A Dark Vector Cognition product

Item 1C. Cybersecurity.

8K characters. Original on sec.gov · Markdown

Item 1C. Cybersecurity.

We have a cybersecurity program to assess and manage risks to the confidentiality, integrity, and availability of our data, networks and technology assets across WBD. Our board of directors oversees risk management at WBD and has delegated functional oversight of cybersecurity and information technology risks to our board of directors’ audit committee (the “Audit Committee”). Our Chief Information Security Officer (“CISO”) is responsible for the management of such risks and oversees a global organization whose responsibilities include proactively managing and monitoring information and content security, cybersecurity risk, and processes to enable secure and resilient access to, and use of, WBD products and services.

Risk Management and Strategy

We have a cybersecurity risk management strategy for safeguarding our digital assets that includes both technical and non-technical cybersecurity controls. Our cybersecurity risk management processes are designed to evolve in response to changes in our business, technological environment, and the broader threat landscape and are aligned and integrated into our overall enterprise risk management approach. Our multi-layered technical defense involves a series of protective measures across various levels of our technological environment. This includes fortifying our network perimeter through intrusion detection and prevention systems, securing individual devices with antivirus solutions and endpoint detection, implementing network security measures, and ensuring the resilience of applications. In addition to these technical security solutions, we also leverage non-technical methods, such as promoting a cybersecurity-conscious culture throughout WBD which includes mandatory annual cybersecurity training for all employees, a regular cadence of cybersecurity messaging to our employees, and frequent phishing simulations. Further, we engage independent third parties to conduct annual internal and external penetration testing and independent assessments of our cybersecurity risk management practices using the National Institute of Standards and Technology’s cybersecurity framework and other leading industry practices as guidelines. We also engage an independent third party to conduct a biennial cybersecurity maturity assessment to evaluate the maturity of our entire cybersecurity program.

We also invest in cybersecurity incident detection and response. Our Cybersecurity Operations Center provides continuous threat monitoring and anomaly detection that is intended to prevent or minimize damage from a cybersecurity attack. We have a Cybersecurity Incident Response Plan that establishes procedures, roles, responsibilities, and communication protocols for WBD executive management and technical staff in the event of a cybersecurity incident. We periodically review and enhance our cybersecurity incident response processes and conduct exercises involving relevant stakeholders to assess preparedness and response effectiveness. We test the efficacy of the Cybersecurity Incident Response Plan and assess our response capabilities by conducting annual tabletop exercises that simulate cybersecurity threat scenarios.

We have ongoing processes to identify and assess cybersecurity risks associated with current and prospective third-party service providers. Our third-party cybersecurity risk management processes are risk-based and ongoing and are designed to assess cybersecurity considerations throughout the vendor relationship lifecycle. These processes include a vendor cybersecurity compliance assessment at the time of onboarding, contract renewal and/or as needed in the event of a cybersecurity incident affecting such third-party vendor. In addition, we require our providers to meet appropriate security requirements, controls and responsibilities and notify us in the event of a cybersecurity incident that impacts us.

We have established cybersecurity information sharing and collaboration practices with both government agencies and industry partners, which we believe enhances our overall cybersecurity resilience.

We periodically experience cybersecurity incidents, but, as of December 31, 2025, we are not aware of any such incidents that have materially impacted or are reasonably likely to materially impact our business, financial condition or results of operations. However, despite our efforts, we cannot eliminate all risks from cybersecurity threats or provide assurances that we have not experienced undetected cybersecurity incidents or will not discover additional information about previously detected events. See Item 1A, “Risk Factors” for details on the risks from cybersecurity threats that we face.

Governance

We have established a cybersecurity governance framework designed to provide effective oversight, clear accountability and appropriate escalation across WBD. Our cybersecurity program is led by our CISO, who is responsible for the design, implementation and operation of controls to prevent, detect, mitigate and remediate cybersecurity threats. The CISO assesses and monitors our cybersecurity posture through ongoing engagement with our content and information security team and provides regular reporting to WBD executive management and the Audit Committee in accordance with established governance and escalation protocols.

WBD executive management is engaged in the governance of our cybersecurity program through defined oversight, reporting and escalation mechanisms. Our Chief Financial Officer, Chief Legal Officer, Chief Audit and Risk Officer and Chief Information Officer receive regular updates regarding cybersecurity risks, incidents and program initiatives and participate in governance, prioritization and escalation decisions as appropriate to their respective enterprise responsibilities.

Our board of directors oversees our overall enterprise risk management approach, including risks related to cybersecurity and information technology. Our board of directors has delegated primary oversight responsibility for cybersecurity and information technology risks to the Audit Committee. The Audit Committee receives regular reports from our CISO, at least quarterly, regarding our cybersecurity risk posture, significant developments in the threat landscape, the effectiveness of controls, and progress on initiatives to strengthen and enhance our cybersecurity program. The Audit Committee also receives updates outside of the regular reporting cadence when warranted by significant events, emerging risks or regulatory developments and may devote additional meeting time to in-depth review of cybersecurity matters or education on relevant topics. The Chair of the Audit Committee provides readouts to our board of directors on matters, including cybersecurity matters, reviewed at meetings of the Audit Committee.

We maintain a Cybersecurity Incident Response Plan that defines incident severity thresholds, escalation protocols and reporting requirements and facilitating coordination across multiple parts of the Company. We also have processes in place designed to ensure that decisions regarding public disclosure and reporting of cybersecurity incidents can be made in a timely manner. Cybersecurity incidents that meet established escalation criteria are reported to WBD executive management and as appropriate, to the Audit Committee, to support timely oversight and response.

Our cybersecurity governance framework also includes ongoing assessment and testing of controls and response capabilities, including tabletop exercises, penetration testing and third-party assessments, to help evaluate program effectiveness and inform continuous improvement.

Our CISO brings extensive experience leading global cybersecurity and information security programs across complex public- and private-sector organizations, with expertise in cybersecurity risk management, data protection and regulatory compliance, and holds industry-recognized cybersecurity certifications.

Previous: Item 1B. Unresolved Staff Comments. · Next: Item 2. Properties.