Consolidated Edison Company of New York, Inc. (Con Edison) filed its 10-K Item 1C disclosure for fiscal year 2025. The filing details the company's cybersecurity risk management framework, which is aligned with NIST CSF and ISO 27001/27002. Con Edison reports no material cybersecurity incidents in the last three years but outlines robust preventive measures, including a 24/7/365 SOC, third-party risk assessments, and regulatory audits by FERC, NERC, and CISA. The company maintains insurance for cyber incidents and has established clear incident response and disclosure protocols.