Read how a company says it manages and oversees cyber risk
Since SEC rules adopted in 2023, a 10-K carries a dedicated cybersecurity item, Item 1C, describing how the company identifies and manages cyber risk and how its board and management oversee it. The wording ranges from specific to boilerplate. Ask Search+ "Who is responsible for cybersecurity here, and how does the board stay informed?" and the answer cites the passages, so you can judge the substance for yourself.
Creating an account needs no payment.
Last updated October 2026
How to read a cybersecurity disclosure with Search+
- Upload the 10-K and any related current reports
Add the annual report PDF, and if the company has disclosed an incident, the 8-K that reported it. Item 1C describes processes, while a reported incident usually appears in a separate filing, so having both in the workspace gives the full picture.
- Ask about process and governance separately
Ask one question about risk management, such as how threats are assessed and how vendors are overseen, and another about governance, such as which board committee is responsible. The two halves of Item 1C answer different concerns.
- Check the cyber risk factors too
Ask what the risk factors say about breaches, ransomware or reliance on third-party systems. Reading the cited risk factor next to Item 1C shows whether the risks described match the controls described.
Questions people ask about a 10-K cybersecurity section
Which executive leads cybersecurity, what experience does the filing say that person has, and who do they report to?
Which board committee oversees cyber risk, and how often does the filing say it receives updates?
What does the company say about identifying cyber risks that come from third-party service providers?
Does the filing say any cybersecurity incident has materially affected the company or is reasonably likely to?
Does the company say it uses outside assessors, consultants or auditors as part of its cybersecurity program?
Across the 10-K filings in this workspace, which companies place cyber oversight with the audit committee and which with a separate committee?
What to look for in Item 1C
Item 1C sits in Part I of the 10-K, after Item 1A Risk Factors and Item 1B Unresolved Staff Comments. Filings for fiscal years before the rule took effect do not have it, so older reports discuss cyber risk mainly in the risk factors.
This half describes how the company assesses, identifies and manages material cyber risks, whether that work is part of its wider risk management, and how it handles risk from service providers.
This half covers the board's oversight, often through a named committee, and management's role: which positions are responsible, what expertise they have and how they report up.
Item 1C is about how risk is handled. A material incident is normally reported separately in a current report on Form 8-K, so the annual report may only refer back to it.
Some disclosures name frameworks, testing practices and reporting lines; others stay general. Asking for concrete details, such as how often the board is briefed, shows quickly which kind you are reading.
Search+ finds relevant passages by meaning, so a question about board oversight can surface the right paragraph even if the filing uses different words. Each answer cites the excerpt it relied on.
Cybersecurity wording and what to ask next
| Wording you may see | What it usually signals | A follow-up question |
|---|---|---|
| "Chief Information Security Officer" | A named role leads the program | What experience and reporting line does the filing give for this role? |
| "Audit Committee" or "Risk Committee" | Where board oversight sits | How and how often is that committee briefed on cyber risk? |
| "third-party service providers" | Vendor risk is part of the program | How does the company assess and monitor those providers? |
| "integrated into our overall risk management" | Cyber is handled within enterprise risk processes | Which risk management process does the filing tie it to? |
| "have not materially affected" | No incident the company considers material so far | Does the filing describe any incidents it considers immaterial? |
| "consultants, auditors or other third parties" | Outside parties test or assess the program | What role does the filing give those outside parties? |
What is a 10-K cybersecurity disclosure?
A 10-K cybersecurity disclosure is the part of the annual report, Item 1C, where a company describes its processes for assessing and managing material cybersecurity risks and how its board and management oversee those risks.
Questions about cybersecurity in a 10-K
Where is the cybersecurity section of a 10-K?
My filing is older and has no Item 1C. Can I still ask about cyber risk?
Can I compare how several companies describe board oversight of cyber risk?
Will Search+ tell me whether a company had a breach?
Does Search+ rate how strong a company's cybersecurity is?
What if the answer misreads who reports to whom?
Read past the boilerplate on cyber risk
Start a workspace, upload the 10-K, and ask who oversees cybersecurity and how.
Start a workspace