Consolidated Edison, Inc.
bd_860ccef64cb883fe · schema v1 · pii pii-v1
Full breach record for Consolidated Edison, Inc. →Consolidated Edison Company of New York, Inc. (Con Edison) filed its 10-K Item 1C disclosure for fiscal year 2025. The filing details the company's cybersecurity risk management framework, which is aligned with NIST CSF and ISO 27001/27002. Con Edison reports no material cybersecurity incidents in the last three years but outlines robust preventive measures, including a 24/7/365 SOC, third-party risk assessments, and regulatory audits by FERC, NERC, and CISA. The company maintains insurance for cyber incidents and has established clear incident response and disclosure protocols.
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1047862/000104786226000031/ed-20251231.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 19, 2026
- Raw hash
- 40ca43427b44c5bbad971bce7db2d2b5f5eafb5d0a7f7b34f991ee3a569ebb52
Source filing
Reporting entity
- Name
- CONSOLIDATED EDISON COMPANY OF NEW YORK, INC.norm: consolidated edison company of new york
- SEC CIK
- 0000922039
- Domain
- conedison.com
- Industry
- Energy Utilities
Victim entity
- Name
- Consolidated Edison, Inc.norm: consolidated edison
- SEC CIK
- 1047862
- Domain
- conedison.com
- Industry
- Energy Utilities
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PII
- Attack vector
- Unknown
- Regulator citations
- Audited by FERC, North American Electric Reliability Corporation, TSA, Cybersecurity and Infrastructure Security Agency, NYSPSC, and United States Coast Guard
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.