Commvault's Form 10-K Item 1C cybersecurity disclosure describes its NIST-aligned cybersecurity program, Security Incident Response Plan, third-party assessments (SOC 2 Type 2, ISO 27001, HIPAA, PCI DSS), and board/Audit Committee governance structure led by the CSO. The filing explicitly states no cybersecurity incidents have materially affected the company to date. No specific breach or incident is disclosed.