1 unchanged sentence
CYBERSECURITY
−Removed: acknowledge the increasing importance of cybersecurity in today’s digital and interconnected world.
−Removed: Cybersecurity threats pose
−Removed: significant risks to the integrity of our systems and data, potentially impacting our business operations, financial condition and reputation.
−Removed: a smaller reporting company, we currently do not have enhanced cybersecurity measures, a dedicated cybersecurity team or robust protocols
−Removed: in place to manage cybersecurity risks.
−Removed: We have not yet conducted comprehensive risk assessments, established an incident response plan
−Removed: or engaged with external cybersecurity consultants for assessments or services.
−Removed: We intend to invest more resources into improving our
−Removed: assessment and response to cybersecurity risk in the future.
−Removed: our current stage of cybersecurity development, we have not experienced any significant cybersecurity incidents to date.
−Removed: recognize that the absence of a formalized cybersecurity framework may leave us vulnerable to cyberattacks, data breaches and other cybersecurity
−Removed: Such events could potentially lead to unauthorized access to, or disclosure of, sensitive information, disrupt our business
−Removed: operations, result in regulatory fines or litigation costs and negatively impact our reputation among customers and partners.
−Removed: cybersecurity incidents could have material adverse effects on our business strategy, financial condition, and results of operations
−Removed: (e.g., a significant breach could result in direct financial losses due to fraud, system downtime impacting revenue generation, increased
−Removed: compliance costs or contractual liabilities with third-party vendors and customers).
−Removed: are in the process of evaluating our cybersecurity needs and developing appropriate measures to enhance our cybersecurity posture.
−Removed: includes considering the engagement of external cybersecurity experts to advise on best practices, conducting vulnerability assessments
−Removed: and developing an incident response strategy.
−Removed: Our goal is to establish a cybersecurity framework that is commensurate with our size,
−Removed: complexity and the nature of our operations, thereby reducing our exposure to cybersecurity risks.
−Removed: addition, the Board will oversee any cybersecurity risk management framework, and the Board’s governance committee will review
−Removed: and approve any cybersecurity policies, strategies and risk management practices.
−Removed: Board (or designated committee or officer) will receive periodic updates on cybersecurity risks, including emerging threats, mitigation
−Removed: efforts and incident response activities.
−Removed: The updates will be provided at least annually, or more frequently as needed, to ensure cybersecurity
−Removed: risks are appropriately managed and integrated into our broader risk oversight strategy.
−Removed: our efforts to improve our cybersecurity measures, there can be no assurance that our initiatives will fully mitigate the risks posed
−Removed: by cyber threats.
−Removed: The landscape of cybersecurity risks is constantly evolving, and we will continue to assess and update our cybersecurity
−Removed: measures in response to emerging threats.
−Removed: We may consider cybersecurity insurance coverage in the future, which will cover damages from
−Removed: a range of potential cyber security issues including but not limited to property damage, privacy liability, privacy regulatory defense,
−Removed: cyber extortion and post breach remediation.
−Removed: a discussion of potential cybersecurity risks affecting us, please refer to the “ Risk Factors ” section.
+Added: Company recognizes the increasing complexity and significance of cybersecurity risks in safeguarding its technology, operations, proprietary
+Added: systems, and data.
+Added: The Company’s operations rely on interconnected digital infrastructure, cloud-based systems, and proprietary software
+Added: platforms, including systems supporting digital asset management and cryptocurrency operations, making cybersecurity an essential component
+Added: of its risk management framework.
+Added: Company has implemented a cybersecurity program designed to identify, assess, mitigate, and respond to cybersecurity risks.
+Added: is informed by recognized industry practices, including the National Institute of Standards and Technology (“NIST”) Cybersecurity
+Added: Framework (“CSF”).
+Added: The following disclosure outlines the Company’s cybersecurity risk management strategy and governance, including
+Added: the Board’s oversight and management’s role.
+Added: Cybersecurity Risk Management
+Added: Company employs a structured cybersecurity risk management program to assess, identify, and manage cybersecurity risks across its information
+Added: technology environment, including corporate systems and cloud-based platforms.
+Added: The Company currently operates in part through shared
+Added: IT infrastructure and personnel, which provides continuity of cybersecurity controls and practices while the Company develops its standalone
+Added: capabilities.
+Added: Key elements of the program include:
+Added: assessments and periodic evaluation of cybersecurity risks across systems and environments.
+Added: detection and monitoring, including alert triage and investigation, to identify suspicious
+Added: activity and potential incidents.
+Added: ● Vulnerability
+Added: management, including scanning, prioritization, and remediation activities.
+Added: controls and security protections, including multi-factor authentication, encryption protocols,
+Added: and endpoint security measures where appropriate.
+Added: ● Third-party
+Added: risk management, including evaluation of vendors and service providers that may access Company
+Added: data or systems.
+Added: ● Cybersecurity
+Added: risks are evaluated in coordination with management and are considered within the Company’s
+Added: broader operational and enterprise risk considerations.
+Added: Governance and Oversight
+Added: Cybersecurity
+Added: oversight is a shared responsibility between the Company’s Board of Directors and management.
+Added: The Vice President provides cybersecurity
+Added: updates to the full Board as appropriate, including information regarding the Company’s cybersecurity posture, risk environment, incident
+Added: trends, and mitigation efforts.
+Added: The Company is in the process of establishing a formal cadence of cybersecurity reporting to the Board
+Added: as part of its ongoing business transition.
+Added: In addition to scheduled updates, management’s incident response procedures require that
+Added: potential material cybersecurity incidents are escalated to senior leadership and the Board promptly, as appropriate.
+Added: The Company enforces
+Added: a top-down approach to cybersecurity governance, ensuring accountability and continuous risk monitoring at all levels of the organization.
+Added: Management’s Role in Cybersecurity
+Added: is responsible for the day-to-day execution of the Company’s cybersecurity program.
+Added: The Vice President oversees cybersecurity initiatives
+Added: and supervises cybersecurity personnel and processes.
+Added: The Company’s cybersecurity incident response governance is supported by an Incident
+Added: Response Policy that is in the process of being established and will define roles and responsibilities, incident classification, documentation
+Added: expectations, evidence preservation requirements, and communication protocols.
+Added: Cybersecurity Strategy and Resilience
+Added: Company maintains cybersecurity resilience measures designed to support business continuity and protect critical assets.
+Added: These measures
+Added: include monitoring and response capabilities, as well as processes for containment, remediation, and recovery when incidents occur.
+Added: Material Cybersecurity Incidents
+Added: fiscal year 2025, the Company did not experience any material cybersecurity incidents.
+Added: No cybersecurity incidents required disclosure
+Added: under Form 8-K Item 1.05 during 2025.
+Added: Impact of Cyber Incidents
+Added: Cybersecurity
+Added: incidents, if material, could adversely affect the Company’s financial condition, results of operations, operational stability, and reputation.
+Added: Potential impacts may include remediation costs, operational disruptions, litigation or regulatory exposure, and reputational harm.
+Added: Company evaluates cybersecurity risks as part of its ongoing risk assessment processes.
+Added: Board Expertise in Cybersecurity
+Added: Board’s cybersecurity oversight is informed through management briefings and periodic updates.
+Added: The Company may enhance Board education
+Added: on cybersecurity trends and governance practices as appropriate.
+Added: Use of Third-Party Services
+Added: Company uses third-party service providers to support certain technology and security functions.
+Added: Digital asset custody services are provided
+Added: by BitGo, a qualified custodian maintaining its own security controls and compliance frameworks.
+Added: The Company evaluates third-party cybersecurity
+Added: risks through vendor due diligence processes, including review of security documentation and reports where applicable, and monitors third-party
+Added: risks on an ongoing basis.
+Added: Given the nature of the Company’s cryptocurrency-focused operations, the security practices of digital asset
+Added: custodians and blockchain infrastructure providers are a particular focus of the Company’s third-party risk management process.
+Added: Regulatory and Legal Compliance Risks
+Added: Company is subject to cybersecurity and data privacy requirements, including applicable data privacy laws and SEC disclosure requirements.
+Added: Failure to comply with applicable requirements could result in financial penalties, legal liabilities, and reputational harm.
+Added: performs compliance-focused activities as part of its cybersecurity program.
+Added: Incident Response Plan
+Added: Company maintains an incident response policy framework intended to support timely identification, containment, investigation, remediation,
+Added: and recovery.
+Added: Incident response procedures include incident severity classification, escalation, documentation, evidence preservation,
+Added: and communications protocols.
+Added: Cyber Insurance
+Added: Company does not maintain standalone cybersecurity insurance coverage.
+Added: The Company evaluates risk mitigation and risk transfer options
+Added: as part of its broader risk management considerations.
+Added: Historical Cyber Incidents
+Added: Company did not record any material cybersecurity incidents during fiscal year 2025.
+Added: Technology and Infrastructure Risks
+Added: Company’s cybersecurity program includes measures intended to protect systems and data, including monitoring, endpoint protections, access
+Added: controls, and vulnerability management.
+Added: As cybersecurity threats continue to evolve, the Company may adjust its cybersecurity tools,
+Added: processes, and controls over time.
+Added: Data Security and Privacy Policies
+Added: Company maintains policies and controls intended to protect sensitive data, including access controls and other security measures designed
+Added: to safeguard data confidentiality and integrity.
+Added: Ongoing Cybersecurity Efforts
+Added: Company continues to invest in cybersecurity capabilities, including monitoring, vulnerability management, employee awareness training,
+Added: and improvements to policies and procedures, to address evolving cybersecurity threats.
+Added: As a company in transition, the Company expects
+Added: to continue developing its standalone cybersecurity infrastructure and formalizing its governance processes accordingly.
+Added: The Company is currently essentially “virtual.”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.