10-K SECTIONS

Read how a company says it manages and oversees cyber risk

Since SEC rules adopted in 2023, a 10-K carries a dedicated cybersecurity item, Item 1C, describing how the company identifies and manages cyber risk and how its board and management oversee it. The wording ranges from specific to boilerplate. Ask Search+ "Who is responsible for cybersecurity here, and how does the board stay informed?" and the answer cites the passages, so you can judge the substance for yourself.

Creating an account needs no payment.

Last updated October 2026

How to read a cybersecurity disclosure with Search+

  1. Upload the 10-K and any related current reports

    Add the annual report PDF, and if the company has disclosed an incident, the 8-K that reported it. Item 1C describes processes, while a reported incident usually appears in a separate filing, so having both in the workspace gives the full picture.

  2. Ask about process and governance separately

    Ask one question about risk management, such as how threats are assessed and how vendors are overseen, and another about governance, such as which board committee is responsible. The two halves of Item 1C answer different concerns.

  3. Check the cyber risk factors too

    Ask what the risk factors say about breaches, ransomware or reliance on third-party systems. Reading the cited risk factor next to Item 1C shows whether the risks described match the controls described.

Questions people ask about a 10-K cybersecurity section

Who is in charge

Which executive leads cybersecurity, what experience does the filing say that person has, and who do they report to?

Board oversight

Which board committee oversees cyber risk, and how often does the filing say it receives updates?

Vendors and suppliers

What does the company say about identifying cyber risks that come from third-party service providers?

Past incidents

Does the filing say any cybersecurity incident has materially affected the company or is reasonably likely to?

Outside help

Does the company say it uses outside assessors, consultants or auditors as part of its cybersecurity program?

Across a sector

Across the 10-K filings in this workspace, which companies place cyber oversight with the audit committee and which with a separate committee?

What to look for in Item 1C

Its place in the filing

Item 1C sits in Part I of the 10-K, after Item 1A Risk Factors and Item 1B Unresolved Staff Comments. Filings for fiscal years before the rule took effect do not have it, so older reports discuss cyber risk mainly in the risk factors.

Risk management and strategy

This half describes how the company assesses, identifies and manages material cyber risks, whether that work is part of its wider risk management, and how it handles risk from service providers.

Governance

This half covers the board's oversight, often through a named committee, and management's role: which positions are responsible, what expertise they have and how they report up.

Process, not incident detail

Item 1C is about how risk is handled. A material incident is normally reported separately in a current report on Form 8-K, so the annual report may only refer back to it.

Specific or generic

Some disclosures name frameworks, testing practices and reporting lines; others stay general. Asking for concrete details, such as how often the board is briefed, shows quickly which kind you are reading.

Search by meaning, cite the source

Search+ finds relevant passages by meaning, so a question about board oversight can surface the right paragraph even if the filing uses different words. Each answer cites the excerpt it relied on.

Cybersecurity wording and what to ask next

Wording you may seeWhat it usually signalsA follow-up question
"Chief Information Security Officer"A named role leads the programWhat experience and reporting line does the filing give for this role?
"Audit Committee" or "Risk Committee"Where board oversight sitsHow and how often is that committee briefed on cyber risk?
"third-party service providers"Vendor risk is part of the programHow does the company assess and monitor those providers?
"integrated into our overall risk management"Cyber is handled within enterprise risk processesWhich risk management process does the filing tie it to?
"have not materially affected"No incident the company considers material so farDoes the filing describe any incidents it considers immaterial?
"consultants, auditors or other third parties"Outside parties test or assess the programWhat role does the filing give those outside parties?

What is a 10-K cybersecurity disclosure?

A 10-K cybersecurity disclosure is the part of the annual report, Item 1C, where a company describes its processes for assessing and managing material cybersecurity risks and how its board and management oversee those risks.

It is different from an incident report: a material cybersecurity incident is disclosed in a Form 8-K current report, while Item 1C explains the program. It is also separate from the cyber risk factors in Item 1A, which describe what could go wrong.

Questions about cybersecurity in a 10-K

Where is the cybersecurity section of a 10-K?
In recent annual reports it is Item 1C in Part I, right after the risk factors and unresolved staff comments. Ask Search+ for the company's cybersecurity governance and the answer cites that item directly.
My filing is older and has no Item 1C. Can I still ask about cyber risk?
Yes. Ask what the filing says about cybersecurity, data breaches or system failures, and the answer will draw on wherever the topic appears, often the risk factors, with a citation to each passage.
Can I compare how several companies describe board oversight of cyber risk?
Put their annual reports in one workspace and ask which committee oversees cybersecurity at each company. The answer cites each filing, so you can read the governance wording side by side.
Will Search+ tell me whether a company had a breach?
It tells you what the documents in your workspace say. If the 10-K or an uploaded 8-K describes an incident, the answer cites it; if neither mentions one, Search+ cannot know about it from your files.
Does Search+ rate how strong a company's cybersecurity is?
No. It helps you find and read what the company discloses. It does not give investment advice or audit a security program, so treat the cited text as the company's own description, not an assessment.
What if the answer misreads who reports to whom?
That can happen, which is why each answer links to its source. Open the cited passage and check the reporting line in the company's own words before you repeat it.

Read past the boilerplate on cyber risk

Start a workspace, upload the 10-K, and ask who oversees cybersecurity and how.

Start a workspace