XML 57 R32.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Cybersecurity presents an ever-evolving challenge to the electric power industry and Edison International and SCE have identified cybersecurity as a key enterprise risk. SCE's operations require the continuous availability of critical information and operational technology systems, sensitive customer and employee data, and infrastructure information, all of which are targets for malicious actors. Cybersecurity attacks, which can arise from external actors, internal threats, or through SCE's supply chain, are continually becoming more frequent and more sophisticated. SCE's grid modernization efforts and the transition to a more connected grid, including incorporating communication and operating technologies aimed at enabling SCE to respond faster, operate its systems more efficiently and reliably, and incorporate DERs at a greater level, also increases SCE’s vulnerability to cybersecurity attacks. To SCE's knowledge it has not experienced a material cybersecurity incident to date.
SCE’s increased reliance on technology necessarily increases cybersecurity risk. Cybersecurity incidents that may cause a major disruption of SCE's operations, and therefore may materially affect Edison International and SCE's financial
condition, operations, and business reputation, include cyber attacks designed to compromise or exfiltrate data (e.g., ransomware attacks), damage or destroy systems, interrupt availability, conduct future malicious actions, and/or gain control of or otherwise interrupt the operation of SCE’s electric grid. For additional information on risks from cybersecurity threats that may have a material effect on Edison International and SCE, see the "Risks Relating to Edison International and Southern California Edison Company—Cybersecurity and Physical Security Risks."
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] SCE's grid modernization efforts and the transition to a more connected grid, including incorporating communication and operating technologies aimed at enabling SCE to respond faster, operate its systems more efficiently and reliably, and incorporate DERs at a greater level, also increases SCE’s vulnerability to cybersecurity attacks
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
Risk Management, Strategy and Oversight
SCE assesses and monitors cybersecurity risks to current infrastructure, new projects, and third parties, including vendors. SCE maintains incident response plans, utilizes cybersecurity incident response exercises, performs targeted audits, leverages third party assessments and uses the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) as a guideline to identify, evaluate and manage material risks from cybersecurity threats. SCE also engages consultants, and coordinates with the Federal government and industry peers, to assist in identifying, evaluating and managing its cybersecurity risks, and uses contractual terms to establish cybersecurity requirements with certain third parties. Identified cybersecurity risks are documented and presented to management to review and advise on cybersecurity strategies and mitigation measures. Based on management reviews, cybersecurity strategies and remediation plans are developed or adjusted to address pertinent risks. Edison International and SCE leverage training, policies, technical and procedural controls, and mitigation plans to address risks from cybersecurity threats.
Management has established a cybersecurity oversight group comprised of a multidisciplinary senior management team, including its Vice President of Enterprise Risk Management, to monitor and provide strategic direction for the prevention, detection, mitigation, and remediation of risks from cybersecurity threats. A Boards of Directors’ liaison regularly attends meetings of the cybersecurity oversight group and provides reports to the Safety and Operations Committees of the Boards of Directors. Other members of the Boards of Directors are invited to attend meetings and typically attend at least one meeting annually.
The Edison International and SCE Audit and Finance Committees of the Boards of Directors oversee enterprise risk management, including risks from cybersecurity threats. Annually, Edison International and SCE’s enterprise risk management team conducts a review of enterprise risks, including risks from cybersecurity threats, and presents the results of its review to management and the Audit and Finance Committees. In addition, the Boards of Directors have assigned primary responsibility for cybersecurity operations oversight to the Edison International and SCE Safety and Operations Committees, which receive regular cybersecurity updates from SCE’s Chief Security Officer on specific topics, including the dynamic cybersecurity landscape and defense and risk mitigation strategies. To inform its oversight over cybersecurity threats, SCE’s Chief Security Officer also presents to the full Boards of Directors annually. The Boards of Directors also receive a periodic cybersecurity report from an external SCE consultant that includes an assessment of SCE's cybersecurity program and organization.
SCE’s Chief Security Officer has primary responsibility for assessing and managing risks from cybersecurity threats, and serves as Edison International and SCE’s chief information security officer. SCE’s Chief Security Officer has extensive experience in the cybersecurity industry, including previous experience in cybersecurity roles at Southern Company, the MITRE Corporation, the National Institute of Standards and Technology (NIST), and the Federal Bureau of Investigation (FBI). SCE's Chief Security Officer earned a bachelor’s degree in computer information systems from Clemson University and is a Certified Information Systems Security Professional (CISSP).
For additional information on the Edison International Board of Directors cybersecurity related experience and oversight of cybersecurity risk management, see Edison International’s Proxy Statement under the headings "Director Skills Matrix" and "Board Oversight of Strategy, Risk and ESG."
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Edison International and SCE Audit and Finance Committees of the Boards of Directors oversee enterprise risk management, including risks from cybersecurity threats
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] A Boards of Directors’ liaison regularly attends meetings of the cybersecurity oversight group and provides reports to the Safety and Operations Committees of the Boards of Directors
Cybersecurity Risk Role of Management [Text Block] The Edison International and SCE Audit and Finance Committees of the Boards of Directors oversee enterprise risk management, including risks from cybersecurity threats. Annually, Edison International and SCE’s enterprise risk management team conducts a review of enterprise risks, including risks from cybersecurity threats, and presents the results of its review to management and the Audit and Finance Committees. In addition, the Boards of Directors have assigned primary responsibility for cybersecurity operations oversight to the Edison International and SCE Safety and Operations Committees, which receive regular cybersecurity updates from SCE’s Chief Security Officer on specific topics, including the dynamic cybersecurity landscape and defense and risk mitigation strategies.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] SCE’s Chief Security Officer also presents to the full Boards of Directors annually. The Boards of Directors also receive a periodic cybersecurity report from an external SCE consultant that includes an assessment of SCE's cybersecurity program and organization.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] SCE’s Chief Security Officer has extensive experience in the cybersecurity industry, including previous experience in cybersecurity roles at Southern Company, the MITRE Corporation, the National Institute of Standards and Technology (NIST), and the Federal Bureau of Investigation (FBI). SCE's Chief Security Officer earned a bachelor’s degree in computer information systems from Clemson University and is a Certified Information Systems Security Professional (CISSP).
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] SCE’s Chief Security Officer also presents to the full Boards of Directors annually. The Boards of Directors also receive a periodic cybersecurity report from an external SCE consultant that includes an assessment of SCE's cybersecurity program and organization
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true