Shake Shack Inc.'s 10-K Item 1C describes its NIST CSF-based cybersecurity risk management program, governance via the Audit Committee, and CISO oversight. The company states it has identified ongoing threats such as credential phishing, bot attacks, and social engineering, but has not identified any prior cybersecurity incidents that have materially affected or are reasonably likely to materially affect the company. No specific breach is disclosed in this filing.