2 unchanged sentences
Our processes for assessing, identifying, and managing material risks from cybersecurity threats are part of our overall enterprise risk management system and processes.
−Removed: Enterprise risks, including cybersecurity risks, and their associated mitigations are reviewed at least annually by senior management and the Board of Directors.
+Added: Enterprise risks, including cybersecurity risks, and their associated mitigations are reviewed at least annually by senior management and the Board.
Throughout the year, we regularly assess our cybersecurity program and continue to invest in hardening and maturing our cybersecurity measures as further described below.
12 unchanged sentences
We also maintain cybersecurity incident response plans that establish a cross-functional incident response team and processes to guide our response to cybersecurity incidents, including processes for reporting and escalating cybersecurity incidents to senior management and the Audit Committee or the Board, as appropriate.
−Removed: We conduct tabletop exercises annually to test our incident response processes.
+Added: We conduct tabletop exercises regularly to test our incident response processes.
• Assessments, Testing and Audits .
−Removed: We conduct different types of security assessments, testing and audits to help us proactively identify and mitigate potential cybersecurity threats and vulnerabilities to our information technology and
−Removed: operational technology systems.
+Added: We conduct different types of security assessments, testing and audits to help us proactively identify and mitigate potential cybersecurity threats and vulnerabilities to our information technology and operational technology systems.
For example, we conduct security-related risk assessments on proposed software, hardware and third-party technology solutions used by CenterPoint Energy prior to deployment in our network.
10 unchanged sentences
Computer viruses, threat actors, employee or vendor incidents and other external hazards could expose our information systems, and those of third parties who process our data, provide access to systems or that have access to our systems, to security breaches, cybersecurity incidents or other disruptions, any of which could materially and adversely affect our business, reputation, results of operations and financial condition, and subject us to possible legal claims and liability.
−Removed: While we have experienced cybersecurity incidents in the past, as of the date of the filing of this Form 10-K, the Company has not identified any cybersecurity threats that have materially affected or are reasonably anticipated to have a material effect on us, including our business strategy, results of operations, or financial condition.
+Added: While we have experienced cybersecurity incidents in the past, as of the date of the filing of this Form 10-K, CenterPoint Energy has not identified any cybersecurity threats that have materially affected or are reasonably anticipated to have a material effect on us, including our business strategy, results of operations, or financial condition.
Board of Directors Oversight
−Removed: Our Audit Committee, comprised of independent directors from our Board, oversees the Board’s responsibilities relating to CenterPoint Energy’s cybersecurity and data privacy programs, including cybersecurity risk management and cybersecurity disclosures required by applicable securities laws or regulations, as appropriate.
−Removed: As part of its risk oversight responsibilities, the Audit Committee receives quarterly reports from our Executive Vice President and General Counsel, Senior Vice President and Chief Information Security Officer (CISO) or other representatives from our cybersecurity or data privacy groups and periodic reports from our third-party consultants.
−Removed: These reports include updates on certain cybersecurity or data privacy matters, including, among other items, CenterPoint Energy’s progress in maturing its cybersecurity program, results of significant cybersecurity assessments and testing, the cybersecurity landscape and emerging threats, status of ongoing initiatives and strategies, incident reports and learnings from any cybersecurity events, compliance with regulatory requirements and industry standards, data privacy matters, and the cybersecurity budget.
+Added: Our Audit Committee, comprised of independent directors from our Board, oversees the Board’s responsibilities relating to CenterPoint Energy’s cybersecurity, data privacy and AI programs, including cybersecurity and AI risk management and cybersecurity disclosures required by applicable securities laws or regulations, as appropriate.
+Added: As part of its risk oversight responsibilities, the Audit Committee receives quarterly reports from our Executive Vice President and General Counsel, Chief Security Officer (CSO) or other representatives from our cybersecurity or data privacy groups and periodic reports from our third-party consultants.
+Added: These reports include updates on certain cybersecurity or data privacy matters, including, among other items, CenterPoint Energy’s progress in maturing its cybersecurity program, results of cybersecurity assessments and testing, the cybersecurity landscape and emerging threats, status of ongoing initiatives and strategies, incident reports and learnings from any cybersecurity events, compliance with regulatory requirements and industry standards, data privacy matters, and the cybersecurity budget.
Risk Management Personnel
CenterPoint Energy’s Executive Vice President and General Counsel is responsible for overseeing our cybersecurity and data privacy programs.
−Removed: CenterPoint Energy’s CISO is responsible for the day-to-day management of our cybersecurity program and reports directly to the Executive Vice President and General Counsel.
+Added: CenterPoint Energy’s CSO is responsible for the day-to-day management of our cybersecurity program and reports directly to the Executive Vice President and General Counsel.
CenterPoint Energy’s Senior Vice President, Deputy General Counsel, and Chief Ethics & Compliance Officer (CECO) is responsible for day-to-day management of our data privacy program and also reports directly to the Executive Vice President and General Counsel.
−Removed: Our cybersecurity and data privacy teams, which report directly to our CISO and CECO, respectively, are tasked with implementing our programs in support of cybersecurity and data privacy risk management.
−Removed: We also have management-level teams and committees, which include and/or collaborate with our CISO and CECO, that support, among other things, our processes to assess and manage cybersecurity risk.
+Added: Our cybersecurity and data privacy teams, which report directly to our CSO and CECO, respectively, are tasked with implementing our programs in support of cybersecurity and data privacy risk management.
+Added: We also have management-level teams and committees, which include and/or collaborate with our CSO and CECO, that support, among other things, our processes to assess and manage cybersecurity risk.
These teams and committees provide summary reports on their activities and initiatives to appropriate senior executives, including the Executive Vice President and General Counsel and the Audit Committee or the Board, as appropriate.
−Removed: CenterPoint Energy’s CISO joined the Company in September 2024 and has over two decades of experience serving in multiple global leadership roles in cybersecurity, as well as technology and industrial systems at a Fortune 500 global industrial company, for which he was responsible for, among other things, building and maintaining enterprise programs relating to cybersecurity and managing cybersecurity risk.
+Added: CenterPoint Energy’s CSO joined CenterPoint Energy in September 2025 and has over two decades of experience in cybersecurity and risk management across diverse industries, and most recently served in senior leadership roles, including Chief Information Security Officer, for a global engineering, procurement, consulting and construction company.
Our Executive Vice President and General Counsel has significant risk management, governance and litigation experience, which we believe are important leadership skills to help incorporate risk management, legal, disclosure and governance perspectives into the design of our cybersecurity program and in evaluating and responding to potential cybersecurity incidents.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.