While no company is immune from attempted cyberattacks, Cleveland-Cliffs has not experienced an information security breach resulting in a material impact to the Company in the last three years. During that period, the Company has incurred no material expenses and has paid no penalties or settlements arising from information security breaches.

From time to time, vendors and business partners notify us of cybersecurity incidents in their own environments. The Company maintains a formal third-party risk management program to assess, monitor, and respond to these events; no third-party incident has resulted in a material impact to the Company.

The Company's information security program is aligned with recognized industry frameworks, including standards published by NIST, the National Institute of Standards and Technology of the U.S. Department of Commerce. Elements of the program are assessed by independent third parties, information technology general controls are tested annually by Internal Audit and by the Company's independent external auditor, and the Company maintains information security risk insurance.