While no company is immune from attempted attacks, Cleveland-Cliffs has not experienced an information security breach resulting in a material impact to the Company in the last three years. During that period, the Company has incurred no material expenses and has paid no penalties or settlements arising from information security breaches.
From time to time, vendors and business partners notify us of cybersecurity incidents in their own environments. The Company maintains a formal third-party risk management program to assess, monitor, and respond to these events; no third-party incident has resulted in a material impact to the Company.
The Company's information security program is aligned with recognized industry frameworks, including standards published by NIST. Elements of the program are assessed by independent third parties, information technology general controls are tested annually by Internal Audit and by the Company's independent external auditor, and the Company maintains information security risk insurance.