4 unchanged sentences
Throughout the year, we regularly assess our cybersecurity program and continue to invest in hardening and maturing our cybersecurity measures as further described below.
−Removed: Managing Material Risks & Integrated Overall Risk Management
−Removed: As a foundation of this approach, we have implemented a layered governance structure to help assess, identify, and manage cybersecurity risks.
−Removed: It starts with our internal Cybersecurity Operations Center (CSOC), which routinely analyzes threat information from external sources, monitors network activity, and responds to potential security incidents.
−Removed: In addition, our cybersecurity and privacy policies encompass incident response procedures and information security governance.
−Removed: As part of our ongoing assessment of our cybersecurity program, we monitor and make adjustments, as necessary, in support of compliance with current and emerging cybersecurity and privacy laws, regulations and guidance applicable to us in jurisdictions where we do business (including NERC CIP reliability standards and TSA security directives), as further described in Item 1A “Risk Factors.” Our internal audit team conducts regular internal security audits and vulnerability assessments of CenterPoint Energy’s systems and user data security practices.
−Removed: In addition, CenterPoint Energy’s cybersecurity program is increasingly leveraging intelligence-sharing capabilities about emerging threats within the energy industry, across other industries, with specialized vendors, and through public-private partnerships with U.S.
−Removed: government intelligence agencies.
−Removed: By engaging with utility-specific organizations, CenterPoint Energy benefits from quality analysis and rapid sharing of security information across the energy sector.
−Removed: Such intelligence helps allow for better detection and prevention of emerging cyber threats before they materialize.
−Removed: Just as it tests its policies and plans internally, CenterPoint Energy also engages in external exercises such as the bi-annual GridEx Security Exercise to evaluate and address the preparedness of the industry as a whole.
−Removed: Oversee Third-Party Risk
−Removed: We conduct security risk assessments on proposed software, hardware, and third-party technology solutions used by CenterPoint Energy, including a diligence review of enterprise and security architecture, vendor security, and a privacy impact assessment when deemed appropriate.
−Removed: These assessments evaluate these technologies prior to deployment in CenterPoint Energy’s network environment.
−Removed: Further, we maintain a vendor risk management program, a component of which assesses the maturity of certain third parties and their cybersecurity and data privacy programs to help protect information shared with approved third parties.
−Removed: We also leverage third-party cybersecurity ratings of companies to inform our risk rating when conducting these assessments.
−Removed: Additionally, CenterPoint Energy imposes contractual obligations on vendors and other third-party business partners related to privacy, confidentiality, and data security based on their access to our data and systems and the nature and sensitivity of the data and systems.
−Removed: Such contractual provisions may specify the measures and safeguards that the parties must implement to protect our data from unauthorized access use, disclosure, modification, or destruction.
−Removed: Engage Third Parties on Risk Management
−Removed: We also undergo periodic external security audits, vulnerability assessments, and penetration testing of CenterPoint Energy’s systems and user data security practice, conducted by third-party consultants.
−Removed: We also conduct tabletop exercises to
−Removed: test our incident response processes.
−Removed: Further, as discussed below, we engage third parties to provide guidance and support to our cybersecurity management team.
−Removed: Risks from Cybersecurity Threats
+Added: Risk Management Strategy and Processes
+Added: We maintain a cybersecurity program to help us assess, identify, and manage cybersecurity risks to our systems and data, including to help us defend against and mitigate emerging and existing cybersecurity threats to our information technology and operational technology systems.
+Added: Our strategies and processes for managing cybersecurity risks are informed by relevant industry frameworks and laws, regulations and standards applicable to us in the jurisdictions in which we do business, including those applicable to utilities that operate bulk electric systems or critical pipeline facilities.
+Added: We maintain various policies, procedures, technologies and other controls to help prevent, detect, mitigate and manage cybersecurity threats and incidents.
+Added: We also use third-party consultants and service providers to support our risk management efforts, such as services for cybersecurity intelligence, monitoring, testing and assessments.
+Added: Key aspects of our risk management processes include:
+Added: • Threat Monitoring .
+Added: We receive information on emerging cybersecurity threats and vulnerabilities from different sources, including vendors, cybersecurity organizations and U.S.
+Added: government agencies, to help support our ability to detect and defend against threats to the security of our information technology and operational technology systems.
+Added: We maintain several cybersecurity monitoring tools and services to help us detect unauthorized activities involving our systems and potential cybersecurity threats and vulnerabilities to our systems.
+Added: • Incident Response .
+Added: We maintain a Cybersecurity Operations Center that is dedicated to monitoring for cybersecurity threats to our systems and responding to potential cybersecurity incidents.
+Added: We also maintain cybersecurity incident response plans that establish a cross-functional incident response team and processes to guide our response to cybersecurity incidents, including processes for reporting and escalating cybersecurity incidents to senior management and the Audit Committee or the Board, as appropriate.
+Added: We conduct tabletop exercises annually to test our incident response processes.
+Added: • Assessments, Testing and Audits .
+Added: We conduct different types of security assessments, testing and audits to help us proactively identify and mitigate potential cybersecurity threats and vulnerabilities to our information technology and
+Added: operational technology systems.
+Added: For example, we conduct security-related risk assessments on proposed software, hardware, and third-party technology solutions used by CenterPoint Energy prior to deployment in our network.
+Added: We also undergo periodic vulnerability assessments, penetration tests and cybersecurity reviews of our systems and security controls.
+Added: We engage third parties to support certain of these assessments and tests and to provide guidance and support to our cybersecurity management team.
+Added: Our internal audit team also conducts audits of certain CenterPoint Energy systems and data security controls.
+Added: • Third-Party Risk Management .
+Added: We maintain a vendor risk management program, a component of which assesses the cybersecurity and data privacy practices of certain third-party service providers to help us assess and manage cybersecurity risks associated with third-party access to our systems and data.
+Added: To help identify and mitigate third-party cybersecurity risks, we conduct vendor security reviews and privacy impact assessments when deemed appropriate based on the nature of the systems and data that will be accessed by the third-party.
+Added: We also impose contractual obligations on certain of our service providers related to data privacy, confidentiality and security based on, among other factors, their extent of access to our data and systems and the nature and sensitivity of the data and systems to which they have access.
+Added: • Training and Awareness .
+Added: We hold regular employee trainings on privacy, cybersecurity, AI and records and information management, conduct simulated phishing tests, and generally seek to promote awareness of cybersecurity risk through communication and education of our employee population.
As described in Item 1A “Risk Factors,” our operations rely on the secure processing, storage, and transmission of confidential, sensitive, and other information within our computer systems and networks.
−Removed: Computer viruses, hackers, employee or vendor incidents, and other external hazards could expose our information systems—and those of our third parties who process our data, provide access to systems, or that have access to our systems—to security breaches, cybersecurity incidents or other disruptions, any of which could materially and adversely affect our business, reputation, results of operations and financial condition, and subject us to possible legal claims and liability.
−Removed: While we have experienced cybersecurity incidents in the past, to date none have materially affected us, including our business strategy, results of operations or financial condition.
−Removed: As part of our overall risk management approach, we prioritize the identification and management of cybersecurity risks at several levels, including Board oversight, executive commitment, management support, and employee training.
+Added: Computer viruses, threat actors, employee or vendor incidents, and other external hazards could expose our information systems, and those of third parties who process our data, provide access to systems, or that have access to our systems, to security breaches, cybersecurity incidents or other disruptions, any of which could materially and adversely affect our business, reputation, results of operations and financial condition, and subject us to possible legal claims and liability.
+Added: While we have experienced cybersecurity incidents in the past, as of the date of the filing of this Form 10-K, the Company has not identified any cybersecurity threats that have materially affected or are reasonably anticipated to have a material effect on us, including our business strategy, results of operations, or financial condition.
Board of Directors Oversight
−Removed: As of December 2023, our Audit Committee, comprised of independent directors from our Board, oversees the Board’s responsibilities relating to CenterPoint Energy’s cybersecurity and data privacy programs, including cybersecurity risk management.
−Removed: Prior to December 2023, our Governance, Environmental and Sustainability Committee, comprised of independent directors from our Board, oversaw cybersecurity responsibilities.
−Removed: As part of their risk oversight responsibilities, the applicable committee received quarterly reports from our Executive Vice President and General Counsel, or representatives from our cybersecurity or data privacy groups, and periodic reports from our third party consultants.
−Removed: Based on these reports, the applicable committee reported to the Board regarding certain cybersecurity or data privacy related items, including, among other items, CenterPoint Energy’s progress in maturing its cybersecurity program, results of audits, penetration and vulnerability testing of CenterPoint Energy’s cybersecurity program, the cybersecurity landscape and emerging threats, status of ongoing initiatives and strategies, incident reports and learnings from any cybersecurity events, compliance with regulatory requirements and industry standards, data privacy matters, and the cybersecurity budget.
+Added: Our Audit Committee, comprised of independent directors from our Board, oversees the Board’s responsibilities relating to CenterPoint Energy’s cybersecurity and data privacy programs, including cybersecurity risk management and cybersecurity disclosures required by applicable securities laws or regulations, as appropriate.
+Added: As part of its risk oversight responsibilities, the Audit Committee receives quarterly reports from our Executive Vice President and General Counsel, Senior Vice President and Chief Information Security Officer (CISO) or other representatives from our cybersecurity or data privacy groups and periodic reports from our third-party consultants.
+Added: These reports include updates on certain cybersecurity or data privacy matters, including, among other items, CenterPoint Energy’s progress in maturing its cybersecurity program, results of significant cybersecurity assessments and testing, the cybersecurity landscape and emerging threats, status of ongoing initiatives and strategies, incident reports and learnings from any cybersecurity events, compliance with regulatory requirements and industry standards, data privacy matters, and the cybersecurity budget.
Risk Management Personnel
−Removed: Since January 2023, our cybersecurity program has been overseen by our Executive Vice President and General Counsel.
−Removed: Our Executive Vice President and General Counsel has significant risk management, governance and litigation experience.
−Removed: We believe these skills are needed in leadership of our cybersecurity program to help ensure that risk management, legal, disclosure and governance perspectives are considered in the design of our cybersecurity program and in evaluating and responding to potential cyber incidents.
−Removed: CenterPoint Energy currently engages a third-party consultant, who reports directly to the Executive Vice President and General Counsel, to provide Chief Information Security Officer (CISO) advisory services.
−Removed: This consultant has 15 years of experience serving in cybersecurity leadership positions, including as a CISO at a large U.S.-based power, utility, and gas company and also at a large multi-national energy products and services company.
−Removed: We also have management-level committees and an experienced CSOC team that support our processes to assess and manage cybersecurity risk as follows:
−Removed: • The Data Privacy Office, led by our Senior Vice President, Deputy General Counsel, Chief Ethics and Compliance Officer, and Data Privacy Officer, addresses the collection, storage, usage, disclosure and destruction of data for specific business purposes and addresses existing and emerging laws, regulations, trends, expectations and best practices with regards to maintaining a mature data privacy program.
−Removed: • The Risk Oversight Committee, which is supported by our Enterprise Risk Management function and chaired by our Executive Vice President and General Counsel, is comprised of senior executives from across CenterPoint Energy, monitors and oversees risks facing CenterPoint Energy, as well as provides risk assessments and control oversight for certain business activities, including overseeing CenterPoint Energy’s cybersecurity risks.
−Removed: • The crisis management team, which includes senior executives across CenterPoint Energy, is alerted as appropriate to cybersecurity incidents, natural disasters, and business outages.
−Removed: This team has established and continually assesses CenterPoint Energy’s communications plan in the event of a crisis.
−Removed: Additionally, as appropriate, the Audit Committee
−Removed: or the Board are made aware of significant cybersecurity incidents in accordance with our cybersecurity incident response playbook.
−Removed: • The Cybersecurity Awareness Governance Committee, which includes leaders from across CenterPoint Energy’s corporate functions and business units, each with expertise in, or with specific responsibility for, managing or protecting CenterPoint Energy’s assets, information and personnel.
−Removed: This committee provides strategic direction and oversight for CenterPoint Energy’s cybersecurity awareness and training initiatives.
−Removed: • The Artificial Intelligence (AI) Steering Committee was established by CenterPoint Energy to provide strategic direction, oversight, and guidance in the planning, development, deployment, and management of AI initiatives within the organization.
−Removed: The committee's primary objective is to ensure that AI technologies are aligned with business goals, ethical considerations, appropriate security protections, and industry best practices while driving innovation and enhancing competitiveness.
−Removed: These committees provide periodic summary reports on their activities and initiatives to appropriate senior executives, and the Executive Vice President and General Counsel and/or various members of the cyber and data privacy teams communicates updates to the Audit Committee or the Board.
−Removed: At the employee level, we maintain an experienced information technology team that is tasked with implementing our privacy and cybersecurity programs and supporting the cybersecurity consultant in carrying out reporting, security and mitigation functions.
−Removed: We also hold employee trainings on privacy, cybersecurity, AI, records and information management, conduct phishing tests, and generally seek to promote awareness of cybersecurity risk through communication and education of our employee population.
−Removed: The Governance, Environmental and Sustainability Committee was, and now the Audit Committee will be, provided with periodic reports on our employee cybersecurity awareness efforts.
+Added: CenterPoint Energy’s Executive Vice President and General Counsel is responsible for overseeing our cybersecurity and data privacy programs.
+Added: CenterPoint Energy’s CISO is responsible for the day-to-day management of our cybersecurity program and reports directly to the Executive Vice President and General Counsel.
+Added: CenterPoint Energy’s Senior Vice President, Deputy General Counsel, and Chief Ethics & Compliance Officer (CECO) is responsible for day-to-day management of our data privacy program and also reports directly to the Executive Vice President and General Counsel.
+Added: Our cybersecurity and data privacy teams, which report directly to our CISO and CECO, respectively, are tasked with implementing our programs in support of cybersecurity and data privacy risk management.
+Added: We also have management-level teams and committees, which include and/or collaborate with our CISO and CECO, that support, among other things, our processes to assess and manage cybersecurity risk.
+Added: These teams and committees provide summary reports on their activities and initiatives to appropriate senior executives, including the Executive Vice President and General Counsel and the Audit Committee or the Board, as appropriate.
+Added: CenterPoint Energy’s CISO joined the Company in September 2024 and has over two decades of experience serving in multiple global leadership roles in cybersecurity, as well as technology and industrial systems at a Fortune 500 global industrial company, for which he was responsible for, among other things, building and maintaining enterprise programs relating to cybersecurity and managing cybersecurity risk.
+Added: Our Executive Vice President and General Counsel has significant risk management, governance and litigation experience, which we believe are important leadership skills to help incorporate risk management, legal, disclosure and governance perspectives into the design of our cybersecurity program and in evaluating and responding to potential cybersecurity incidents.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.