FE 2022 Annual Report

system operates reliably. NERC, RFC and FERC can be expected to continue to refine existing reliability standards as well as develop and adopt new reliability standards. Compliance with modified or new reliability standards may subject us to higher operating costs and/or increased investments. If we were found not to be in compliance with the mandatory reliability standards, we could be subject to sanctions, including substantial monetary penalties. FERC has authority to impose penalties up to and including $1.5 million per day for failure to comply with these mandatory electric reliability standards. In addition to direct regulation by FERC, we are also subject to rules and terms of participation imposed and administered by various RTOs and ISOs that can have a material adverse impact on our business. For example, the independent market monitors of ISOs and RTOs may impose bidding and scheduling rules to curb the perceived potential for exercise of market power and to ensure the markets function appropriately. Such actions may materially affect our ability to sell, and the price we receive for, our energy and capacity. In addition, PJM may direct our transmission-owning affiliates to build new transmission facilities to meet PJM's reliability requirements or to provide new or expanded transmission service under the PJM Tariff. We may be allocated a portion of the cost of transmission facilities built by others due to changes in RTO transmission rate design. We may be required to expand our transmission system according to decisions made by an RTO rather than our own internal planning processes. Various proposals and proceedings before FERC may cause transmission rates to change from time to time. In addition, RTOs have been developing rules associated with the allocation and methodology of assigning costs associated with improved transmission reliability, reduced transmission congestion and firm transmission rights that may have a financial impact on us. As a member of PJM, which is an RTO, we are subject to certain additional risks, including those associated with the allocation among members of losses caused by unreimbursed defaults of other participants in PJM’s market and those associated with complaint cases filed against PJM that may seek refunds of revenues previously earned by its members. Risks Related to Business Operations Generally Temperature Variations as Well as Severe Weather Conditions or Other Natural Disasters Could Have an Adverse Impact on Our Results of Operations and Financial Condition Weather conditions directly influence the demand for electric power. Demand for power generally peaks during the summer and winter months, with market prices also typically peaking at that time. Overall operating results may fluctuate based on weather conditions. In addition, we have historically sold less power, and consequently received less revenue, when seasonal weather conditions are milder. In addition, severe weather, such as tornadoes, hurricanes, ice or snowstorms, droughts, high winds or other natural disasters, may cause outages and property damage that may require us to incur additional costs that are generally not insured and that may not be recoverable from customers. The effect of the failure of our facilities to operate as planned under these conditions would be particularly burdensome during a peak demand period and could have an adverse effect on our financial condition and results of operations, which adverse effects could be further exacerbated by an increased frequency of such severe weather events. Cyber-Attacks, Data Security Breaches and Other Disruptions to Our Information Technology Systems, or Those of Third Parties We Do Business With, Could Compromise Our Business Operations, Critical and Proprietary Information and Employee and Customer Data, Which Could Have a Material Adverse Effect on Our Business, Results of Operations, Financial Condition and Reputation In the ordinary course of our business, we depend on information technology systems that utilize sophisticated operational systems and network infrastructure to run all facets of our regulated generation, transmission and distribution services. Additionally, we store sensitive data, intellectual property and proprietary or personally identifiable information regarding our business, employees, shareholders, customers, suppliers, business partners and other individuals in our data centers and on our networks. We may also need to provide sensitive data to vendors and service providers who require access to this information. The secure maintenance of information and information technology systems is critical to our operations. Over the last several years, there has been an increase in the frequency of cyber-attacks by terrorists, hackers, international activist organizations, countries and individuals. These and other unauthorized parties may attempt to gain access to our network systems or facilities, or those of third parties with whom we do business in many ways, including directly through our network infrastructure or through fraud, trickery, or other forms of deceiving our employees, contractors and temporary staff. Additionally, our information and information technology systems and those of our vendors and service providers may be increasingly vulnerable to data security breaches, damage and/or interruption due to viruses, human error, malfeasance, faulty password management or other malfunctions and disruptions. Further, hardware, software, or applications we develop or procure from third parties may contain defects in design or manufacture or other problems that could unexpectedly compromise information and/or security. Despite security measures and safeguards we have employed, including certain measures implemented pursuant to mandatory NERC Critical Infrastructure Protection standards, our infrastructure may be increasingly vulnerable to such attacks as a result of the rapidly evolving and increasingly sophisticated means by which attempts to defeat our security measures and gain access to 13

RkJQdWJsaXNoZXIy NTIzOTM0