XML 58 R40.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
NiSource has implemented and maintains a comprehensive cybersecurity program that includes a variety of security controls and measures designed to identify, assess, and manage material cybersecurity risks. The program is a part of NiSource’s enterprise risk management strategy. The enterprise risk team and the Risk Management Committee review material risks to any NiSource operating company based on perspectives from external experts, peer surveys, and the potential impact to NiSource’s enterprise assets and strategic objectives.

Risk events are classified based on both the timing of impact and NiSource’s ability to preventatively mitigate the risk. For the cybersecurity risks that can be preventively mitigated, the enterprise risk team gathers quarterly updates on mitigation gap closure from risk owners. The Risk Management Committee reviews any mitigation gaps identified by risk owners and approves or rejects the pace of mitigation activities as a statement of risk tolerance and then directs that mitigation activities be included in budgets and the business plan as appropriate.

The NiSource cybersecurity program includes the following key components:

Risk assessment. NiSource regularly assesses its cybersecurity risks to identify and prioritize the most significant threats. The risk assessment process considers a variety of factors, including those specific to the utility/energy industry, the types of data NiSource collects and stores, and the threats posed by known vulnerabilities. NiSource engages third parties to perform independent assessments of its cybersecurity program, provide intelligence about the threat environment, and to provide operational assistance in managing the program. Annually, a third-party independent assessment is performed to evaluate NiSource cybersecurity maturity against a framework of cybersecurity controls. NiSource also performs bi-annual penetration testing and social engineering assessments performed by a third-party.

Third-party risk management. NiSource performs cyber assessments periodically on third-party vendors and service providers with whom NiSource shares data, relies on for critical business functions, or provides access to the NiSource network or systems. NiSource’s Supply Chain function works with the Legal and Cyber functions to periodically update cybersecurity contractual provisions in its vendor agreements, with deviations from such provisions requiring approval from the Legal and Cyber functions. NiSource’s Supplier Code of Business Conduct requires, among other things, that suppliers ensure safe and secure use of information assets, comply with applicable law relating to personal information, and adhering to standards relative to the use and protection of Company information, including that of our employees, customers, vendors and other stakeholders. In addition, all vendors and contractors that have access and/or connectivity to the NiSource environment must complete cybersecurity training annually.

Security controls. NiSource has implemented a variety of security controls to mitigate cybersecurity risks. These controls include technical controls, such as firewalls and intrusion detection systems, as well as administrative controls, such as employee training and security awareness programs. To ensure cybersecurity controls, NiSource OT within the electric business adheres to the NERC CIP. Within the natural gas business, cybersecurity controls are managed and monitored based on the TSA Security Directives.
Incident response. NiSource has a comprehensive incident response plan in place to respond to cybersecurity incidents. The plan includes steps for detection, analysis, containment, eradication, and recovery from incidents, as well as steps for notifying affected individuals and regulators.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
NiSource has implemented and maintains a comprehensive cybersecurity program that includes a variety of security controls and measures designed to identify, assess, and manage material cybersecurity risks. The program is a part of NiSource’s enterprise risk management strategy. The enterprise risk team and the Risk Management Committee review material risks to any NiSource operating company based on perspectives from external experts, peer surveys, and the potential impact to NiSource’s enterprise assets and strategic objectives.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
The NiSource Board of Directors' Audit Committee has responsibility for oversight of the cybersecurity program and risks from cybersecurity threats. The Audit Committee regularly reviews NiSource’s cybersecurity posture. The CISO briefs the Audit Committee on cybersecurity risks and risk mitigation initiatives and actions. In addition, the Board of Directors remains informed of key and emerging cybersecurity risks and receives updates by the Audit Committee after each of its regularly scheduled meetings.

At the management level, the CISO leads the cybersecurity program and is responsible for assessing and managing cybersecurity risks. Our CISO has expertise and experience in cybersecurity derived from over 15 years of cyber related work experience and possesses several certifications including CISSP, CRISC, and CISA. The CISO is supported by the NiSource
Enterprise Security team which performs the cybersecurity function and engages directly on the prevention, detection, mitigation, and remediation of cybersecurity incidents.

As of the date of filing this Annual Report on Form 10-K, NiSource is not aware of any material cybersecurity incidents during the past year. NiSource monitors the increasing sophistication of cybersecurity threats and continues to allocate resources to enhance its cybersecurity program to protect its information systems and assets. No cybersecurity program is effective to identify and mitigate all threats and NiSource cannot guarantee that it will be able to prevent all cybersecurity incidents. Such an incident could interrupt our normal operations and require us to incur significant costs to remediate any such incident and could have a material impact on our businesses, operations and financial condition. For more information regarding the risks associated with cybersecurity, refer to “Item 1A. Risk Factors” of this Annual Report on Form 10-K.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The NiSource Board of Directors' Audit Committee has responsibility for oversight of the cybersecurity program and risks from cybersecurity threats. The Audit Committee regularly reviews NiSource’s cybersecurity posture. The CISO briefs the Audit Committee on cybersecurity risks and risk mitigation initiatives and actions. In addition, the Board of Directors remains informed of key and emerging cybersecurity risks and receives updates by the Audit Committee after each of its regularly scheduled meetings
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The NiSource Board of Directors' Audit Committee has responsibility for oversight of the cybersecurity program and risks from cybersecurity threats. The Audit Committee regularly reviews NiSource’s cybersecurity posture. The CISO briefs the Audit Committee on cybersecurity risks and risk mitigation initiatives and actions. In addition, the Board of Directors remains informed of key and emerging cybersecurity risks and receives updates by the Audit Committee after each of its regularly scheduled meetings.
Cybersecurity Risk Role of Management [Text Block]
At the management level, the CISO leads the cybersecurity program and is responsible for assessing and managing cybersecurity risks. Our CISO has expertise and experience in cybersecurity derived from over 15 years of cyber related work experience and possesses several certifications including CISSP, CRISC, and CISA. The CISO is supported by the NiSource
Enterprise Security team which performs the cybersecurity function and engages directly on the prevention, detection, mitigation, and remediation of cybersecurity incidents.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
The NiSource Board of Directors' Audit Committee has responsibility for oversight of the cybersecurity program and risks from cybersecurity threats. The Audit Committee regularly reviews NiSource’s cybersecurity posture. The CISO briefs the Audit Committee on cybersecurity risks and risk mitigation initiatives and actions. In addition, the Board of Directors remains informed of key and emerging cybersecurity risks and receives updates by the Audit Committee after each of its regularly scheduled meetings.

At the management level, the CISO leads the cybersecurity program and is responsible for assessing and managing cybersecurity risks. Our CISO has expertise and experience in cybersecurity derived from over 15 years of cyber related work experience and possesses several certifications including CISSP, CRISC, and CISA. The CISO is supported by the NiSource
Enterprise Security team which performs the cybersecurity function and engages directly on the prevention, detection, mitigation, and remediation of cybersecurity incidents.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Our CISO has expertise and experience in cybersecurity derived from over 15 years of cyber related work experience and possesses several certifications including CISSP, CRISC, and CISA. The CISO is supported by the NiSource Enterprise Security team which performs the cybersecurity function and engages directly on the prevention, detection, mitigation, and remediation of cybersecurity incidents.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
The NiSource Board of Directors' Audit Committee has responsibility for oversight of the cybersecurity program and risks from cybersecurity threats. The Audit Committee regularly reviews NiSource’s cybersecurity posture. The CISO briefs the Audit Committee on cybersecurity risks and risk mitigation initiatives and actions. In addition, the Board of Directors remains informed of key and emerging cybersecurity risks and receives updates by the Audit Committee after each of its regularly scheduled meetings.

At the management level, the CISO leads the cybersecurity program and is responsible for assessing and managing cybersecurity risks. Our CISO has expertise and experience in cybersecurity derived from over 15 years of cyber related work experience and possesses several certifications including CISSP, CRISC, and CISA. The CISO is supported by the NiSource
Enterprise Security team which performs the cybersecurity function and engages directly on the prevention, detection, mitigation, and remediation of cybersecurity incidents.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true