Norfolk Southern Railway Company (NSC) filed its 10-K Item 1C disclosing its cybersecurity risk management and governance. NSC employs a multi-layered defense strategy based on the NIST Cybersecurity Framework (NIST CSF). The Board has direct oversight of cybersecurity risks, receiving periodic reports from the CISO and CIDO. NSC has experienced prior technology outages and cybersecurity events but states future events could have a materially adverse effect. The company conducts internal and third-party assessments of IT vulnerabilities and resiliency. NSC engages third-party service providers for periodic reviews and requires vendors to maintain security protections. Management reports material incidents to the Board prior to filing 8-Ks. NSC provides cybersecurity awareness training to employees and uses technology-based tools to mitigate risks.