NBT (Form 10-K Item 1C) discloses no known material cybersecurity incidents in the prior three fiscal years. The filing details a robust cybersecurity governance framework, including Board oversight via a Risk Management Committee, a designated Senior Director of Information Security (DISO), and an Incident Response Team (IRT). NBT employs a risk-based approach, NIST framework alignment, third-party audits, and cybersecurity insurance. No specific breach event, data exfiltration, or material impact is reported.