Item 1C. CYBERSECURITY
27K characters. Original on sec.gov · Markdown
Item 1C. CYBERSECURITY
As a highly regulated global financial services company, we understand the substantial operational risks for companies in our industry as well as the importance of protecting the information and data of our clients, third parties and employees and the resilience of our systems. As such, our Global Informational Security (GIS) Program is designed and operated to mitigate information security risks and threats to the company. Its intent is to safeguard the confidentiality, integrity and availability of our information and services. The GIS Program is designed to strengthen the integrity of the global markets we support, protect CME Group’s information assets, maintain client, third party and employee trust, support our pursuit of strategic objectives, contribute to shareholder value and preserve our reputation and brand. We implement technical, physical and administrative safeguards to protect the confidential and sensitive information of our clients, third parties, employees and other information under CME Group’s stewardship. We manage cybersecurity risk to the organization as part of our business strategy, risk management and financial functions in alignment with our overall Enterprise Risk Management Program and regularly engage with the risk committee of the board of directors and the board of directors as a whole regarding the effectiveness of the GIS Program and the management of our cybersecurity risks.
The GIS Program is led by CME Group’s Chief Information Security Officer (CISO), who has worked in various roles in information security for over 20 years and has led our GIS Program for more than five years since joining the company in 2016 in a senior role in GIS. The CISO reports to our Chief Information Officer (CIO), a member of our Management Team. Our GIS team is comprised of over 200 full-time employees, many of whom hold cybersecurity, risk, or management certifications, such as Certified Information Systems Security Professional, Certified Information Security Manager, Certified in Risk and Information Systems Control, Series 99, Certified Information Systems Auditor, Project Management Professional, various cloud provider certifications and various levels of ITIL certifications. As part of our GIS Program, CME Group operates a Cyber Defense Center that virtually links 24/7 to our international cybersecurity teams and serves as a global hub for cybersecurity risk management activities, including log collection, event monitoring, threat detection and incident response, resiliency, operations, vulnerability management and the proactive collection and processing of both open source and proprietary threat and intelligence feeds allowing the company to efficiently manage, investigate and respond to cybersecurity events. Our GIS team conducts analyses and aims to prevent, detect and respond to systemic events that might threaten our company, industry or the economy.
The GIS Program includes a Cyber Defense team, which manages the Incident Response Plan (IRP), and consists of subject matter experts from GIS and Information Governance, who work together to monitor and respond to cybersecurity incidents. The IRP outlines our cyber and incident response policies and governs our incident response lifecycle, which divides overall incident response into serial phases. The Crisis Management Team (CMT) is responsible for oversight during an incident, in conjunction with the Cyber Coordination Team (CCT). The CCT manages responses to cybersecurity and compliance incidents, collaborating with subject matter experts from various departments in response to specific incidents. When an incident reaches a certain threshold of severity, our CISO and CIO escalate the matter to our Chief Operating Officer, who is another member of our Management Team, to determine next steps, as well as possible customer and external communication. Throughout the incident response process, the Legal team is engaged, as appropriate, and helps consider whether disclosure is required once a determination is made in connection with the company’s leadership and the CMT.
We identify, assess and manage material risks from cybersecurity threats through our GIS Program as follows:
-
We deploy a defense-in-depth strategy, acknowledging the importance of people, processes and technology in upholding information security. The strategy incorporates multiple layers of controls, including, monitoring, vulnerability management, identity and access management and security assessments.
-
Our program is aligned with the National Institute of Standards and Technology Cybersecurity Framework (NIST) and other technical standards and frameworks.
-
We have a robust cybersecurity defense response plan that provides a documented framework for handling security incidents and facilitates coordination across multiple parts of the company.
-
We invest in threat intelligence and operate a Cyber Defense Center, which acts as our hub of information sharing and threat intelligence analysis.
-
We incorporate external expertise and reviews into our cybersecurity risk management program and continue to engage leading professional consulting firms to assist our company in incorporating cybersecurity best practices.
-
We provide annual cybersecurity awareness and ongoing phishing training, and we routinely conduct cybersecurity attack simulation exercises, which includes participation from various levels of management.
-
Following a risk-based approach, we conduct due diligence reviews of our third party providers for potential cybersecurity risks to the company. We also maintain a cross-functional Third Party Risk Management program, which partners with our GIS, Information Governance, and Operational Resilience teams, among others, to manage and monitor third party risk presented by CME Group vendors and certain third parties of third parties (fourth parties). The teams conduct initial due diligence on vendors and monitor cyber-related incidents and known vulnerabilities with the goal of enhancing processes, improving risk management and partnering on exit planning and testing for certain vendors associated with essential functions.
-
We have insurance against certain cybersecurity and privacy risks and attacks.
-
We are an active participant in the financial services industry and government forums and information sharing programs, designed to improve both internal and sector cybersecurity defense. These valuable external partnerships are established and maintained in order to gain more timely, comprehensive and actionable threat information across geographies and industries and to facilitate the exchange of best practices and security techniques. They allow for a high degree of collaboration and cooperation with local, state, federal, and international law enforcement and intelligence agencies, industry groups, and other private sector chief information security officers.
-
We regularly test the design and effectiveness of our information security controls and processes through a program of testing performed by internal and independent third-party teams. Remediation of gaps and opportunities identified through testing are tracked through to closure. Testing activities support a variety of regulatory requirements and external industry certifications held by CME Group.
The board provides oversight of cybersecurity risks and has designated primary responsibility to the risk committee which oversees our information security programs, including cybersecurity, and is actively involved in monitoring the progress of key cybersecurity initiatives. Our board and risk committee receive regular updates on the activities and effectiveness of our GIS Program, including reports on incident response plan testing exercises and results of compliance testing and third-party evaluation results. Our CISO provides quarterly, or as needed, reports and updates to our board and risk committee on the company's cybersecurity risk management program and meets with the risk committee at least annually in a private session. The CISO has an indirect reporting line to the risk committee. We also engage with leading professional consulting firms to provide periodic updates to the board on cybersecurity-related risks in the evolving threat landscape and to provide education on best practices for board oversight of our GIS Program.
To date, the company is not aware of risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect the company, including our business strategy, results of operations or financial condition.
See "Item 1A - Risk Factors" beginning on page 16 for additional information on cyber attacks and other cybersecurity risks the company faces.
2025 Proxy Statement
We have adopted an insider trading policy governing the purchase, sale and other dispositions of our securities by our directors, officers, and employees, as well as by the company itself. We believe our insider trading policy is reasonably designed to promote compliance with insider trading laws, rules and regulations, and listing standards applicable to the company. A copy of our insider trading policy is filed with our most recent Annual Report on Form 10-K as Exhibit 19.1.
PAY VERSUS PERFORMANCE
| Year | Summary Compensation Table Total for Terrence A. Duffy****1 ($) | Compensation Actually Paid to Terrence A. Duffy****1,2,3 ($) | Average Summary Compensation Table Total for Non-PEO NEOs****1 ($) | Average Compensation Actually Paid to Non-PEO NEOs****1,2,3 ($) | **Value of Initial Fixed $100 Investment based on:**4 | Net Income ($ Millions) | Cash Earnings****5 ($ Millions) | ||||||||||||||||||||||
| TSR ($) | Peer Group TSR ($) | ||||||||||||||||||||||||||||
| 2024 | $ | 23,945,589 | $ | 26,813,826 | $ | 3,425,778 | $ | 3,983,777 | $ | 141.71 | $ | 172.05 | $ | 3,526 | $ | 3,865 | |||||||||||||
| 2023 | 23,468,000 | 34,175,281 | 3,803,969 | 4,637,219 | 122.76 | 148.62 | 3,226 | 3,573 | |||||||||||||||||||||
| 2022 | 22,943,077 | 12,471,976 | 3,408,739 | 1,212,892 | 93.50 | 122.06 | 2,691 | 3,088 | |||||||||||||||||||||
| 2021 | 22,924,737 | 26,891,265 | 3,321,407 | 4,505,841 | 121.26 | 140.56 | 2,637 | 2,583 | |||||||||||||||||||||
| 2020 | 16,118,467 | 12,115,067 | 3,046,801 | 1,882,475 | 93.66 | 117.40 | 2,106 | 2,572 |
1Terrence A. Duffy was our PEO for each year presented. The individuals comprising the Non-PEO named executive officers for each year presented are listed below.
| 2020 | 2021 | 2022 | 2023 | 2024 | ||||||||||
| John W. Pietrowicz | John W. Pietrowicz | John W. Pietrowicz | Lynne C. Fitzpatrick | Lynne C. Fitzpatrick | ||||||||||
| Kevin D. Kometer | Kevin D. Kometer | Julie Holzrichter | Julie Holzrichter | Derek L. Sammann | ||||||||||
| Julie Holzrichter | Julie Holzrichter | Sean P. Tully | Derek L. Sammann | Julie M. Winkler | ||||||||||
| Sunil K. Cutinho | Sunil K. Cutinho | Sunil K. Cutinho | Sunil K. Cutinho | Sunil K. Cutinho | ||||||||||
| John W. Pietrowicz |
2The amounts shown for "Compensation Actually Paid" have been calculated in accordance with Item 402(v) of Regulation S-K and do not reflect compensation actually earned, realized, or received by the company's NEOs. These amounts reflect the "Total" from the Summary Compensation Table with certain adjustments as described in footnote 3 below.
3"Compensation Actually Paid" reflects the exclusions and inclusions of certain amounts for the PEO and the Non-PEO NEOs as set forth below. Equity values are calculated in accordance with Financial Accounting Standards Board ASC Topic 718. Amounts in the "Exclusion of Stock Awards" column are the amounts from the "Stock Awards" column set forth in the Summary Compensation Table. Amounts in the "Exclusion of Change in Pension Value" column reflect the amounts attributable to the "Change in Pension Value" reported in the Summary Compensation Table. Amounts in the "Inclusion of Pension Service Cost" are based on the service cost for services rendered during the listed year.
| Year | Summary Compensation Table Total for Terrence A. Duffy ($) | Exclusion of Change in Pension Value for Terrence A. Duffy ($) | Exclusion of Stock Awards for Terrence A. Duffy ($) | Inclusion of Pension Service Cost for Terrence A. Duffy ($) | Inclusion of Equity Values for Terrence A. Duffy ($) | Compensation Actually Paid to Terrence A. Duffy ($) | |||||||||||||||||
| 2024 | 23,945,589 | (58,832) | (13,512,333) | 26,185 | 16,413,217 | 26,813,826 | |||||||||||||||||
| 2023 | 23,468,000 | (55,146) | (12,594,380) | 24,427 | 23,332,380 | 34,175,281 | |||||||||||||||||
| 2022 | 22,943,077 | (36,092) | (12,530,269) | 25,060 | 2,070,200 | 12,471,976 | |||||||||||||||||
| 2021 | 22,924,737 | (35,942) | (11,563,324) | 24,198 | 15,541,596 | 26,891,265 | |||||||||||||||||
| 2020 | 16,118,467 | (45,422) | (10,933,603) | 23,466 | 6,952,159 | 12,115,067 |
| Year | Average Summary Compensation Table Total for Non-PEO NEOs ($) | Average Exclusion of Change in Pension Value for Non-PEO NEOs ($) | Average Exclusion of Stock Awards for Non-PEO NEOs ($) | Average Inclusion of Pension Service Cost for Non-PEO NEOs ($) | Average Inclusion of Equity Values for Non-PEO NEOs ($) | Average Compensation Actually Paid to Non-PEO NEOs ($) | |||||||||||||||||
| 2024 | 3,425,778 | (20,778) | (1,773,691) | 21,469 | 2,330,999 | 3,983,777 | |||||||||||||||||
| 2023 | 3,803,969 | (65,419) | (2,082,032) | 21,610 | 2,959,091 | 4,637,219 | |||||||||||||||||
| 2022 | 3,408,739 | 0 | (1,703,264) | 26,028 | (518,610) | 1,212,892 | |||||||||||||||||
| 2021 | 3,321,407 | (28,338) | (1,951,311) | 24,227 | 3,139,856 | 4,505,841 | |||||||||||||||||
| 2020 | 3,046,801 | (72,079) | (1,845,104) | 22,351 | 730,507 | 1,882,475 |
The amounts in the "Inclusion of Equity Values" in the tables above are derived from the amounts set forth in the following tables:
| Year | Year-End Fair Value of Equity Awards Granted During Year That Remained Unvested as of Last Day of Year for Terrence A. Duffy ($) | Change in Fair Value from Last Day of Prior Year to Last Day of Year of Unvested Equity Awards for Terrence A. Duffy ($) | Vesting-Date Fair Value of Equity Awards Granted During Year that Vested During Year for Terrence A. Duffy ($) | Change in Fair Value from Last Day of Prior Year to Vesting Date of Unvested Equity Awards that Vested During Year for Terrence A. Duffy ($) | Fair Value at Last Day of Prior Year of Equity Awards Forfeited During Year for Terrence A. Duffy ($) | Value of Dividends or Other Earnings Paid on Stock or Option Awards Not Otherwise Included for Terrence A. Duffy ($) | Total - Inclusion of Equity Values for Terrence A. Duffy ($) | |||||||||||||||||||
| 2024 | 7,395,740 | 2,137,573 | 6,566,926 | 312,978 | 0 | 0 | 16,413,217 | |||||||||||||||||||
| 2023 | 6,481,849 | 10,556,378 | 6,294,153 | 0 | 0 | 0 | 23,332,380 | |||||||||||||||||||
| 2022 | 6,530,171 | (9,033,730) | 5,461,954 | (888,195) | 0 | 0 | 2,070,200 | |||||||||||||||||||
| 2021 | 12,602,892 | 2,049,192 | 0 | 889,511 | 0 | 0 | 15,541,596 | |||||||||||||||||||
| 2020 | 6,433,902 | (2,767,707) | 4,962,787 | (1,676,822) | 0 | 0 | 6,952,159 |
| Year | Average Year-End Fair Value of Equity Awards Granted During Year That Remained Unvested as of Last Day of Year for Non-PEO NEOs ($) | Average Change in Fair Value from Last Day of Prior Year to Last Day of Year of Unvested Equity Awards for Non-PEO NEOs ($) | Average Vesting-Date Fair Value of Equity Awards Granted During Year that Vested During Year for Non-PEO NEOs ($) | Average Change in Fair Value from Last Day of Prior Year to Vesting Date of Unvested Equity Awards that Vested During Year for Non-PEO NEOs ($) | Average Fair Value at Last Day of Prior Year of Equity Awards Forfeited During Year for Non-PEO NEOs ($) | Average Value of Dividends or Other Earnings Paid on Stock or Option Awards Not Otherwise Included for Non-PEO NEOs ($) | Total - Average Inclusion of Equity Values for Non-PEO NEOs ($) | |||||||||||||||||||
| 2024 | 1,832,803 | 428,204 | 0 | 69,992 | (261,945) | 0 | 2,330,999 | |||||||||||||||||||
| 2023 | 1,547,777 | 1,525,158 | 0 | 148,101 | (261,945) | 0 | 2,959,091 | |||||||||||||||||||
| 2022 | 1,630,119 | (2,021,505) | 0 | (127,224) | 0 | 0 | (518,610) | |||||||||||||||||||
| 2021 | 2,126,740 | 744,382 | 0 | 268,733 | 0 | 0 | 3,139,856 | |||||||||||||||||||
| 2020 | 1,923,248 | (835,552) | 0 | (357,189) | 0 | 0 | 730,507 |
4The "Peer Group TSR" set forth in this table utilizes a custom group of peer companies, which we also utilize in the stock performance graph required by Item 201(e) of Regulation S-K included in our Annual Report for the year ended December 31, 2024. The comparison assumes $100 was invested for the period starting December 31, 2019, through the end of the listed year in the company and in the custom group of peer companies used in our performance graph, respectively. The custom peer group consists of: Cboe Global Markets Inc, Deutsche Boerse Ag, Intercontinental Exchange Inc, London Stock Exchange Group Plc and Nasdaq Inc. Historical stock performance is not necessarily indicative of future stock performance.
5We determined cash earnings to be the most important financial performance measure used to link company performance to "Compensation Actually Paid" to our PEO and Non-PEO NEOs in 2024. More information about cash earnings can be found in the annual bonus section of the Compensation Discussion and Analysis beginning on page 60.
RELATIONSHIP BETWEEN PEO AND OTHER NEOS COMPENSATION ACTUALLY PAID AND COMPANY AND PEER GROUP TOTAL SHAREHOLDER RETURN
The following chart sets forth the relationship between Compensation Actually Paid to our PEO, the average of Compensation Actually Paid to our other NEOs, and the Company's and Peer Group's cumulative TSR over the five most recently completed fiscal years.

RELATIONSHIP BETWEEN PEO AND OTHER NEO COMPENSATION ACTUALLY PAID AND NET INCOME
The following chart sets forth the relationship between Compensation Actually Paid to our PEO, the average of Compensation Actually Paid to our other NEOs, and our Net Income during the five most recently completed fiscal years.

RELATIONSHIP BETWEEN PEO AND OTHER NEOS COMPENSATION ACTUALLY PAID AND CASH EARNINGS
The following chart sets forth the relationship between Compensation Actually Paid to our PEO, the average of Compensation Actually Paid to our other NEOs, and our Cash Earnings during the five most recently completed fiscal years.

TABULAR LIST OF MOST IMPORTANT FINANCIAL PERFORMANCE MEASURES
The following table presents the financial performance measures that the company considers to have been the most important in linking Compensation Actually Paid to our PEO and other NEOs for 2024 Company performance. The measures in this table are not ranked.
| Cash Earnings | ||
| Relative TSR | ||
| Net Income Margin |
EQUITY GRANT PRACTICES
The following is a summary of our equity grant practices and the role of the committee in approving awards:
-
Our annual equity awards are granted on September 15th, or in the event the 15th is not a business day, the closest business day thereto. We do not time the grant of equity compensation in relation to the disclosure of material nonpublic information.
-
At a meeting prior to the annual grant date, the committee approves the awards for the senior management group based upon the target equity opportunities and recommendations from the Chairman and Chief Executive Officer (for executives other than himself) using a pre-set calculation of a percentage of base salary to determine the award value. Actual awards are granted based on the previously approved award value and the closing price on the actual grant date. The committee receives a report of the actual awards at a subsequent meeting.
-
The committee has delegated authority to the individual in the role of Chief Executive Officer to approve annual, sign-on, retention and initiative-based equity awards to employees below our senior management group other than our chief accounting officer, within parameters set by the committee. The committee is provided with an annual report on awards granted under such delegated authority.
-
Our Omnibus Stock Plan and our Director Stock Plan prohibit the granting of options or stock appreciation rights below the market value on the date of grant, the repricing of existing awards, and payment of dividends on performance-based shares prior to the achievement of performance goals. Dividends relating to outstanding shares of unvested time-based restricted stock are accrued and paid out at vesting.
The equity targets for our named executive officers were established based upon a review of the nature of the responsibility of the position of the executive within CME Group, the competitive market data derived through our benchmarking practices and
the ability of the employee to impact the overall growth and performance of CME Group based upon his or her role within the company. As discussed in more detail on page 63, we generally target total compensation in the 50th percentile of our peer group. Through competitive compensation analysis, we compare equity compensation on a standalone basis as well as part of an executive's overall total compensation.
The committee has the discretion to adjust the annual equity awards to distinguish for individual performance. The annual equity awards for the named executive officers were made at the target levels for 2024 and were comprised of 50% performance shares and 50% time-vested restricted stock. The performance shares, if earned, vest in full following the three-year performance period and the restricted shares vest ratably over a four-year period unless otherwise provided.
2025 Forms 10-Q
ITEM 5. OTHER INFORMATION
On February 18, 2025, Jonathan Marcus, Senior Managing Director and General Counsel adopted a trading plan intended to satisfy the affirmative defense of Rule 10b5-1(c). The plan provides for the potential sale of up to 6,568 shares of the company's Class A common stock. The actual number of shares sold under Mr. Marcus’ plan will depend on the number of shares delivered at the time that certain of his equity awards vest during the term of the plan following the fulfillment of tax withholding obligations and subject to other conditions as set forth in the plan.
The plan expires on March 31, 2026 or upon the earlier completion of all authorized transactions under the plan. In determining the number of shares that may be sold under the plan it is assumed that the performance shares vesting during the plan vest at target.
ITEM 5. OTHER INFORMATION
During the quarter ended June 30, 2025, no director or officer of the Company adopted or terminated a “Rule 10b5-1 trading arrangement” or “non-Rule 10b-5 trading arrangement” as such terms are defined in Item 408(a) of Regulation S-K.
ITEM 5. OTHER INFORMATION
During the quarter ended September 30, 2025, no director or officer of the company adopted or terminated a “Rule 10b5-1 trading arrangement” or “non-Rule 10b-5 trading arrangement” as such terms are defined in Item 408(a) of Regulation S-K.
Previous: Item 9B. OTHER INFORMATION · Next: Item 9C. DISCLOSURE REGARDING FOREIGN JURISDICTIONS THAT PREVENT INSPECTIONS