Xylem's Item 1C disclosure in its annual report describes its cybersecurity program, governance structure (CIO/CISO/Board/Audit Committee/Cyber Risk Committee), NIST CSF and ISA/IEC 62443-aligned risk management, employee training, third-party risk processes, and incident response plan. The filing explicitly states the Company has not experienced any material cybersecurity threats or incidents as of the date of the Report. No breach incident is disclosed.