{"url_path":"/sec/sunb/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C Cybersecurity.","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-23","source_url":"https://www.sec.gov/Archives/edgar/data/2083785/0001628280-26-044888-index.html","accession_number":"0001628280-26-044888","cik":"0002083785","ticker":"SUNB","issuer_name":"Sunbelt Rentals Holdings, Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/2083785/0001628280-26-044888-index.html","primary_entity_key":"0002083785","primary_entity_name":"Sunbelt Rentals Holdings, Inc."},"word_count":1387,"has_tables":true,"body_markdown":"Item 1C.    Cybersecurity.\n\nWe rely on information technology systems, digital platforms, networks, cloud services, third-party vendors, and other service providers to support our operations, customer service, financial reporting, supply chain, and administrative functions. As a result, cybersecurity threats present risks to the confidentiality, integrity, and availability of our systems and information, as well as to business continuity, regulatory compliance, and stakeholder trust.\n\nCybersecurity Risk Management Program\n\nWe have developed and maintain a cybersecurity risk management program designed to assess, identify, and manage risks from cybersecurity threats. The program is informed by and aligned with industry-recognized frameworks, including the National Institute of Standards and Technology Cybersecurity Framework and the Payment Card Industry Data Security Standard. The program is supported by policies, standards, and procedures establishing expectations for cybersecurity governance, risk management, incident response, and the protection of our systems and information.\n\nCybersecurity risks are considered as part of our Enterprise Risk Management process and may inform risk mitigation plans, resource allocation, strategic initiatives, and reporting to management, executive leadership, and, as appropriate, the Board or its Audit Committee.\n\nRisk Assessments\n\nWe conduct cybersecurity risk assessments periodically and in connection with significant changes to our technology environment, business processes, or risk profile, as appropriate. These assessments are designed to identify and evaluate cybersecurity risks that could affect the confidentiality, integrity, or availability of our systems and information, including risks associated with critical systems, sensitive information, third-party vendors and service providers, regulatory requirements, and emerging technologies. Results from these assessments are used, as appropriate, to inform risk mitigation plans, control enhancements, resource prioritization, and reporting to management, executive leadership, and, as appropriate, the Board or its Audit Committee.\n\nTechnical Safeguards and Monitoring\n\nWe maintain a layered cybersecurity strategy that includes technical safeguards, monitoring capabilities, and security processes designed to help protect our systems and information from cybersecurity threats. These safeguards may include, as appropriate, network security controls, endpoint protection, identity and access management controls, vulnerability management, email and cloud security tools, logging and alerting capabilities, and other technologies designed to support prevention, detection, analysis, containment, eradication, and recovery. We also use monitoring tools and processes across our network, endpoint, and cloud environments, together with threat intelligence and threat hunting activities, to support proactive awareness of potential threats, suspicious activity, vulnerabilities, and emerging attack techniques. Information from these activities may be used to prioritize remediation efforts, enhance security controls, inform incident response activities, and report relevant trends or risks to management.\n\nIncident Response and Recovery\n\nWe maintain a Cybersecurity Incident Response Plan (“IRP”) that is regularly reviewed and updated. The IRP includes playbooks for common incident types. We periodically evaluate our IRP’s processes through tabletop exercises, technical simulations, and other readiness activities involving members of management and relevant functional stakeholders. These exercises are designed to assess escalation procedures, decision-making, communications, recovery capabilities, and opportunities to improve our preparedness for cybersecurity incidents.\n\nWe maintain backup and recovery processes designed to support business continuity and the restoration of critical systems and information following a cybersecurity incident, system disruption, or other business interruption.\n\n37\n\n[Table of Contents](#i569de63b8944464ca95bf3044154e78f_7)\n\nThird-Party Risk Management\n\nWe maintain a risk-based third-party cybersecurity risk management process designed to assess cybersecurity risks associated with vendors, service providers, and other third parties that access our systems or information. This process may include due diligence, contractual security requirements, review of independent audit reports, periodic reassessments, and additional risk mitigation activities based on the nature and criticality of the relationship.\n\nSecurity Awareness and Education\n\nWe maintain a security awareness and education program that includes simulated email phishing campaigns, computer-based training content, periodic newsletters and communications, and other initiatives to educate employees on the vital role they play in keeping our systems and information secure. Employees are required to complete cybersecurity awareness training as part of onboarding and are also provided with training content and communications throughout the calendar year. Certain employees may receive additional role-based training based on their job responsibilities and access to our systems or information.\n\nAssessment, Testing, and Continuous Improvement\n\nWe engage in periodic assessments and testing of our cybersecurity risk management program to evaluate the program’s effectiveness and identify opportunities for improvement. These activities may include vulnerability scanning, penetration testing, application security testing, red team and purple team exercises, incident response tabletop exercises, and other readiness or resilience activities. Testing and assessment activities are performed by qualified internal resources, external cybersecurity advisors, or a combination of both, as appropriate. Results from these activities are reviewed by management and may be used to prioritize remediation activities, enhance technical and operational controls, update policies and procedures, inform training and awareness efforts, and support reporting to management, executive leadership, and, as appropriate, the Board or its Audit Committee.\n\nManagement engages external cybersecurity advisors, assessors, consultants, auditors, outside counsel, and other third-party experts, as appropriate, to assist with assessments, testing, incident response readiness, regulatory considerations, and program improvement.\n\nImpact of Cybersecurity Risks\n\nTo date, we are not aware of any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition. For a discussion of risks from cybersecurity threats that could be reasonably likely to materially affect us, see the risk factor entitled “Disruptions in our or our third-party vendors’ information technology systems could adversely affect our operating results by limiting our ability to effectively monitor and control our operations, adjust to changing market conditions, implement strategic initiatives or support our online ordering system” under Item 1A “Risk Factors.”\n\nGovernance\n\nThe Board oversees risks from cybersecurity threats directly and through its Audit Committee. The Audit Committee has primary responsibility for oversight of cybersecurity risk management and receives reports from management at least annually and more frequently as appropriate. The Board also receives updates on cybersecurity matters, including significant cybersecurity risks, program maturity, incident trends, and significant cybersecurity incidents, as appropriate.\n\nManagement's Role\n\nManagement is responsible for assessing and managing material risks from cybersecurity threats. Our information security organization is led by the Senior Vice President, Technology Operations Support and Security, who oversees our information security strategy, security operations, and governance, risk, and compliance program. The Senior Vice President, Technology Operations Support and Security has over 30 years of experience in information technology, cybersecurity, infrastructure, risk management, and related disciplines.\n\nThe Senior Vice President, Technology Operations Support and Security is supported by the Director, Information Security Risk and Compliance and the Director, Information Security Operations and Engineering. The Director, Information Security Risk and Compliance is responsible for governance, risk, and compliance, cybersecurity policy governance, security awareness, vulnerability management, and third-party cybersecurity risk management, and has 14 years of experience in information technology, cybersecurity, auditing, risk management, compliance, security awareness, and vulnerability management. The Director, Information Security Operations and Engineering is responsible for security\n\n38\n\n[Table of Contents](#i569de63b8944464ca95bf3044154e78f_7)\n\noperations, engineering, monitoring, incident response, threat intelligence, security tooling, and technical security controls, and has 35 years of experience in information technology, cybersecurity operations, engineering, incident response, threat monitoring, and related disciplines.\n\nInformation security leadership meets at least monthly, or more frequently as needed, to discuss the threat landscape, key risks, and associated mitigation strategies. Management monitors cybersecurity risks through established security processes, reporting channels, assessment activities, and escalation procedures, and the Senior Vice President, Technology Operations Support and Security reports cybersecurity matters to executive leadership and, as appropriate, the Board or its Audit Committee.\n\nProcesses for Monitoring and Reporting\n\nThe Company has established escalation procedures designed to ensure that cybersecurity incidents meeting defined severity or reporting thresholds are communicated to appropriate members of management, executive leadership, and, where appropriate, to the Board or its Audit Committee. These procedures are intended to support timely assessment of potential business impact, materiality, and disclosure obligations.\n\nManagement is informed about the prevention, detection, mitigation, and remediation of cybersecurity incidents through multiple channels, including continuous monitoring tools and alerts, threat intelligence feeds, regular reports from our Security Operations Center (“SOC”), third-party SOC services, and the escalation procedures established in our IRP. When a potential incident is identified, our Cybersecurity Incident Response Team (“CSIRT”) is activated. Based upon the IRP’s established escalation processes and thresholds, the CSIRT’s Incident Response Commander, in coordination with General Counsel and other relevant stakeholders, evaluates the incident's severity, potential materiality, and any associated reporting obligations."}