Idaho Power operates in an industry that requires the continuous use and operation of sophisticated information technology and increasingly complex operational technology systems and network infrastructure. Idaho Power's generation and transmission facilities and its grid operations are potential targets for terrorist acts and threats, acts of war, social unrest, cyber and physical security attacks, and other disruptive activities of individuals or groups, including by nation states or nation state-sponsored groups. There have been cyber and physical attacks on energy infrastructure within the energy industry and on Idaho Power specifically in the past, and there are likely to be additional attacks in the future. Idaho Power and its vendors have been subject to, and will likely continue to be subject to, attempts to gain unauthorized access to systems and confidential information or to disrupt operations. The utility industry is continuing to experience an increase in the frequency and sophistication of cybersecurity incidents.
Some of Idaho Power's facilities are deemed "critical infrastructure" under federal standards, in that incapacity or destruction of the facilities could have a debilitating impact on security, reliability, or operability of the bulk electric power system, national economic security, and public health and safety. Infrastructure facilities, such as power generation facilities and electric transmission or distribution facilities, could be direct targets of, or potential indirect casualties of, an act of terror or war or cyber or physical attack (whether originating internal to Idaho Power or externally), which might affect Idaho Power's operations by limiting the ability to generate, purchase, or transmit power. Idaho Power's electric transmission systems are part of an interconnected regional grid, and therefore, it faces the risk of causing or being subject to a long-term power outage due to grid disturbances or disruptions on a neighboring interconnected grid system. Cyber and physical threats and attacks can have cascading impacts that unfold with increasing speed across networks, information systems, and other technologies. Network, information systems, and technology-related events, including those caused by IDACORP or Idaho Power through process breakdowns, human error, security architecture or design vulnerabilities, or by third parties through cyber or physical security attacks, could result in a degradation or disruption in the energy grid and the services of the companies, as well as the ability to record, process, and report customer, business, and financial information. Physical or cyber attacks against key suppliers or service providers could have a similar effect on Idaho Power.
Idaho Power's business operations require the continuous availability of information technology systems and network infrastructure, and in the normal course of business, Idaho Power or its vendors collect and store sensitive and confidential customer and employee information and proprietary information of Idaho Power. Idaho Power's technology systems are dependent upon connectivity to the internet and third-party vendors to host, maintain, modify, and update its systems, which may experience significant system failures or cyber attacks that could compromise the security of Idaho Power's assets and information. All information technology systems are vulnerable to being disabled, unauthorized access, unintentional defects, user error, errors in system changes, and cybersecurity incidents. Idaho Power is in the process of pursuing complex business system upgrades, and these significant changes increase the risk of system interruption. Any data security breaches, such as misappropriation, misuse, leakage, falsification or accidental release or loss of information maintained in Idaho Power's information technology systems or on third-party systems, including customer or employee data, could result in violations of privacy and other laws and associated litigation and liability for damages, fines, and penalties; financial loss to Idaho Power or to its customers; customer dissatisfaction or diminished customer confidence; and damage to Idaho Power's reputation, all of which could materially adversely affect Idaho Power's financial condition and results of operations.
No security measures can completely shield Idaho Power's systems, infrastructure, and data from vulnerabilities to cyber attacks, human error, intrusions, or other catastrophic events that could result in their failure or reduced functionality, and ultimately the potential loss of sensitive information or the loss of Idaho Power's ability to fulfill critical business functions and provide reliable electric power to customers. Despite the steps Idaho Power may take to detect, mitigate, or eliminate threats and respond to security incidents, the techniques used by those who seek to obtain unauthorized access, and possibly disable or sabotage systems or abscond with information and data, change frequently and Idaho Power may not be able to protect against all such actions. Idaho Power actively monitors developments in cybersecurity and is involved in various related government and industry groups, and the company's board receives security updates at least quarterly. Although Idaho Power continues to make investments in its cybersecurity program, including personnel, technologies, and training of personnel, there can be no assurance that these systems or their expected functionality will be implemented, maintained, or expanded effectively; nor can security measures completely eliminate the possibility of a cybersecurity breach. Further, the implementation of security guidelines and measures has resulted in, and Idaho Power expects to continue to result in, increased costs.
Terrorist attacks, acts of war, social unrest, cyber and physical security attacks, and similar incidents can also have indirect impacts by creating political, economic, social, or financial market instability, and can cause damage to or interference with Idaho Power's operating assets, customers, or suppliers. This may result in business interruption, lost revenue, higher commodity prices, disruption in fuel supplies, lower energy consumption, and unstable commodity and financial markets,particularly with respect to electricity and natural gas, any of which may materially adversely affect Idaho Power. These events, and governmental actions in response, could result in a material decrease in revenues and increase costs to protect, repair, and insure Idaho Power's assets and operate its infrastructure, systems, and business.