HSBC USA Inc.'s 10-K Item 1C cybersecurity disclosure describes its risk-management program, three-lines-of-defense structure, board/Risk Committee oversight, and reliance on HSBC Group and Americas Regional CISO leadership. The filing states risks from cybersecurity threats, including prior incidents, have not materially affected the company to date, and notes an observed increase in ransomware attacks against its suppliers without material impact. No specific incident is disclosed.