A Dark Vector Cognition product

Item 1B. Unresolved staff comments

2K characters. Original on sec.gov · Markdown

Item 1B. Unresolved staff comments

Not applicable.

Item 1C. Cybersecurity

Cybersecurity program

As a technology company in the global payments industry entrusted with the safeguarding of sensitive information (including personal information), cybersecurity risk management is an integral part of our overall enterprise risk management program. A robust program to protect our network from cyber and information security threats is critical to managing risk effectively. Our network and platforms incorporate multiple layers of protection, providing greater resiliency and security protection. Our programs are assessed by third parties and incorporate benchmarking and other data from peer companies and consultants. We engage in many efforts to mitigate information security challenges, including maintaining an information security program, an enterprise resilience program and insurance coverage, as well as regularly testing our systems to address potential vulnerabilities. We work with experts across the organization (as well as through other sources such as public-private partnerships) to monitor and respond quickly to a range of cyber and physical threats, including threats and incidents associated with the use of services provided by third-party providers. Our cybersecurity program provides (among other things) a framework for handling cybersecurity threats and incidents, which includes steps for identifying the nature of a cybersecurity threat (including whether the threat is associated with a third-party provider), assessing the severity of a cybersecurity threat (including advancing to key members of management where appropriate for determination of potential materiality) and implementing cybersecurity processes and procedures.

MASTERCARD 2025 FORM 10-K 41

PART I

Previous: Item 1A. RISK FACTORS · Next: Item 1C. CYBERSECURITY