Arrow's Form 10-K Item 1C cybersecurity disclosure describes its layered cybersecurity risk management program, governance structure (Board, CIO, Director of IT, enterprise risk management group), and controls. The filing states that Arrow has not experienced, and does not believe it is reasonably likely to experience, a material cybersecurity incident. No specific breach or incident is disclosed.