Torrid's Item 1C cybersecurity disclosure in its Annual Report describes its cybersecurity risk management program, governance (CTO-led, Audit Committee oversight), use of the CIS Critical Security Controls framework, penetration testing, employee training, third-party risk management, and incident response plan. The filing states that, as of the report date, no material risks from known cybersecurity incidents have materially affected the company. No specific breach incident is disclosed.