8 unchanged sentences
Management monitors and reviews the results of this analysis, integrating them into the enterprise risk assessment processes and implements appropriate mitigating actions as needed.
−Removed: Xcel Energy’s cybersecurity policies, standards, practices and readiness are regularly assessed by third-party consultants.
+Added: Xcel Energy’s cybersecurity policies, standards, practices, annual cybersecurity training content and readiness are regularly assessed by third-party consultants.
These partners are engaged to perform independent penetration testing and other security related services to assist in the prevention, detection, monitoring, mitigation and remediation of cybersecurity incidents and risks.
5 unchanged sentences
The Company deploys periodic monitoring activities to assess compliance with our cybersecurity control framework and investigates security incidents that have impacted our third-party service providers as appropriate .
−Removed: Management has assigned responsibility for the security risk program to the Chief Security Officer who has extensive experience in critical infrastructure protection, including multiple years of experience with the Department of Defense.
+Added: Management has assigned responsibility for the security risk program to the Chief Security Officer who has multiple years of experience in the Defense Industrial Base.
The Chief Security Officer is informed about and monitors prevention, detection, mitigation and remediation efforts through a team of security professionals, many of whom are Certified Information Systems Security Professionals, Certified Information Security Managers or have received other cybersecurity certifications.
−Removed: The team has extensive experience selecting, deploying and operating cybersecurity technologies, initiatives and processes that aid in preventing, remediating and mitigating known and unknown cybersecurity threats.
−Removed: The Chief Security Officer or members of management brief the Board on routine and regular cybersecurity risk and threat updates, typically on a quarterly basis.
+Added: The team has extensive experience selecting, deploying and operating cybersecurity technologies, initiatives and processes that aid in preventing, remediating and mitigating known and unknown security threats.
+Added: The Chief Security Officer or members of management brief the Board on routine and regular cybersecurity risk and threat updates, typically on an annual basis.
In the event of a significant threat or incident, management and the Chief Security Officer leverage Xcel Energy’s incident response processes to assess impacts and resolve incidents.
When a significant cybersecurity incident occurs, management communicates with the Board of Directors and relevant committees.
−Removed: The Board of Directors oversees the risks associated with cybersecurity and the physical security of our assets, with information security matters being discussed at each regular board meeting as well as at the ONES and Audit Committee meetings throughout the year.
+Added: The Board of Directors oversees the risks associated with cybersecurity and the physical security of our assets, with information security matters being discussed at board meetings as well as at the ONES and Audit Committee meetings throughout the year.
While the ONES Committee has primary committee responsibility for cybersecurity due to the operational issues involved, the Board of Directors has determined that the topic is of sufficient importance to warrant this comprehensive oversight approach.
−Removed: Augmenting such oversight efforts, the Board of Directors conducts drills to practice its response in a possible emergency situation to ensure it is well prepared and positioned to perform in a possible crisis.
+Added: Augmenting such oversight efforts, the enterprise has the ability to notify and update the Board of Directors in the event of a possible crisis situation.
Cybersecurity risks are a part of Xcel Energy’s normal course of business.
−Removed: To date, no cybersecurity incident or attack has had a material impact on our business or results of operations.
+Added: To date, no cybersecurity incident or attack affecting us or our vendors has had a material impact on our business or results of operations.
27, 2025 there have been no material cybersecurity incidents to report.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.