Cincinnati Financial 10-K 2025-12-31

Filed 2026-02-23. 2 sections, 879K characters. Original on sec.gov · Markdown · JSON

What changed since the 2024-12-31 10-KNew, removed and reworded risk factor headings, then every item sentence by sentence.

Cover and table of contents

United States Securities and Exchange Commission

Washington, D.C. 20549

Form 10-K

☑ANNUAL REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934.

For the fiscal year ended December 31, 2025.

☐TRANSITION REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934.

For the transition period from _____________________ to _____________________.

Commission file number 000-04604

Cincinnati Financial Corporation

(Exact name of registrant as specified in its charter)

Ohio31-0746871
(State of incorporation)(I.R.S. Employer Identification No.)

6200 S. Gilmore Road

Fairfield, Ohio 45014-5141

(Address of principal executive offices) (Zip Code)

(513) 870-2000

(Registrant’s telephone number, including area code)

Securities registered pursuant to Section 12(b) of the Act:

Title of each classTrading Symbol(s)Name of each exchange on which registered
Common stock, $2.00 parCINFNasdaq Global Select Market

Securities registered pursuant to Section 12(g) of the Act:

None

Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes ☑ No ☐

Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐ No ☑

Indicate by check mark whether the registrant: (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports) and (2) has been subject to such filing requirements for the past 90 days.

Yes ☑ No ☐

Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes ☑ No ☐

Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or emerging growth company. See definition of “large accelerated filer,” “accelerated filer,” “smaller reporting company" and "emerging growth company" in Rule 12b-2 of the Exchange Act.

Cincinnati Financial Corporation - 2025 10-K - Page 1

Large accelerated filer ☑ Accelerated filer ☐ Non-accelerated filer ☐ Smaller reporting company ☐

Emerging growth company ☐

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐

Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☑

If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. ☐

Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☐

Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Act). Yes ☐ No ☑

The aggregate market value of voting stock held by nonaffiliates of the Registrant based on the closing price of $148.92 per share as reported on Nasdaq Global Select Market on June 30, 2025, was $22,846,561,651.

As of February 17, 2026, there were 155,617,576 shares of common stock outstanding.

Document Incorporated by Reference

Portions of the definitive Proxy Statement for Cincinnati Financial Corporation’s Annual Meeting of Shareholders to be held on May 2, 2026, are incorporated by reference into Part III of this Form 10-K.

Cincinnati Financial Corporation - 2025 10-K - Page 2

2025 ANNUAL REPORT ON FORM 10-K

T****ABLE OF C****ONTENTS

Part I5
Item 1.Business5
Cincinnati Financial Corporation – Introduction5
Our Business and Our Strategy6
Our Segments14
Other25
Regulation26
Item 1A.Risk Factors30
Item 1B.Unresolved Staff Comments41
Item 1C.Cybersecurity41
Item 2.Properties42
Item 3.Legal Proceedings42
Item 4.Mine Safety Disclosures42
Part II43
Item 5.Market for the Registrant’s Common Equity, Related Stockholder Matters and Issuer Purchases of Equity Securities43
Item 6.[Reserved]44

Showing the first 8K of 173K characters. Open the full section

Item 1C. Cybersecurity

Risk Management and Strategy

As discussed further in Item 1, Regulation, Enterprise Risk Management, we manage cybersecurity as part of our overall enterprise risk programs.

As part of this program to keep our systems and data secure and to assist in understanding, assessing, identifying and managing material risks from cybersecurity threats, we take various measures through internal risk management efforts and testing by third-party experts. Those measures assess our cybersecurity program structure and capabilities and include blocking attempted cyber intrusions, defending against service disruptions, performing frequent vulnerability assessments and maintaining procedures to ensure timely notification of critical cybersecurity incidents and performance of related disclosure controls. We also have developed procedures and reporting processes when we identify an attempted cyber intrusion to the systems of one of our independent agents.

Additionally, the company uses third-party service providers, or vendors, in the course of conducting its operations. As such, the company has measures in place to help identify material risks from cybersecurity threats associated with the use of those vendors. When work with a vendor is evaluated, we consider, among other items, the availability of system and organization control reports, the use of artificial intelligence, interactions with our systems, the data involved and its level of sensitivity, the amount of data the vendor will process, where the data will be stored, how the data will be protected, what they will do with the data and destruction of data. Once a vendor is approved by the appropriate personnel, expectations regarding incident reporting are established and followed.

We are not aware of having experienced a material cybersecurity incident and we take commercially reasonable measures, described above and below, to monitor and respond to threats to keep our systems and data secure. However, we acknowledge that administrative, technical and internal accounting controls as well as other preventative actions may be insufficient to prevent security breaches to our systems or those of third parties with whom we do business due to, among other factors, changing technologies as well as criminal and state-sponsored cybercrime and cyber threats. Further, a material breach of our security or the security of a vendor that results in unauthorized access to our data could expose us to a disruption or challenges relating to our daily operations as well as to data loss, litigation, damages, fines and penalties, significant increases in compliance costs and reputational damage and could affect the company's strategy, results of operations or financial condition. See Item 1A, Risk Factors, for additional details.

Governance

Cybersecurity matters are an important part of reporting to our board of directors, executive management team, risk committee and disclosure committee. From a board perspective, the audit committee oversees the company's cybersecurity efforts along with additional oversight from the entire board. Two members of the audit committee have obtained certifications in cybersecurity oversight. Each quarter, the chief information officer and chief information security officer report to the audit committee on cybersecurity risks and controls. Also occurring each quarter, the entire board, and our senior executive team, as appropriate, receives a comprehensive report from the chief risk officer on the status and management of risk and other metrics relative to identified tolerances and limits, risk assessments and risk plans. Additionally, the chief risk officer has direct access to all members of the board of directors and presents in person at board meetings twice each year.

At the executive management and management levels, the chief information security officer leads the process of assessing and managing material risks from cybersecurity threats. Our chief information security officer has over 25 years of experience as a technology professional with in-depth knowledge of IT management processes and holds multiple degrees and professional designations, including as a certified information systems security professional (CISSP). The chief information security officer also works in collaboration with our chief information officer and chief risk officer and is supported by a cross-functional group of qualified and experienced professionals across various committees and functions. On a quarterly basis, the chief information officer provides a cybersecurity update to the disclosure committee and, on a monthly basis, the information security office team delivers a cybersecurity report to members of the senior executive team. Also refer to Item 10, Directors, Executive Officers and Corporate Governance, for additional qualification, experience and responsibility details.

Cincinnati Financial Corporation - 2025 10-K - Page 41

Associates involved in this area stay informed of industry trends and evolving threats using various resources including government authorities, peers, continuous education, industry publications, news outlets and other external parties that provide pertinent information. We take administrative, technical and internal accounting control measures to protect against cybersecurity incidents, including actions to monitor for, prevent, detect, mitigate and remediate any incidents that occur. These measures and actions include endpoint controls, multi-factor authentication and general cybersecurity education directed at our workforce and independent agents.

From a monitoring perspective, generally speaking, our information security office associates monitor the environment for threats, events and potential incidents. Depending on the potential severity of any identified incident, the company's incident response process, modeled after National Institute for Standards and Technology (NIST) frameworks, is initiated. As part of this process, each incident is evaluated and inventoried by our incident response team and reported to our legal compliance subcommittee for further action. Depending on severity, certain other internal and external parties may participate in the incident response process from a compliance and financial reporting perspective.

Incidents, regardless of severity, are evaluated and documented and are shared with the audit committee. In 2025, the audit committee received four updates on matters related to cybersecurity. The process of evaluating and documenting individual incidents, even when not deemed material, assists in determining how previous incidents have or may reasonably likely have a material effect on the company in the future.

I****TEM 2. Properties

Cincinnati Financial Corporation owns our headquarters building located on 107 acres of land in Fairfield, Ohio. This building has 1,508,200 square feet of total space. The property, including land is recorded in our financial statements at $127 million at December 31, 2025, and is classified as Land, building and equipment, net, for company use. John J. & Thomas R. Schiff & Co. Inc., a related party, occupies 9,056 square feet (less than 1%). This property is used for the operations described in the Consolidated Financial Statements and accompanying Notes.

Cincinnati Financial Corporation owns Gilmore Pointe, located on the northwest corner of our headquarters property. This four-story building contains approximately 103,000 square feet of usable space. The property is recorded in the financial statements at $3 million at December 31, 2025, and is classified as investment property in Other invested assets. At December 31, 2025, unaffiliated tenants occupied 90%, with no Cincinnati Financial affiliates occupying the property.

The Cincinnati Insurance Company owns the CFC Winton Center used for multiple operations with approximately 48,000 square feet of total space, located approximately six

Showing the first 8K of 706K characters. Open the full section