N-1Work Order - Redacted
4 passages
DESCRIPTION: This project is an initiative to improve NS Power's Identity and Access Management (IAM) procedures and tools. This project will design, deploy, and configure a modern Privileged Access Management (PAM) ecosystem through the i...
AI summary This initiative aims to modernize NS Power's Identity and Access Management (IAM) systems by implementing CyberArk's Privileged Access Management (PAM) infrastructure, Saviynt's Identity Governance and Administration (IGA) platform, and transitioning IAM operations to IBM's Managed Security Services (MSS). The project seeks to reduce cybersecurity risks, improve regulatory compliance, and establish a scalable foundation for future identity-centric security programs.
Why do this project? As the technology threat landscape becomes more complex and the frequency and sophistication of attacks increases, NS Power's cyber security standards must continually evolve. One critical piece of any organization's c...
AI summary NS Power emphasizes the need to strengthen Identity and Access Management (IAM) controls to address evolving cybersecurity threats. Implementing standardized IAM tools and governance processes aims to enhance security, streamline access management, and align with future operational needs.
Why do this project now? With cyber threats growing in both frequency and sophistication, making strong Identity and Access Management (IAM) is essential to protecting NS Power's systems. Modern IAM capabilities are now required to maintai...
AI summary NS Power is implementing advanced Identity and Access Management (IAM) solutions to counter growing cyber threats, reduce security gaps, and ensure a secure operating environment. The project, initiated in 2024, includes deploying Privileged Access Management (PAM) and Identity Governance and Administration (IGA) tools, with Release One completed in February 2026 and full operationalization expected by October 2026.
Reason for Variance The increase of $2.4 million from the 2026 ACE Plan subsequent submittal estimate of $4,324,589 is primarily driven by higher-than-anticipated consulting costs relative to the initial estimate. During project planning a...
AI summary The increase of $2.4 million in the 2026 ACE Plan is attributed to higher consulting costs due to project milestone reorganization, extended timelines, and updates to the National Institute of Standards and Technology's Cyber Security Framework since the 2025 ACE Plan estimate.
N-2NSPI (CA) RIR 1 to 8 - Redacted
7 passages
NON-CONFIDENTIAL Filing Matter Number CI# Project Title Approved Budget (including contingency) Contingency ACE Plan Notes Scope 14 immediate pause in project activities. Following the incident, after approximately one month, work 15 was r...
AI summary The text discusses a project pause due to a cybersecurity incident, followed by resumed work on the Capital Work Order (CWO) in January 2026. The application was finalized and filed with the regulator in March 2026. The RFP and bid evaluation documentation were initiated during the 2024–2025 period and no additional RFPs or bid evaluations were conducted after this timeframe.
10 Software Description Source Page # IGA Saviynt Licensing Attachment 3 of the application - Section 8.1 31 of 66 PAM CyberArk Licensing Attachment 3 of the application - Section 8.2 31of 66 WPM CyberArk Workforce Password Manager Change...
AI summary The text lists software and licensing information related to cybersecurity and identity management, including IGA, PAM, and WPM, with details on their sources and page numbers.
12 Please refer to the table below for the source, including page number, for each item listed 13 under Consulting in the detailed cost estimate: Item Scope Source Page # Privileged Access PAM Deployment (workstream B) and change Attachmen...
AI summary The document outlines various IT initiatives and consulting services related to Identity and Access Management (IAM) for Nova Scotia Power Inc. (NSPI), including deployment of PAM and IGA, managed security services onboarding, staff augmentation, RFP planning, and infrastructure build activities.
NON-CONFIDENTIAL Item Scope Source Page # implementing CyberArk Privileged Cloud (PAM tool). Infrastructure Build MSP (OnX) provides infrastructure services n/a (PAM-SIA) (i.e. server builds), networking services (i.e. Firewall rule implem...
AI summary The document outlines infrastructure and project management activities related to implementing cybersecurity tools such as CyberArk Privileged Access Management (PAM) and Secure Infrastructure Access (SIA). MSP (OnX) provides infrastructure and networking services, while Deloitte offers project management expertise.
1 7 11 3 4 (d) Project Management Consulting was a staff augmented Project Manager leading the project 5 on behalf of NS Power until November 2025, when they were replaced by an internal NS 6 Power Project Manager. 8 Project Management Ser...
AI summary The text discusses the transition of project management roles within NS Power, including the replacement of a Project Manager by an internal NS Power manager in November 2025. It also mentions the discontinuation of a Project Management Services vendor related to IAM and references an attachment from NSEB IR-7.
18 Cost Element Total 17 prudent selection for a project at this level of definition. 18 19 (b) The in-service date for all of the application software is February 2026. The consulting in 20 service dates are: 21 22 • PAM – in-service date...
AI summary The document discusses the in-service dates for various cybersecurity and access management systems, including PAM and IGA, and outlines the deployment timeline for these systems. It also references a request (IR-7) and response regarding the status of items classified as 'Preliminary' in the Maturity Matrix.
REDACTED 1 Request IR-8: 2 3 With respect to Appendix A, please provide the following information: 4 5 (a) Working copy of the TCO Project Financials. 6 7 (b) Identify sources of each figure included in the analysis, and provide supporting...
AI summary The document outlines a request for detailed financial information on the TCO Project, including sources for figures, trend explanations, and cost-minimization strategies. NSPI responds by referencing attachments and tables, including Managed Security Services (MSS) licensing details and SaaS cost assumptions.
N-3NSPI (DOE) RIR 1 to 14 - Redacted
7 passages
CI C0068714 – IT – Identity and Access Management (NSEB M12743) NSPI Responses to Nova Scotia Department of Energy Information Requests 1 Request IR-1: 6 ensuring that the right people get the right access. The scale and scope of managing...
AI summary NSPI is responding to information requests regarding Identity and Access Management (IAM) implementation and cost savings from transitioning to a SaaS version of CyberArk PAM. The transition is expected to save $192,000 annually starting in 2026, with savings delayed due to overlap between the old and new systems during implementation.
REDACTED Request IR-7: Prior Identity (IAM) project Investments
AI summary The document discusses prior investments in the Identity and Access Management (IAM) project, focusing on previous initiatives related to identity and access management within Nova Scotia Power Inc.
(c) Please explain which specific investments areas in these prior projects failed to provide the 'automated credential lifecycle management' and 'credential vaulting', now deemed critical in this application. (d) Given that NSPI has frequ...
AI summary The text requests NSPI to explain which investments in prior projects failed to provide automated credential lifecycle management and credential vaulting. It also asks if NSPI anticipates further capital projects in Identity and Access Management beyond CI C0068714.
REDACTED 1 2 (c) Yes, NS Power anticipates that there will be ongoing capital needs within IAM, because 3 identity is the primary control point for access and security. As NS Power's cybersecurity 4 posture continues to evolve, identity go...
AI summary NS Power anticipates ongoing capital needs in IAM due to the importance of identity as a primary control point for access and security. As cybersecurity posture evolves, investments in identity governance, lifecycle automation, and directory modernization are expected to continue.
CI C0068714 – IT – Identity and Access Management (NSEB M12743) NSPI Responses to Nova Scotia Department of Energy Information Requests
AI summary This document outlines Nova Scotia Power Inc.'s responses to information requests from the Nova Scotia Department of Energy regarding Identity and Access Management (IAM) under the IT matter NSEB M12743.
NON-CONFIDENTIAL 1 Request IR-11: 2 3 Please provide a detailed list of the specific identity controls that were in place prior to the 4 March 2025 incident. Identify which of these pre-breach controls were found to be non 5 functional, or...
AI summary The response to Request IR-11 explains that the project aims to transition from on-premise IAM tools to SaaS cloud-based tools provided by a specialized vendor to enhance identity and access management services. The project was planned and submitted to the NESB prior to the March 2025 incident and its scope has not changed.
CI C0068714 – IT – Identity and Access Management (NSEB M12743) NSPI Responses to Nova Scotia Department of Energy Information Requests
AI summary This document outlines Nova Scotia Power Inc.'s responses to information requests from the Nova Scotia Department of Energy regarding Identity and Access Management (IAM) practices as part of a regulatory proceeding.
N-5NSPI (NSEB) RIR 1 to 22 - Redacted
3 passages
CI C0068714 – IT – Identity and Access Management (NSEB M12743) NSPI Responses to NSEB Information Requests 1 Request IR-1: 2 3 What is NS Power's threshold for classifying an account high-risk? 4 5 (a) How many high-risk accounts does NS...
AI summary NS Power responds to information requests regarding high-risk account thresholds and Identity/Access Management (IAM) system replacement. It cites cybersecurity risks to withhold high-risk account numbers and explains that the current IAM system, not a single platform, is sustained through incremental improvements. The old PAM solution, nearing end-of-life in 2026, is being replaced by new assets from CI 49094 and CI C0054455.
NON-CONFIDENTIAL 1 Request IR-4: 2 3 What type of support will NS Power receive following implementation? 4 5 (a) Please describe how the managed support capabilities from operational support 6 services will augment NS Power's existing sta...
AI summary The document discusses NS Power's transition to a Managed Security Services (MSS) model for Identity and Access Management (IAM) and related platforms. It outlines how MSS will enhance cybersecurity posture through centralized support and automated processes, while NS Power retains governance and accountability. Updates to the software will be managed by the vendor, with limited impact on NS Power.
Project Overview Project Details Reference ID RFP-08/2024-350 Project Name IAM - Identity and Access Management Services/Solution Project Owner Ron Fox Project Type RFP Department IT - Operations Budget $ – an application will be made for...
AI summary Nova Scotia Power Inc. (NSPI) and Tampa Electric Company Inc. (TECO) are seeking proposals for Identity and Access Management (IAM) services, including upgrades to existing Privilege Access Management (PAM) solutions and the implementation of automation for IAM controls and processes.
N-6NSPI (SBA) RIR 1 to 5 - Redacted
3 passages
CI C0068714 – IT – Identity and Access Management (NSEB M12743) NSPI Responses to Small Business Advocate Information Requests 1 Request IR-1: 2 3 Referring to M12743, Exhibit N-1, NS Power Inc. Application for Approval of Capital Work 4 O...
AI summary The document discusses NS Power Inc.'s response to information requests regarding the C0068714 Project - Redacted, explaining the difference between 'IAM procedures and tools' and 'Core deliverables'. It outlines how IAM is achieved through processes and tools, and defines core deliverables as tangible outputs like policies, documentation, and compliance evidence.
CI C0068714 – IT – Identity and Access Management (NSEB M12743) NSPI Responses to Small Business Advocate Information Requests
AI summary The document outlines NSP's responses to information requests from the Small Business Advocate regarding Identity and Access Management (IAM) practices within the Nova Scotia Power organization.
REDACTED 1 Request IR-4: 2 3 Refer to Exhibit N-1, the C0068714 Project-Redacted, in the section Contingency Statement, 4 on page 2 of 5 and Reason for Variance, on page 2 of 5 and refer also to Exhibit N-1(C) NS 5 Power Inc. Application f...
AI summary The document discusses responses to information requests regarding the C0068714 Project-Redacted, focusing on the 2026 ACE Plan variance and the capitalization of software costs. It outlines reasons for the increase in the ACE Plan estimate and clarifies that software service agreements are not capitalized, but assets from the project are depreciated over 10 years. Cybersecurity updates are managed by the vendor, with expected updates occurring a few times per year.
N-8Rebuttal Evidence - NSPI
12 passages
2.2 Impact of Cybersecurity Incident on Project AFUDC Costs - The CA raises further concerns regarding the AFUDC included in NS Power's application and - recommends that the Board disallow a portion of these costs. This position is based o...
AI summary The CA recommends disallowing a portion of AFUDC costs for NS Power's IAM project due to a 12-month delay attributed to insufficient internal resources, potentially linked to a cybersecurity incident. NS Power disagrees, stating the delay was due to changes in project scope, the NIST Cybersecurity Framework, and evolving technology, not the incident itself.
DATE FILED: July 7, 2026 Page 10 of 17 1 3.0 RESPONSE TO SBA SUBMISSIONS 2 3 The SBA has identified two principal concerns regarding this application. First, it questions 4 whether the cyber incident contributed to cost increases, the over...
AI summary The SBA raises concerns about the impact of a cyber incident on project costs and the completeness of the application. NS Power responds by stating that the project was initially identified in the 2025 ACE Plan and was deferred due to the cyber incident, with resources reallocated to restoration efforts.
DATE FILED: July 7, 2026 Page 11 of 17 that it had not yet reached an appropriate level of scope and estimate refinement for approval. As explained above in Section 2.2 and in the application, the increase from the 2026 ACE Plan subsequent...
AI summary The document discusses the increase in costs for the 2026 ACE Plan due to project development and the evolution of the NIST Cybersecurity Framework. It also addresses concerns raised by the SBA regarding the value of the IAM project in preventing future cyber breaches and enhancing cybersecurity.
ycle management, stronger security controls, improved compliance, and a more efficient user experience. The project addresses critical cybersecurity vulnerabilities by replacing an outdated, on-premises PAM solution that exited vendor supp...
AI summary The text discusses the need for a new cybersecurity solution to replace an outdated PAM system, addressing evolving threats targeting privileged identities. It highlights the importance of stronger security controls and compliance.
ing the network perimeter, threat actors now target identities, particularly privileged accounts. This SBA Submissions, page 3. DATE FILED: July 7, 2026 Page 12 of 17
AI summary The text discusses the impact of a cybersecurity incident on Project AFUDC costs, highlighting that threat actors now target identities, especially privileged accounts, which can affect construction costs during a project.
trend is expected to accelerate as threats become faster, more sophisticated, and increasingly automated through artificial intelligence. In this environment, identity becomes a core security control. This project enables NS Power to reduc...
AI summary The document discusses the impact of a cybersecurity incident on AFUDC costs, emphasizing the need for modern PAM and IAM capabilities to reduce risk and ensure compliance. It highlights the transition to IBM's MSS and the importance of continuous monitoring and improvement of IAM processes.
used and useful. The SBA questions the relationship between this application and previously approved IT capital projects of similar scope and magnitude, including whether DATE FILED: July 7, 2026 Page 13 of 17
AI summary The document discusses the impact of a cybersecurity incident on Project AFUDC costs, highlighting concerns raised by the SBA regarding the relationship between this application and previously approved IT capital projects of similar scope and magnitude.
ionship between this application and previously approved IT capital projects of similar scope and magnitude, including whether DATE FILED: July 7, 2026 Page 13 of 17
AI summary This section discusses the impact of a cybersecurity incident on the Allowance for Funds Used During Construction (AFUDC) costs for Project AFUDC. It references the relationship between this application and previously approved IT capital projects of similar scope and magnitude.
any components of existing systems can continue to provide value and whether assets not yet fully depreciated should now be considered no longer used and useful. [19](#page-13-0) The assets created by CI C0068714 will replace those associa...
AI summary The text discusses the replacement of an outdated on-premises PAM system with a modern cloud-based solution, highlighting the end of life for the legacy system and the infeasibility of reusing its components due to security and integration risks. It also mentions how prior PAM assets will continue to be amortized under the 2026–2027 GRA framework.
DATE FILED: July 7, 2026 Page 14 of 17 1 3.3 Project Status 2 3 The SBA's final assertion is that this application provides an incomplete picture of the IAM 4 project, particularly with respect to total cost, timing of full deployment, and...
AI summary NS Power responds to the SBA's assertion that their IAM project application is incomplete by clarifying that the project's scope and total cost are clearly defined, with a total capital investment of $6,756,522. They emphasize that the project is already delivering cybersecurity value and that additional capabilities will continue to be deployed with measurable improvements.
Privilege Manager (EPM) to enforce least-privilege access on workstations and servers, and expanded cloud security capabilities to extend PAM controls across hybrid environments. Phased deployment is both appropriate and necessary for a pr...
AI summary The document discusses the phased deployment of Privilege Manager (EPM) to enforce least-privilege access and expand cloud security capabilities across hybrid environments. It emphasizes that a phased approach reduces risk, supports testing, and allows incremental value delivery, with full deployment expected by August 2026.
NS Power submits that the capital expenditures outlined in this application are reasonable, prudent, and in the best interest of customers. This project is necessary to maintain effective cybersecurity controls and to position NS Power to...
AI summary NS Power argues that the proposed capital expenditures are reasonable, prudent, and in the best interest of customers, emphasizing the need for cybersecurity improvements. The request is for approval of CI C0068714 IT Identity & Access Management.
101843NSEB (NSPI) IR 1 to IR 22 - Redacted
3 passages
Request IR-5: - Pages 1 and 2 of the application describe the Identity and Access Management (IAM) framework - as a partnership to operate and maintain IAM practices which will effectively allow NS Power to - outsource elements of cybersec...
AI summary Request IR-5 seeks clarification on NS Power's IAM framework partnership with Saviynt, including data control, cybersecurity protections, service locations, and potential vendor lock-in. Questions focus on whether the investment is a service, data security measures, and geographic risks of outsourcing.
Request IR-7: - Page 2 of the application explains that the selected approach was chosen through a competitive procurement process. - a) Please provide the quotes received for all proposals. - b) Please provide the documentation used in ev...
AI summary Request IR-7 seeks details on NS Power's procurement of an IAM solution, including quotes, evaluation criteria, reference checks with Saviynt, platform testing, and justification for selecting this IAM as the only feasible option meeting NIST cybersecurity standards.
Request IR-12: The SOW states a) Which specific under this contract are subject to ? b) What process does NS Power use to determine ? c) What is the estimated cost of providing ? i. Please identify where in the detailed project estimate th...
AI summary The text contains a series of requests (IR-12 to IR-22) related to a contract involving identity and access management (IAM) and privileged access management (PAM) by NS Power. The requests focus on controls, data residency, security certifications, due diligence, and data quality, among other topics.