XML 464 R45.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block] Risk management and strategy
bp has implemented a threat-focused strategy to assess cyber security
risks and protect against, detect, respond to, and recover from cyber
attacks. bp maintains internal teams focused on cyber security
intelligence and emergency response to monitor the external threat
landscape and the threats to bp’s IT and operational technology
infrastructure. bp partners with third-party specialists to augment its in-
house capabilities as necessary. bp has a defined protocol for cyber
incident notification based on severity and bp’s internal cyber security
teams brief the CISO, technology EVP, other senior leadership and
relevant board and management committees about incidents on an as
needed basis.
Cyber security risk management is integrated into bp’s overall risk
management process. bp’s entities are required to identify, assess and
report key risks, including cyber security risks, to relevant members of
senior leadership. bp maintains additional procedures to manage cyber
security risks related to third-party service providers, including
conducting information security assessments for certain providers,
providing relevant trainings for bp employees, and maintaining
information security requirements for suppliers.
Our business strategy, results of operations and financial condition
have not been materially affected by risks from cyber security threats,
including as a result of previously identified cyber security incidents. For
more information on our cyber security related risks, see Risk Factors
on page 67.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] Cyber security risk management is integrated into bp’s overall risk
management process. bp’s entities are required to identify, assess and
report key risks, including cyber security risks, to relevant members of
senior leadership
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] The board oversees bp’s internal control and risk management
framework. The board is supported by the safety and sustainability
committee which oversees cyber security risk and received reports
from bp’s chief information security officer (CISO) on cyber security
incidents at every committee meeting in 2025, including information on
bp’s response to incidents. This allows an ongoing assessment by the
committee of the effectiveness of bp’s overall cyber security
programme. A session is held once a year to review bp’s roadmap and
progress for addressing cyber security risk. Read more in the safety and
sustainability committee report on page 82.
At management level, assessment and management of material risks
from cyber security threats is led by bp’s executive vice president of
technology, a member of bp’s leadership team with deep experience in
bp’s engineering and operations functions, with support from bp’s
CISO, who has over 20 years of experience in the information
technology industry. bp’s digital safety operational risk committee
brings together additional senior members of bp’s digital leadership
team to assist in ensuring that cyber security risks across bp are
identified, understood, accurately quantified and are managed in
accordance with bp’s internal controls framework.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The board oversees bp’s internal control and risk management framework.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The board is supported by the safety and sustainability
committee which oversees cyber security risk and received reports
from bp’s chief information security officer (CISO) on cyber security
incidents at every committee meeting in 2025, including information on
bp’s response to incidents.
Cybersecurity Risk Role of Management [Text Block] At management level, assessment and management of material risks
from cyber security threats is led by bp’s executive vice president of
technology, a member of bp’s leadership team with deep experience in
bp’s engineering and operations functions, with support from bp’s
CISO, who has over 20 years of experience in the information
technology industry. bp’s digital safety operational risk committee
brings together additional senior members of bp’s digital leadership
team to assist in ensuring that cyber security risks across bp are
identified, understood, accurately quantified and are managed in
accordance with bp’s internal controls framework.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] At management level, assessment and management of material risks
from cyber security threats is led by bp’s executive vice president of
technology, a member of bp’s leadership team with deep experience in
bp’s engineering and operations functions, with support from bp’s
CISO, who has over 20 years of experience in the information
technology industry. bp’s digital safety operational risk committee
brings together additional senior members of bp’s digital leadership
team to assist in ensuring that cyber security risks across bp are
identified, understood, accurately quantified and are managed in
accordance with bp’s internal controls framework.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] bp’s executive vice president of
technology, a member of bp’s leadership team with deep experience in
bp’s engineering and operations functions, with support from bp’s
CISO, who has over 20 years of experience in the information
technology industry
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The board is supported by the safety and sustainability
committee which oversees cyber security risk and received reports
from bp’s chief information security officer (CISO) on cyber security
incidents at every committee meeting in 2025, including information on
bp’s response to incidents. This allows an ongoing assessment by the
committee of the effectiveness of bp’s overall cyber security
programme. A session is held once a year to review bp’s roadmap and
progress for addressing cyber security risk. Read more in the safety and
sustainability committee report on page 82.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true