Cybersecurity Our Cybersecurity Disclosure Policy and Incident Response Plan establish acceptable uses of electronic devices, communications systems and network resources as well as a framework for reporting and managing cybersecurity incidents. Our Board and senior management oversee matters relating to cybersecurity. Under its charter, the Audit and Finance Committee of our Board is responsible for reviewing the security of our information technology systems and operations, including programs and defenses against cyber threats. The full Board is briefed on cybersecurity at least annually and receives more frequent updates as needed. Our Audit and Finance Committee has direct oversight for cyber risk and receives quarterly updates. Our Senior Vice President and Chief Financial Officer is responsible for cybersecurity matters at the management level. Employees complete cybersecurity training programs semiannually or more frequently as warranted by changes to the business operating environment. In 2024, 100% of Royal Gold employees completed cybersecurity training. CYBER RISK SCORE 790 ISS Cyber Risk Score as of January 20, 2025 The Information Security Standard (ISS) Cyber Risk Score predicts the likelihood of an organization suffering a material cybersecurity breach within a 12-month period. Appendices Investment Stewardship Operators and Communities Our People Governance About Royal Gold Introduction ROYAL GOLD 41 2024 Investment Stewardship Report “At Royal Gold, cybersecurity is everyone’s responsibility. Continued investment in employee training ensures that we stay vigilant against cyber threats, protecting our data, our business and the trust of our partners.” Paul Libner Royal Gold Senior Vice President and Chief Financial Officer
2024 Investment Stewardship Report Page 40 Page 42