{"url_path":"/sec/hsic/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C Cybersecurity","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-02-24","source_url":"https://www.sec.gov/Archives/edgar/data/1000228/0001000228-26-000013-index.html","accession_number":"0001000228-26-000013","cik":"0001000228","ticker":"HSIC","issuer_name":"HENRY SCHEIN INC","edgar_url":"https://www.sec.gov/Archives/edgar/data/1000228/0001000228-26-000013-index.html","primary_entity_key":"0001000228","primary_entity_name":"HENRY SCHEIN INC"},"word_count":1187,"has_tables":false,"body_markdown":"Item 1C.\n\nCybersecurity\n\nWe rely on information systems in our business to obtain, rapidly process, analyze, manage and store customer,\n\nproduct, supplier and employee data to, among other things: maintain\n\nand manage multiple information systems\n\nworldwide to facilitate the purchase and distribution of thousands of\n\ninventory items from numerous distribution\n\ncenters; receive, process and ship orders on a timely basis; manage the\n\naccurate billing and collections for\n\nthousands of customers; process payments to suppliers and vendors; provide\n\nproducts and services that maintain\n\ncertain of our customers’ electronic medical or dental records (including\n\nprotected health information of their\n\npatients) and maintain and manage global human resources, compensation\n\nand payroll systems.\n\nFor these purposes,\n\nwe define “information systems” in a manner consistent with the definition\n\ncontained in the rules adopted by the\n\nSEC to mean “electronic information resources, owned or used by the\n\nregistrant, including physical or virtual\n\ninfrastructure controlled by such information resources, or components thereof,\n\norganized for the collection,\n\nprocessing, maintenance, use, sharing, dissemination, or disposition\n\nof the registrant's information to maintain or\n\nsupport the registrant's operations.”\n\nCybersecurity Risk Management and Strategy\n\nWe have developed and implemented a cybersecurity risk mitigation strategy intended to protect our information\n\nsystems.\n\nOur cybersecurity risk mitigation strategy is designed\n\nso that the Company’s cybersecurity program is\n\naligned with generally accepted cybersecurity standards and frameworks,\n\nin particular the NIST Cybersecurity\n\nFramework, or “NIST CSF,” and our Company is externally audited, or certified, with ISO27001 partial scope.\n\nWe maintain an Office of Cybersecurity (“OCS”), led by our Chief Information Security Officer (“CISO”), which\n\noversees\n\nthe operations of our cyber risk mitigation strategy.\n\nThe OCS is a cross-functional, enterprise-wide\n\nmanagement team, which continuously evaluates our global cybersecurity\n\nprogram’s effectiveness and is focused\n\non maintaining and protecting our information systems.\n\nIn overseeing the operations of our cyber risk mitigation\n\nstrategy, the OCS partners with our Global Technology Solutions team, which is led by our Chief Technology\n\nOfficer (“CTO”) and is comprised of over one hundred professionals that support our information\n\nsystems and\n\noperations.\n\nOur cyber risk mitigation strategy includes\n\nmonitoring\n\nfor and addressing risks that materialize within\n\nthe Company’s information systems, as well as at our\n\nthird-party\n\nvendors, suppliers and other third-party business\n\npartners.\n\nOur CISO reports to our CTO.\n\nOur CTO,\n\nwho also serves as Senior Vice President,\n\nhas more than 30 years of\n\nexperience leading large-scale global IT organizations and received a Bachelor of Business Administration\n\nin\n\nBusiness Computer Information Systems and a Master of Business Administration\n\nfrom Hofstra University.\n\nSee\n\nalso\n\n[Item 1. Business, Other Executive Management](#a23131)\n\n[.](#a23131)\n\nOur Vice President, Global CISO, who also serves as Vice\n\nPresident and Head of the Office of Cyber Security, has over 30 years of experience leading global cybersecurity\n\nand technology programs in large and complex corporations, and holds a Certified\n\nInformation Systems Security\n\nProfessional and a Certified Information Systems Auditor certification.\n\nHe also received a BS, Information\n\nTechnology and Security from Baker College.\n\nThe cybersecurity risk mitigation strategy is also overseen by\n\nsenior\n\nmanagers who are members of our Executive Steering Committee, comprised\n\nof the Company’s most senior\n\ntechnology, legal and internal auditing officers.\n\nOur CEO is regularly briefed on issues, incidents, and\n\ndevelopments, and our Board oversees our risk mitigation strategy principally\n\nthrough its Audit Committee and\n\nRegulatory, Compliance and Cybersecurity Committee, as described in more detail below.\n\nOur cybersecurity risk management program includes, among other\n\nelements:\n\n•\n\nrisk assessments designed to help identify material cybersecurity risks\n\nto our information systems;\n\n•\n\na security team principally responsible for managing our (i) cybersecurity\n\nrisk assessment processes, and\n\n(ii) defining cybersecurity control standards;\n\n•\n\nthe use of expert external service providers to assess, test or otherwise assist\n\nwith aspects of our\n\ncybersecurity controls, and to respond to specific cybersecurity threats;\n\n•\n\nthe review and assessment of past cybersecurity incidents with a view to\n\nlearning from those events to\n\nfurther strengthen our cyber risk mitigation strategy;\n\n[Table of Contents](#a296)\n\n[Index to Financial Statements](#a33909)\n\n44\n\n•\n\na written cybersecurity incident response plan that includes procedures\n\nfor responding to cybersecurity\n\nincidents; and\n\n•\n\na Global Information Security Policy, together with more detailed information security policies,\n\nprocedures, standards, and guidelines.\n\nIn addition, all employees with systems access are required to participate\n\nin mandatory annual cybersecurity and\n\nanti-phishing courses, along with compliance programs.\n\nOur employees who perform financial gatekeeper roles\n\nalso receive additional mandatory annual data security training specific\n\nto spoofing, phishing and similar data\n\nsecurity threats.\n\nPer written Company policies, employees are also required\n\nto safeguard confidential information.\n\nOur cybersecurity risk strategy is integrated into our overall enterprise\n\nrisk management program, and our\n\ncybersecurity team is supported by and connected with the enterprise risk management\n\nteam.\n\nCyber Incidents\n\nIn addition to immaterial and unrelated incidents at certain of our subsidiaries,\n\nin October 2023 Henry Schein\n\nexperienced a cyber incident that primarily affected the operations of our North American\n\nand European dental and\n\nmedical distribution businesses.\n\nHenry Schein One, our practice management software, revenue cycle\n\nmanagement\n\nand patient relationship management solutions business was not affected, and\n\nour manufacturing businesses were\n\nmostly unaffected.\n\nThe October 2023 cyber incident disrupted key business operations,\n\nadversely impacted our\n\nfinancial results for the fourth quarter and full year 2023, diverted\n\nattention of management, and caused the\n\nCompany to incur significant remediation costs.\n\nThe incident had residual impact on our financial results in 2024.\n\nCybersecurity Governance\n\nOur Board has a Regulatory, Compliance and Cybersecurity Committee that focuses on cybersecurity oversight,\n\ntogether with other board committees, principally the Audit Committee.\n\nThe purpose of the Regulatory,\n\nCompliance and Cybersecurity Committee is to assist the Board by providing\n\nguidance to, and oversight of, the\n\nCompany’s senior management responsible for assessing and managing Company-wide regulatory, corporate\n\ncompliance and cybersecurity risk management programs.\n\nThe primary responsibilities of the Regulatory,\n\nCompliance and Cybersecurity Committee are to (i) discuss cybersecurity\n\nstrategic decisions, issues, challenges and\n\nopportunities relating thereto, (ii) provide expertise to guide assessment\n\nand monitoring of Company-wide\n\nregulatory, corporate compliance and cybersecurity risk management budgeting, spending and capital investment,\n\n(iii) monitor progress and status of the Company’s regulatory, corporate compliance and cybersecurity risk\n\nmanagement programs, (iv) review and evaluate major regulatory, corporate compliance and cybersecurity risk\n\nmanagement initiatives to identify emerging and future opportunities for synergy or to\n\nleverage regulatory,\n\ncorporate compliance and cybersecurity risk management investments\n\nmore effectively and cost efficiently,\n\n(v) report to the Audit Committee on regulatory, corporate compliance and cybersecurity risk management matters\n\nreviewed by the Regulatory, Compliance and Cybersecurity Committee that may impact the Company’s financial\n\nreporting and (vi) be generally available to, and communicate with,\n\nthe Company’s senior management, and to\n\ninform the Board in the areas described above.\n\nOur CISO and CTO, along with other key executives who are part of our Executive\n\nSteering Committee, review\n\nstrategy, policy,\n\nprogram effectiveness, standards, enforcement and cybersecurity issue management\n\nwith the\n\nBoard’s Regulatory,\n\nCompliance and Cybersecurity Committee on at least a quarterly basis and\n\nwith the Audit\n\nCommittee on at least a bi-annual basis.\n\nOur CTO\n\nmeets\n\nwith Board members outside of the formal meetings on a\n\nregular basis as well as in connection with specific cybersecurity issues or\n\nthreats.\n\n[Table of Contents](#a296)\n\n[Index to Financial Statements](#a33909)\n\n45"}