QUANTA SERVICES, INC. 10-K Cybersecurity GRC - 2024-02-22

Page last updated on July 16, 2024

QUANTA SERVICES, INC. reported their cybersecurity risk management and governance process in a yearly 10-K filed on 2024-02-22 09:56:10 EST.

Filings

10-K filed on 2024-02-22

QUANTA SERVICES, INC. filed a 10-K at 2024-02-22 09:56:10 EST
Accession Number: 0001050915-24-000009

Note: filing items unformatted. Drop us a note with the above URL to help us prioritize formatting it!

Item 1C. Cybersecurity.

ITEM 1C. Cybersecurity Cybersecurity Risk Management and Strategy We have developed and implemented a cybersecurity risk management program intended to protect the confidentiality, integrity, and availability of our critical systems and information. Our cybersecurity risk management program includes a cybersecurity incident response plan and is integrated with our overall enterprise risk management program, sharing common methodologies, reporting channels and governance processes that apply across the enterprise risk management program to other legal, compliance, strategic, operational and financial risk areas. While we may not meet any particular standard, specification or requirement of the Center for Internet Security Critical Security Controls, we utilize such controls as a guide to help us identify, assess and manage cybersecurity risks relevant to our business. Our cybersecurity risk management program includes, among other things: - risk assessments designed to help identify material cybersecurity risks to our critical systems and information services; 37 - a team comprising information technology (IT) security, IT infrastructure, and IT compliance personnel principally responsible for directing (i) our cybersecurity risk assessment processes, (ii) our security processes and (iii) our response to cybersecurity incidents; - the use of external cybersecurity service providers, where appropriate, to assess, test or otherwise assist with aspects of our security processes; - cybersecurity awareness training of employees with access to our IT systems; - a cybersecurity incident response plan and Security Operations Center to respond to cybersecurity incidents; and - a third-party risk management process for service providers. During the year ended December 31, 2023, we have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected our operations, business strategy, results of operations or financial condition. However, we expect to continue to face certain risks from ongoing cybersecurity threats that, if realized, are reasonably likely to materially affect us, including our operations, business strategy, results of operations or financial condition. See " Risk Factors - Disruptions to our information technology systems or our failure to adequately protect critical data, sensitive information and technology systems could materially affect our business or result in harm to our reputation ." Cybersecurity Governance Our Board considers cybersecurity risk as part of its risk oversight function and considers cybersecurity and IT risks as key strategic risks of Quanta. The Board oversees management’s implementation of our cybersecurity risk management program, receiving regular reports from management (including our Vice President of IT) on our cybersecurity risks, including briefings on our cyber risk management program and cybersecurity incidents, and reviewing cybersecurity topics impacting companies with management and external experts. Our Vice President of IT reports to the Chief Financial Officer and leads our IT and cybersecurity functions and has primary responsibility for leading our overall cybersecurity risk management program, supervising both our internal cybersecurity personnel and our external cybersecurity service providers. Our cybersecurity function is responsible for assessing and managing our material risks from cybersecurity threats, as well as informing management about and monitoring the prevention, detection, mitigation, and remediation of cybersecurity risks and incidents through various means, which include briefings with internal security personnel, threat intelligence and other information obtained from governmental, public or private sources, including external cybersecurity service providers and alerts and reports produced by security tools deployed in the IT environment. Our Vice President of IT has significant global experience in managing and leading information systems and deploying cybersecurity technologies and holds a cybersecurity certification from a leading cybersecurity training and research institute.


Company Information

NameQUANTA SERVICES, INC.
CIK0001050915
SIC DescriptionElectrical Work
TickerPWR - NYSE
Website
CategoryLarge accelerated filer
Fiscal Year EndDecember 30