6 unchanged sentences
NRG engages certified external assessors to ensure compliance with these standards.
−Removed: The Company’s strategy seeks to align underlying processes not only with industry standards but also mirror best practices among peer organizations.
−Removed: The strategy ensures a standardized method across all activities at NRG allowing for consistent recognition, assessment and potential mitigation of significant cybersecurity risks.
+Added: The Company’s strategy seeks to align underlying processes not only with industry standards but also takes into account best practices among peer organizations.
+Added: The strategy helps ensure a standardized method across all activities at NRG that is designed to allow for consistent recognition, assessment and potential mitigation of significant cybersecurity risks.
To further the strategy, the Company established the NRG Cybersecurity Integration Center ("CIC") which is composed of experienced team members from across cybersecurity disciplines with relevant educational and industry experience.
7 unchanged sentences
The Company has established a comprehensive approach to identify and manage cybersecurity risks associated with providers including, but not limited to, rigorous due diligence and assessments of third-party service providers' cybersecurity protocols before engagement, requirements relating to information handling, incident notification and assessment against the Company's cybersecurity requirements.
−Removed: Furthermore, the Company has implemented additional control measures and procedures in business processes to enable continuous risk identification and assessment, and to support monitoring mechanisms to oversee and manage supplier cybersecurity practices .
−Removed: As of December 31, 2024, the Company is not aware of any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially affected or are reasonably likely to have a material affect on NRG’s business strategy, results of operations and financial condition .
−Removed: Despite efforts to maintain processes which mitigate cybersecurity risks, there is no guarantee that such risks may not have a material affect on NRG’s business strategy, results of operations, and financial condition in the future.
+Added: Furthermore, the Company has implemented additional control measures and procedures in business processes designed to enable continuous risk identification and assessment, and to support monitoring mechanisms to oversee and manage supplier cybersecurity practices .
+Added: As of December 31, 2025, the Company is not aware of any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially affected or are reasonably likely to have a material effect on NRG’s business strategy, results of operations and financial condition .
+Added: Despite efforts to maintain processes which mitigate cybersecurity risks, there is no guarantee that such risks may not have a material effect on NRG’s business strategy, results of operations, and financial condition in the future.
For additional information on cybersecurity risks the Company may face, see Item 1A — Risk Factors – “The operation of the Company's businesses is subject to advanced persistent cyber-based security threats and integrity risk.
1 unchanged sentence
The Chief Information Security Officer ("CISO") is the head of cybersecurity for the Company and leads the CIC.
−Removed: The CISO has decades of professional experience, education, and certification in security analysis, design, implementation, and management, with a particularly strong background in technical vulnerability assessment and program development.
−Removed: Within various roles throughout the CISO's career, he has overseen information assurance and cybersecurity efforts, including critical infrastructure protection in government agencies and industry.
+Added: The CISO has decades of professional experience, education, and certification in security analysis, design, implementation, and management, with a particularly strong background in technical vulnerability assessment, threat intelligence, and cybersecurity
+Added: program development.
+Added: Throughout their career, the CISO has overseen cybersecurity efforts across a range of roles, including responsibility for critical infrastructure protection in the energy and utility sectors.
At least twice per year, the CISO provides comprehensive updates to the Board of Directors on cybersecurity and any recent developments impacting the Company.
8 unchanged sentences
This framework provides a foundation for a systematic and consistent approach to preparing for, identifying, containing, eradicating, and recovering from incidents.
−Removed: The effectiveness of these protocols is routinely verified through tabletop exercises involving relevant teams and Company leadership.
+Added: The effectiveness of these protocols is routinely assessed through tabletop exercises involving relevant teams and Company leadership.
In accordance with the Company’s process and procedures, incidents which may have a material impact on the Company are promptly referred to senior leadership and the Board of Directors for review and appropriate determination.
Board of Directors
−Removed: The Board of Directors is primarily responsible for the risk oversight of the Company, and has delegated oversight of risks related to cybersecurity to the Finance and Risk Management ("FARM") Committee of the Board.
+Added: The Board of Directors is primarily responsible for the risk oversight of the Company, and has delegated primary oversight of risks related to cybersecurity to the Finance and Risk Management ("FARM") Committee of the Board.
The FARM Committee regularly reports on its activities to the Board of Directors after each meeting .
The FARM Committee, as well as the overall Board of Directors, is composed of members with diverse expertise, including risk management, incident response and technology.
−Removed: The Board of Directors is aware of the critical nature of managing risks associated with cybersecurity threats and has worked with the Company’s management to establish comprehensive oversight mechanisms to ensure effective cybersecurity governance.
+Added: The Board of Directors is aware of the critical nature of managing risks associated with cybersecurity threats and has worked with the Company’s management to establish comprehensive oversight mechanisms to help ensure effective cybersecurity governance.
The FARM Committee and the Board of Directors receive updates on any significant developments in the cybersecurity domain, seeking to ensure that the Board of Director’s oversight is proactive and responsive.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.