The Companies and other operators of critical energy infrastructure and energy market participants face a heightened risk of cyber attack and the Companies' businesses require the continued operation of information systems and network infrastructure. See Item 1 for a description of the businesses of the Utilities and Con Edison Transmission. Cyber attacks may include hacking, viruses, malware, denial of service attacks, ransomware, exploited vulnerabilities or other security breaches, including loss of data and communications. Cyber threats in general, and in particular to critical infrastructure, are increasing in sophistication, magnitude and frequency and the techniques used in cyberattacks change rapidly, including from emerging technologies, such as artificial intelligence. Interconnectivity with customers, independent system operators, energy traders and other energy market participants, suppliers, contractors and others also exposes the Companies' information systems and network infrastructure to an increased risk of cyber incidents, including attacks. Such interconnectivity increases the risk that a cyber incident or attack on the Companies could affect others and that a cyber incident or attack on others could affect the Companies. In the event of a cyber incident or attack that the Companies were unable to defend against or mitigate, the Companies could have their operations and the operations of their customers and others disrupted. The Companies could also have their financial and other information systems and network infrastructure impaired, property damaged, and customer and employee information stolen; experience substantial loss of revenues, response costs and other financial loss; and be subject to increased regulation, litigation, penalties and damage to their reputation. In October 2023, threat actors exploited a vulnerability in Citrix NetScaler that was remediated and reported to the relevant regulatory authorities by the Companies. Also during 2023, the Companies experienced increases in malicious attempts to disrupt traffic to their websites and in attacks against third-party vendors employed by the Companies. The Companies have experienced cyber incidents and attacks in the past and expect to experience them in the future. Although none of these incidents has had a material impact on the Companies, the scope and impact of any future incident cannot be predicted. In the event of a cybersecurity incident or attack that the Companies were unable to defend against or mitigate, the Companies' business strategy, results of operations or financial condition are reasonably likely to be materially affected.