1 unchanged sentence
Cyber security
−Removed: For purposes of the following disclosure, the terms “cybersecurity incident” and “cybersecurity threat” have the meanings given to such terms in Item 106 of Regulation S-K promulgated under the Securities Exchange Act of 1934.
+Added: For purposes of the following disclosure, the terms “cybersecurity incident” and “cybersecurity threat” have the meanings given to such terms in Item 106 of Regulation S-K promulgated under the Exchange Act.
Risk management and strategy
20 unchanged sentences
During the fiscal year ended, and as of, December 31, 2024, there were no risks from cybersecurity threats (including as a result of previous cybersecurity incidents) that have materially affected or are reasonably likely to materially affect the Company (including its business strategy, results of operations, or financial condition).
−Removed: Unitil Corporation’s Board of Directors (the “Board”) is responsible for oversight of the Company’s ERM program, including risks from cybersecurity threats.
+Added: The Board is responsible for oversight of the Company’s ERM program, including risks from cybersecurity threats.
The Board has not assigned that responsibility to any committee or subcommittee of the Board.
1 unchanged sentence
The Company’s cybersecurity management team is responsible for assessing and managing the Company’s material risks from cybersecurity threats, including implementing the Cybersecurity Plan.
−Removed: The team includes the Company’s Chief Technology Officer and Vice President of Information Technology (the “CTO”), the Director of Information Security, and two Cybersecurity Analysts, all of whom have an educational background relevant to, professional experience in, or other expertise in cybersecurity.
+Added: The team includes the Company’s Chief Technology Officer and Vice President of Information Technology (the “CTO”), the Director of Information Security and Cyber Operations, Manager of Cyber Security Operations and two Cyber Operations Engineers, all of whom have an educational background relevant to, professional experience in, or other expertise in cybersecurity.
This team is supported by the Company’s Information Technology department.
The CTO holds a Master of Business Administration and a Bachelor of Science in Electrical Engineering with over 30 years of professional experience in the utility industry with extensive management experience in engineering, operations and information technology.
−Removed: The CTO also assumes responsibilities as the Company’s Chief Information Security Officer and its Chief Cyber Security Officer.
+Added: The CTO also assumes responsibilities as the Company’s Chief Information Security Officer and Chief Cyber Security Officer.
The CTO has overall management responsibility for the Company’s cybersecurity.
The CTO reports to the Company’s Chief Executive Officer.
−Removed: The Director of Information Security holds a Bachelor of Science in Computer Science and a Masters Certificate in Cyber Security with a concentration in Power Systems and has over 30 years of experience in the information technology field.
−Removed: The Director of Information Security has primary responsibility for the cyber security program including threat and vulnerability management, vendor security posture assessment, Industrial Control System (ICS) and SCADA infrastructure protection at electric substations and natural gas plants, as well as leading the Cyber Incident Response Team.
−Removed: One of the Cybersecurity Analysts has a Bachelor of Science in Information Technology and the other has a Bachelor of Science in Criminal Justice / Computer Crime and Digital Forensics, and the Cybersecurity Analysts have a combined 25 years of experience in various information technology and cyber roles.
+Added: The Director of Information Security and Cyber Operations holds a Bachelor of Science in Computer Science and a Masters Certificate in Cyber Security with a concentration in Power Systems and has over 30 years of experience in the information technology field.
+Added: The Director of Information Security and Cyber Operations has primary responsibility for the cyber security program including threat and vulnerability management, vendor security posture assessment, Industrial Control System (ICS) and SCADA infrastructure cyber security protection at electric substations and natural gas plants, as well as leading the Cyber Incident Response Team.
+Added: The Manager of Cyber Security Operations has a Bachelor of Science in Information Technology and over 20 years of experience in various information technology and cyber roles.
The Company’s cybersecurity management team assesses and manages the Company’s material risks from cybersecurity threats through or by:
• active monitoring of cyber threat alerts, warnings, advisories, notices, vulnerability assessments, incident bulletins, security briefings, reports and white papers from industry and national organizations, including:
−Removed: Natural Gas Information Sharing and Analysis Center;
+Added: downstream Natural Gas Information Sharing and Analysis Center;
Electricity Information Sharing and Analysis Center;
3 unchanged sentences
• vendor security posture assessment;
−Removed: · Industrial Control System and Supervisory Control and Data Acquisition infrastructure protection at electric substations and natural gas plants;
+Added: • Industrial Control System and Supervisory Control and Data Acquisition infrastructure cyber security protection at electric substations and natural gas plants;
• leading the Company’s Cyber Incident Response Team.
1 unchanged sentence
In the event of a cybersecurity threat, the CTO and these parties would collaborate to assess and manage the risk with ultimate responsibility residing with the Board.
−Removed: Also, in the event of a cybersecurity threat or cybersecurity incident, the Company’s cybersecurity management team will conduct an investigation and impact analysis and, as necessary, the CTO will activate the Company’s Cyber Incident Response Team.
+Added: Also, in the event of a cybersecurity threat or cybersecurity incident, the Company’s cybersecurity management team will investigate and perform impact analysis and, as necessary, the CTO will activate the Company’s Cyber Incident Response Team.
The Cyber Incident Response Team is a subset of the Company’s Crisis Response Team, which has responsibility for operational and business resilience, as well as tactical and strategic response.
1 unchanged sentence
In the event that a cybersecurity incident occurs which results in damage to the Company’s data or infrastructure, the Cyber Incident Response Team would follow the Company’s Cyber Incident Response Plan.
−Removed: The Cyber Incident Response Plan was developed using the guidelines described in the National Institute of Standards and Technology Special Publication 800-61 Revision 2 Computer Security Incident Handling Guide, has been reviewed and assessed by outside experts, is updated annually, and is used to train for cybersecurity incidents.
+Added: The Cyber Incident Response Plan was developed using the guidelines described in the National Institute of Standards and Technology Special Publication 800-61 Revision 2 Computer Security Incident Handling Guide, has been reviewed and assessed by outside experts, is updated
+Added: annually, and is used to train for cybersecurity incidents.
The Cyber Incident Response Plan details the identification, containment, eradication and recovery processes specific to the Company’s environment with prioritization of critical assets.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.