XML 67 R44.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
The Company leverages a comprehensive, multi-tiered cybersecurity strategy to manage cybersecurity risk based on criteria established by the NIST Cybersecurity Framework. As part of its cybersecurity strategy, the Company utilizes a range of industry and regulatory standards including, but not limited to, NERC-CIP, Payment Card Industry Data Security Standard, and IoT Security Assurance Framework. Compliance with NERC-CIP standards is mandated for entities involved in power generation, transmission, and distribution by regulatory bodies responsible for protecting critical infrastructure within the United States. NRG engages certified external assessors to ensure compliance with these standards.
The Company’s strategy seeks to align underlying processes not only with industry standards but also mirror best practices among peer organizations. The strategy ensures a standardized method across all activities at NRG allowing for consistent recognition, assessment and potential mitigation of significant cybersecurity risks. To further the strategy, the Company established the NRG Cybersecurity Integration Center ("CIC") which is composed of experienced team members from across cybersecurity disciplines with relevant educational and industry experience. The CIC provides the following functions to the Company: cyber governance, operations, detection and response, engineering, testing, cyber risk management (including third-party risks), compliance, training and awareness, and reporting. The CIC utilizes advanced continuous monitoring systems and investigative techniques for real-time threat detection. The systematic monitoring approach allows for risk classification and prioritization based on potential impacts, and facilitates targeted resource allocation according to risk severity. The Company conducts regular penetration testing to proactively identify vulnerabilities and enhance its defense measures. The Company engages third-party assessors to gain comprehensive insights into its cyber risk profile.
The Company relies on third-party service providers in the normal course of business. The Company has established a comprehensive approach to identify and manage cybersecurity risks associated with providers including, but not limited to, rigorous due diligence and assessments of third-party service providers' cybersecurity protocols before engagement, requirements relating to information handling, incident notification and assessment against the Company's cybersecurity requirements. Furthermore, the Company has implemented additional control measures and procedures in business processes to enable continuous risk identification and assessment, and to support monitoring mechanisms to oversee and manage supplier cybersecurity practices.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] The Company’s strategy seeks to align underlying processes not only with industry standards but also mirror best practices among peer organizations. The strategy ensures a standardized method across all activities at NRG allowing for consistent recognition, assessment and potential mitigation of significant cybersecurity risks. To further the strategy, the Company established the NRG Cybersecurity Integration Center ("CIC") which is composed of experienced team members from across cybersecurity disciplines with relevant educational and industry experience. The CIC provides the following functions to the Company: cyber governance, operations, detection and response, engineering, testing, cyber risk management (including third-party risks), compliance, training and awareness, and reporting. The CIC utilizes advanced continuous monitoring systems and investigative techniques for real-time threat detection
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
The Board of Directors is primarily responsible for the risk oversight of the Company, and has delegated oversight of risks related to cybersecurity to the Finance and Risk Management ("FARM") Committee of the Board. The FARM Committee regularly reports on its activities to the Board of Directors after each meeting. The FARM Committee, as well as the overall Board of Directors, is composed of members with diverse expertise, including risk management, incident response and technology. The Board of Directors is aware of the critical nature of managing risks associated with cybersecurity threats and has worked with the Company’s management to establish comprehensive oversight mechanisms to ensure effective cybersecurity governance.
The FARM Committee and the Board of Directors receive updates on any significant developments in the cybersecurity domain, seeking to ensure that the Board of Director’s oversight is proactive and responsive. The Board of Directors remains involved in ensuring that cybersecurity considerations are integrated into the Company’s broader strategic objectives. Pursuant to the charter of the FARM Committee, the FARM Committee's responsibilities include an annual review of the Company’s cybersecurity program and the effectiveness of its risk management strategies. This review is intended to help identify areas for improvement and ensure the alignment of cybersecurity efforts with the overall risk management framework.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Board of Directors is primarily responsible for the risk oversight of the Company, and has delegated oversight of risks related to cybersecurity to the Finance and Risk Management ("FARM") Committee of the Board. The FARM Committee regularly reports on its activities to the Board of Directors after each meeting.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The FARM Committee regularly reports on its activities to the Board of Directors after each meeting.
Cybersecurity Risk Role of Management [Text Block]
The Chief Information Security Officer ("CISO") is the head of cybersecurity for the Company and leads the CIC. The CISO has decades of professional experience, education, and certification in security analysis, design, implementation, and management, with a particularly strong background in technical vulnerability assessment and program development. Within various roles throughout the CISO's career, he has overseen information assurance and cybersecurity efforts, including critical infrastructure protection in government agencies and industry.
At least twice per year, the CISO provides comprehensive updates to the Board of Directors on cybersecurity and any recent developments impacting the Company. These updates include, among other items:
Incident reports and developments from any cybersecurity events;
Current cybersecurity landscape and emerging cybersecurity threats, with a particular emphasis on Company and industry-specific threats; and
Status of ongoing initiatives to strengthen the Company's cybersecurity program.
In addition, the CISO regularly informs other members of senior management, including the President and CEO, of all aspects related to cybersecurity risks and incidents. This is intended to ensure that the highest levels of management remain updated on the cybersecurity risk preparedness and potential risks facing the Company. Furthermore, significant cybersecurity matters and strategic risk management decisions are escalated to the Board of Directors ensuring that they have comprehensive oversight and can provide guidance on critical cybersecurity issues.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The Board of Directors is primarily responsible for the risk oversight of the Company, and has delegated oversight of risks related to cybersecurity to the Finance and Risk Management ("FARM") Committee of the Board. The FARM Committee regularly reports on its activities to the Board of Directors after each meeting
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] The Chief Information Security Officer ("CISO") is the head of cybersecurity for the Company and leads the CIC. The CISO has decades of professional experience, education, and certification in security analysis, design, implementation, and management, with a particularly strong background in technical vulnerability assessment and program development.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
At least twice per year, the CISO provides comprehensive updates to the Board of Directors on cybersecurity and any recent developments impacting the Company. These updates include, among other items:
Incident reports and developments from any cybersecurity events;
Current cybersecurity landscape and emerging cybersecurity threats, with a particular emphasis on Company and industry-specific threats; and
Status of ongoing initiatives to strengthen the Company's cybersecurity program.
In addition, the CISO regularly informs other members of senior management, including the President and CEO, of all aspects related to cybersecurity risks and incidents. This is intended to ensure that the highest levels of management remain updated on the cybersecurity risk preparedness and potential risks facing the Company. Furthermore, significant cybersecurity matters and strategic risk management decisions are escalated to the Board of Directors ensuring that they have comprehensive oversight and can provide guidance on critical cybersecurity issues.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true