Unresolved Staff Comments
+Added: The Company first received a comment letter from the staff of the Division of Corporation Finance (the “Staff”) of the Securities and Exchange Commission (the “Commission”) dated April 25, 2025 relating to the Company’s Form 10-K, filed with the Commission on February 28, 2025.
+Added: The Company has responded to the Staff on their initial questions and subsequent questions and we have made revisions to clarify certain factual portions of our disclosure in response.
+Added: As of December 31, 2025, we do not believe any of the revisions or unresolved comments would have a material impact on our business, operations, or financial results.
+Added: Once formally resolved, further updates will be made in future filings.
Cybersecurity
Risk Management and Strategy Disclosure
−Removed: The Company’s Information Security team is responsible for executing the Company’s enterprise-wide cybersecurity strategy, which is based upon the Center for Internet Security’s best practice controls, including
−Removed: providing subject matter expertise, accountability, and oversight in the areas of policy and standards development, security architecture, engineering, and development practices, third-party IT and Security risk, compliance with industry, state, and federal regulations, and security education, awareness, and training.
+Added: The Company’s Information Security team is responsible for executing the Company’s enterprise-wide cybersecurity strategy, which is based upon the Center for Internet Security’s best practice controls, including providing subject matter expertise, accountability, and oversight in the areas of policy and standards development, security architecture, engineering, and development practices, third-party IT and Security risk, compliance with industry, state, and federal regulations, and security education, awareness, and training.
The Information Security program is managed and overseen by a full-time Chief Information Security Officer (“CISO”) with over 29 years in information technology leadership, service management, operations, information security, risk management, and regulatory compliance.
13 unchanged sentences
As set forth in the Company’s charter, our Audit Committee, comprised of fully independent directors, is responsible for reviewing with management of the Company, the Company’s policies and practices with respect to risk assessment and risk management, including cybersecurity risk.
−Removed: The CRO reports information and cybersecurity risks to the Audit Committee.
+Added: The CRAO reports information and cybersecurity risks to the Audit Committee.
F&G has adopted a “three lines of defense” governance model for information and cybersecurity risk management.
4 unchanged sentences
The assessment results are presented at quarterly Operational Risk Sub-Committee (“ORSC”) and ERMC meetings.
−Removed: ERM, jointly with the Information Security professionals, annually conducts a Cybersecurity Risk Assessment based
−Removed: on critical security controls set forth by the Center for Internet Security.
+Added: ERM, jointly with the Information Security professionals, annually conducts a Cybersecurity Risk Assessment based on critical security controls set forth by the Center for Internet Security.
The assessment is reported to the CRO, CISO and CIO.
19 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.