BlackRock's annual 10-K Item 1C cybersecurity disclosure describes its enterprise risk management framework, governance structure (Risk Committee, TRCC, CISO), multi-layered controls, third-party risk management, and incident response planning. As of December 31, 2025, BlackRock states it is not aware of any cybersecurity risks that have materially affected or are reasonably likely to materially affect its business strategy, results of operations, or financial condition. No specific cybersecurity incident is disclosed.