IBPNYSESEC EDGAREDGAR

Installed Building Products, Inc.

General Bldg Contractors - Residential Bldgs·COLUMBUS, OH·FY end 12/31·CIK 1580905

Board of Directors

9 members · 7 independent · FY 2025
DirectorRoleTenureAgeCommitteesIndep.Annual fees
Michael T. MillerCEO and Director12y61
Marchelle E. MooreDirector3y53CompNCG
Robert H. SchottensteinDirector4y73
Margot L. CarterLead Independent Director11y58AuditNCG
David R. MeuseDirector6y80Comp
Michael H. ThomasDirector12y76Audit
Jeffrey W. EdwardsChair and CEO27y62
Lawrence A. HilsheimerDirector12y68AuditNCG
Janet E. JacksonDirector12y73CompNCG

Risk-factor diff

FY 2025 10-K vs. FY 2024
+5 new5 removed

Net-new paragraphs in the most recent 10-K's Item 1A. Companies rarely add risk language without a real reason — additions here are often a leading signal of management concerns.

NEW · FY 2025

of the Board, which is responsible for oversight of our cybersecurity risk management processes. The chairman of our Audit Committee has earned a CERT Certificate in Cybersecurity Oversight from the National Association of Corporate Directors, which aids the Audit Committee’s understanding of cybersecurity risks and assists the Audit Committee in overseeing the risk management program.

NEW · FY 2025

The Audit Committee and the Board actively participate in discussions with management and amongst themselves regarding cybersecurity risks. Senior leadership, including our CIO, briefs the Board and the Audit Committee on cybersecurity risks and the effectiveness of our cybersecurity program as part of updates on our overall ERM program. Our Vice President of Internal

NEW · FY 2025

Audit also provides the Audit Committee with an assessment of any material changes to cybersecurity risks and controls as a result of cybersecurity threats on at least a semi-annual basis.

NEW · FY 2025

IT and/or IS inform the CIO concerning cybersecurity risks and events, including any mitigation and remediation efforts. Cybersecurity incidents are escalated to the Incident Response Team (“IRT”), which is headed by the CIO. The IRT is responsible for overseeing our incident response strategy, including remediation. For ongoing events, those responsible for investigating the incident are required to continuously update the IRT and the CIO until the event is considered to be resolved. Significant cybersecurity incidents are referred to a committee responsible for evaluating whether the inciden…

NEW · FY 2025

using criteria based on our ERM program. This committee is comprised of a cross functional team of various senior members of management including the areas of Finance, Accounting, Legal, IT, IS and Risk.

Policies & disclosures

Clawback, anti-hedging, stock ownership, and related-party policies will populate from extracted proxy sections.