ACE Plan CONFIDENTIAL (Attachments Only) 1 9.0 GENERAL PLANT 2 3 General Plant includes information technology (IT), operational technology (OT), computer 4 infrastructure, vehicle replaceme...
AI summary The 2026 Annual Capital Expenditure (ACE) Plan outlines General Plant investments, which include IT, OT, infrastructure, and communication equipment. These investments support NS Power’s digital transformation, regulatory compliance, and operational resilience, aligning with strategic initiatives like grid modernization and cybersecurity.
/02 2026/12 245,130 164,874 - 410,004 Total Telecommunications 2,038,491 3,508,360 2,866,859 8,413,711 C0061284 IT - OT Cyber Security Control 2023/11 2026/12 1,957,397 1,917,601 2,905,463 6,780,461 Implementation Phase 1 C0047277 IT - GIS...
AI summary The document outlines various IT projects and their associated costs under the 2026 Annual Capital Expenditure (ACE) Plan. These projects span cybersecurity, data migration, customer service improvements, and infrastructure upgrades, with detailed cost breakdowns and timelines provided.
delivering customer care, billing and communications 27 to customers. CIS needs to be replaced in order to address the risks associated with 28 the existing software and to continue to deliver bills and serve customers reliably. 29 30 In a...
AI summary NS Power plans to replace the Customer Information System (CIS) to address risks with the current software and support new tariff designs like Time of Use and Critical Peak Pricing. A ransomware attack discovered in April 2025 may influence the project's direction and timeline, which has been temporarily paused. The CIS Replacement project application is planned for 2026, with the new system expected to launch in 2029.
725,124 869,124 Cancelled Less than $1M Scope of this project included in C0061289 - IT - Network Next Generation Security Design. C0032202 Sydney T&D Depot Consolidation 1,578,174 1,879,855 Deferred 2026 Subsequent Submittal Deferred to b...
AI summary Several IT-related projects have been deferred due to a cyber event, requiring resources for priority restoration. These include the IT - CIS Replacement, IT - Oracle MDM Upgrade, and others, with some projects linked to broader initiatives like the IT - Network Next Generation Security Design.
4,353,461 Deferred 2026 Subsequent Submittal This project is delayed due to the cyber event. Resources were required for priority restoration. C0068718 IT - DERMS Solution Project 1,950,047 2,993,200 Deferred 2026 Subsequent Submittal Defe...
AI summary The document lists several IT projects that have been deferred due to a cyber event, requiring resources for priority restoration. These include the IT - DERMS Solution Project, IT - Identity and Access Management, and IT - Managed Detect & Respond. All are part of the 2026 Annual Capital Expenditure Plan and were submitted as Subsequent Submittals.
SEB on December 1, 2025 52314 1C-GT1/UT1 Replacement 11/30/2020 2,032,393 1,678,006 FIN CWO submitted to NSEB on December 1, 2025 This project is now complete; however, the final cost application is being held until the functionality C0042...
AI summary The text provides information on several completed projects with pending final cost applications, including IT security upgrades, wood pole retreatment, and smart grid initiatives. These projects are being processed by the Nova Scotia Energy Board (NSEB) under various proceedings, with final costs contingent on investigations and asset disposition processes.
N-5NSPI (IG) RIR 1 to 25
5 passages
NON-CONFIDENTIAL 2 (c) Yes, NS Power did consider mitigating approaches but found that any potential approaches 16 for approval, they were included in NSPI's overall 2025 capital spending forecast total 17 of $692.4 million? If not, explai...
AI summary The text outlines questions raised regarding NS Power's consideration of mitigating approaches for capital projects, the impact of a 2025 cybersecurity breach on project deferrals, the meaning of 'Resources were required for priority restoration,' and the cybersecurity implications of deferring IT projects.
(d) All projects to perform a lifecycle upgrade or replacement of technology assets would enhance IT Security by implementing assets that are the current vendor supported version. This applies to the following investments from the list in...
AI summary The text discusses IT projects aimed at enhancing cybersecurity through lifecycle upgrades and replacements of technology assets, including IT CIS Replacement, IT Oracle MDM Upgrade, and IT Identity and Access Management. These projects are part of efforts to improve IT security by implementing current vendor-supported versions of assets and implementing interim risk mitigation measures.
NON-CONFIDENTIAL 1 • IT - Managed Detect & Respond: The purpose of this project was to replace and 2 enhance the Security Information Event Monitoring (SIEM) technology and the 3 security detection and response service. The SIEM and monito...
AI summary This document discusses the deferral of several IT projects by NS Power, including the replacement of SIEM technology and enhancements to cybersecurity risk management. These projects have been postponed, with compensating measures in place to manage cybersecurity risks until long-term solutions are implemented. The request also asks for an explanation of the variance in forecasted expenses between the 2025 and 2026 ACE Plans for specific IT projects.
3 1 Request IR-13: 17 investment in NS Power's current fleet of hydro assets and is not related to investment in new 18 renewable generation. This is driven by two changes in 2026: (1) the Life Extension and 19 Modernization project at the...
AI summary The text discusses changes in investment in NS Power's hydro assets in 2026, including the completion of the Wreck Cove Life Extension and Modernization project and a decrease in dam refurbishment activities. It also requests information about a cybersecurity project deferred to 2025 and its impact on NSPI's cybersecurity risk profile.
1 1 Request IR-19: 1 Request IR-22: 2 3 Reference: N-1, 2026 ACE Plan, page 133, lines 30-31, and page 134, lines 1-10. 4 5 In addition, NS Power anticipates the scope of the CIS Replacement project 6 would also include enhancements to ena...
AI summary NS Power is considering enhancements to the CIS Replacement project, including new tariff designs and programs like Green Choice, due to the impact of a recent ransomware attack. However, NS Power does not anticipate filing a scope change application for the project.
N-6NSPI (NSEB) RIR 1 to 202 - Redacted
9 passages
2026 ACE Plan NSEB IR-7 Attachment 1 Page 1 of 1 REDACTED (CONFIDENTIAL INFORMATION REMOVED) CI# Project # Project Long Title Invesment Trigger C0061285 IT - Enterprise Governance, Risk, and Compliance 664,056 1,179,857 Deferred 2026 Subse...
AI summary The document outlines several IT projects that have been deferred due to a cyber event, with resources redirected to priority restoration efforts. It also references the Susie Lake Substation Addition project, which has been included in multiple ACE Plans as a subsequent submittal item.
5 (ii) Please refer to the table below. Note that the table denotes net change in kilometers 6 of distribution line on the system, not total distance added, as it is derived from a 7 snapshot in time from NS Power's GIS database. Also note...
AI summary The text refers to a table detailing the net change in kilometers of distribution line, derived from a snapshot in NS Power's GIS database. It notes that a cyber incident has temporarily affected NS Power's ability to update as-builts in the GIS database. The document is part of NSPI's responses to NSEB information requests regarding the 2026 Annual Capital Expenditure (ACE) Plan.
8.11 Cybersecurity
AI summary The section titled '8.11 Cybersecurity' introduces the topic of cybersecurity in the context of Nova Scotia's energy sector, likely discussing measures and considerations related to protecting critical infrastructure and systems.
iii. Cyber Insurance Yes, we have cyber insurance.
AI summary The entity confirms that they have cyber insurance coverage in place.
iii. Transient Cyber Assets (TCA) Yes, we do use transient cyber assets to connect to our products supplied to NSPI, assuming laptops and mobile devices
AI summary The document discusses the use of transient cyber assets, such as laptops and mobile devices, by the Nova Scotia Energy Board (NSEB) to connect to products supplied to Nova Scotia Power Incorporated (NSPI).
Mature Security Program We do not formally have a mature security program yet, but in the process of attaining NIST Standards
AI summary The organization is currently in the process of developing a mature security program and is working towards attaining NIST Standards, though it does not yet have a fully established program.
2026 ACE Plan NSEB IR-71 Attachment 1 Page 23 of 139 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Nova Scotia Power Incorporated RFP-06/2025-545 Tufts Cove Shoreline Sheet Pile Rock Revetment .2 Monitored 24/7 Yes, most sites .3 Video Camer...
AI summary The document outlines security measures for a Nova Scotia Power Incorporated project, including 24/7 monitoring, video surveillance, and a physical security policy. It also notes that an Application Security Questionnaire is not applicable.
Tufts Cove Shoreline Sheet Pile Rock Revetment #RFP-06/2025-545 F. ENVIRONMENTAL REGULATORY DIRECTIVES/OFFENCES/ORDERS Please be advised that Elliot Excavators Limited has not been given any regulatory directives/orders from the Provincial...
AI summary The document states that Elliot Excavators Limited has not received any environmental regulatory directives from the Provincial Department of Environment. It also notes that the company's products do not collect or store data, do not have external connectivity, and do not require updates for known vulnerabilities. However, the company does not have a mature security program, though its main office is secured with a locked gate and 24/7 video surveillance.
2026 Annual Capital Expenditure (ACE) Plan (NSEB M12619) NSPI Responses to NSEB Information Requests 1 (b) NS Power will measure direct benefits through baselining current datasets prior to project C0047278 IT - Oracle MDM Upgrade vendor s...
AI summary The document outlines NSPI's responses to NSEB information requests regarding the 2026 Annual Capital Expenditure (ACE) Plan. It includes details on IT projects such as Oracle MDM Upgrade, Cloud Integration Platform, Identity & Access Management, and DERMS Solution Project, focusing on cybersecurity, data integration, and grid management.
103410Decision
5 passages
- [1] Each year, Nova Scotia Power Incorporated files an Annual Capital Expenditure (ACE) Plan outlining its proposed capital expenditures for the upcoming year. In accordance with ss. 35, 35A and 35AA of the Public Utilities Act, RSNS 198...
AI summary Nova Scotia Power Incorporated submitted its 2026 Annual Capital Expenditure (ACE) Plan for approval, seeking Board approval for projects totaling $76.7 million and Routine Capital Expenditures of $207.3 million. The Board approved the plan, except for the RTU Deployment project, which was deferred pending a Synapse Energy Economics Consultants report. The Board also addressed broader issues related to capital spending and reliability planning.
8.1 Impacts on Capital Planning [209] On April 25, 2025, NS Power discovered a cybersecurity breach which impacted certain parts of its information technology network resulting in an inability to access certain systems and data. The Board...
AI summary NS Power experienced a cybersecurity breach in April 2025, leading to delayed capital project filings and reliance on GIS databases for data gaps. The Board is reviewing the incident in two proceedings, with a specific focus on its impact on capital planning.
8.2 Cost Implications in 2026 ACE Plan [211] While a detailed review was undertaken though the IR process and in questioning at the oral hearing, no additional capital costs were identified in the 2026 ACE Plan that specifically related to...
AI summary The 2026 ACE Plan did not identify additional capital costs related to cybersecurity incident restoration. NS Power used a coding system to exclude such costs from the rate base. Cybersecurity restoration costs were covered by insurance or shareholders. Inflationary pressures may arise from deferred projects, which could be managed internally or through Board approval.
8.3 Considerations for Subsequent Submittal Items [212] There was discussion about IT or cybersecurity-related projects listed as subsequent submittal items in the 2026 ACE Plan. Two projects, in particular, raised several concerns. The Id...
AI summary The document discusses concerns raised about the increasing costs of IT and cybersecurity-related projects, specifically the Identity and Access Management and Customer Information System (CIS) Replacement projects. The Industrial Group recommends that future submittals include detailed cost explanations related to the 2025 cyber incident. NS Power argues that current processes already provide necessary information, but the Board agrees that specific references to the impact of the cyber incident on cost variances should be included in future submissions.
2027 ACE Plan . - 10. The Board directs NS Power, to the extent feasible and possible, to engage and coordinate with the IESO Nova Scotia and report on that coordination in future ACE Plan filings. - 11. The Board directs NS Power to provi...
AI summary The Board has directed NS Power to provide various updates and analyses in the 2027 ACE Plan, including coordination with the IESO, an update on the Mersey Redevelopment Project, monitoring of upgraded wooden poles, and a rate impact analysis. The Board also requires specific references to cyber incidents in future capital applications.
100699IG (NSPI) IR 1 to 25 - PDF
4 passages
- 6 (b) Please elaborate on how the cybersecurity breach in 2025 impacted the 7 decision to defer or cancel any of the listed capital projects in 2025, as 8 referenced in Appendix C, including specifically the nine IT projects 9 deferred t...
AI summary The text includes questions about the impact of a 2025 cybersecurity breach on capital project decisions, the meaning of 'Resources were required for priority restoration,' and the cybersecurity implications of deferring IT projects. It also asks about updated risk assessments and mitigation plans.
- 28 (a) Please explain the variance in forecasted total expense between the 2025 29 ACE Plan and the 2026 ACE Plan for each of the following projects, 1 2 including key drivers (scope, schedule, vendor costs, resourcing, cyber related req...
AI summary The document requests an explanation of the variance in forecasted total expense between the 2025 and 2026 ACE Plans for specific IT projects, including the impact of the 2025 cybersecurity breach, reconciliation of project treatment, and an explanation of the significant increase in spending and number of under-£1M projects in 2026.
9 Request IR-15: - 10 Reference: N-1, 2026 ACE Plan, page 57, Figure 32: General Plant Carry-over Capital - 11 Spending Summary, "C0061284 IT OT Cyber Security Control Implementation Phase 1". - 12 (a) Please confirm this project was origi...
AI summary Request IR-15 focuses on the C0061284 IT OT Cyber Security Control Implementation Phase 1 project, its deferral from the 2024 ACE Plan to 2025, and its impact on NSPI's cybersecurity risk profile. The request also asks about any broader cybersecurity implementation plans by NSPI.
Request IR-22: Reference: N-1, 2026 ACE Plan, page 133, lines 30-31, and page 134, lines 1-10. In addition, NS Power anticipates the scope of the CIS Replacement project would also include enhancements to enable new tariff designs such as...
AI summary NS Power anticipates enhancements to the CIS Replacement project, including new tariff designs and programs like Green Choice. A ransomware attack discovered on April 25, 2025, has led to a temporary pause in the project as investigations into impacted systems may affect future requirements.
100700IG (NSPI) IR 1 to 25 - Word
4 passages
If NSPI does not agree, please explain. 3. Please confirm whether NSPI intends to apply the updated definitions in future CI filings and scope change determinations in 2026. If not, please explain. Reference: N-1, 2026 ACE Plan, page 29, l...
AI summary The document requests clarification from NSPI regarding the application of updated definitions in future filings, the status of capital projects deferred or cancelled in 2025, the impact of a 2025 cybersecurity breach on capital decisions, and the implications for NSPI's cybersecurity risk profile.
PI’s cybersecurity risk profile, as assessed internally and/or by third‑party advisors, including any updated risk assessments, audit findings, or mitigation plans (provide documents where available). Reference: N-1, 2026 ACE Plan, page 29...
AI summary The document requests an explanation of the variance in forecasted total expenses for several IT projects between the 2025 and 2026 ACE Plans, including the impact of a 2025 cybersecurity breach. It also asks for reconciliation of the treatment of one project that appears in both 'Subsequent Submittal' and 'Carry-over Capital Spending' categories.
h NSPI’s 2030 Clean Power Plan? Reference: N-1, 2026 ACE Plan, page 57, Figure 32: General Plant Carry-over Capital Spending Summary, “C0061284 IT - OT Cyber Security Control Implementation Phase 1”. 1. Please confirm this project was orig...
AI summary The text raises questions about NSPI’s 2030 Clean Power Plan, specifically regarding the deferral of a cybersecurity project and the increase in funding for Class 3 Work Vehicle Replacements. It also references forecasting methodologies for distribution routine spending, derived from a 5-year historical average excluding extreme weather events.
E Plan, pages 112-113, “Update on storm performance and related capital investments”. Preamble: NSPI identifies capital programs for storm response/reactive work for 2026 including D008 and T001. 1. Please describe how NSPI allocates storm...
AI summary NSPI outlines capital programs for storm response in 2026, including D008 and T001, and discusses the allocation of storm-related costs between capital and operating expenses. The document also references the CIS Replacement project and its potential scope changes due to a ransomware attack and new tariff design requirements.
103410Decision
4 passages
- [1] Each year, Nova Scotia Power Incorporated files an Annual Capital Expenditure (ACE) Plan outlining its proposed capital expenditures for the upcoming year. In accordance with ss. 35, 35A and 35AA of the Public Utilities Act, RSNS 198...
AI summary Nova Scotia Power Incorporated submitted its 2026 Annual Capital Expenditure (ACE) Plan for approval, seeking authorization for projects totaling $76.7 million and routine expenditures of $207.3 million. The Board approved the plan, except for the RTU Deployment project, which was deferred pending the final report from Synapse Energy Economics Consultants in Matter M12558. The Board also addressed several general issues related to capital spending and project approvals.
8.1 Impacts on Capital Planning [209] On April 25, 2025, NS Power discovered a cybersecurity breach which impacted certain parts of its information technology network resulting in an inability to access certain systems and data. The Board...
AI summary NS Power experienced a cybersecurity breach in April 2025, leading to system and data access issues. This has caused delays in capital project filings and increased reliance on the GIS database for data gaps. The Board is reviewing the incident in two proceedings, with a specific focus on capital planning impacts.
8.3 Considerations for Subsequent Submittal Items [212] There was discussion about IT or cybersecurity-related projects listed as subsequent submittal items in the 2026 ACE Plan. Two projects, in particular, raised several concerns. The Id...
AI summary The document discusses concerns raised about the increasing costs of IT and cybersecurity-related projects in the 2026 ACE Plan, particularly the Identity and Access Management and Customer Information System Replacement projects. The Industrial Group recommends that future submittals include detailed explanations of cost variances, especially those related to the 2025 cyber incident. NS Power argues that existing processes already cover necessary information, but the Board agrees that specific references to cyber incident impacts are needed.
2027 ACE Plan . - 10. The Board directs NS Power, to the extent feasible and possible, to engage and coordinate with the IESO Nova Scotia and report on that coordination in future ACE Plan filings. - 11. The Board directs NS Power to provi...
AI summary The Board provides several directives to NS Power regarding the 2027 ACE Plan, including coordination with the IESO, updates on the Mersey Redevelopment Project, monitoring of upgraded wooden poles, and a rate impact analysis. It also requires specific references to cyber incidents in future capital applications.
20260421-1Hearing Transcript — 04/21/2026 (Revised Transcript - Refiled May 20, 2026)
8 passages
I N D E X O F P R O C E E D I N G S April 21, 2026 PAGE NO. U-10 To provide the inspection reports for the one-year period starting before August 2024 for Project C0053234, and provide the two site assessment reports, dated October 2024 an...
AI summary The document outlines a hearing schedule and proceedings related to various regulatory matters, including inspection reports, vegetation management costs, and data discrepancies, taking place on April 21, 2026, with Richard Melanson as the Chair of the Nova Scotia Energy Board.
OPENING STATEMENT 25 NS DEPT. OF ENERGY 1 issue must remain outstanding until IESO NS can complete a 2 review and lead a competitive procurement process. 3 More widely, NSPI's continued high 4 level transmission spending must not risk dupl...
AI summary The Department of Energy highlights concerns with NSPI's transmission spending, cybersecurity vulnerabilities, and project management practices. A major cybersecurity breach in 2025 affected customer data, leading to a loss of public trust. NSPI has budgeted for CIS replacement and cybersecurity upgrades but faces scrutiny over potential double recovery from ratepayers. The ACE Plan is criticized for lacking accountability in project management and cost overruns.
OPENING STATEMENT 27 NS DEPT. OF ENERGY 1 the burden of those overruns falls onto ratepayers. 12 Minister of Energy. 13 Thank you. 14 THE CHAIR: Thank you. 15 I just have a question, because I want 16 to make sure I understand the issue wi...
AI summary The discussion centers on cybersecurity projects and concerns about potential double recovery for system failures. The Chair questions whether the Customer Information System Project is part of the ACE Plan, and the response clarifies that the statement is theoretical and not tied to any specific current expenditure.
NS POWER PANEL 65 Cr-ex, (Murphy) 1 yes. 20 In this case, we certainly wouldn't 21 have had all that information, some of it due to the cyber 22 event that we had last year. We did lose certain 23 information. But our accounting software d...
AI summary The text discusses the impact of a cyber event on data tracking at Nova Scotia Power, particularly in relation to labour hours and capital projects. It highlights the use of PowerPlan software for tracking labour and the challenges faced due to data loss.
NS POWER PANEL 249 Cr-ex, (Rudderham) 1 investment decision, it would consider customer 1 historically, we have not provided a full project list of 2 capital project spend throughout the year as part of the 3 Q4 reports. 4 And I'm not sure...
AI summary The discussion focuses on the potential impact of a cybersecurity breach on NSP's capital expenditures, specifically whether costs related to the breach are included in the additional $59 million of capital expenses. The question also explores the types of costs incurred, such as labor, third-party consulting, system recovery, and remediation.
NS POWER PANEL 257 Cr-ex, (Rudderham) 1 you also verify; is that correct? 2 (Beaton) Correct, yes. It's done A. 3 in real time and obviously once a month, when we have 4 final results for that month, that review then takes 5 place. 6 Okay....
AI summary The discussion verifies the real-time review of monthly results and confirms that approximately 60 projects were deferred or cancelled from the 2025 ACE Plan. It also addresses whether deferred projects have increased in cost due to a cybersecurity incident, noting that cost analysis is done on a project-by-project basis during preliminary engineering and approval processes.
NS POWER PANEL 259 Cr-ex, (Rudderham) Plan, asking about any changes in the forecasted costs. And then (b), if you just don't mind scrolling down there, the projects are just listed there. And then (b) asks about to what extent, if any, th...
AI summary Ms. Rudderham is questioning NSPI about the impact of a cybersecurity breach on the costs of the Identity and Access Management Project. NSPI confirms a $3 million variance but asserts that the increase was not caused by the breach, as the project would have increased regardless of when the incident occurred.
NS POWER PANEL 331 Cr-ex, (Mahody) 1 2 requirements. 3 And in response, if we just go down to 4 the bottom of that page and just to the top of the other 5 one, we see yes, you've got it there you indicate: 6 7 8 9 10 11 12 13 14 15 Please...
AI summary The text discusses a cyber incident affecting data availability at NS Power, with concerns about the recovery of data needed to respond to a board inquiry. An undertaking is mentioned to provide a response to Board IR 127(a), specifically regarding the impacts of the cyber incidence.