CFC (a financial services entity) discloses in its 10-K Item 1C that it has not experienced any material cybersecurity incidents to date. The filing details a robust cybersecurity governance framework, including Board oversight, a three-lines-of-defense model, quarterly employee training, and regular third-party penetration testing and risk assessments. No specific breach, data exfiltration, or financial impact is reported.