AEP's 10-K Item 1C describes its enterprise-wide cybersecurity program, NERC/FERC compliance, NIST CSF alignment, CSO governance, board oversight via the Technology Committee, 24/7 Cybersecurity Intelligence and Response Center, third-party risk governance, employee phishing training, and cyber liability insurance. AEP states it is not aware of any cybersecurity incident that has materially affected or is reasonably likely to materially affect its business. No specific breach is disclosed in this filing.