Reporting-line record
Who does the security function report to?
Every public company's 10-K now includes an Item 1C disclosure describing its cybersecurity risk management and, often, who the security function reports to. This record states that line exactly as each filing describes it, one company at a time, built as this site reads filings rather than pulled from a feed. It carries no view on which structure is better; a reporting line is a structural fact, not a mark of quality.
- BK Technologies CorporationBK Technologies' 2025 Form 10-K describes its cybersecurity program as run by the CISO and CFO together, with a reporting line to the CEO.
- Cytokinetics, IncorporatedCytokinetics' 2025 Form 10-K states its Chief Information Security Officer, CEO and CFO together brief the Audit Committee on cybersecurity risk.
- Heritage Commerce CorpHeritage Commerce Corp's 2025 Form 10-K says its CISO reports directly to the COO and regularly to the Board's Audit Committee.
- Leonardo DRS, Inc.Leonardo DRS's 2025 Form 10-K states its Chief Information Security Officer regularly briefs the Board's Government Security Committee.
- Powell Industries, Inc.Powell Industries' 2025 Form 10-K states its Chief Information Security Officer reports to the Chief Financial Officer.
- Urban Outfitters, Inc.Urban Outfitters' fiscal 2026 Form 10-K states its Chief Information Security Officer reports to the Audit Committee at least annually.
- Veeco Instruments Inc.Veeco Instruments' 2025 Form 10-K states its Chief Information Security Officer updates the Audit Committee quarterly and the full Board annually.