BlackRock's 10-K Item 1C cybersecurity disclosure describes its Enterprise Risk Management framework, governance structure (Board, Risk Committee, TRCC), CISO leadership, and multilayered control program. As of December 31, 2025, BlackRock states it is not aware of any cybersecurity risks that have materially affected or are reasonably likely to materially affect its business strategy, results of operations or financial condition. No specific cybersecurity incident is disclosed.