Tompkins Financial Corporation (Form 10-K, Item 1C) discloses its cybersecurity risk management and governance framework. The company states it is not aware of any cybersecurity incidents that have materially affected its business, results of operations, or financial condition. The disclosure details the enterprise-wide Information and Cyber Security Program, including the use of FAIR and MITRE ATT&CK frameworks, third-party penetration testing, and governance by the Board's Directors Risk Committee.