XML 355 R46.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block] Risk management and strategy
bp has implemented a threat-focused strategy to assess cyber security
risks and protect against, detect, respond to, and recover from cyber
attacks. bp maintains internal teams focused on cyber security intelligence
and emergency response to monitor the external threat landscape and the
threats to bp’s IT and operational technology infrastructure. bp partners
with third-party specialists to augment its in-house capabilities as
necessary. bp has a defined protocol for cyber incident notification based
on severity and bp’s internal cyber security teams brief the CISO,
technology EVP, other senior leadership and relevant board and
management committees about incidents on an as needed basis.
Cyber security risk management is integrated into bp’s overall risk
management process. bp’s entities are required to identify, assess and
report key risks, including cyber security risks, to relevant members of
senior leadership. bp maintains additional procedures to manage cyber
security risks related to third-party service providers, including conducting
information security assessments for certain providers, providing relevant
trainings for bp employees, and maintaining information security
requirements for suppliers.
Our business strategy, results of operations and financial condition have
not been materially affected by risks from cyber security threats, including
as a result of previously identified cyber security incidents. For more
information on our cyber security related risks, see Risk Factors (pages
79-67).
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] Cyber security risk management is integrated into bp’s overall risk
management process. bp’s entities are required to identify, assess and
report key risks, including cyber security risks, to relevant members of
senior leadership
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] The board oversees bp’s internal control and risk management framework.
The board is supported by the safety and sustainability committee which
oversees cyber security risk and received reports from bp’s chief
information security officer (CISO) on cyber security incidents at every
committee meeting in 2024, including information on bp’s response to
incidents. This allows an ongoing assessment by the committee of the
effectiveness of bp’s overall cyber security programme. A session is held
once a year to review bp’s roadmap and progress for addressing cyber
security risk. Read more in the safety and sustainability committee report
on page 80.
At management level, assessment and management of material risks from
cyber security threats is led by bp’s executive vice president of technology,
a member of bp’s leadership team with deep experience in bp’s engineering
and operations functions, with support from bp’s CISO, who has over 20
years of experience in the information technology industry. bp’s digital
safety operational risk committee brings together additional senior
members of bp’s digital leadership team to assist in ensuring that cyber
security risks across bp are identified, understood, accurately quantified
and are managed in accordance with bp’s internal controls framework.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The board oversees bp’s internal control and risk management framework.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The board is supported by the safety and sustainability committee which
oversees cyber security risk and received reports from bp’s chief
information security officer (CISO) on cyber security incidents at every
committee meeting in 2024, including information on bp’s response to
incidents.
Cybersecurity Risk Role of Management [Text Block] At management level, assessment and management of material risks from
cyber security threats is led by bp’s executive vice president of technology,
a member of bp’s leadership team with deep experience in bp’s engineering
and operations functions, with support from bp’s CISO, who has over 20
years of experience in the information technology industry. bp’s digital
safety operational risk committee brings together additional senior
members of bp’s digital leadership team to assist in ensuring that cyber
security risks across bp are identified, understood, accurately quantified
and are managed in accordance with bp’s internal controls framework.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] At management level, assessment and management of material risks from
cyber security threats is led by bp’s executive vice president of technology,
a member of bp’s leadership team with deep experience in bp’s engineering
and operations functions, with support from bp’s CISO, who has over 20
years of experience in the information technology industry. bp’s digital
safety operational risk committee brings together additional senior
members of bp’s digital leadership team to assist in ensuring that cyber
security risks across bp are identified, understood, accurately quantified
and are managed in accordance with bp’s internal controls framework.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] bp’s executive vice president of technology,
a member of bp’s leadership team with deep experience in bp’s engineering
and operations functions, with support from bp’s CISO, who has over 20
years of experience in the information technology industry
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The board is supported by the safety and sustainability committee which
oversees cyber security risk and received reports from bp’s chief
information security officer (CISO) on cyber security incidents at every
committee meeting in 2024, including information on bp’s response to
incidents. This allows an ongoing assessment by the committee of the
effectiveness of bp’s overall cyber security programme. A session is held
once a year to review bp’s roadmap and progress for addressing cyber
security risk. Read more in the safety and sustainability committee report
on page 80.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true