HomeCybersecurityM12835Evidence
Topic/Matter Intersection

Topic:"Cybersecurity" in M12835

Matter: Nova Scotia Power Inc. - Annual and Regulated Financial Statements - 2025
40 passages 4 documents

Cybersecurity across all matters →

N-12025 Annual Financial Statements - Redacted 16 passages
Cybersecurity Incident p. p. 54
Cybersecurity Incident On April 25, 2025, NSPI discovered a cybersecurity incident (the "Cybersecurity Incident") involving unauthorized access into certain parts of its information technology ("IT") network and servers supporting portions...

AI summary On April 25, 2025, NSPI experienced a cybersecurity incident involving unauthorized IT network access, with no physical operational disruption. The company implemented business continuity measures, incurred $7 million in after-tax costs for 2025, and maintains cyber insurance to address claims.

Cybersecurity Incident : p. p. 54
Cybersecurity Incident : On May 14, 2025, the NSEB initiated an inquiry into the Cybersecurity Incident. For further information on the "Cybersecurity Incident", refer to note 1.

AI summary On May 14, 2025, the Nova Scotia Energy Board (NSEB) initiated an inquiry into a Cybersecurity Incident. The text directs readers to note 1 for further details about the incident.

Cybersecurity Incident: p. p. 54
Cybersecurity Incident: On April 25, 2025, NSPI discovered a cybersecurity incident (the "Cybersecurity Incident") involving unauthorized access into certain parts of its IT network and servers supporting portions of its business applicati...

AI summary On April 25, 2025, NSPI detected a cybersecurity incident involving unauthorized access to its IT network and servers, though physical operations remained unaffected. The incident did not disrupt NSPI's physical operations.

2025 Annual Financial Statements Attachment 3 Page 5 of 30 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 54
2025 Annual Financial Statements Attachment 3 Page 5 of 30 REDACTED (CONFIDENTIAL INFORMATION REMOVED) The Company implemented business continuity processes for certain impacted business and administrative functions. The systematic restora...

AI summary The Company incurred $7 million in after-tax costs for the year ended December 31, 2025, related to a cybersecurity incident. It implemented business continuity processes and maintains cyber insurance coverage. Costs recognized in Q4 2025 totaled $1 million. Risks associated with cybersecurity incidents are detailed in the 'Enterprise Risk and Risk Management' section.

Cybersecurity Risk p. p. 54
Cybersecurity Risk NSPI is exposed to potential risks related to cyberattacks, data breaches, cyber-extortion, and unauthorized access that could result in a Material Adverse Effect. The Company increasingly relies on IT systems, networks...

AI summary NSPI faces cybersecurity risks from cyberattacks, data breaches, and unauthorized access, potentially causing material adverse effects. The company relies on IT systems, third-party providers, and cloud infrastructure, increasing vulnerability to nation-state threats and AI-enhanced attacks. Breaches could disrupt energy operations, compromise data, and impact customer services.

2025 Annual Financial Statements Attachment 3 Page 22 of 30 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 54
2025 Annual Financial Statements Attachment 3 Page 22 of 30 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Cyberattacks or unauthorized access may cause lost revenues, costs, losses, regulatory penalties and third-party damages all, or some o...

AI summary The document outlines cybersecurity risks to the Company, including financial losses, regulatory penalties, and third-party damages, which may not be recoverable. It highlights the Company's mitigation strategies, such as adhering to cybersecurity standards, conducting assessments, and hiring experts, while noting compliance with NSEB-approved regulations and quarterly reporting to the Board of Directors.

Technology Risk p. p. 54
Technology Risk NSPI relies on various technology systems to manage operations, including increasing reliance on IT solutions operated by third parties, such as software as a service and third party cloud hosting. This subjects NSPI to inh...

AI summary NSPI faces technology risks from reliance on third-party IT systems, cloud services, and SaaS, including operational disruption, cyber threats, and AI integration challenges. Digital transformation efforts, like Generative AI investments, increase project risks. Failure to manage these could lead to operational, financial, and reputational impacts.

Cybersecurity Incident p. p. 108
Cybersecurity Incident On April 25, 2025, NSPI discovered the Cybersecurity Incident involving unauthorized access into certain parts of its IT network and servers supporting portions of its business applications. There was no disruption t...

AI summary NSPI discovered a cybersecurity incident on April 25, 2025, involving unauthorized IT network access. No physical operations were disrupted. The company implemented business continuity processes and incurred $7 million in after-tax costs for the year ended December 31, 2025, with $1 million recognized in Q4 2025.

Safety and Security p. pp. 140-141
Safety and Security Safety remains our highest priority and the standard we hold ourselves to every day. In 2025, we continued to strengthen safety practices across our operating companies—assessing performance, identifying root causes, an...

AI summary Nova Scotia Power improved safety metrics in 2025, with reduced injury rates, but a workplace fatality at Tampa Electric highlights ongoing challenges. A cyber incident in 2025 prompted enhanced cybersecurity measures.

Board Governance p. p. 142
Board Governance The Board's disciplined oversight helped keep Emera focused on creating and delivering long-term value, balance sheet strength, and responsible growth as we advanced major investments. In a year marked by record performanc...

AI summary The Board emphasized its oversight in ensuring Emera's long-term value and responsible growth, highlighted new board member Isabelle Courville, and noted the departure of Brian Porter and Jackie Sheppard. Cybersecurity and digital resilience were key focus areas, with the Board reinforcing vigilance amid evolving threats and digital transformation efforts.

Forward-Looking Information p. p. 146
FLI is based on reasonable assumptions and is subject to risks, uncertainties and other factors that could cause actual results to differ materially from historical results or results anticipated by the FLI. Factors that could cause result...

AI summary Forward-Looking Information (FLI) is subject to risks including regulatory changes, economic conditions, commodity price fluctuations, cybersecurity threats, and climate impacts. These factors could cause actual results to diverge from expectations, affecting dividend growth, capital investments, and operational stability for entities like Emera and NSPI.

Cybersecurity Incident p. p. 160
Cybersecurity Incident On April 25, 2025, Emera and NSPI discovered a cybersecurity incident involving unauthorized access into certain parts of its Canadian IT network and servers supporting portions of its business applications (the "Cyb...

AI summary On April 25, 2025, Emera and NSPI detected a cybersecurity incident involving unauthorized access to Canadian IT networks. No operational disruptions occurred, and business continuity measures were implemented. The incident is not expected to materially impact financial position or results, with cyber insurance claims underway.

Cybersecurity Risk p. p. 180
Cybersecurity Risk Emera is exposed to potential risks related to cyberattacks, data breaches, cyber-extortion, and unauthorized access that could result in a Material Adverse Effect. The Company increasingly relies on IT systems, networks...

AI summary Emera faces cybersecurity risks from cyberattacks, data breaches, and unauthorized access, which could cause a Material Adverse Effect. The company relies on IT systems and third-party providers, increasing vulnerability to attacks, especially from nation-state actors and evolving AI tools.

2025 Annual Financial Statements Attachment 6 Page 51 of 138 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 180
2025 Annual Financial Statements Attachment 6 Page 51 of 138 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Strategic Overview Management's Discussion and Analysis Consolidated Financial Statements Emera Leadership and Board Shareholder infor...

AI summary The document highlights cybersecurity risks to Emera's systems, including potential breaches leading to operational disruptions, financial losses, and regulatory penalties. Emera mitigates these risks through compliance with standards like NIST and NAERC, regular assessments, and cybersecurity training, while acknowledging insurance coverage limitations and talent challenges.

Technology Risk p. p. 180
Technology Risk Emera relies on various technology systems to manage operations, including increasing reliance on solutions operated by third parties, such as software as a service and third-party cloud hosting. This subjects Emera to inhe...

AI summary Emera faces technology risks from reliance on third-party systems, including operational disruptions, cybersecurity vulnerabilities, and challenges in integrating AI. The rapid evolution of AI could disrupt business models, while digital transformation efforts increase project risks. Failure to manage these risks may lead to operational, financial, or reputational harm.

Cybersecurity Incident p. p. 199
Cybersecurity Incident On April 25, 2025, Emera and NSPI discovered a cybersecurity incident (the "Cybersecurity Incident") involving unauthorized access into certain parts of its Canadian IT network and servers supporting portions of its...

AI summary On April 25, 2025, Emera and NSPI identified a cybersecurity incident involving unauthorized access to their Canadian IT network. No operational disruptions occurred, and business continuity measures were implemented. System restoration is ongoing, and cyber insurance claims are being processed.

N-2Refiled Statements - NSPI - Redacted 19 passages
Cybersecurity Incident p. p. 54
Cybersecurity Incident On April 25, 2025, NSPI discovered a cybersecurity incident (the "Cybersecurity Incident") involving unauthorized access into certain parts of its information technology ("IT") network and servers supporting portions...

AI summary On April 25, 2025, Nova Scotia Power Inc. (NSPI) experienced a cybersecurity incident involving unauthorized IT network access. No physical operations were disrupted, but the company incurred $7 million in after-tax costs for 2025, including $1 million in Q4 2025. Business continuity processes were implemented during restoration, with phased system recovery ongoing.

Cybersecurity Incident : p. p. 54
Cybersecurity Incident : On May 14, 2025, the NSEB initiated an inquiry into the Cybersecurity Incident. For further information on the "Cybersecurity Incident", refer to note 1.

AI summary On May 14, 2025, the Nova Scotia Energy Board (NSEB) initiated an inquiry into a cybersecurity incident. Further details on the incident are referenced in note 1 of the document.

Cybersecurity Incident: p. p. 54
Cybersecurity Incident: On April 25, 2025, NSPI discovered a cybersecurity incident (the "Cybersecurity Incident") involving unauthorized access into certain parts of its IT network and servers supporting portions of its business applicati...

AI summary On April 25, 2025, Nova Scotia Power Inc. (NSPI) discovered a cybersecurity incident involving unauthorized access to its IT network and servers. No physical operations were disrupted.

2025 Annual Financial Statements Attachment 3 Page 5 of 30 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 54
2025 Annual Financial Statements Attachment 3 Page 5 of 30 REDACTED (CONFIDENTIAL INFORMATION REMOVED) The Company implemented business continuity processes for certain impacted business and administrative functions. The systematic restora...

AI summary The Company incurred $7 million in after-tax costs for a cybersecurity incident in 2025, with $1 million recognized in Q4 2025. Cyber insurance is being utilized for claims, and IT system restoration continues. Cybersecurity risks are detailed in the 'Enterprise Risk and Risk Management' section.

Class Action Lawsuit: p. p. 54
Class Action Lawsuit: NSPI was named as a defendant in a claim for a class action lawsuit filed with the Supreme Court of Nova Scotia, seeking damages arising from the Cybersecurity Incident. The amount of damages has not been specified. D...

AI summary Nova Scotia Power Inc. (NSPI) is a defendant in a class action lawsuit related to a cybersecurity incident. The lawsuit seeks unspecified damages, and the legal proceedings are in an early stage with no estimated loss.

Cybersecurity Risk p. p. 54
Cybersecurity Risk NSPI is exposed to potential risks related to cyberattacks, data breaches, cyber-extortion, and unauthorized access that could result in a Material Adverse Effect. The Company increasingly relies on IT systems, networks...

AI summary NSPI faces cybersecurity risks from cyberattacks, data breaches, and unauthorized access, which could disrupt operations, compromise sensitive data, and impact energy infrastructure. The company relies on IT systems, third-party providers, and cloud infrastructure, increasing vulnerability to evolving threats, including AI-driven attacks. Breaches could lead to service outages, financial losses, and safety issues.

2025 Annual Financial Statements Attachment 3 Page 22 of 30 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 54
2025 Annual Financial Statements Attachment 3 Page 22 of 30 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Cyberattacks or unauthorized access may cause lost revenues, costs, losses, regulatory penalties and third-party damages all, or some o...

AI summary The document outlines risks from cyberattacks, including financial losses and regulatory penalties, and notes potential insurance coverage limits. The company mitigates these risks through cybersecurity frameworks, assessments, and compliance with standards like those from the NSEB. Challenges in retaining cybersecurity talent could hinder risk management efforts.

Technology Risk p. p. 54
Technology Risk NSPI relies on various technology systems to manage operations, including increasing reliance on IT solutions operated by third parties, such as software as a service and third party cloud hosting. This subjects NSPI to inh...

AI summary NSPI faces operational and cybersecurity risks due to reliance on third-party IT systems and cloud solutions, potential disruptions from AI integration, and vulnerabilities from rapid technological changes. Digital transformation efforts, including Generative AI, increase project risks and dependency on external providers, with possible adverse impacts on operations, finances, and data security.

CAUTIONARY NOTE REGARDING FORWARD-LOOKING INFORMATION p. p. 108
CAUTIONARY NOTE REGARDING FORWARD-LOOKING INFORMATION This AIF, including the documents incorporated herein by reference, contains "forward-looking information" and "forward-looking statements" within the meaning of applicable securities l...

AI summary This document contains forward-looking information about NSPI's financial performance, operations, and regulatory compliance. It includes projections and assumptions regarding revenue, capital investments, regulatory decisions, environmental initiatives, and potential challenges such as cyber incidents and global economic conditions.

Cybersecurity Incident p. p. 108
Cybersecurity Incident On April 25, 2025, NSPI discovered the Cybersecurity Incident involving unauthorized access into certain parts of its IT network and servers supporting portions of its business applications. There was no disruption t...

AI summary On April 25, 2025, NSPI discovered a cybersecurity incident involving unauthorized access to its IT network and servers. No physical operations were disrupted, but the company incurred significant after-tax costs, including $1 million in Q4 2025 and $7 million for the year ended December 31, 2025. Business continuity processes were implemented, and the company is working with its insurer on the claims process.

2025 Annual Financial Statements Attachment 5 Page 16 of 26 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 108
2025 Annual Financial Statements Attachment 5 Page 16 of 26 REDACTED (CONFIDENTIAL INFORMATION REMOVED) cybersecurity incidents generally, refer to the 'Enterprise Risk and Risk Management' section of the MD&A, which is incorporated herein...

AI summary The text references a section on cybersecurity incidents in the MD&A, directing readers to the 'Enterprise Risk and Risk Management' section, which is available electronically on SEDAR+ under NSPI's profile.

Forward-Looking Information p. p. 146
FLI is based on reasonable assumptions and is subject to risks, uncertainties and other factors that could cause actual results to differ materially from historical results or results anticipated by the FLI. Factors that could cause result...

AI summary Forward-looking information (FLI) is subject to various risks and uncertainties that could cause actual results to differ significantly from expectations. These include regulatory, economic, environmental, technological, and operational risks, among others.

Cybersecurity Incident p. p. 160
Cybersecurity Incident On April 25, 2025, Emera and NSPI discovered a cybersecurity incident involving unauthorized access into certain parts of its Canadian IT network and servers supporting portions of its business applications (the "Cyb...

AI summary On April 25, 2025, Emera and NSPI discovered a cybersecurity incident involving unauthorized access to parts of their Canadian IT network. No physical operations were disrupted, and the company is restoring affected systems through planned processes. The incident is not expected to have a material financial impact.

Cybersecurity Risk p. p. 180
Cybersecurity Risk Emera is exposed to potential risks related to cyberattacks, data breaches, cyber-extortion, and unauthorized access that could result in a Material Adverse Effect. The Company increasingly relies on IT systems, networks...

AI summary Emera faces cybersecurity risks from cyberattacks, data breaches, and unauthorized access, which could result in a Material Adverse Effect. The company relies heavily on IT systems, third-party service providers, and cloud infrastructure to manage its critical energy infrastructure, making it a potential target for cyber threats, including those from nation-state actors.

2025 Annual Financial Statements Attachment 6 Page 51 of 138 REDACTED (CONFIDENTIAL INFORMATION REMOVED) p. p. 180
2025 Annual Financial Statements Attachment 6 Page 51 of 138 REDACTED (CONFIDENTIAL INFORMATION REMOVED) Strategic Overview Management's Discussion and Analysis Consolidated Financial Statements Emera Leadership and Board Shareholder infor...

AI summary The document highlights the potential risks associated with cybersecurity breaches and their impact on Emera's operations, including system failures, loss of service, and financial losses. It outlines measures taken by the company to manage these risks, such as aligning with cybersecurity standards, conducting assessments, and engaging third-party experts.

Technology Risk p. p. 180
Technology Risk Emera relies on various technology systems to manage operations, including increasing reliance on solutions operated by third parties, such as software as a service and third-party cloud hosting. This subjects Emera to inhe...

AI summary Emera depends on various technology systems and third-party solutions, which introduces operational, financial, and cybersecurity risks. The company's digital transformation strategy, including investments in AI and infrastructure modernization, increases project risks and potential disruptions if not managed effectively.

System Operating and Maintenance Risks p. p. 180
System Operating and Maintenance Risks The safe and reliable operation of electric generation and electric and natural gas transmission and distribution systems is critical to Emera's operations. There are a variety of hazards and operatio...

AI summary The document highlights the operational and maintenance risks associated with Emera's electric and natural gas systems, including mechanical failures, cyberattacks, natural disasters, and third-party activities. These risks could impact public safety, infrastructure, and customer confidence, with potential losses not fully covered by insurance or regulatory recovery mechanisms.

Change in ICFR p. p. 190
Change in ICFR In April 2025, the Company experienced a Cybersecurity Incident that impacted certain financial systems and processes at its Canadian affiliates. As a result, the Company transitioned these to business continuity processes a...

AI summary In April 2025, a Cybersecurity Incident affected financial systems at the Company's Canadian affiliates, leading to a transition to business continuity processes and changes in ICFR. The Company later restored systems and transitioned back, resulting in another material change in ICFR during the second half of 2025. No other material changes in ICFR occurred during the year ended December 31, 2025.

Cybersecurity Incident p. p. 199
Cybersecurity Incident On April 25, 2025, Emera and NSPI discovered a cybersecurity incident (the "Cybersecurity Incident") involving unauthorized access into certain parts of its Canadian IT network and servers supporting portions of its...

AI summary On April 25, 2025, Emera and Nova Scotia Power Inc. discovered a cybersecurity incident involving unauthorized access to parts of their Canadian IT network and servers. No disruption to physical operations occurred, and the company is implementing business continuity processes and working with insurers on claims.

N-4NSPI (NSEB) RIR 1 to 12 - Redacted 2 passages
Social p. p. 24
Social There were no Social factors that had a relevant or significant effect on the credit analysis. As a regulated utility, NSPI provides an essential service to its customers. NSPI is also committed to the safety of its employees and cu...

AI summary The document discusses the social factors related to NSPI's credit analysis, highlighting its essential service to customers, operational safety, and performance metrics. While NSPI improved its SAIFI score in 2024, its SAIDI remained above the threshold. A cybersecurity incident in April 2025 did not impact operations, and the company provided free credit monitoring to customers.

NON-CONFIDENTIAL p. p. 24
NON-CONFIDENTIAL 1 due to the 2025 cybersecurity incident is the primary factor driving the increase in accounts 2 receivable year over year. 3 4 Following the incident, collection activities, including the application of interest on late...

AI summary The 2025 cybersecurity incident significantly increased accounts receivable due to suspended collection activities and delayed payments. NS Power evaluated historical data, including the impact of the COVID-19 pandemic, to determine that the allowance for credit losses is adequate.

103196NSEB (NSPI) IR-13 to IR-19 3 passages
Request IR-13:
Request IR-13: - Please confirm if there were costs associated with the 2025 Cybersecurity incident included in - NS Power's 2025 regulated financial statements.

AI summary The document requests confirmation of whether costs related to the 2025 Cybersecurity incident were included in NS Power's 2025 regulated financial statements.

Request IR-14:
Request IR-14: - If any Cybersecurity incident costs were recorded in the regulated statements, please provide a - breakdown by cost category, account number, financial statement line item, amount incurred, - amount recovered or expected t...

AI summary Request IR-14 asks for a breakdown of cybersecurity incident costs recorded in regulated statements, including categorization, financial details, insurance recovery, and customer recovery considerations.

Request IR-16:
Request IR-16: - a) Please identify any indirect costs recognized in 2025 that arose from the Cybersecurity incident, including insurance premium changes, deductibles, business continuity costs, temporary staffing, billing and collection c...

AI summary Request IR-16 asks for the identification of indirect costs from a 2025 Cybersecurity incident and an explanation of their accounting and regulatory treatment, including insurance, legal, and customer notification expenses.

Disclaimer: These summaries were generated by AI from the filings they describe. We take care to make them accurate, but errors are possible - and they aren't advice. Only the filings themselves are the record: if you're relying on something here, confirm it against the source documents or the Nova Scotia Energy Board's own record. Full disclaimer →