Item 1C. CYBERSECURITY

9K characters. Original on sec.gov · Markdown

Item 1C. CYBERSECURITY

Cybersecurity Risk Management and Strategy

Our cybersecurity risk management strategy and processes are designed to identify, assess, and manage risks to the confidentiality, integrity, and availability of our information technology environment, systems, and information. The cybersecurity risk management process is managed centrally and is led by our global chief information security officer

(“CISO”) who reports to our global chief information officer. Our cybersecurity program takes a risk-based approach and is integrated with our global enterprise risk management program. Our cybersecurity risk strategy is aligned with cyber/information security frameworks and industry standards, including the National Institute of Standards and Technology Cybersecurity Framework.

Our cybersecurity program includes the following risk management practices:

●a formal cybersecurity risk assessment is performed annually in collaboration with our enterprise risk management function, resulting in updates to plans and actions that are incorporated into improvement projects;
●our cybersecurity program maturity is benchmarked annually against industry standards and norms. The result serves as a guide to identifying evolving risks, prioritizing improvements, and enhancing the program;
●cybersecurity threats are evaluated throughout the year by our around-the-clock security operations center, utilizing a variety of third-party subscription and threat intelligence data sources and data collected via internal monitoring and scanning processes;
●annual security awareness trainings are required to be completed by employees, and monthly phishing campaigns and additional function-specific cybersecurity trainings are also conducted;
●security and risk metrics are reviewed monthly and reported to leadership quarterly;
●external penetration tests are conducted annually by independent third parties and appropriate actions are taken to strengthen controls;
●a cybersecurity incident response charter and plan, and playbooks are maintained by the cybersecurity incident response team. The plan and playbooks are utilized during table-top exercises and trainings. Participants may include information technology, business, corporate function, and external resources depending on the table-top scenario; and
●third-party supplier security reviews are conducted based on risk. Reviews may include the assessment of security architecture, connections between our systems and the third party, data security controls, and user access controls.

To date, we do not believe that any risks from cybersecurity threats, nor any previous cybersecurity incidents, have materially affected our business strategy, results of operations, or financial condition. However, the sophistication of cyber threats continues to increase, and the preventative actions we have taken and continue to take to reduce the risk of cyber incidents and protect our systems and information may not successfully protect against future cyber incidents, which could materially affect our business strategy, results of operations, or financial condition. For additional information on certain risks associated with cybersecurity, refer to the risk factors related to cybersecurity and information technology systems in “Part I, Item 1A. Risk Factors.”

Cybersecurity Program Governance

Our cybersecurity program is governed by the information security committee (“ISC”), composed of our leaders from information technology, enterprise risk, legal, compliance, strategy, human resources, finance, internal audit, and various business units. On a quarterly basis, the CISO reports to the ISC on topics such as risk mitigation project status, audit results, security metrics, cyber incidents investigated and impact, if any, and significant changes that contribute toward protecting the enterprise from cybersecurity threats.

Our CISO has over 20 years of experience in information security leadership roles and over 8 years as our CISO. Nearly half of our board of directors have completed cybersecurity program trainings or have cybersecurity and information security industry experience.

Cybersecurity incidents are evaluated by a cross-functional management team based on defined quantitative and qualitative criteria and communicated to leadership. We have cybersecurity and information technology third-party consultants to assist in performing forensic and technical analyses and advising leadership as needed.

The cybersecurity committee of our board of directors has oversight responsibility for cybersecurity risks. The CISO provides updates at least twice a year to the cybersecurity committee regarding matters related to information technology and cybersecurity risks including the state of our cybersecurity programs, emerging cybersecurity developments and threats, and our strategy to mitigate cybersecurity risk. Additionally, the full board of directors receives updates on our cybersecurity program twice a year as part of the enterprise risk management meetings.

ITEM 2. PROPERTIES

During fiscal 2024, our principal executive office was located in Schaffhausen, Switzerland. In connection with our change in place of incorporation, Galway, Ireland became the new location of our principal executive office in fiscal 2025. As of fiscal year end 2024, we owned approximately 17 million square feet and leased approximately 10 million square feet of aggregate floor space, used primarily for manufacturing, warehousing, and office space. We believe our facilities are suitable for the conduct of our business and adequate for our current needs.

We manufacture our products in over 25 countries worldwide. Our manufacturing sites focus on various aspects of our manufacturing processes, including our primary processes of stamping, plating, molding, extrusion, beaming, and assembly. We consider the productive capacity of our manufacturing facilities sufficient. As of fiscal year end 2024, our principal centers of manufacturing output by segment and geographic region were as follows:

​​​​​​​​​​
​TransportationIndustrialCommunications​
​​Solutions​Solutions​Solutions​Total
​(number of manufacturing facilities)​
EMEA2018139​
Asia–Pacific109827​
Americas725234​
Total375211100​

​

​

ITEM 3. LEGAL PROCEEDINGS

In the normal course of business, we are subject to various legal proceedings and claims, including product liability matters, employment disputes, disputes on agreements, other commercial disputes, environmental matters, antitrust claims, and tax matters, including non-income tax matters such as value added tax, sales and use tax, real estate tax, and transfer tax. In addition, we operate in an industry susceptible to significant patent legal claims. At any given time in the normal course of business, we are involved as either a plaintiff or defendant in a number of patent infringement actions. If infringement of a third party’s patent were to be determined against us, we might be required to make significant royalty or other payments or might be subject to an injunction or other limitation on our ability to manufacture or sell one or more products. If a patent owned by or licensed to us were determined to be invalid or unenforceable, we might be required to reduce the value of the patent on our Consolidated Balance Sheet and to record a corresponding charge, which could be significant in amount.

Management believes that these legal proceedings and claims likely will be resolved over an extended period of time. Although it is not feasible to predict the outcome of these proceedings, based upon our experience, current information, and applicable law, we do not expect that the outcome of these proceedings, either individually or in the aggregate, will have a material effect on our results of operations, financial position, or cash flows.

Previous: Item 1B. UNRESOLVED STAFF COMMENTS · Next: Item 4. MINE SAFETY DISCLOSURES