KBR's Form 10-K Item 1C cybersecurity disclosure describes its risk management program, NIST/ISO 27001-based framework, CISO/CIO governance structure, and board oversight via Cybersecurity and Audit Committees. The filing explicitly states that in the last three fiscal years the Company has not experienced any material information security breach incidents and has not incurred material penalties or settlements related to any cybersecurity breach. No specific incident is disclosed.