The Kroger Co. filed its 10-K Item 1C disclosing its cybersecurity risk management and governance framework. The company states it is not aware of any material cybersecurity threats that have materially affected its business, financial condition, or results of operations in the last three years. The filing details the Kroger Cybersecurity Risk Management (CRM) program, Third-Party Cybersecurity Risk Management (TPCRM) program, and Cyber Incident Response Plan (IR Plan). Governance is overseen by the Audit Committee with quarterly reporting from the CDO and CISO.