UNRESOLVED STAFF COMMENTS
−Removed: Not applicable.
CYBERSECURITY
−Removed: We recognize the critical importance of creating a multifaceted defense-in-depth cybersecurity ecosystem to protect the confidentiality, integrity, and availability of Company systems and data.
−Removed: Managing Material Risk
−Removed: The Company’s approach to risk management is tailored to its reporting segments.
−Removed: FrameVR.io, which was moved to the North American Realty segment during the first quarter of 2025, independently identifies, assesses, and manages its material risk from cybersecurity threats, and North American Realty, International Realty, and, recently, Other Affiliated Services, operate under a joint risk framework due to the similarities in cybersecurity risk they face.
−Removed: While educational resources about cybersecurity risks are shared amongst Information Technology (“IT”) staff across segments, segment-specific IT staff are empowered to evaluate and address cybersecurity risks within their reporting segment in alignment with the Company’s overall business objectives and operational needs.
−Removed: Where required, IT staff in each reporting segment may communicate with their counterparts in different reporting segments or with executive management of the Company to ensure compliance with cybersecurity incident and data breach reporting requirements under applicable law.
−Removed: Staff across all segments are required to complete company facilitated cybersecurity training at least annually.
−Removed: Engage Third Parties on Risk Management
−Removed: Understanding the complexity and evolving nature of cybersecurity threats, each reporting segment may engage with a range of external experts, including cybersecurity assessors and consultants, to assess, identify, and manage material risks posed by cybersecurity threats, as determined by each reporting segment.
−Removed: Each reporting segment may enable external technologies and specialists, as deemed necessary by the reporting segment, to test, alert, and report on the Company’s various computing ecosystems.
−Removed: These external assets allow the reporting segment leaders to leverage cybersecurity tools applicable to their segment’s risks, ensuring our cybersecurity strategies and processes continue to align with business objectives and operational needs.
−Removed: Segment personnel that engage such third-parties collaborate with these third-parties to review and discuss vulnerabilities and threats, consult on security enhancements for better risk identification, and audit risk management systems.
−Removed: Oversee Third -Party Risk
−Removed: The Company recognizes that third-party service providers may introduce cybersecurity risks related to access to certain systems and data.
−Removed: The Company’s cybersecurity processes include documentation of certain third-party service providers’ security postures, with risk-related information recorded in TrustArc or similar internal tracking tools.
−Removed: Where applicable, these processes involve requesting third-party audit reports.
−Removed: Certain third-party relationships, including individual AI licenses and vendors onboarded through non-IT channels, may not be documented or reviewed as part of the Company’s cybersecurity processes.
−Removed: Where applicable, the Company maintains written contractual provisions requiring third-party service providers to report security incidents.
−Removed: Any information obtained through such reporting may be reviewed and recorded by security personnel.
−Removed: The Company does not routinely provide feedback to third parties on identified risks but may document available security information to facilitate internal awareness.
−Removed: Risk of Cybersecurity Threats
−Removed: To date, the Company has not identified a cybersecurity threat in any reporting segment, including as a result of any previous cybersecurity incidents, that has or is reasonably likely to have a current or future material effect on our business strategy, financial condition, results of operations, liquidity, capital expenditures, or capital resources.
−Removed: For more information regarding risks from cybersecurity threats, see “Item 1A - Risk Factors” in this Annual Report, in particular under the caption “Cybersecurity incidents could disrupt our business operations, result in the loss of critical and confidential information, adversely impact our reputation and harm our business.”
−Removed: Cybersecurity Governance
−Removed: The Company’s Board of Directors (the “Board”) is aware of the critical nature of managing risks associated with cybersecurity threats and meets regularly to discuss managing risk from cybersecurity threats, among other risks facing the Company.
−Removed: The Board has established oversight mechanisms to manage risks associated with cybersecurity threats.
−Removed: Board of Directors Oversight
−Removed: The Board’s Nominating and Corporate Governance Committee is central to the Board’s oversight of cybersecurity risks and bears the primary responsibility for cybersecurity risk oversight.
−Removed: When required, additional information is provided from the IT management from North American Realty and additional staff for each reporting segment for further insight and analysis.
−Removed: The Company is continually monitoring its cybersecurity oversight, strategy and governance for improvement and refinement.
−Removed: Management’s Role Managing Risk
−Removed: The Company’s Chief Technology Officer (“CTO”) oversees cybersecurity risks for North American Realty, International Realty, and, as of recently, Other Affiliated Services;
−Removed: provided, however, that cybersecurity risk management for FrameVR.io, which was moved to the North American Realty segment during the first quarter of 2025, is overseen by the Vice President of FrameVR.io, in consultation with the CTO as requested.
−Removed: The CTO provides comprehensive briefings to the Nominating and Corporate Governance Committee on a quarterly basis covering a broad range of topics, including, without limitation:
−Removed: ● Current cybersecurity landscape and emerging threats;
−Removed: ● Status of ongoing cybersecurity initiatives and strategies within his purview;
−Removed: ● Incident reports and learnings from any cybersecurity events;
−Removed: ● Compliance with regulatory requirements and industry standards.
−Removed: The CTO receives updates on any significant developments in the cybersecurity domain from North American (excluding FrameVR.io), International Realty, and, recently, Other Affiliated Services which the CTO then reports to the Nominating and Corporate Governance Committee, ensuring the Board’s oversight is proactive and responsive.
−Removed: Personnel from FrameVR.io are empowered to report cybersecurity risk to their respective leaders who may then report to the Nominating and Corporate Governance Committee directly or funnel such reporting to the CEO.
−Removed: Risk Management Personnel
−Removed: Primary oversight and responsibility for managing the Company’s cybersecurity risks resides with the CEO.
−Removed: With over 25 years of experience in technology leadership, entrepreneurship, and real estate innovation, his expertise lies in leveraging technology to transform traditional industries, including pioneering the first fully cloud-based real estate brokerage model.
−Removed: The CEO’s career began in the technology sector, where he founded eShippers.com, an eCommerce and logistics platform that integrated online storefronts with a national fulfillment network.
−Removed: This experience in developing scalable, technology-driven solutions laid the groundwork for his later success in building the Company .
−Removed: His vision for integrating advanced IT systems into real estate has driven eXp Realty’s growth to over 82,000 agents across 24 countries.
−Removed: He holds a degree in Economics and Computer Science from the University of Oklahoma, which supports his ability to align technology initiatives with strategic business goals.
−Removed: Under the CEO’s leadership, the Company continues to innovate through immersive virtual environments, advanced data systems, and scalable global operations, ensuring its position as a leader in real estate technology.
−Removed: Accompanying the CEO with the development of the security ecosystem is key personnel at each reporting segment, including:
−Removed: ● North American Realty and International Realty’s Chief Innovation Officer.
−Removed: The person in this role has over 20 years of experience as a technologist, startup founder, and technology executive with expertise in software development, product management, and real estate technology innovation.
−Removed: He holds a Bachelor of Arts from the College of Charleston and has led transformative technology initiatives, including two successful PropTech startup exits.
−Removed: ● North American Realty and International Realty’s Chief Technology Officer.
−Removed: The person in this role has over 20 years of experience leading global technology teams, delivering innovative software solutions, and driving business transformation.
−Removed: He is experienced in building and delivering secure, scalable technology solutions, with a focus on software reliability, data integrity, and secure system architecture.
−Removed: He is also actively expanding his expertise in cybersecurity, focusing on cloud security, threat mitigation, and risk management to strengthen enterprise system protection.
−Removed: He holds a Master of Science in Computer Science and a Bachelor of Engineering in Mechanical Engineering.
−Removed: He also completed a postgraduate degree in AI and machine learning from the University of Texas at Austin.
−Removed: ● North American Realty and International Realty’s Senior Director of Information Security.
−Removed: The person currently in this role has over 25 years of experience managing enterprise level cyber security programs in various industries in addition to having a Bachelor of Science in Information Technology Management and is a Certified Information Security Manager (CISM), along with ITIL and ISO certifications.
−Removed: ● North American Realty and International Realty’s Senior Director of Data Privacy & GRC.
−Removed: The person in this role has over 15 years of experience in data privacy, governance, and compliance, with expertise in managing enterprise-wide privacy programs and mitigating regulatory risks.
−Removed: She holds a Master of Public Administration and a Bachelor of Science in Political Science, both from Kennesaw State University, and is a Certified Information Privacy Manager (CIPM) and Certified Data Privacy Solutions Engineer.
−Removed: ● Vice President, FrameVR.io.
−Removed: The person currently in this role has Master in Education Technology and a decade working at the intersection of collaboration and spatial computing as a developer and technical product manager.
−Removed: They also have general experience working with information security and privacy frameworks such as SOC-2, GDPR, and COPPA.
−Removed: The Vice President of FrameVR.io reports to the CIO.
−Removed: Monitoring Cybersecurity Incidents
−Removed: Daily security assessments, alert monitoring, and the management of cybersecurity threats are the responsibility of each reporting segment and each reporting segment deploys an approach that is tailored to their risk environment within the Company and its overall business objectives.
−Removed: Notwithstanding the foregoing, Frame.
−Removed: FrameVR.io is independently responsible for its assessments, alert monitoring, and management of cybersecurity threats.
−Removed: When appropriate, each reporting segment escalates information to the CEO of the Company or CTO to ensure awareness of relevant cybersecurity risks across the reporting segments and to enable required incident management procedures applicable to each reporting segment.
−Removed: The reporting segments and FrameVR.io provide information and analysis to aid in the remediation of cybersecurity incidents.
−Removed: Reporting to Board of Directors
−Removed: The CTO , together with reporting segment and FrameVR.io key personnel listed above and with input from the CEO, inform the Nominating and Corporate Governance Committee of relevant material aspects related to cybersecurity risks and threats.
−Removed: This ensures the highest levels of oversight are aware and updated about the cybersecurity posture and potential risks facing the
−Removed: Furthermore, cybersecurity incidents, strategic risk management decisions, and materiality analysis are escalated to the Board, ensuring that they have comprehensive oversight and can provide guidance on critical cybersecurity issues.
+Added: The Company maintains a cybersecurity program designed to identify, assess, and manage material risks from cybersecurity threats across all business segments.
+Added: Our cybersecurity program considers cybersecurity risks alongside other company risks as part of our overall enterprise risk assessment process, and shares common methodologies, reporting channels and governance processes that apply to other risks impacting the company, such as regulatory, financial and operational risks.
+Added: Each reporting segment is responsible for monitoring and responding to risks within its operations, supported by annual training, standardized controls, and companywide policies.
+Added: The Company engages third-party consultants and technology providers to test and evaluate its security posture, provide independent assessments, and support remediation efforts.
+Added: The Company also assesses cybersecurity risks presented by key suppliers and service providers , document their security posture through internal tools, and in certain cases requires third party audit reports or contractual notification of security incidents.
+Added: Daily monitoring and incident response activities are carried out by IT staff, with escalation protocols to the Company’s Chief Technology Officer (“CTO”) and Chief Executive Officer (CEO) as appropriate.
+Added: FrameVR.io maintains its own cybersecurity program in consultation with the CTO.
+Added: The Company has processes in place to log, track, and remediate incidents, and to coordinate responses across reporting segments.
+Added: To date, the Company has not identified any cybersecurity threats or incidents that have had, or are reasonably likely to have, a material effect on the Company’s business strategy, financial condition, or results of operations.
+Added: Oversight of risks from cybersecurity threats is provided by the Board through the Board’s Nominating and Corporate Governance Committee , which receives quarterly reports from the CTO on emerging threats, program initiatives, regulatory compliance, and any incident activity.
+Added: The CTO, in coordination with IT team members and legal team support segment leaders, ensures that significant developments are escalated to the Board, and the CEO retains ultimate responsibility for the Company’s cybersecurity risk management.
+Added: The CEO has over 25 years of technology leadership experience.
+Added: The CEO also holds a degree in Economics and Computer Science from the University of Oklahoma, which supports his ability to align technology initiatives with strategic business goals.
+Added: The CTO has over 20 years of experience leading digital product and technology teams with a focus on delivering innovative software solutions that have served millions of consumers globally and internal enterprise groups.
+Added: She drives business transformation through secure, scalable platforms focused on software reliability, user experience, data integrity, and system architecture.
+Added: She has extensive experience in dealing with system security implementations, data architectures, risk mitigation and system protections.
+Added: She holds a Master of Business Administration, with a specialty in Executive Leadership, from Royal Roads University and undergraduate degrees from Queen's University and the University of British Columbia .
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.