Cybersecurity risks have increased in recent years as a result of the proliferation of new technologies and the increased sophistication, magnitude and frequency of cyberattacks and data security breaches. Duke Energy relies on the continued operation of sophisticated digital information technology systems and network infrastructure, which are part of an interconnected regional grid. Additionally, connectivity to the internet continues to increase through grid modernization and other operational excellence initiatives. Because of the critical nature of the infrastructure, increased connectivity to the internet and technology systems’ inherent vulnerability to disability or failures due to hacking, viruses, acts of war or terrorism or other types of data security breaches, the Duke Energy Registrants face a heightened risk of cyberattack from foreign or domestic sources and have been subject, and will likely continue to be subject, to attempts to gain unauthorized access to information and/or information systems or to disrupt utility operations through computer viruses and phishing attempts either directly or indirectly through its material vendors or related third parties. In the event of a significant cybersecurity breach on either the Duke Energy Registrants or with one of our material vendors or related third parties, the Duke Energy Registrants could (i) have business operations disrupted, including the disruption of the operation of our natural gas and electric assets and the power grid, theft of confidential company, employee, retiree, shareholder, vendor or customer information, and general business systems and process interruption or compromise, including preventing the Duke Energy Registrants from servicing customers, collecting revenues or the recording, processing and/or reporting financial information correctly, (ii) experience substantial loss of revenues, repair and restoration costs, penalties and costs for lack of compliance with relevant regulations, implementation costs for additional security measures to avert future cyberattacks and other financial loss and (iii) be subject to increased regulation, litigation and reputational damage. While Duke Energy maintains insurance relating to cybersecurity events, such insurance is subject to a number of exclusions and may be insufficient to offset any losses, costs or damage experienced. Also, the market for cybersecurity insurance is relatively new and coverage available for cybersecurity events is evolving as the industry matures. The Duke Energy Registrants are subject to standards enacted by the North American Electric Reliability Corporation and enforced by FERC regarding protection of the physical and cyber security of critical infrastructure assets required for operating North America's bulk electric system. The Duke Energy Registrants are also subject to regulations set by the Nuclear Regulatory Commission regarding the protection of digital computer and communication systems and networks required for the operation of nuclear power plants. The Duke Energy Registrants that operate designated critical pipelines that transport natural gas are also subject to security directives issued by the Department of Homeland Security's Transportation Security Administration (TSA) requiring such registrants to implement specific cybersecurity mitigation measures. While the Duke Energy Registrants believe they are in compliance with, or, in the case of the recent TSA security directives, are in the process of implementing such standards and regulations, the Duke Energy Registrants have from time to time been, and may in the future be, found to be in violation of such standards and regulations. In addition, compliance with or changes in the applicable standards and regulations may subject the Duke Energy Registrants to higher operating costs and/or increased capital expenditures as well as substantial fines for non-compliance.