Cybersecurity Program

Cybersecurity Program Overview

Cybersecurity is a core part of BlackRock’s fiduciary responsibility and is integrated into the firm’s governance, risk management, and control framework. BlackRock maintains a multi-layered information security program that is designed to protect the confidentiality, integrity, and availability of information and technology systems. This program supports legal and regulatory obligations and helps sustain client trust through a resilient, well-governed control environment.

Our Commitment

BlackRock is committed to maintaining a resilient and sustainable cybersecurity posture. Our information security program is designed to:

  • Protect client and firm information from unauthorized access, modification, and disclosure
  • Maintain effective controls aligned with legal, regulatory, and industry expectations
  • Continuously identify, assess, monitor, and manage cybersecurity risk
  • Respond to and recover from cyber events in a timely, coordinated manner
  • Promote awareness and accountability for information security across the workforce

Governance and Oversight

The information security program is led by the Chief Information Security Officer (CISO), who is accountable for the design, implementation, and oversight of cybersecurity controls. The CISO provides regular reporting to senior management, the boards, and relevant risk committees.

Governance follows a three-lines-of-defense model, with clear responsibilities across risk management, oversight, and independent assurance. Enterprise and regional risk committees oversee cybersecurity by reviewing threats, vulnerabilities, control effectiveness, and program performance. This structure supports formal escalation, informed decision-making, and accountability at the appropriate levels of the organization.

Risk Management Framework

BlackRock seeks to address cybersecurity risks through a global, multi-layered strategy of control programs that are designed to preserve the confidentiality, integrity and availability of BlackRock information. Information security risks are identified, assessed, and mitigated through ongoing evaluation of internal and external factors, including regulatory developments, threat intelligence, audits, and risk assessments. Controls and risk mitigation strategies are regularly reviewed to reflect changes in the threat landscape and regulatory environment.

Core Cybersecurity Capabilities

BlackRock’s information security program is supported by integrated control domains designed to manage cybersecurity risk across the enterprise, including:

  • Identity and Access Management
  • Threat Detection and Incident Response
  • Secure Technology and Infrastructure
  • Third-Party Risk Management
  • Security Training and Awareness

BlackRock maintains information security policies, standards, and procedures that are aligned to best practices from the industry-recognized frameworks.

Compliance and Industry Standards

BlackRock’s information security program is designed to align with recognized cybersecurity frameworks and regulatory expectations. It uses industry standards, including the NIST Cybersecurity Framework, ISO 27001/27002, and the Cyber Risk Institute framework to support a consistent, risk-based approach to control design, implementation, and evaluation.

Controls are continuously assessed and enhanced to remain aligned with evolving legal, regulatory, and industry expectations.

Commitment to Continuous Improvement

BlackRock’s cybersecurity program is continuously monitored, tested, and improved to support effective risk management and operational resilience. Independent assessments, internal oversight, and regular reporting to governance forums reinforce accountability and transparency. Together, these measures help protect information assets and support the expectations of regulators, clients, and stakeholders.

Security Incident Reporting

If you become aware of a security incident, please escalate in accordance with our Responsible Disclosure Program.