{"url_path":"/sec/ghm/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C Cybersecurity","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-08","source_url":"https://www.sec.gov/Archives/edgar/data/716314/0001193125-26-260688-index.html","accession_number":"0001193125-26-260688","cik":"0000716314","ticker":"GHM","issuer_name":"GRAHAM CORP","edgar_url":"https://www.sec.gov/Archives/edgar/data/716314/0001193125-26-260688-index.html","primary_entity_key":"0000716314","primary_entity_name":"GRAHAM CORP"},"word_count":635,"has_tables":true,"body_markdown":"Item 1C. Cybersecurity\n\nRisk Management and Strategy\n\nWe maintain a comprehensive cybersecurity risk management program (“CRMP”) designed to protect the confidentiality, integrity, and availability of our critical systems and information. The CRMP includes enterprise‑level procedures for Graham Corporation and tailored procedures for each of our business units. It also incorporates formal incident response plans (“IRPs”) for Graham Manufacturing, BN, and P3.\n\nThe IRPs establish a structured, systematic process for identifying, escalating, responding to, and documenting information security incidents affecting our systems, networks, or data—including data managed by third‑party vendors or service providers.\n\nOur CRMP is integrated into our broader enterprise risk management framework. Oversight of the IRPs for Graham Corporation and its subsidiaries is assigned to our Chief Information Officer (“CIO”), who has more than 25 years of cybersecurity experience and holds a Certified Information Systems Security Professional (\"CISSP\") certification. Each business unit also maintains dedicated cybersecurity personnel responsible for implementing and managing local cybersecurity and data‑privacy programs.\n\nThe CIO and Business Unit IT Managers are responsible for:\n\n•\nImplementing IRPs specific to each business unit.\n\n•\nIdentifying and managing an incident response team (“IRT”) responsible for cybersecurity risk assessments, security controls, and incident response activities.\n\n•\nCoordinating IRT operations, including escalation procedures, decision‑making protocols, and documentation of cybersecurity incidents.\n\n•\nConducting post‑incident reviews to evaluate response effectiveness and address gaps in security controls.\n\n•\nProviding cybersecurity training and periodic exercises to enhance organizational preparedness.\n\n•\nReviewing and updating the IRP when material changes in business practices may affect incident‑response procedures.\n\nOur CRMPs include:\n\n•\nRisk assessments to identify material risks to systems, information, products, services, and the broader IT environment, including ransomware‑related risks.\n\n•\nEngagement of external service providers to assess, test, or support our security controls.\n\n•\nCybersecurity awareness training for employees, incident‑response personnel, and senior management.\n\n22\n\n \n\n•\nA formal cybersecurity incident response plan outlining procedures for responding to cybersecurity events.\n\n•\nA third‑party risk management process for service providers, suppliers, and vendors.\n\nFrom time to time, we may engage assessors, consultants, auditors or other third parties in connection with our CRMP and IRP processes. We have established processes to identify and oversee cybersecurity risks associated with third‑party service providers. These include security reviews during vendor onboarding and ongoing, risk‑based monitoring.\n\nWe are currently integrating FlackTek into our CRMP and IRP processes, with completion expected during fiscal 2027.\n\nAs of March 31, 2026, we are not aware of any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations, and financial condition. As with most organizations, we may experience cyber incidents in the future. Additional information regarding cybersecurity risks is included in Item 1A, Risk Factors.\n\n \n\nGovernance\n\nOversight of cybersecurity risk management has been delegated to the Audit Committee of the Board of Directors as part of its broader risk‑oversight responsibilities, as outlined in the Audit Committee Charter. The Audit Committee receives periodic reports from our CIO—at least annually—on cybersecurity risks and is updated as needed regarding any material cybersecurity incidents or incidents with lesser potential impact.\n\nOur management team is responsible for assessing and managing material risks from cybersecurity threats. The CIO and Business Unit IT Managers regularly brief senior management on cybersecurity posture, risks, and incidents to ensure visibility at the highest levels of the organization. Management oversees the overall cybersecurity risk management program and supervises both internal cybersecurity personnel and external cybersecurity consultants.\n\nManagement’s oversight activities include efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents. These efforts may involve:\n\n•\nBriefings from internal security personnel.\n\n•\nThreat intelligence from governmental, public, and private sources.\n\n•\nInformation from external cybersecurity consultants.\n\n•\nAlerts and reports generated by security tools deployed across our IT environment.\n\n \n\n23"}