A Dark Vector Cognition product

Item 1C. Cybersecurity.

6K characters. Original on sec.gov · Markdown

Item 1C. Cybersecurity.

Risk Management and Security

As a diversified healthcare services leader that is dedicated to advancing health outcomes for patients everywhere, cybersecurity risk management is integral to our enterprise risk management strategy. Our management, with involvement and input from external consultants and oversight from our Board of Directors (“Board”), performs an annual enterprise-wide risk assessment (“ERA”) to identify key existing and emerging risks. One of the principal risks identified and assessed through this process is cybersecurity, which remains a key focus for the Company, management, and our Board.

Our Cybersecurity Program is aligned with the National Institute of Standards and Technology Cybersecurity Framework (“NIST CSF”) and other industry best practices. The Cybersecurity Program is designed to identify, assess and mitigate material cybersecurity risks.

We have implemented cybersecurity controls designed to protect our systems, data, and operations from cybersecurity risks. Enterprise-wide cybersecurity and privacy training continues to serve an important role in risk reduction and protection of the Company and our stakeholders. We require periodic access-based and role-based privacy and cybersecurity training, which is updated to reflect changes in the threat environment, audit findings, laws, and regulations. We also engage and educate employees through cybersecurity and privacy awareness programs and communication campaigns. In addition, as cybersecurity attacks become increasingly complex in part due to the emergence of new AI enabled technologies that allow threat actors to target particular entities and IT systems, we are taking measures to manage these risks by deploying new tools and capabilities, including AI.

Our Cybersecurity Incident Response Plan (“CIRP”) provides a framework for responding to cybersecurity incidents. The CIRP is based on the NIST CSF framework and governs activities such as preparation, detection, coordination, eradication and recovery. It also provides processes for appropriate escalations to the Company’s senior management, disclosure committee, Board, and relevant Board committees. The CIRP is routinely tested, reviewed, and updated as appropriate under the leadership of our Chief Information Officer and Chief Technology Officer (“CIO/CTO”) with the assistance of the Company’s Chief Information Security Officer (“CISO”).

We also engage internal and external assessors, consultants, auditors, and other third-parties, to assess our Cybersecurity Program’s maturity. We manage cybersecurity risks associated with third parties, including vendors, service providers, and external users of our systems. This includes conducting due diligence on the third parties we use along with using third party cybersecurity monitoring and alerting tools.

Although we believe that we maintain reasonable cybersecurity measures, we recognize that cyber threats continue to evolve, and no system is immune to risk.

As of March 31, 2026, we are not aware of any cybersecurity incidents that have materially affected, or are reasonably likely to materially affect, our business strategy, results of operations, or financial condition. For a discussion of whether and how any risks from cybersecurity threats have affected or, if realized, are reasonably likely to materially affect the Company, see “Risk Factors” in Item 1A of Part I above for additional information on risks related to our business, including for example, risks related to privacy and data protection, cybersecurity incidents, third-party relationships, and continuity of our information systems and networks, operational technology, and technology products or services.

Table of Contents

McKESSON CORPORATION

Governance

Our CIO/CTO leads management’s assessment and management of cybersecurity risk with the assistance of the Company’s CISO who reports to the CIO/CTO. The CIO/CTO reports to our CEO, is a member of the Executive Operating Team, and provides updates to the Board about cybersecurity matters. Our CIO/CTO has more than 30 years of experience managing technology and risks, and advising on cybersecurity issues and our CISO has more than 22 years of relevant experience, is a Certified Information System Security Professional (CISSP), and a Certified Information Systems Auditor (CISA).

Cybersecurity is among the risks identified by our ERA for Board-level oversight. The Audit Committee of the Board has oversight of information technology controls related to financial reporting, while the Compliance Committee of the Board has oversight of technology-related risk, including privacy and cybersecurity. The Audit Committee and Compliance Committee meet jointly at least annually to review cybersecurity risks and programs, and they are updated as needed on cybersecurity threats, incidents, or new developments in our cybersecurity risk profile. The chairs of the Audit Committee and Compliance Committee provide updates to the Board after each committee meeting. The CIO/CTO and CISO provide regular updates to the Board, Audit Committee, or Compliance Committee about material risks from cybersecurity threats. The CIO/CTO or CISO also provides regular updates to the Board, Audit Committee, or Compliance Committee about cybersecurity trends and regulatory updates, data governance and usage, technology infrastructure, our training and compliance efforts, and implications for our business strategy. In addition to the information provided in these meetings, members of our Board have access to continuing education, which includes topics relating to cybersecurity risks.

Previous: Item 1B. Unresolved Staff Comments. · Next: Item 2. Properties.