2 unchanged sentences
Risk Management and Strategy
−Removed: To mitigate cybersecurity risks, we continuously assess and enhance our security processes and procedures.
−Removed: We collaborate with industry-leading managed security service providers to strengthen our ability to identify, assess, prevent, and respond to cybersecurity threats.
−Removed: Our information technology operations and security processes are being aligned with the National Institute of Standards and Technology (NIST) framework to further standardize and improve our security posture.
−Removed: As part of our commitment to a cloud-first strategy, we prioritize the use of SaaS-based solutions for critical business functions.
−Removed: These third-party providers conduct annual Statement on Standards for Attestation Engagements ("SSAE") audits, ensuring compliance with industry best practices.
−Removed: We have adopted a cybersecurity risk management framework designed to identify and mitigate potential cybersecurity risks, which is being integrated into our overall enterprise risk management program.
−Removed: Our risk assessments are informed by third-party cybersecurity experts, who conduct annual internal penetration tests and monthly vulnerability scans to continuously evaluate and strengthen our security posture.
−Removed: Cybersecurity risks are categorized using a Critical, High, Medium, and Low risk scoring methodology.
−Removed: These assessments are performed through a combination of automated tools, manual audits, and expert evaluations, allowing us to implement effective controls that enhance our security framework.
−Removed: In addition, we have introduced annual cybersecurity awareness training, phishing simulations, and ongoing communication initiatives to strengthen organizational awareness of cybersecurity risks and threat prevention.
−Removed: To date, we and our subsidiaries have not experienced any material cybersecurity incidents.
−Removed: Cybersecurity is a key component of our enterprise risk oversight framework, with our Board of Directors actively engaged in overseeing cybersecurity risk management.
−Removed: While management is responsible for day-to-day cybersecurity operations, the Board ensures that our cybersecurity risk management strategies are effectively implemented.
−Removed: The Board is briefed on material cybersecurity incidents as necessary to maintain transparency and informed decision-making.
−Removed: Our Vice President of Information Technology leads our cybersecurity strategy, programs, and risk management processes.
−Removed: With over 30 years of experience in IT, including 15+ years in cybersecurity, the Vice President provides strategic oversight and ensures alignment with industry best practices.
−Removed: This role is supported by a team of cybersecurity professionals with formal training and specialized expertise, as well as partnerships with managed security service providers focused on proactive threat detection, incident response, and risk mitigation.
−Removed: As part of our annual enterprise risk assessment, cybersecurity risks are ranked and reviewed by executive management.
−Removed: In the event of a cybersecurity incident, the Vice President of Information Technology, in collaboration with our cybersecurity partners, would conduct a comprehensive impact assessment.
−Removed: This assessment would outline both potential and actual risks, along with
−Removed: necessary remediation steps.
−Removed: If an incident is deemed material, the Vice President would escalate the matter to the Board of Directors, who would determine whether disclosure to customers or investors is required.
+Added: Cybersecurity is embedded within Comstock’s enterprise risk management framework and is treated as a core operational priority.
+Added: Over the past year, the Company materially strengthened its cybersecurity governance structure, formalized policy oversight, expanded independent testing, and enhanced preventive and detective controls across the organization.
+Added: Our cybersecurity program is aligned with the National Institute of Standards and Technology Cybersecurity Framework and is integrated into the Company’s broader risk oversight processes.
+Added: In 2025, Comstock formalized and implemented a comprehensive Written Information Security Policy Framework, which was approved by the Board of Directors.
+Added: This framework establishes defined risk classifications, control standards, documentation requirements, and escalation protocols.
+Added: During the year, we enhanced and formalized our Incident Response Plan to include severity-based classifications, executive notification thresholds, structured remediation workflows, defined disclosure evaluation procedures, and coordinated response procedures with external security partners.
+Added: Independent Monitoring, Detection, and Testing
+Added: We have engaged nationally recognized cybersecurity firms to provide continuous monitoring and independent validation of our control environment.
+Added: These services include:
+Added: • 24x7 managed detection and response
+Added: • Continuous endpoint monitoring
+Added: • Monthly external vulnerability scanning
+Added: • Annual independent penetration testing
+Added: • Email threat monitoring and impersonation defense
+Added: • Incident triage and forensic response support
+Added: Vulnerabilities and findings are ranked using a standardized Critical, High, Medium, and Low methodology and tracked from discovery through remediation to closure.
+Added: This risk-ranking model is incorporated into our enterprise risk matrix and reviewed quarterly with executive leadership and the Audit Committee.
+Added: The expansion of third-party monitoring, formal testing, and documented remediation tracking materially strengthened our ability to detect, contain, and remediate potential cybersecurity threats.
+Added: To date, we have not experienced a material cybersecurity incident.
+Added: We experience routine cybersecurity threats and attempts;
+Added: however, none have had a material impact, or are reasonably likely to have a material impact, on the Company’s operations, financial condition, or results of operations.
+Added: Identity, Endpoint, and Cloud Controls
+Added: Consistent with our cloud-first operating strategy, we prioritize SaaS-based enterprise platforms hosted by providers that undergo independent annual audit examinations, including SOC reporting.
+Added: We maintain a structured third-party risk management process that includes review of service provider security practices, evaluation of independent audit reports, contractual security requirements, and notification expectations in the event of a cybersecurity incident.
+Added: During the year, we strengthened core security controls across identity and endpoint management, including:
+Added: • Enterprise-wide multi-factor authentication enforcement
+Added: • Centralized identity governance and conditional access controls
+Added: • Privileged access management oversight
+Added: • Advanced endpoint detection and response deployment
+Added: • Business email compromise and impersonation protections
+Added: • Mobile device management and remote security enforcement
+Added: These measures reduce exposure to credential compromise, ransomware, phishing-based attacks, and unauthorized access risks across our environment.
+Added: Security Awareness and Organizational Discipline
+Added: We formalized a structured cybersecurity training program applicable to all employees.
+Added: All new hires complete mandatory cybersecurity awareness training during onboarding, including phishing identification and reporting procedures.
+Added: Comstock conducts quarterly phishing simulation campaigns across the organization.
+Added: Ongoing communication reinforces awareness, accountability, and reporting expectations across the Company.
+Added: Incident Review and Operational Resilience
+Added: Cybersecurity incidents are reviewed quarterly by the Vice President and Head of IT and presented to the Audit Committee of the Board of Directors and executive leadership team.
+Added: This recurring cadence supports trend analysis, accountability, and continuous improvement.
+Added: We maintain documented backup and recovery procedures designed to preserve operational continuity.
+Added: Backup integrity is monitored and recovery processes are periodically evaluated to support defined resilience objectives and company standards.
+Added: External cybersecurity partners serve as first responders in the event of a suspected incident, providing containment guidance, forensic analysis, and remediation support.
+Added: Management Oversight
+Added: The Company’s cybersecurity program is overseen by the Vice President and Head of IT , who is responsible for cybersecurity strategy, policy governance, vulnerability management, third-party security oversight, and coordination of incident response activities.
+Added: The Vice President and Head of IT has more than 30 years of experience in information technology and over 15 years in technology leadership roles, including oversight of enterprise infrastructure, cloud platforms, and cybersecurity risk management programs.
+Added: In this role, the Vice President and Head of IT oversees the Company’s security technologies and managed security service providers, monitors emerging threats and vulnerabilities, and evaluates cybersecurity risks across the Company’s information systems.
+Added: Cybersecurity posture, incident trends, and control enhancements are reviewed quarterly with executive leadership and the Audit Committee of the Board of Directors, ensuring cybersecurity risk remains visible, measurable, and accountable at the highest levels of management.
+Added: Board Oversight
+Added: The Board of Directors formally approved the Comstock’s Written Information Security Policy Framework and assigned cybersecurity oversight responsibility to both the Company's General Counsel and the Vice President and Head of IT.
+Added: The Company’s General Counsel, in partnership with the Vice President and Head of IT, provides regular updates to the Board of Directors regarding cybersecurity posture, risk exposure, and significant control enhancements.
+Added: In the event of a cybersecurity incident determined to be material, management would promptly inform the Board of Directors.
+Added: In consultation with the Company’s General Counsel, the Board would evaluate disclosure obligations and stakeholder communications as required.
+Added: Continued Program Advancement
+Added: Over the past year, Comstock transitioned from foundational controls to a formally governed, independently tested, and continuously monitored cybersecurity program with defined executive and Board oversight.
+Added: Key advancements include:
+Added: • Board-approved Written Information Security Policy Framework
+Added: • Defined Legal and IT shared oversight structure
+Added: • Formalized Incident Response Plan with severity classifications and escalation thresholds
+Added: • Quarterly executive and Audit Committee cybersecurity review process
+Added: • Expanded 24x7 managed detection and response capabilities
+Added: • Continuous vulnerability scanning and annual independent penetration testing
+Added: • Enterprise-wide multi-factor authentication enforcement
+Added: • Centralized identity and privileged access governance
+Added: • Structured phishing simulation and remedial training framework
+Added: • Standardized cybersecurity risk-ranking methodology integrated into enterprise risk management
+Added: Cybersecurity is not static.
+Added: Threat actors continue to evolve, and regulatory expectations continue to mature.
+Added: The Company expects to continue enhancing monitoring capabilities, automation, third-party risk oversight, and incident response readiness as part of its ongoing risk management strategy.
+Added: We believe the enhancements implemented during 2025 strengthened our cybersecurity posture and governance framework and further aligned Comstock with leading public companies with regards to cybersecurity risk management and oversight.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.