|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2025
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
TEP’s cybersecurity risk management program is informed by the National Institute of Standards and Technology Cybersecurity Framework. This program includes dedicated investments in people, processes, and technology to manage and reduce cybersecurity risk, including third-party threats. Multiple layers of security controls are deployed across asset and technology classes with a special emphasis on the reliable and safe operation of TEP’s utility systems. Cybersecurity controls employed include firewalls, access management, multi-factor authentication, backups, endpoint protection, threat intelligence, and security monitoring. TEP continues to adjust and refine this program in response to the shifting threat landscape (including AI-related threats), third-party assessments, and industry best practices.Cybersecurity risk is tactically and strategically managed by TEP’s Enterprise Cybersecurity team comprised of experienced professionals with various cybersecurity certifications, including CISSP and GICSP. This team uses governmental and industry threat intelligence, such as the Electricity Information Sharing and Analysis Center, Cybersecurity and Infrastructure Security Agency, and internal cybersecurity tools to proactively identify, assess, manage, and respond to risk, including network monitoring and vulnerability scanning.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|
TEP’s cybersecurity risk management program is informed by the National Institute of Standards and Technology Cybersecurity Framework. This program includes dedicated investments in people, processes, and technology to manage and reduce cybersecurity risk, including third-party threats. Multiple layers of security controls are deployed across asset and technology classes with a special emphasis on the reliable and safe operation of TEP’s utility systems. Cybersecurity controls employed include firewalls, access management, multi-factor authentication, backups, endpoint protection, threat intelligence, and security monitoring. TEP continues to adjust and refine this program in response to the shifting threat landscape (including AI-related threats), third-party assessments, and industry best practices.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|The UNS Energy Board Environmental, Safety, and Security Committee oversees cybersecurity strategy, performance, and risk, and timely reviews cybersecurity events, depending on severity, even if not material to TEP.
TEP's Security Steering Committee provides management oversight to its cybersecurity strategy, performance, and risk assessment and management. This committee also reviews significant cybersecurity events, including the scope of the incident and the associated prevention, detection, mitigation, and remediation efforts. This committee includes the Chief Operating Officer, Chief Information Officer, Chief Compliance Officer, Chief Financial Officer, Senior Director overseeing Enterprise Security, and others with the requisite cybersecurity experience, training, and skills who oversee TEP’s ERM program. The Chief Information Officer has 20 years of experience leading technology strategy, operations, transformation, cybersecurity, and compliance across diverse industries, including large public and private equity-owned firms. The Senior Director overseeing Enterprise Security has 17 years of experience in managing technology and risks and advising on cybersecurity issues, and holds CISSP and GICSP certifications.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|TEP's Security Steering Committee provides management oversight to its cybersecurity strategy, performance, and risk assessment and management.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|This committee also reviews significant cybersecurity events, including the scope of the incident and the associated prevention, detection, mitigation, and remediation efforts.
|Cybersecurity Risk Role of Management [Text Block]
|
Cybersecurity risk is identified and tracked through TEP’s ERM program that consists of formal vetting and quarterly reporting to the UNS Energy Audit and Risk Committee and the UNS Energy Board. The UNS Energy Board Environmental, Safety, and Security Committee oversees cybersecurity strategy, performance, and risk, and timely reviews cybersecurity events, depending on severity, even if not material to TEP. The UNS Energy Board is notified of significant cybersecurity events as outlined in UNS Energy's Cybersecurity Incident Response and Reporting Plan.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|
TEP's Security Steering Committee provides management oversight to its cybersecurity strategy, performance, and risk assessment and management. This committee also reviews significant cybersecurity events, including the scope of the incident and the associated prevention, detection, mitigation, and remediation efforts. This committee includes the Chief Operating Officer, Chief Information Officer, Chief Compliance Officer, Chief Financial Officer, Senior Director overseeing Enterprise Security, and others with the requisite cybersecurity experience, training, and skills who oversee TEP’s ERM program. The Chief Information Officer has 20 years of experience leading technology strategy, operations, transformation, cybersecurity, and compliance across diverse industries, including large public and private equity-owned firms. The Senior Director overseeing Enterprise Security has 17 years of experience in managing technology and risks and advising on cybersecurity issues, and holds CISSP and GICSP certifications.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|Cybersecurity risk is identified and tracked through TEP’s ERM program that consists of formal vetting and quarterly reporting to the UNS Energy Audit and Risk Committee and the UNS Energy Board.This committee includes the Chief Operating Officer, Chief Information Officer, Chief Compliance Officer, Chief Financial Officer, Senior Director overseeing Enterprise Security, and others with the requisite cybersecurity experience, training, and skills who oversee TEP’s ERM program. The Chief Information Officer has 20 years of experience leading technology strategy, operations, transformation, cybersecurity, and compliance across diverse industries, including large public and private equity-owned firms. The Senior Director overseeing Enterprise Security has 17 years of experience in managing technology and risks and advising on cybersecurity issues, and holds CISSP and GICSP certifications.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|The UNS Energy Board is notified of significant cybersecurity events as outlined in UNS Energy's Cybersecurity Incident Response and Reporting Plan.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|No Insider Trading Flag
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- Definition
+ References
No Insider Trading Flag
+ Details
No definition available.