{"url_path":"/sec/exp/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C Cybersecurity","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-05-19","source_url":"https://www.sec.gov/Archives/edgar/data/918646/0001193125-26-230979-index.html","accession_number":"0001193125-26-230979","cik":"0000918646","ticker":"EXP","issuer_name":"EAGLE MATERIALS INC","edgar_url":"https://www.sec.gov/Archives/edgar/data/918646/0001193125-26-230979-index.html","primary_entity_key":"0000918646","primary_entity_name":"EAGLE MATERIALS INC"},"word_count":724,"has_tables":true,"body_markdown":"ITEM 1C. Cybersecurity\n\nRISK MANAGEMENT AND STRATEGY\n\nEagle continues to make cybersecurity a priority as the threat landscape evolves and becomes increasingly complex and sophisticated.\n\nManaging Material Risks and Integrated Overall Risk Management\n\nWe have strategically integrated cybersecurity risk management into our broader risk management framework to promote a company-wide culture of cyber risk awareness. Our Director of Information Security (DIS), under the direction of our Chief Financial Officer (CFO), continuously evaluates and addresses cyber risks in alignment with business objectives, operational needs, and industry-accepted standards, such as National Institute of Standards and Technology frameworks.\n\nThe Company has processes and procedures in place intended to prevent, detect, mitigate, and remediate cybersecurity risks. These include but are not limited to:\n\n•\nmaintaining a defined and practiced incident response plan\n\n•\nmaintaining cyber insurance coverage\n\n•\nemploying appropriate incident prevention and detection safeguards\n\n•\nmaintaining defined disaster recovery procedure and employing disaster recovery software, where appropriate\n\n•\neducating, training and testing our user community on information security practices and identification of potential cybersecurity risks and threats\n\n•\nreviewing and evaluating new developments in the cyber threat landscape.\n\nEngaging Third Parties on Risk Management\n\nRecognizing the complexity and evolving nature of cybersecurity risk, we engage with a range of external security support providers, including cybersecurity consultants, in evaluating, monitoring, and testing our cyber management systems and related cyber risks. The Company’s collaboration with these third parties includes threat and vulnerability assessments, incident response plan testing, company-wide monitoring of cybersecurity risks, and consultation on security enhancements.\n\nManaging Third-Party Risk\n\nWe recognize the risks associated with the use of vendors, service providers, and other third parties that provide information system services to us, process information on our behalf, or have access to our information systems, and the Company has processes in place to oversee and manage these risks. We conduct thorough security assessments of these third-party engagements and maintain ongoing monitoring to ensure compliance with our cybersecurity standards. This monitoring includes both annual and ongoing assessments.\n\nRisks from Cybersecurity Incidents\n\nTo our knowledge, the Company has not been subject to cybersecurity incidents that have materially affected, or are reasonably likely to materially affect, the Company, its operations, or financial standing.\n\n \n\n \n\n37\n\n \n\nGOVERNANCE\n\nRisk Management Personnel\n\nThe Company’s cybersecurity risk management program is overseen by management at multiple levels. Under the direction of our CFO, the DIS plays a key role in assessing, monitoring, and managing the Company’s cybersecurity risks with support from Company management, external cybersecurity consultants, and dedicated information technology and security personnel. Our DIS has over 35 years of IT experience, including 30 years of specializing in cybersecurity practices. Our DIS holds numerous certifications including as an ISC2, Certified Information Systems Security Professional (CISSP), and ISACA Certified Information Security Manager (CISM). Our DIS also has extensive experience in architecting, implementing, and managing cyber security control systems including vulnerability management, endpoint detection and response (EDR), security information and event management (SIEM), email fraud defense, and identity access management (IAM) solutions.\n\nMonitor Cybersecurity Incidents\n\nOur DIS is continually informed and updated on the latest developments in cybersecurity, including emerging threats and innovative risk management techniques. Our Director of Technology (DIT), supported by our DIS, implements and oversees processes for the regular monitoring of our information systems. This includes the deployment of advanced security measures and regular system audits to identify potential vulnerabilities. In the event of a cybersecurity incident, the Company is equipped with a defined and practiced incident response plan, which details immediate actions to mitigate the impact and long-term strategies for remediation and prevention of future incidents.\n\nBoard of Directors Oversight\n\nThe Audit Committee of Eagle's Board is responsible for overseeing the Company’s policies and practices related to cyber risk. Based on details provided by the DIS, the Chief Financial Officer (CFO), together with the Company's third-party experts, provides the Audit Committee quarterly updates that encompass a broad range of topics, including:\n\n•\ncurrent cybersecurity threat landscape and emerging threats\n\n•\nstatus of ongoing cybersecurity initiatives and strategies\n\n•\nincident reports and learnings from unique cybersecurity events, including those of other companies\n\n•\ncompliance status and initiatives related to regulatory requirements and industry standards.\n\nIn addition, the CFO provides updates to the full Board upon request, and timely updates regarding unique developments such as regulatory updates or vulnerability developments, based on details provided by the DIS.\n\n \n\n \n\n38"}