The Hartford (HIG) discloses in its 10-K Item 1C that no cybersecurity threats have materially affected or are reasonably likely to materially affect its business, results of operations, or financial condition. The filing details a 'defense-in-depth' program aligned with NIST CSF, including multi-factor authentication, intrusion prevention, and ransomware detection. Governance involves the Audit Committee, FIRMCo, and an Executive Privacy & Security Council (EPSC). The company assesses third-party vendor security and complies with regulations like NYDFS and the NAIC Insurance Data Security Model Law.