MBIA's Form 10-K Item 1C Cybersecurity disclosure describes the company's cybersecurity risk-management program, governance structure (Audit Committee oversight, Enterprise Security Council, CISO/CIO roles, CIRT), and controls including MFA, vulnerability management, penetration testing, third-party monitoring, and employee training. The filing explicitly states the company has not experienced any cybersecurity incidents that have materially affected, or are reasonably likely to materially affect, its business strategy, operations, or financial condition. No specific incident is disclosed.