N-23M12835 Exhibit N-2 Att 3 2025 Managements Discussion AnalysisHIGHLIGHTED
3 passages
Weather Risk A Material Adverse Effect may arise from weather seasonal variations impacting energy consumption, as well as severe weather events, changing air temperatures, wildfires and other severe weather conditions that are expected to...
AI summary The document discusses how weather-related risks, including seasonal variations, severe weather events, and climate change impacts, can affect energy consumption, infrastructure, and financial stability. These risks may lead to reduced revenues, increased costs, and potential Material Adverse Effects if not mitigated through insurance or regulatory processes.
Transition Risk: As government policy related to the environment, renewable energy, and decarbonization continues to shift, the Company is exposed to increased uncertainty and risk arising from policy, legal, regulatory, technology, and ma...
AI summary The Company faces transition risks due to evolving environmental policies, renewable energy mandates, and decarbonization efforts. These changes require significant capital investment and may affect customer demand, rates, and the Company's ability to recover costs. Insurance and legal risks are also increasing as carbon-emitting assets become harder to insure and face potential litigation.
System Operating and Maintenance Risks The safe and reliable operation of electric generation transmission and distribution systems is critical to NSPl's operations. There are a variety of hazards and operational risks inherent in operatin...
AI summary The document discusses the operational and maintenance risks faced by Nova Scotia Power Inc. (NSPI) in managing its electric generation, transmission, and distribution systems. These risks include mechanical failures, cyberattacks, natural disasters, and supply chain issues, all of which could lead to infrastructure damage, public safety concerns, and financial losses. The regulatory framework allows NSPI to recover prudently incurred costs.
100853NS Power's Monthly Update #2 (M12273)
3 passages
Technology Enablement The Incident disrupted foundational technology services, which created dependencies that impacted the restoration of some business functions and required employees to rely on contingency solutions. To address these ch...
AI summary The Incident disrupted foundational technology services, leading to dependencies that impacted business functions. A secure network rebuild, device re-imaging, and backup programs are underway to restore operations and ensure continuity.
Ongoing Regulatory Matters As a result of the impacts noted above, several matters before the Board have been affected, including: • rates-related, - customer billing, - capital and ACE Plan, - financial reporting and statements, - Fuel Ad...
AI summary The document outlines how various regulatory matters before the Nova Scotia Energy Board have been impacted by an incident, including rates, billing, capital, financial reporting, and demand-side management. The Board is being kept informed of evolving impacts, and communication with stakeholders is emphasized.
Rates-Related Matters Rates-related matters have been affected by the Incident. Time Varying Pricing As noted by the NSEB in its letter of September 17, 2025, the Time Varying Pricing (TVP) matter has been affected by the Incident. NS Powe...
AI summary The Incident has disrupted the preparation of reports and calculations related to Time Varying Pricing, TOU RTP tariffs, and the ELIADC tariff. NS Power is unable to produce the 2025 report due to missing data and is investigating file recovery. Systems required for cost calculations are currently unavailable, and NS Power plans to run retroactive calculations once systems are restored.
100856NS Power's Monthly Update #5 (M12273)
4 passages
Technology Enablement NS Power has continued to strengthen foundational technology required to support core business operations. Key integrations across operational systems have been restored, and work to restore and further fortify networ...
AI summary NS Power has enhanced core technology infrastructure, restored system integrations, and advanced disaster recovery preparations. Efforts include replacing virtual firewalls with physical devices to improve reliability and configuring disaster recovery infrastructure to support system resiliency.
Additional Capabilities NS Power continues to expand access to real-time operational data, with progress made in restoring the plant information systems and onboarding users for access. Connections have now been established for several gen...
AI summary NS Power is enhancing real-time data access, restoring reporting systems, and rebuilding operational applications. Progress includes establishing connections for generating assets, restoring critical reports, and advancing asset management and fuel management systems to support decision-making and operational oversight.
Recovery Timeline NS Power remains focused on restoring its most critical business functions by continuing to rebuild and stabilize the supporting technologies and infrastructure that enable them. Over the past month, significant progress...
AI summary NS Power is focused on restoring critical business functions by rebuilding infrastructure and technology platforms, with progress made in data integration, networking, and disaster recovery. System restoration is expected to continue through 2026, prioritizing operational needs and long-term resiliency.
a. Steps to address potential failures or inaccuracies. - NS Power did act on contingency plans when billing resumed in June 2025. This included estimated billing, and the concurrent hiring, training and deployment of meter readers. - NS P...
AI summary NS Power implemented contingency plans, including estimated billing and meter reader deployment, after a 2025 billing system failure. Moving forward, they plan disaster recovery solutions for smart meters, enhanced monitoring, and CIS system modernization to improve bill accuracy and reliability.
101524David MacLeod (NSPI) IR A-1 to G-5
5 passages
- Explicitly warned that Russian state-sponsored actors were targeting Canadian critical - infrastructure in response to Canada's support for Ukraine. - NCTA 2025-2026 (Canadian Centre for Cyber Security, 2024): Published in October 2024 -...
AI summary The text highlights the threat posed by Russian state-sponsored actors to Canadian critical infrastructure, including the electricity sector, as outlined in the NCTA 2025-2026 and CCCS assessments. Nova Scotia's strategic importance in Canada's defense posture and the documented use of cyber threats like phishing are emphasized, urging infrastructure operators to account for these risks.
A.4 The Ukrainian Grid Attacks as Proof of Concept - The academic and technical literature establishes beyond reasonable dispute that Russian-nexus - actors demonstrated both the capability and the intent to attack electricity infrastructu...
AI summary The text discusses the Ukrainian grid attacks as proof of concept, highlighting the capability and intent of Russian-nexus actors to attack electricity infrastructure. It outlines three major cyberattacks: the 2015 BlackEnergy/Sandworm attack, the 2016 Industroyer/CRASHOVERRIDE attack, and the 2022 Industroyer2 attack, all attributed to Sandworm, a GRU-affiliated group.
B. NSP's Acknowledged Risk and Inadequate Response - The evidentiary record before the Board contains a critical and damaging admission. On - February 27, 2025 NSP's Chief Operating Officer, Dave Pickles, filed a report with the UARB - tit...
AI summary Nova Scotia Power (NSP) acknowledged the rising cybersecurity threats but failed to implement a comprehensive response. Their plan focused only on operational technology (OT) systems, ignored IT systems and customer data, and did not address specific Russian-nexus threats. The breach went undetected for 37 days, and NSP lacked a backup site, leading to long-term system impairments and data exposure.
IR B-2 — IT/OT Segmentation - (a) Describe the segmentation controls that existed between NSP's IT and OT networks as of March 18, 2025. - (b) NSP's Monthly Update 6 (March 2026) disclosed that post-attack remediation included "the continu...
AI summary The document requests details about IT/OT network segmentation controls at NSP as of March 2025, the replacement of virtual firewalls with physical devices post-attack, and the attack path used by the threat actor, including failed segmentation controls.
GROUP G — POST-INCIDENT REMEDIATION AND FORWARD COMMITMENTS - These Interrogatories address NSP's post-attack remediation program, the adequacy and pace - of that program, and NSP's forward commitments to prevent recurrence. They are relev...
AI summary This section addresses NSP's post-incident remediation efforts, their adequacy and pace, and forward commitments to prevent recurrence. It is relevant to the Board's evaluation of NSP's accountability and whether ratepayers should bear remediation costs.