{"url_path":"/sec/mgre/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C Cybersecurity","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-02-17","source_url":"https://www.sec.gov/Archives/edgar/data/1004434/0001628280-26-008665-index.html","accession_number":"0001628280-26-008665","cik":"0001004434","ticker":"AMG","issuer_name":"AFFILIATED MANAGERS GROUP, INC.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1004434/0001628280-26-008665-index.html","primary_entity_key":"0001004434","primary_entity_name":"AFFILIATED MANAGERS GROUP, INC."},"word_count":988,"has_tables":true,"body_markdown":"Item 1C.Cybersecurity\n\nRisk Management and Strategy\n\nOur cybersecurity risk management program is integrated into our overall risk management framework.  We regularly\n\nassess risks from cybersecurity threats, monitor our information systems for potential vulnerabilities, and test those systems\n\npursuant to our cybersecurity policies, processes, and practices.  To protect our information systems from cybersecurity threats,\n\nwe use various security tools that help us identify, escalate, investigate, resolve, and recover from security incidents in a timely\n\nmanner.\n\nWe recognize the importance of protecting information assets such as the personally identifiable information of our\n\nemployees, and proprietary business information regarding our Affiliates and their clients, and have adopted policies,\n\nmanagement oversight, accountability structures, and technology processes designed to safeguard this information.  All of our\n\nemployees are required to attest annually to our information security policies and participate in regular security awareness\n\n20\n\n[Table of Contents](#ibfa0590d77ac4199aa63edb4b8813f49_7)\n\ntraining to protect their information and the AMG data and systems to which they have access.  These trainings also instruct\n\nemployees on how to report any potential privacy or data security issues.\n\nOur information security organization comprises internal and external resources designed to identify, protect, detect,\n\nmitigate, resolve, and recover from various threats and attacks by malicious actors.  We leverage 24x7x365 monitoring tools\n\nand services to address the confidentiality, integrity, and availability of AMG assets and data.  Regular internal and third-party\n\nreviews are performed on our processes and technologies to validate the effectiveness of our privacy and data security controls\n\nand safeguards.  We monitor industry best practices and developments in data privacy and security and have increased scrutiny\n\nof third-party service providers with access to sensitive AMG data, including through security risk assessments at the time of\n\ninitial contract, periodically as part of our third-party risk management process, and upon detection of an increase in the\n\nvendor’s risk profile.  In addition, we require key providers to meet appropriate security requirements and controls, and we\n\ninvestigate security incidents that have impacted our third-party providers, as appropriate.  We also have our own fully\n\ndocumented proprietary security incident response plan, with defined roles and responsibilities that address notification\n\nobligations and incident response procedures in the event of a data security breach.  We are dedicated to business continuity and\n\nresiliency, and have documented strategies, policies, and procedures in place designed to protect employee, business, Affiliate,\n\nand Affiliate client data in the event of an emergency or natural disaster.\n\nAlthough we provide our Affiliates with operational autonomy in managing their businesses and may have limited\n\ninvolvement in the design, oversight, and maintenance of their respective technology systems and networks, we offer \n\ncybersecurity support to Affiliates through our information security program, including with respect to conducting Affiliate\n\nprogram assessments and assisting, as appropriate and practicable, in their identification of, and response to, an actual or\n\nsuspected cybersecurity incident.  Additionally, prior to any investment in a new Affiliate, we conduct a diligence review of its\n\ninformation security program.\n\nWe work with third-party service providers to proactively assess our information security program and provide us with an\n\nindustry view of the cyberthreat landscape, in addition to monitoring and supporting our control environment and breach\n\nnotification and response processes.\n\nAs of the date of this Annual Report on Form 10-K, cybersecurity threats have not materially affected and we believe are\n\nnot reasonably likely to materially affect AMG, including our business strategy, results of operations, or financial condition. \n\nRefer to the risk factor captioned “Failure to maintain and properly safeguard an adequate technology infrastructure may limit\n\nour or our Affiliates’ growth, result in losses or disrupt our or our Affiliates’ businesses” in Part I, Item 1A. “Risk Factors” for\n\nmore information regarding cybersecurity risks and potential related impacts on AMG.\n\nGovernance\n\nWe have a formal information security program, designed to develop and maintain privacy and data security practices to\n\nprotect AMG assets and sensitive third-party information, including personal and Affiliate information.  This program is\n\ngoverned by a committee comprising members of senior management, including our Chief Information Officer (“CIO”), which\n\nmeets regularly and reports to the Board of Directors at least annually (the “Information Security Governance Committee”). \n\nMembers of the Information Security Governance Committee oversee communications with the Board of Directors regarding\n\nmaterial cybersecurity incidents and provide the Board with a summary of risks from current cybersecurity threats on a regular\n\nbasis, as well as updates on management’s information security program oversight and maintenance activities, and any material\n\nchanges to AMG’s information security practices and procedures. The Board of Directors is also regularly provided with\n\ncybersecurity educational sessions, including perspectives from external advisors that are invited to present on current\n\ncybersecurity topics.\n\nWe take a risk-based approach to cybersecurity and have implemented policies throughout our operations that are designed\n\nto address cybersecurity threats and our response to actual or suspected incidents.  In particular, the Information Security\n\nGovernance Committee is responsible for the ongoing identification and assessment of reasonably foreseeable cybersecurity\n\nthreats and based on these assessments, evaluating and overseeing the implementation of safeguards for limiting such risks,\n\nincluding employee training and compliance, and detection and prevention mechanisms.  If a cybersecurity incident occurs, the\n\nInformation Security Governance Committee will assemble an incident response team responsible for the identification,\n\nremediation, and post-incident review of such incident, engage outside advisors and notify third parties as appropriate, and\n\nassess the materiality of the nature, scope, and timing of a given incident and whether public disclosure is required.\n\nThe CIO, in coordination with the Information Security Governance Committee, is responsible for leading the assessment\n\nand management of cybersecurity risks.  The current CIO has over 25 years of experience in information security, including\n\nserving as our CIO since 2016, and holds a B.A. in Business with a focus in Computer Science.  The CIO reports to the Board\n\n21\n\n[Table of Contents](#ibfa0590d77ac4199aa63edb4b8813f49_7)\n\nof Directors as part of the Information Security Governance Committee’s updates discussed above and regularly communicates\n\nwith the other members of the Information Security Governance Committee and senior management regarding cybersecurity\n\nrisks."}