11 unchanged sentences
Integration with Overall Risk Management :
−Removed: Management’s cybersecurity processes have been integrated into overall risk management system and processes.
+Added: Management’s cybersecurity processes have been integrated into the overall risk management system and processes.
Management considers cybersecurity threat risks alongside other company risks as part of its overall risk assessment process.
10 unchanged sentences
Disclosure of Risks :
−Removed: Management describes how risks from cybersecurity threats could materially affect its business strategy, results of operations, or financial condition, as part of its risk factor disclosures at Part I, Item 1A of this Annual Report on Form 10-K.
+Added: Management describes how risks from cybersecurity threats could materially affect its business strategy, results of operations, or financial condition, as part of its risk factor disclosures at Part I, Item 1A.
+Added: Risk Factors of this Annual Report on Form 10-K.
+Added: To date, Williams has not experienced any cybersecurity threats or incidents that have resulted in a material adverse effect on our business strategy, results of operations, or financial condition.
+Added: However, management continues to monitor and assess risks that could have a material impact in the future.
Management is committed to continually enhancing its cybersecurity processes and practices to address the dynamic nature of the threats it faces and to ensure the security and integrity of its systems and data.
2 unchanged sentences
Each member of Williams’ organization, which includes Transco and NWP, from facility operators to board members, has a responsibility to safeguard the organization’s cybersecurity.
−Removed: The Chief Information Security Officer (CISO) is responsible for the cybersecurity strategy and execution, while the Board and the Audit Committee are responsible for oversight of cybersecurity risk.
−Removed: The Cybersecurity Governance Committee is led by the CISO and includes cybersecurity managers and other subject matter experts as standing members.
−Removed: The Cybersecurity Governance Committee is tasked with developing, implementing, and maintaining the Cybersecurity Program.
−Removed: The Cybersecurity Executive Advisory Board (Executive Advisory Board) is led by the CISO, with the Chief Information Officer (CIO), Chief Financial Officer, Chief Human Resources Officer, the General Counsel, and the Chief Operations Officer as standing members.
−Removed: The Executive Advisory Board’s purpose is to ensure enterprise alignment with the Cybersecurity Program and provide executive oversight of the Cybersecurity Program.
+Added: The Chief Information Security Officer (CISO) collaborates with internal stakeholders to develop, implement and maintain the Cybersecurity Program, ensuring that the program addresses the evolving cybersecurity risk landscape.
+Added: The CISO also engages with executive leadership to ensure that cybersecurity remains integrated with Williams’ overall risk management and strategic objectives.
The Board of Directors oversees cybersecurity-related policy and strategy.
−Removed: As part of this oversight, the CISO provides a cybersecurity dashboard that is reviewed by the Board at every regularly scheduled Board meeting, which includes key performance indicators for cybersecurity process maturity, operational performance, and enterprise performance toward Transportation Security Administration (TSA) compliance.
−Removed: Additionally, the CIO and/or CISO presents to the Board bi-annually regarding the cybersecurity risks and strategies, including as part of the Board’s annual long-term strategy session.
−Removed: The Audit Committee, comprised of independent directors, reviews the implementation and effectiveness of cybersecurity risk management protocols and reviews the effectiveness of cybersecurity as part of the Company’s accounting and internal control policies.
−Removed: As part of this oversight, the CIO presents to the Audit Committee bi-annually, as well as periodically in conjunction with any internal audits related to cybersecurity.
+Added: As part of this oversight, the CISO provides a cybersecurity dashboard that is reviewed by the Board annually, which includes key performance indicators for cybersecurity process maturity, operational performance, and enterprise performance toward TSA compliance.
+Added: Additionally, the Audit Committee, comprised of independent directors, reviews the implementation and effectiveness of cybersecurity risk management protocol as part of the company’s accounting and internal control policies.
+Added: As part of this oversight, the Chief Information Officer (CIO) presents to the Audit Committee bi-annually, as well as periodically in conjunction with any internal audits related to cybersecurity.
+Added: Management has implemented processes and controls designed to prevent, detect, mitigate, and remediate cybersecurity incidents, ensuring ongoing protection of the company’s systems and data.
Additionally, management has protocols by which cybersecurity incidents that meet established reporting thresholds are escalated internally and, where appropriate, are reported to the Board, as well as ongoing updates regarding any such incident until it has been addressed.
−Removed: Williams’ new CIO joined the company in February 2025, and will succeed the company’s retiring CIO, who is retiring in March 2025.
−Removed: The new CIO brings over 20 years of experience in information technology and leadership within the energy industry and has extensive expertise in digital transformation, cloud strategies, enterprise AI initiatives, and cybersecurity, as well as managing large-scale system implementations and integrations.
−Removed: He holds an Executive MBA from the University of Texas at San Antonio, a Master of Computer Science and Engineering from the University of Texas at Arlington, and a Bachelor of Information Science and Engineering from Bangalore University.
−Removed: The retiring CIO had been in his role at Williams for over 10 years and had over 30 years of combined information technology experience with a broad scope of responsibility.
−Removed: He provided senior leadership support of the cybersecurity and risk management programs since 2013.
−Removed: He holds a bachelor’s degree in management information systems (MIS) from the University of Oklahoma and a Master of Business Administration in MIS from the University of Dallas.
−Removed: The CISO has been at Williams for over 25 years.
−Removed: During that time, he has held a variety of information technology positions at multiple levels in the organization ranging from network engineering to application development and project management, as well as several IT Manager and Director roles.
−Removed: He has had oversight of the cybersecurity and risk management programs since 2017.
−Removed: Active in government and private sector partnerships, he is currently serving as the Chair of Emergency Response Working Group under the Oil & Natural Gas Subsector Coordinating Council and recently acted as the Chair of the Interstate Natural Gas Association of America security committee.
−Removed: He holds degrees in Business Administration and MIS from the University of Oklahoma and is certified in Leadership from Harvard Business School’s executive education.
−Removed: In 2018, he obtained his Chief Information Security Officer certification from Carnegie Mellon University.
+Added: Williams’ CIO, who joined the company in February 2025, brings over 20 years of experience in information technology and leadership within the energy industry.
+Added: He has extensive expertise in digital transformation, cloud strategies, enterprise artificial intelligence initiatives, and cybersecurity, as well as managing large-scale system implementations and integrations.
+Added: He holds an Executive Master of Business Administration from the University of Texas at San Antonio, a Master of Computer Science and Engineering from the University of Texas at Arlington, and a Bachelor of Information Science and Engineering from Bangalore University.
+Added: Williams’ CISO joined the company in November 2025, bringing significant experience in cybersecurity and operational technology leadership within the energy industry.
+Added: He holds a Bachelor of Science in Management Information Systems from Kansas State University and is a Certified Information Systems Security Professional.
+Added: His expertise spans operational technology security, infrastructure management, and cybersecurity operations.
+Added: At Williams, he is responsible for the company’s cybersecurity strategy and execution, ensuring robust protection of systems and data in a dynamic threat environment.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.