GPM discloses its cybersecurity risk management program in its 10-K Item 1C. The company states it has not encountered cybersecurity incidents that have materially affected its business, strategy, or financial position as of the filing date. The disclosure outlines governance structures, including a Cybersecurity Special Committee and a CIO, and describes proactive measures such as third-party assessments, penetration testing, and employee training. No specific breach or incident is reported.