Risk and Opportunity Management

Managing risks and opportunities to create value

Overview

Prysmian’s value creation policy has always been based on effective risk and opportunity management. Since 2012, by adopting the provisions on risk management introduced by the Corporate Governance Code for Listed Companies (Corporate Governance Code) of Borsa Italiana, Prysmian has taken the opportunity to strengthen its governance model and implement an evolving risk management system that promotes proactive management of risks and opportunities using a structured and systematic tool to support the main business decision-making processes. 

In fact, this Enterprise Risk Management (ERM) model, developed in line with internationally recognised models and best practices, such as those promoted by the Committee of Sponsoring Organizations of the Treadway Commission (COSO) and the ISO 31000 standard, enables the Board of Directors and managers to make informed assessments of risk scenarios that could jeopardise the achievement of strategic objectives. It also allows to adopt additional tools able to anticipate, mitigate and manage significant exposures and to pursue opportunities in line with the Group’s risk appetite, defined as the type and extent of risk that Prysmian is able and willing to assume.

The risk and opportunity management process involves the Group’s key business/function managers, allowing the most significant risk factors to be identified, assessed, and managed, including climate-, biodiversity- and sustainability-related issues. This results in an integrated and multi-disciplinary company-wide risk management process aimed at ensuring long-term value creation for shareholders and stakeholders. In particular, with regard to the Company’s biodiversity risk assessment, the scope covers Own operations, Adjacent areas to own operations, and specific Upstream activities, ensuring a comprehensive evaluation of potential interactions with ecosystems.

 

ERM in practice

The Group Chief Risk and Compliance Officer, tasked with managing the ERM system, is responsible for ensuring, together with top management, that the main risks and opportunities for Prysmian and its subsidiaries are promptly identified, assessed, treated, and monitored over time.

After reporting to an internal risk management committee consisting of the Group’s top managers, the Group Chief Risk and Compliance Officer periodically meets the Control and Risks Committee — made up of non-executive members of the Board of Directors — to provide updates on the outcomes of the analyses conducted and actions taken, as well as about any developments in the Group’s ERM process.

 

 

Prysmian’s risk appetite

Prysmian’s risk appetite is determined through a process that defines the types and extent of risk that the Company is able and willing to assume in pursuing its strategic objectives.

Identifying risks and setting a clear risk appetite level are essential to achieving an effective ERM framework.

 

Prysmian has not set a single risk appetite statement but rather applies different risk appetite levels based on the range of its activities and may choose to accept different degrees of risk in different areas. For instance, a “Zero tolerance” risk appetite is set for legal & compliance risks (e.g., non-compliance to export control laws and risk related to the whistleblowing system) and for HSE related matters, while a “Low tolerance” risk appetite is set for Cyber risk.

 

 

Risk and opportunity governance

Managing risks and opportunities is an essential part of Prysmian’s culture and fosters greater confidence in achieving strategic objectives and making the business sustainable, together with creating value for all employees, shareholders and stakeholders.

Developing, implementing and promoting a risk and opportunity control and management assurance system is based on the integration of different levels of control:

 

 

 

The ERM process is generally conducted at least twice a year in order to identify, assess, treat and monitor risks and opportunities to ensure that the Group risk exposure is reviewed on a regular basis. For the most relevant risks, for emerging and / or evolving risks, assessment activities are performed even more frequently.

 

Prysmian’s risk and opportunity culture

 

In order to promote an effective risk and opportunity culture throughout the organisation Prysmian has adopted dedicated strategies, including:

  • regular risk and opportunity management education and awareness for all Board members (e.g., the Risk Management & Compliance function regularly updates the Control and Risks Committee about the progress made by the Group’s ERM process and by the various risk management activities) providing deep-dives, inductions and training as needed;

 

  • training focused on risk and opportunity management principles for the whole organisation (e.g., e-learning training through an internal platform);

 

  • dedicated series of training on operational risks (e.g., Project Risk Management) and induction sessions on risk management for new joiners;

 

  • integration of risk and opportunity criteria into the development of products / projects / and services (e.g., risk analysis and deep dives embedded into product and process development, as well as into the bidding and delivery processes);

 

  • financial incentives that incorporate risk management metrics (e.g., the Prysmian Performance evaluation and development programs).

Prysmian’s ERM aims to identify to all types of potentially significant risks and opportunities for the Group, as outlined in its Risk Model — shown in the figure below —, which classifies the internal and external risks of Prysmian’s business model based on five families:

ERM process requires Prysmian Management to use of a clearly defined, common method to assess the Group exposure, to specific risk and opportunity events, measured in terms of impact, likelihood and adequacy of the existing level of risk management, meaning:

  •  Economic-financial impact on expected EBITDA or cash flow, net of existing countermeasures and/or qualitative impact on reputation and/or on operational efficiency/continuity and sustainability, measured on a scale from “low” (1) to “very high” (4);
  • Likelihood, probability that a particular event may occur, measured on a scale from “remote” (1) to “probable” (4);
  • Risk Management Capability, meaning the maturity and effectiveness of existing risk management systems and processes (including controls), measured on a scale from “adequate” (green) to “inadequate/non-existent” (red).

Following the identification and assessment of risks and opportunities, Group exposure is analysed taking into account the future risk and opportunities evolution and outlook (i.e., the possibility that exposure increases, remains constant or decreases over the period considered).

The outcome of the risk assessment is then represented on a 4x4 heatmap, which, by combining the variables in question, provides a clear overview of the most significant risk events.

In particular, sustainability and climate related risks and opportunities are also assessed and reported, taking into account the Group’s latest update of its double materiality matrix for the purposes of the Integrated Report.

The overview of the Group’s risks and opportunities allows the Board of Directors and Top Management to evaluate the Group’s risk appetite and identify the risk and opportunity management strategies to adopt, by assessing and prioritising the types of risk for which it is deemed necessary to implement, improve or optimise mitigation actions and those for which it is sufficient to monitor the exposure over time.

To allow a full coverage of the risks and opportunities to which Prysmian is exposed, risk and opportunity analyses are also carried out through specialised deep dives (e.g. new emerging risks, operational risks, climate change risks). Below are examples of risk & opportunity deep dives performed in Prysmian.

 

Operational risks and focus on Project risk

At Prysmian, the assessment of operational risks is an integral part of the Enterprise Risk Management activities. Departments, Functions and Business Units at all levels, involved in producing and/or delivering products/projects/services to clients, are identified as Risk Owners, being primary responsible for timely identifying, assessing, managing and monitoring risks in day-to-day operations and throughout each product/project/service life cycle.

 

Operational risk management across the Group — covering areas such as HR, HSE, IT and Cyber — is structured across multiple governance layers. According to Prysmian governance, risks are first identified, assessed and monitored at the local level, down to individual plant level where relevant, and subsequently aggregated at Region or Business Unit level as appropriate. Group-level reporting is then carried out by the Risk Management function, which is responsible for risk assessments in close coordination with HQ functions, including the execution of deep-dive analyses where required. The Risk Management process incorporates an analysis of available KPIs and KRIs, with year-on-year and period-on-period trend assessments aimed at evaluating the effectiveness of implemented mitigation actions. In addition, dedicated internal management committees are convened on specific topics to ensure appropriate oversight and structured discussion — for example, the Cyber Security & AI Committee, which focuses on cyber risk-related matters.

 

For relevant risks, the risk assessment outcomes and, where relevant the trend analysis of relevant KPIs/KRIs, are presented and discussed within the Control and Risk Committee.

 

For example, to effectively manage project risks related turn-key projects, Prysmian has implemented a systematic Project Risk Management Process, integrated in Prysmian’s Project Management activities of Transmission segment, during the whole project lifecycle (from bidding to delivery phases). Project Risk Management System is aimed at ensuring expected projects performances, by effectively managing risks during the whole project lifecycle and timely identifying mitigation actions, also promoting proactive and transparent behaviours by all actors involved in risk assessment.

 

Risk assessment activities, as well as risk management, mitigation and monitoring actions are clearly assigned to front-line employees, dedicated working group and functional experts based on each function’s area of competence / expertise, including escalation mechanisms to Top Management and relevant Committees depending on risk evolution and exposure.

 

Climate Change risks

In response to global trends related to climate change, Prysmian has developed analysis on the Group exposure to climate-related risks and opportunities. This deep-dive analysis, aligned with key international standards and frameworks (e.g., TCFD, IPCC, IEA), enables the identification, assessment, and management of climate-related risks. Prysmian considers both physical risks and transition risks and opportunities.

 

The analysis of climate change-related risks and opportunities is fully integrated into the Group’s centralized Enterprise Risk Management system - addressing multi-disciplinary areas and covering the Group with a company-wide perspective - with the aim of considering all relevant categories of risks and opportunities, including those related to climate change, and ensuring continuous alignment between risk assessments and the Group’s short-, medium-, and long-term strategic objectives.

 

To explore and assess the resilience of its business to climate change, Prysmian periodically conducts an analysis on physical and transition risks involving various climate-related scenarios, including a 2°C or less temperature increase, in order to model how the impact and likelihood of the material risks and opportunities identified might change from time to time. In particular, the Group considers two types of models: IPCC RCP scenarios for the physical risk assessment (IPCC RCP 8.5; IPCC RCP 2.6) and IEA Scenario for transition risks and opportunities (IEA STEPS; IEA NZE).

 

The climate-related risk and opportunity analysis is performed over three different time horizons:

  •  Short-term (1 year);
  • Medium term (2-5 years);
  • Long term (more than 5 years through to 2050).

 

Climate risk and opportunity analysis is carried out across the Group’s own operations as well as throughout the value chain, both upstream and downstream. The analysis is performed considering all types of climate related risks and opportunities as per TCFD Classification including physical risks (acute and chronic risks) and transition risks and opportunities (e.g., policy & legal / regulations, technology, market, reputation).

 

By analysing various climate scenarios, Prysmian assesses the adequacy of its strategy in terms of resilience against physical risks, deriving from climate change as a cause of acute events or from chronic changes in climate patterns, and against transition risks, relating to a transition to a low-carbon economy.

 

Below are Prysmian's material climate-related risks and opportunities.

 

Risk / Opportunity description

TCFD classification

Risk / Opportunity impact

Increased severity of extreme natural events (e.g., river flooding, hurricanes, cyclones, etc.), made worse by climate change in progress, causing damage to the Group's production sites/critical assets and halting production and/or distribution 

 

PHYSICAL RISK

Acute

Potential impact on the Group's business continuity in terms of property damage (e.g., damage to plants) and business interruption (e.g., halts to production). At the same time, these extreme events could lead to disruption of Prysmian's upstream value chain, causing difficulties for the supply of key materials

 

Risk linked to availability of the water needed for the Group's production activities, e.g., due to changes in rainfall models

PHYSICAL RISK

Chronic

Increased in operating costs to fund improvements to the resilience of plants and the need to adopt/implement new practices and processes

Risk linked to rising sea levels that could have an impact on the Group's activities

PHYSICAL RISK

Chronic

Potential damage to infrastructure over the life cycle of assets, leading to an increase in operating costs to fund improvements to the resilience of plants, and to costs linked to retained losses

Carbon taxes

TRANSITION RISK

Policy & Legal

Increased carbon offset pricing

impacting Prysmian’s operating cost

Risk of failure to adopt a climate strategy

TRANSITION RISK

Competition

Potential reductions in EBITDA due to both the failure to achieve emission reduction targets by 2035, and the impossibility of new contract awards due to progressively stricter ESG requirements

Shortages of critical minerals in the supply chain

TRANSITION RISK

Market

Increased costs, delays or disruption to production linked to the limited availability of copper, aluminum and other materials key for Prysmian’s business

Entry of new players into the HV market

TRANSITION RISK

Market

Potential entry of new players into the market and the resulting increase in market competition

Emerging technologies (hydrogen, batteries, nuclear) 

TRANSITION RISK

Technology

Potential impact of emerging technological innovations in the energy market, leading to a potential reduction in Prysmian's business. It covers the risks linked to hydrogen, batteries, nuclear and 5G (wireless technologies)

Take advantage of expected growth in the global cables market, driven by the energy transition, electrification and digitalization

TRANSITION OPPORTUNITY
Market

Benefitting from demand growth linked to the energy transition, electrification and digitalization

Successful participation in green tenders, backed not only by solid know-how and financial strength, but also by acknowledged strong sustainability performance

TRANSITION OPPORTUNITY
Market

To Strengthen the Group's reputation and access new projects of global significance

 

 

Emerging risks

To ensure that the ERM process is capable of identifying and managing all risks to which Prysmian may potentially be exposed during its business activities, a dedicated focus on emerging risks is conducted as part of the risk management activities.

The identification of emerging risks is carried out through periodical interviews with Top Management and Business functions, as well as through the analysis of key reference sources such as reports and market studies which provide insights into major forward-looking trends relevant to Prysmian's business context.

 

Below are some examples of emerging potential risks examined in the medium-long term:

  •  Geopolitical risk in Middle East – Given its global footprint and presence in Middle East, Prysmian is potentially exposed to rising geopolitical tensions in the Middle East area, driving a highly volatile and uncertain environment, with a risk of escalation and potential disruption to regional stability and global trade routes. In particular, deteriorating geopolitical conditions may potentially lead to slowdown in business activities and disruptions across key sea and land corridors, as well as cause constraints and price volatility in the supply of critical raw materials. To address this risk, Prysmian has defined mitigation actions among which: (i) establishment of dedicated managerial committees, with regular cross-functional reviews and periodic updates; (ii) continuous monitoring of market dynamics by Management (e.g.; Sales, Operations, Procurement); (iii) monitoring of inbound/outbound flows and safety stock levels.

 

  •  AI-Enabled Cyber Attacks on Industrial OT - Increase in the sophistication and effectiveness of cyber-physical attacks on industrial Operational Technology (OT) systems, driven by the convergence of AI capabilities and geopolitically directed operations potentially targeting critical manufacturing infrastructure. The use of AI significantly enhances attack precision, speed and adaptability. This risk can potentially generate operational impacts (e.g., disruptions on manufacturing), economical impact (e.g., physical damage to industrial assets) and/or breach of confidential information. Prysmian has defined a variety of mitigation actions among which: (i) implementation of a structured cybersecurity governance framework and countermeasures (e.g. on plants and infrastructures); (ii) periodic assessments and monitoring activities (e.g. vulnerability, penetration); (iii) cyber security & AI training initiatives.

Prysmian is committed to the continuous improvement of its Risk Management system. As part of this commitment, the Group's Enterprise Risk Management (ERM) process has been subject to third-party assessments and audits for multiple purposes.

 

Between 2023 and 2025, Prysmian underwent an Enterprise Risk Maturity Assessment conducted by an independent third party to evaluate the maturity level of the Group’s risk management system against leading international frameworks, identify key areas for improvement based on the desired target state, incorporate industry best practices, and benchmark the system against peer organizations. Following the assessment, Prysmian implemented of improvement actions, in alignment with its continuous improvement approach.

 

In 2024, 2025, 2026 the Risk Management Process was also included in audit activities carried-out by the Group Quality Department (latest audit in March 2026), external certification bodies (e.g., as part of the ISO 9001 certification renewal process – latest in April 2026) and other external parties (e.g., external audit with focus on Project Risk management for Transmission Business Unit).