Heat Advisory:Extreme heat is expected in many areas. Conserve Energy and Stay Safe.

Cybersecurity

Cybersecurity

Cybersecurity

We are committed to mitigating the risk of cyber threats, data loss, and service disruption while taking a proactive approach to cybersecurity. We comply with all applicable laws and regulations and partner with thought leaders; industry peers; and local, state, and federal agencies to protect our customers and equipment.

New technology and cybercrime are consistently increasing in sophistication and continue to bring new challenges. As a result, we have categorized cybersecurity as a key enterprise risk. Therefore, we continuously strengthen our cybersecurity and data-protection measures, which include:

  • Monitoring assets.
  • Conducting exercises and phishing tests.
  • Deploying controls that protect our systems and data.
  • Raising employees’ level of understanding and awareness via training and education.
  • Regularly conducting internal and external security audits and vulnerability assessments.

There is a process in place for the Board and the Audit Committee to receive updates and information from the Senior Vice President and Chief Information Officer and the Vice President and Chief Information Security Officer, regarding significant and potentially significant cybersecurity incidents and a range of cybersecurity metrics.

  • The Board receives quarterly reports on cybersecurity risks from the Senior Vice President and Chief Information Officer and the Vice President and Chief Information Security Officer that address various topics, such as recent developments, vulnerability assessments and third-party and independent reviews.
  • The Audit Committee also meets annually with the Senior Vice President and Chief Information Officer and the Vice President and Chief Information Security Officer in executive session, without management present.

At each regular Board meeting (typically at least nine times per year including in 2024), the Board reviews a cybersecurity dashboard prepared by the Senior Vice President and Chief Information Officer that includes updates on a range of cybersecurity metrics and topics. The Audit Committee oversees the ERM program and reviews more in-depth cybersecurity matters and risks on a semi-annual basis.

Download Report
1 2 3 4