{"url_path":"/sec/pyyx/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C Cybersecurity","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-04","source_url":"https://www.sec.gov/Archives/edgar/data/939930/0000939930-26-000017-index.html","accession_number":"0000939930-26-000017","cik":"0000939930","ticker":"PYYX","issuer_name":"PYXUS INTERNATIONAL, INC.","edgar_url":"https://www.sec.gov/Archives/edgar/data/939930/0000939930-26-000017-index.html","primary_entity_key":"0000939930","primary_entity_name":"PYXUS INTERNATIONAL, INC."},"word_count":599,"has_tables":true,"body_markdown":"Item 1C. Cybersecurity\n\nRisk Management and Strategy\n\nThe Company recognizes the importance of maintaining cybersecurity measures to safeguard our information systems and protect the confidentiality, integrity, and availability of our data. Our information security framework leverages information and guidance from external sources and is managed by an internal team, led by the Cybersecurity Manager. This team provides updates on the overall effectiveness of the cybersecurity framework, including information on cyber threats and incidents, to the Information Services leadership team consisting of the Executive Vice President (\"EVP\") – Global Business & Information Services, Vice President (\"VP\") – Global Business Systems, VP – Global Information Technology Operations and Governance,\n\n18\n\nand Senior Director – Data Insights and Innovation. We utilize a multi-layered, risk-based approach to our security controls to prevent, detect, and respond to cybersecurity threats. Our capabilities, processes, and security measures include, and are not limited to:\n\n•reactive endpoint protection to detect and prevent virus and malware threats,\n\n•network perimeter firewalls, including malware prevention,\n\n•e-mail scanning to prevent spam and phishing campaigns,\n\n•vulnerability scanning and remediation of vulnerabilities based on priority,\n\n•logical access controls, including multi-factor authentication,\n\n•incident response procedures, and\n\n•disaster recovery protocols.\n\nThe Company educates its workforce as part of our security awareness program to understand the risks and potential impacts of cybersecurity threats on our business, and ways employees can remain vigilant to prevent cybersecurity incidents from occurring. The program includes annual employee acknowledgement of security related policies, ongoing communication about prevalent vulnerabilities, security awareness training, and simulated phishing campaigns.\n\nWe maintain strategic partnerships with third-party service providers to enhance our security measures and improve resilience against cybersecurity threats. Annual penetration tests are conducted by a third party to evaluate existing security measures and identify improvements. Additionally, the Company engages a managed detection and response service to monitor our end points, identify suspicious activity, and perform actions to prevent or stop attacks.\n\nThe Company maintains a cybersecurity insurance policy that provides coverage for potential losses arising from a cybersecurity incident. Although we maintain cybersecurity insurance, there can be no guarantee that our policy will cover all losses or all types of claims that may arise from such incidents.\n\nGovernance\n\nOur processes for assessing, identifying, and managing material risks from cybersecurity are included in our Enterprise Risk Management (\"ERM\") program. Oversight of the Company's ERM program resides with the Audit Committee and our Board of Directors. The Audit Committee regularly reviews the results from the Company's ERM program with management. The Board of Directors receives updates from the EVP – Global Business & Information Services regarding cybersecurity framework developments and information that may impact the Company’s cybersecurity posture.\n\nThe Company’s EVP – Global Business & Information Services reports to the Chief Executive Officer and has 37 years of experience leading information technology functions, which includes information security and incident management prevention and response. Under the direction of the EVP – Global Business & Information Services and the Chief Executive Officer, an internal team within the Company's Information Services department analyzes cybersecurity risks, considers industry trends, and implements controls, as appropriate, to mitigate these risks.\n\nImpact of Cybersecurity Risks and Threats\n\nAs of the date of this Annual Report on Form 10-K, we are not aware of cybersecurity incidents that have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition. However, there can be no assurance that a material cybersecurity incident will not occur in the future. Additional information on cybersecurity risks is discussed in \"[Item 1A. Risk Factors](#i6f44eae8422d46cd9f377051509c10a4_22),\" which should be read in conjunction with the foregoing information.\n\n19"}