Norfolk Southern Railway Company
bd_4c1b12804834b693 · schema v1 · pii pii-v1
Full breach record for Norfolk Southern Railway Company →Norfolk Southern Railway Company (NSC) filed its 10-K Item 1C disclosing its cybersecurity risk management and governance. NSC employs a multi-layered defense strategy based on the NIST Cybersecurity Framework (NIST CSF). The Board has direct oversight of cybersecurity risks, receiving periodic reports from the CISO and CIDO. NSC has experienced prior technology outages and cybersecurity events but states future events could have a materially adverse effect. The company conducts internal and third-party assessments of IT vulnerabilities and resiliency. NSC engages third-party service providers for periodic reviews and requires vendors to maintain security protections. Management reports material incidents to the Board prior to filing 8-Ks. NSC provides cybersecurity awareness training to employees and uses technology-based tools to mitigate risks.
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/702165/000162828026006268/nsc-20251231.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 9, 2026
- Raw hash
- 770d26b67ba8d7eec7546cf60f7c86e5a21db151390854ea8ae4a76b0b246eb7
Source filing
Reporting entity
- Name
- Norfolk Southern Railway Companynorm: norfolk southern railway
- SEC CIK
- 0000086079
- Domain
- ns.com
- Industry
- Transportation
Victim entity
- Name
- Norfolk Southern Railway Companynorm: norfolk southern railway
- SEC CIK
- 0000086079
- Domain
- ns.com
- Industry
- Transportation
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- —
- Attack vector
- Unknown
- Regulator citations
- Work with government agencies such as the Federal Bureau of InvestigationWork with government agencies such as the Transportation Security AgencyWork with government agencies such as the Department of Homeland Security
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.