{"url_path":"/sec/cik-0002079966/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C Cybersecurity","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-26","source_url":"https://www.sec.gov/Archives/edgar/data/2079966/0001193125-26-283312-index.html","accession_number":"0001193125-26-283312","cik":"0002079966","ticker":null,"issuer_name":"Macquarie Infrastructure Fund, L.P.","edgar_url":"https://www.sec.gov/Archives/edgar/data/2079966/0001193125-26-283312-index.html","primary_entity_key":"0002079966","primary_entity_name":"Macquarie Infrastructure Fund, L.P."},"word_count":516,"has_tables":true,"body_markdown":"Item 1C. Cybersecurity\n\nMacquarie’s cybersecurity risk management processes are integrated into its overall risk management framework through its Information and Cyber Security Program (the “Program”), which outlines the governance structure, risk management strategies, and operational controls used to identify, manage, and mitigate cybersecurity risks across the organization. The Program operates within Macquarie’s Operational Risk Management Framework and is aligned with the US National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) Version 2.0, ensuring consistency with industry best practices and enterprise risk management principles.\n\nThe Program incorporates a comprehensive cybersecurity risk governance structure, supported by a global policy and standards framework, organization‑wide training and awareness initiatives, assurance and control testing activities, and continuous improvement driven by threat intelligence and risk insights. Cybersecurity risks are identified, assessed, and managed as part of Macquarie’s broader operational risk processes, including the assessment of current and emerging risks and internal and external incidents.\n\nMacquarie leverages a combination of internal and independent assurance functions as part of its cybersecurity risk management processes. These include dedicated cybersecurity teams responsible for control design, implementation, and monitoring, as well as independent oversight and challenge provided by the Risk Management Group, Internal Audit and External Audit.\n\nDedicated cybersecurity teams are responsible for designing, implementing, monitoring, and assessing controls across the control environment. These activities include risk identification and reporting to management and the Board, control effectiveness assessments (including for third‑party service providers), data and asset protection, threat detection and monitoring, and incident response. These processes ensure that cybersecurity risk management is embedded across business operations and aligned with enterprise‑wide governance and oversight mechanisms.\n\n100\n\n[Table of Contents](#toc_page)\n\n \n\n \n\nMacquarie applies a “three lines of defense” model, whereby risk ownership resides in the business, with independent oversight and assurance functions providing governance and monitoring. Oversight activities include ongoing monitoring of cybersecurity performance through metrics, review of incident trends and audit findings, and continuous refinement of controls and governance processes. Regular reporting by the Chief Information Security Officer (CISO) to senior management and relevant governance forums further supports integration with enterprise‑level risk management and decision‑making.\n\nThe Program is reviewed at least annually and updated to reflect changes in the threat landscape, business operations, technology, and regulatory requirements, ensuring continued alignment with Macquarie’s risk appetite and overall risk management processes.\n\nMacquarie maintains processes to oversee and identify risks associated with third‑party service providers through its Service Provider Governance Framework, supported by the Service Provider Risk Management Policy and Service Provider Lifecycle Standard. Cybersecurity assessments are performed where service providers access, process, store, or transmit Macquarie data outside of Macquarie’s control environment, in accordance with the Supplier Cyber Governance Standard and a risk‑proportionate approach. Macquarie has not been materially affected by cybersecurity threats and continuously monitors the evolving threat landscape, implements controls to mitigate identified risks, and manages residual risks in line with its defined risk appetite and Operational Risk Management Framework.\n\nAdditionally, the Fund’s Audit Committee reviews the Fund’s and the Adviser’s information technology (“IT”) security controls with management and periodically evaluates the adequacy of the Fund’s and the Adviser’s IT security program, compliance and controls with management."}