Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments
None.
Item 1C. Cybersecurity
Description of Cybersecurity Risk Management and Strategy
To assess, identify and manage material cybersecurity risks, we have endeavored to implement policies, standards and technical controls with the aim of protecting our information technology (“IT”) and operational technology (“OT”) systems (collectively, our “IT systems”). These standards are guided, in part, by the relevant National Institute of Standards and Technology and American Petroleum Institute frameworks. We use various internal and third-party tools, security measures and technologies to aid in seeking to protect our network perimeter and internal systems from unauthorized access, intrusion or disruption. Regular assessments are conducted across our systems, networks and data infrastructure to identify potential cybersecurity threats and vulnerabilities. In addition, a monitoring and detection system has been implemented to help identify cybersecurity threats and incidents. Our cybersecurity program also focuses on providing training and awareness to our employees and contractors on cybersecurity best practices.
We engage assessors, consultants, auditors and other third parties in connection with the above processes. We recognize that third-party service providers may introduce cybersecurity risks. In an effort to mitigate these risks, we have established a process to assess and oversee the cybersecurity practices of our vendors. Before engaging with third-party service providers, we conduct due diligence to evaluate their cybersecurity capabilities and potential vulnerabilities. Additionally, we endeavor to include cybersecurity requirements in our contracts with these providers, including adherence to specific security practices and protocols.
66
Table of Contents
Index to Financial Statements
The above cybersecurity risk management processes are integrated into our overall risk management program. Cybersecurity threats are understood to be dynamic and to intersect with various other enterprise risks. As such, cybersecurity is considered an integral component of our enterprise-wide risk management approach. As of the date of this Report, we are not aware of any previous cybersecurity threats that have materially affected or are reasonably likely to materially affect the Partnership.
Despite the implementation of our cybersecurity programs, our security measures cannot guarantee that a significant cyberattack will not occur. A successful attack on our IT systems or those of our vendors could have significant consequences to our business. While we devote resources to our security measures to protect our systems and information, these measures cannot provide absolute security. See “Item 1A. Risk Factors” for additional information about the risks to our business associated with a breach or compromise to our IT systems.
Cybersecurity Program Governance
Our cybersecurity program is led by our Vice President of Information Services, North America , who reports directly to our CFO and oversees the dedicated team responsible for executing our cybersecurity strategy, including the primary assessment and management of cybersecurity risks. Our cybersecurity leadership team also includes our Senior Director, Enterprise Technology, our Director, Cybersecurity and Technology Risk, and other senior leaders from our Information Services team. The Board receives quarterly updates on material security incidents (if applicable), detection, monitoring, and other key initiatives and notable events from our Vice President of Information Services – North America.
To facilitate effective management, our cybersecurity leadership team holds regular discussions with our dedicated cybersecurity team on cybersecurity risks, threat intelligence, incident trends, security audits, and the effectiveness of our training and testing. Our cybersecurity leadership team convenes regularly to review and monitor programs designed to prevent and detect cybersecurity threats and mitigate and remediate cybersecurity incidents. Our cybersecurity leadership team also receives comprehensive reports on security incidents, threat intelligence, and vulnerability assessments from our cybersecurity team.
Our cybersecurity leadership team is made up of highly experienced professionals with extensive backgrounds in information security, risk management, and incident response, including our Vice President of Information Services – North America, our Senior Director, Enterprise Technology and our Director, Cybersecurity and Technology Risk. Our Vice President of Information Services – North America has been with Plains for over 15 years and has over 25 years’ experience in technology infrastructure and security including senior management level oversight of cybersecurity for organizations in both the health care and oil and gas industries. Our Senior Director, Enterprise Technology reports to the Vice President, Information Services – North America and has accountability for core enterprise technology platforms, including hosting, networks, data platforms, and cybersecurity programs. This individual has over 20 years of experience in the information services industry, including experience with cyber incident detection and response. The Director, Cybersecurity and Technology Risk has responsibility for oversight of cybersecurity strategy across IT and OT environments, implementation of programs aligned with recognized frameworks, and implementation of key security controls. This individual has more than 20 years of experience in enterprise cybersecurity, OT security, and critical infrastructure risk management at publicly traded companies and holds multiple industry-recognized certifications in information security, audit, privacy, and enterprise IT governance. In addition to having the requisite training, knowledge, skills and abilities required for their respective positions, the cybersecurity leadership team collectively holds various relevant U.S. and Canadian information security certifications. The cybersecurity leadership team is supported by a dedicated team of skilled cybersecurity professionals, each bringing diverse expertise in areas such as network security, data protection, and threat intelligence.
Item 3. Legal Proceedings
The information required by this item is included in Note 19 to our Consolidated Financial Statements, and is incorporated herein by reference thereto.
Item 4. Mine Safety Disclosures
Not applicable.
67
Table of Contents
Index to Financial Statements
PART II
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.