Item 1. Business
ITEM
1. BUSINESS
Unless
otherwise indicated or the context requires otherwise, the terms “we,” “us,” “our,” and “our
company” refer to CISO Global, Inc., a Delaware corporation, and our wholly owned subsidiaries. Unless otherwise specified, all
dollar amounts are expressed in United States dollars.
Our
Business
General
Our
company is a leading cybersecurity, compliance, and software firm composed of highly trained and seasoned security professionals. We
collaborate with clients to enhance or establish a stronger cybersecurity posture within their organizations. Cybersecurity, also referred
to as computer or information technology security, protects computer systems and networks from data breaches, hardware damage, software
compromise, and service disruptions.
The
cybersecurity industry faces a significant supply and demand imbalance, with greater demand for services than the market can supply in
terms of expert, seasoned compliance and cybersecurity professionals. To address this, we prioritize identifying, attracting, and retaining
top cybersecurity and compliance talent. Our strategy includes acquisitions, direct hiring, and employee incentivization through stock
options to ensure retention. We continuously seek culturally aligned cyber talent. We have invested in enterprise solutions, executive
leadership, and our proprietary software to integrate our acquisitions into a unified ecosystem. This ecosystem is designed to foster
cross-pollination of solutions, promote additional revenue opportunities and enhance recurring revenue. By emphasizing a security-aware
workforce culture, we aim to become trusted advisors, providing tailored, product-agnostic cybersecurity solutions that align with our
clients’ security needs, financial realities, and strategic goals. Our comprehensive cybersecurity services span compliance, cybersecurity,
and culture. These services include compliance consulting, secured managed services, Security Operations Center (SOC) services, virtual
Chief Information Security Officer (vCISO) services, incident response, certified forensics, technical assessments, and cybersecurity
training. We believe culture forms the foundation of successful cybersecurity programs. To support this, we have developed MCCP+ (“Managed
Compliance & Cybersecurity Provider + Culture”), a holistic solution combining all four pillars under one roof, delivered by
a dedicated team of subject matter experts. Our proprietary software further enhances this offering by streamlining compliance management,
threat detection, and response capabilities, ensuring a faster and more effective security posture for our clients. We differentiate
ourselves through a technology-agnostic approach and a relentless focus on acquiring high-demand cybersecurity talent, expanding both
service capabilities and global reach. Paired with our proprietary CISO software, which enhances threat visibility and accelerates incident
response, we strive to deliver unparalleled value to clients. This strategy aims to drive scalable growth, strengthen recurring revenue
streams, and position us as a leader in a market facing a critical cybersecurity talent shortage. Our integrated service model enhances
our ability for revenue capture and operational efficiency, which has the ability to result in improved profitability and stronger client
retention. Clients benefit from streamlined engagements with a single provider addressing a broad range of needs, leading to faster problem
resolution and superior outcomes compared to multi-vendor approaches. We believe this fosters long-term client partnerships.
- 6 -
We
aim to further differentiate ourselves through our staffing model: our employees are dedicated partners, not consultants, available under
recurring monthly contracts. This structure helps mitigate the challenges associated with hiring experienced cybersecurity professionals.
By integrating our team of industry and subject matter experts into clients’ operations — supported by our proprietary software
— we offer a robust, embedded cybersecurity solution that continuously adapts to evolving threats.
Our
technology-agnostic stance allows us to work compatibly with almost any business, regardless of existing systems or tools. Clients retain
the flexibility to select the best technologies for their needs without impacting their relationship with us.
Building
a world-class technology team with industry-specific expertise remains a cornerstone of our strategy. We will continue acquiring top
cybersecurity talent to expand our services and geographical footprint, reinforcing our ability to deliver exceptional results for clients.
Our goal remains to stay ahead of emerging threats and regulatory changes, ensuring our clients’ safety, compliance, and success
— with our proprietary software serving as a vital tool to support ongoing security, compliance, and operational excellence.
Cybersecurity
Landscape: A Market Poised for Growth
As
global connectivity accelerates, cyberattacks have emerged as one of the most pressing threats to enterprise and personal data, driving
unprecedented economic losses. Cybersecurity Ventures projected global damages from cybercrime will propel global spending on cybersecurity
products and services to $1 trillion (USD) annually by 2031. Ransomware remains one of the fastest-growing attack types, with incidents
expected to occur every two seconds, inflicting an estimated $265 billion in annual damages by 2031 — a dramatic rise from $20
billion and an attack every 11 seconds in 2021. In parallel, an Accenture survey reports that 68% of business leaders perceive increasing
cybersecurity risks. Reflecting this urgency, global cybersecurity spending is forecasted to surpass $520 billion annually (USD) by 2026,
up from $260 billion in 2021. Despite this investment surge, the talent gap remains a critical constraint. According to The New York
Times and Cybersecurity Ventures, 3.5 million cybersecurity roles remain unfilled — a disparity expected to have persisted through
2025.
Market
Drivers: Regulation and Cyber Insurance
Heightened
cyber risks have triggered a wave of regulatory reforms and tighter cyber insurance standards. Governments worldwide are enforcing more
rigorous cybersecurity mandates, while insurers have raised premium costs and minimum underwriting criteria. This evolving landscape
compels organizations to prioritize cybersecurity investments to maintain compliance, secure coverage, and safeguard their operations.
Strategic
Market Leadership and Growth Potential
We
are uniquely positioned to capitalize on this rapidly expanding market, offering end-to-end cybersecurity services with substantial opportunities
for sustained growth and value creation. Key differentiators include:
●
Proven
Acquisition Strategy: Through numerous strategic acquisitions, we have integrated top-tier talent and broadened our capabilities,
creating a comprehensive service portfolio aligned with market demands.
●
Expansive
Client Portfolio: Serving more than 437 clients across diverse sectors, we are strategically positioned to drive revenue growth
through cross-selling and upselling high-value services.
●
Robust
Channel and Partnership Ecosystem: We have cultivated an extensive network of partners, supported by comprehensive training,
enablement resources, and marketing content
●
Innovation
and Intellectual Property Development: Our proprietary technologies and intellectual property provide a competitive edge, enabling
deeper penetration into existing accounts, expansion into new markets, and enhanced partner collaboration opportunities.
Investor
Value Proposition: Positioned for Scalable, Long-Term Success
The
evolving cybersecurity landscape presents a dynamic, high-growth market ripe with opportunity. As threats intensify and regulatory pressures
mount, businesses require an agile, trusted cybersecurity partner. Our proven mergers and acquisitions track record, expansive client
base, channel-first approach, and intellectual property-driven innovation uniquely position us for scalable growth and market leadership.
We
remain steadfast in our commitment to innovation and operational excellence — empowering organizations to stay resilient and secure
in an increasingly complex digital ecosystem.
Cybersecurity
Offerings
We
offer a comprehensive suite of cybersecurity services designed to safeguard our clients’ digital assets and ensure compliance with
applicable industry standards and regulations. Our offerings fall into three main categories: Security Managed Services, Professional
Services, and Cybersecurity Software.
- 7 -
Security
Managed Services
Our
Security Managed Services aims to deliver proactive, scalable, and resilient cybersecurity solutions tailored to meet evolving threat
landscapes and regulatory requirements.
Compliance
Services
We
assist clients in implementing and maintaining appropriate security controls, prioritizing risk mitigation strategies, and help ensure
continuous compliance with key industry frameworks and regulations, including the following:
●
Cybersecurity
Maturity Model Certification (“CMMC”);
●
Federal
Risk and Authorization Management Program;
●
Federal
Information Security Modernization Act (“FISMA”);
●
Health
Insurance Portability and Accountability Act of 1996 (“HIPAA”);
●
Health
Information Trust Alliance;
●
Import
Export Code;
●
International
Organization for Standardization; and
●
National
Institute of Standards and Technology.
Our
team of certified experts provides ongoing monitoring, assessment, and advisory services to help clients navigate the complexities of
regulatory compliance and mitigate operational risks.
Cyber
Defense Operation
Our
U.S.-based, 24/7 SOC leverages advanced technology and expert analysis to provide real-time threat detection, response, and mitigation.
Core capabilities include the following:
●
Managed
Detection and Response (“MDR”);
●
Extended
Detection and Response (“XDR”);
●
Security
Information and Event Management (“SIEM”); and
●
Patch
and Vulnerability Management.
These
services support comprehensive threat visibility, rapid incident response, and continuous improvement of clients’ security postures,
helping to minimize downtime and reduce the potential impact of cyberattacks.
Secured
Managed Services
Our
integrated Secured Managed Services offering combines a robust portfolio of cybersecurity capabilities, including the following:
●
Secure
network architecture design and management;
●
Proprietary
cybersecurity software solutions;
●
SOC-driven
monitoring and response services;
●
Regulatory
compliance support;
●
Incident
remediation and recovery teams; and
●
Advanced
firewall and perimeter security management.
Our
experienced engineers and cybersecurity architects support clients with secure cloud migrations, infrastructure modernization, and tailored
risk mitigation strategies — helping enable operational resilience and business continuity.
- 8 -
Professional
Services
Our
Professional Services division helps deliver comprehensive cybersecurity solutions designed to mitigate risk, enhance resilience, and
protect organizational value.
Incident
Response and Digital Forensics
Leveraging
advanced threat intelligence and real-world adversarial techniques, our elite cybersecurity team specializes in swiftly identifying,
containing, and eradicating cyberattacks. We conduct discreet, environment-wide investigations to assess breach scope, minimize operational
disruption, and remediate persistent threats — positioning us as the trusted partner when others fail.
Security
Testing and Training
We
empower organizations to proactively strengthen their cyber defenses through rigorous security assessments, including red team and purple
team penetration testing, simulated attack exercises, and specialized cybersecurity training. Our programs include industry-recognized
certifications such as CMMC, CompTIA, and ISC2, driving measurable improvements in cybersecurity posture and regulatory readiness.
Cybersecurity
Software
We
offer a comprehensive suite of proactive cybersecurity software solutions designed to protect organizations from evolving cyber threats.
Our offerings encompass advanced threat detection, proactive monitoring, and robust risk management to help ensure enterprise security
and compliance.
CISO
Edge
CISO
Edge is an artificial intelligence (“AI”)-driven cloud security solution that provides comprehensive protection across cloud-first,
hybrid, and remote environments. Purpose-built for large enterprises, government entities, and high-value networks, CISO Edge is designed
to defend against sophisticated cyber threats, including ransomware and AI-powered exploits
CHECKLIGHT ®
Security Monitoring
CHECKLIGHT ®
is a proactive security monitoring software that is designed to detect potential threats to endpoints and alerts users before attacks
can take hold, thereby reducing the impact of breaches. It identifies malicious software such as phishing attacks, malware, ransomware,
and viruses. Since its inception, CHECKLIGHT ® has maintained a record of detecting all breaches, providing organizations
with confidence in their endpoint security, and is backed by a financial warranty.
Argo
Security Management
Argo
is a security management platform that aggregates and curates all security data across various services, including SIEM, MDR, XDR, governance,
risk, compliance, and more. This centralized approach is designed to enhance the effectiveness of security teams by providing environment-wide
cybersecurity visibility through a customizable dashboard, enabling better-informed decisions.
Through
these innovative software solutions, we aim to empower organizations to enhance their cybersecurity measures, protect critical assets,
and maintain compliance in an ever-evolving threat landscape.
- 9 -
Growth
Strategy
We
are executing a phased growth strategy designed to position our company as a leading provider of end-to-end cybersecurity solutions.
Our strategy is built upon strategic acquisitions, development of proprietary intellectual property, and a focus on scalable growth.
We aim to leverage our expertise and advanced technology offerings to drive both organic growth and market expansion, thereby creating
value for our investors.
Phase
I: Foundation of Expertise through Strategic Acquisitions
In
Phase I, we established a solid foundation of cybersecurity expertise by acquiring niche companies with unparalleled capabilities in
various cybersecurity domains. These acquisitions have significantly expanded our talent pool and technical expertise, positioning us
as a leading cybersecurity provider. The acquired talent spans across the United States, with deep domain knowledge in key cybersecurity
areas including the following:
●
Risk
and Compliance;
●
Cyber
Defense Operations;
●
Security
Testing and Training; and
●
Secure
IT and Architecture.
This
diverse expertise, coupled with leadership from seasoned industry executives, has enabled us to address the complex and rapidly evolving
cybersecurity needs of organizations across various sectors.
Phase
II: Expanding Service Offerings and Capitalizing on Cross-Selling Opportunities
Phase
II of our growth strategy focused on leveraging the synergies from our numerous historical acquisitions to expand service offerings to
existing clients. Despite having only penetrated approximately 20% of our 437 clients for multiple services, we saw significant opportunities
for cross-selling and upselling. This presented a substantial revenue growth opportunity as we expanded our service offerings across
our client base.
Additionally,
we have been building and expanding a strong channel and partnership ecosystem. This ecosystem provides value-added training, support,
and partner marketing content. Our growing network of partnerships enhances our ability to acquire new clients while fostering long-term
relationships with existing ones.
Intellectual
Property Development and Innovation
A
key element of Phase II was the development of proprietary intellectual property that addresses the evolving cybersecurity challenges
facing enterprises. We invested heavily in the development of software-first technologies, leveraging cutting-edge advancements such
as machine learning (“ML”), AI, deep learning, neural networks, and proprietary DarkNet threat intelligence. These technologies
are foundational to our offerings, providing differentiated solutions that drive effectiveness, resilience, and advanced threat mitigation
for our clients.
Phase
III: Scaling Through Product-Led Growth and Scalable Technology Solutions
In
Phase III, in 2026, our primary focus will shift toward fueling organic growth through the commercialization and scaling of our proprietary
intellectual property. We plan to accelerate growth through product-led strategies, optimizing the user experience and enabling hands-free
purchasing via digital interfaces. We believe this approach will allow us to expand our client base while reducing the demand on our
services team, driving efficiency and scalability.
As
we expand our technology offerings, we anticipate increasing revenue and operating margins concurrently. The scalability of our intellectual
property-driven solutions positions us to capture a larger share of the cybersecurity market while maintaining high levels of profitability.
- 10 -
Intellectual
Property Suite and Future Growth
At
the heart of our strategy is a comprehensive suite of proprietary software solutions, incorporating AI, neural networks, and the latest
algorithms. These technologies are designed to address the most pressing cybersecurity challenges facing enterprises today, positioning
us at the forefront of the cybersecurity industry.
Through
these efforts, we aim to deliver sustainable, long-term growth while continuing to provide our clients with best-in-class cybersecurity
solutions. Our continued investment in intellectual property and innovative technologies are key drivers of value creation for our investors
as we scale our business and expand our market presence.
Our
intellectual property suite includes the following:
ARGO
Security Management – A
security management platform that is able to aggregate, then curate security data in real time from a client’s entire environment,
including network asset information, currently deployed cyber tools, SOC, vulnerability management, secure managed IT and penetration
testing data.
CISO
Edge Cloud Security Platform – A cloud-first
security solution designed to protect users from untrusted and malicious online threats. CISO Edge uses advanced AI deep learning
as well as artificial neural networks to provide advanced threat detection and monitoring.
CHECKLIGHT ®
Security Monitoring
– A powerful, proactive security monitoring software that detects potential threats to networks and provides advance alerts so
attacks can’t take hold. Relying on the same cybersecurity software engine used by several federal agencies, it identifies unauthorized
processes associated with fraudulent phishing attacks, hacking, imposter scams, malware, ransomware, and viruses, and provides a financial
warranty
DISC
Next Gen VPN – A token exchange-protected remote access solution that replaces traditional VPN connections with enhanced
security and access verification.
Skanda
Breach Assessment Tool – A next-generation,
analysis tool that applies AI-based automation and ML technologies, which looks beyond vulnerabilities identified by most other technology
to deliver continuous security assessments.
Our
Corporate and Acquisition History
We
were formed on March 5, 2019, as a Delaware corporation. Our principal offices are located at 6900 East Camelback Road, Suite 900, Scottsdale,
Arizona 85251.
On
October 2, 2019, we filed a registration statement on Form 10-12G with the Securities and Exchange Commission (“SEC”) to
effect registration of our common stock, par value $0.00001 per share, under the Exchange Act. The registration statement became effective
on December 1, 2019.
On
February 29, 2024, our board of directors approved a 1-for-15 reverse stock split of our common stock. The record date for the reverse
stock split was the close of business on March 7, 2024, with share distribution occurring on March 8, 2024. As a result of the reverse
stock split, stockholders received one share of CISO Global, Inc. common stock, par value $0.00001, for each 15 shares they held as of
the record date. All share and per share amounts have been retroactively restated for the effects of this reverse stock split. Common
stock underlying our outstanding warrants, convertible notes, and options have also been adjusted, and the conversion and exercise prices
have also been adjusted.
We
have substantially expanded our business in recent years through a number of acquisitions that enhanced our product offerings.
- 11 -
The
following table sets forth certain information regarding such acquisitions:
Acquired
Company, Location
Type
of Acquisition
Date
Services
Provided by Acquired Company
GenResults,
LLC (“GenResults”)
Arizona (1)
Stock
April
12, 2019
Cybersecurity
services.
VCAB
Six Corporation (“VCAB”)
Texas
Merger
April
12, 2019
N/A (2)
TalaTek,
LLC (“TalaTek”)
Virginia
Merger
October
1, 2019
Integrated
risk management services, including risk assessments, IT audits, cybersecurity services, and managed compliance services.
Technologyville,
Inc.
Illinois
Stock
May
25, 2020
Managed
IT services.
Clear
Skies Security, LLC
Georgia
Stock
August
1, 2020
Security
assessment and penetration testing.
Alpine
Security, LLC
Missouri
Merger
December
16, 2020
Integrated
risk management services.
Catapult
Acquisition Corporation (“VelocIT”)
New
Jersey
Merger
August
12, 2021
Integrated
risk management services.
Atlantic
Technology Systems, Inc., and
Atlantic
Technology Enterprises, Inc. (collectively, “Atlantic”)
New
Jersey
Stock
October
1, 2021
Integrated
risk management services.
RED74
LLC (“RED74”)
New
Jersey
Merger
November
9, 2021
Integrated
risk management services.
Ocean
Point Equities, Inc. (“Arkavia”)
Santiago,
Chile (3)
Stock
December
1, 2021
Cybersecurity
services.
True
Digital Security, Inc. (“True Digital”)
New
York
Florida
Oklahoma
Stock
January
19, 2022
Cybersecurity
and compliance.
Creatrix,
Inc.
Tennessee
Maryland
Stock
June
1, 2022
Identity
management, systems integration and software engineering, biometrics, vetting, credentialing, and case management.
CyberViking,
LLC
Georgia
Oregon
Stock
July
1, 2022
Application
security services, incident response, threat hunting, and creation and management of security operation centers.
Servicios
Informaticos CUATROi, S.P.A.,
Comercializadora
CUATROi S.P.A.,
CUATROi
Peru, S.A.C., and
CUATROi
S.A.S.
Santiago,
Chile
Bogota,
Columbia, and Lima, Peru (3)
Stock
August
25, 2022
Managed
services and cybersecurity.
NLT
Networks, S.P.A.,
NLT
Technologias, Limitada,
NLT
Servicios Profesionales, S.P.A., and
White
and Blue Solutions, LLC
Providencia,
Chile
Florida (3)
Stock
September
1, 2022
Security
solutions and managed services.
SB
Cyber Technologies, LLC
Virginia
Stock
July
14, 2023
Managed
services and compliance.
(1)
Prior
to our acquisition of GenResults, GenResults was wholly owned by an entity affiliated with David G. Jemmett, our Chief Executive
Officer and a director of our company. Due to the companies being under common control, we accounted for the acquisition as a reorganization.
- 12 -
(2)
At
the time of the VCAB Merger, VCAB was subject to a bankruptcy proceeding and had minimal assets, no equity owners, and no liabilities,
except for approximately 1,500 holders of Class 5 Allowed General Unsecured Claims and a holder of allowed administrative expenses
(collectively the “Claim Holders”). Pursuant to the terms of the VCAB Merger, and in accordance with the bankruptcy plan,
we issued an aggregate of 133,334 shares of our common stock (the “Plan Shares”) to the Claim Holders as full settlement
and satisfaction of their respective claims. As provided in the bankruptcy plan, the Plan Shares were issued pursuant to Section
1145 of the United States Bankruptcy Code. We entered into the VCAB Merger to increase our stockholder base to, among other things,
assist us in satisfying the listing standards of a national securities exchange.
(3)
Entities
were disposed of on July 1, 2024. See Note 4 to our consolidated financial statements appearing
elsewhere in this Annual Report on Form 10-K.
While
acquisitions have contributed to our growth in prior years, we did not complete any acquisitions during the years ended December 31,
2025 and 2024.
Customers
Our
past acquisitions have resulted in expansion of our customer base and increased usage within existing customers. For the year ended December
31, 2025, one customer represented approximately 10% of our total revenue as presented in the consolidated statements of operations and
comprehensive loss. For the year ended December 31, 2024, there were no customers that represented 10% or more of our total revenue as
presented in the consolidated statements of operations and comprehensive loss.
As
of December 31, 2025, the same customer that represented approximately 10% of total revenue accounted for approximately 17% of our accounts
receivable balance. As of December 31, 2024, two customers represented approximately 13% and 11%, respectively, of our accounts receivable
balance.
Cybersecurity
Market Analysis
The
cybersecurity market is highly fragmented, characterized by a diverse landscape of established industry leaders and emerging security
product vendors. While competition within traditional endpoint and IT operations markets remains significant, we anticipate encountering
new competitors as we strategically expand into adjacent markets, thereby increasing our total addressable market.
We
believe our competitive positioning is strengthened by several key differentiators, including:
●
Frontline
Intelligence and Expertise : Our extensive experience in investigating and remediating complex cyber incidents, equips us with
real-time threat intelligence and practical insights. This knowledge directly informs and enhances our solutions, providing customers
with proactive, resilient cybersecurity strategies.
●
Comprehensive,
Integrated Solutions : Our platform integrates a broad suite of SaaS offerings, helping enable clients to seamlessly unify threat
detection, incident response, and cybersecurity validation. This streamlined approach helps reduce complexity and operational overhead
compared to competitors that rely on disjointed point solutions.
●
Ease
of Deployment and Versatility : Our solutions are designed to integrate into diverse IT environments, supporting hybrid, on-premises,
and cloud architectures. This flexibility ensures accelerated time-to-value for clients and minimizes disruption during deployment.
●
Reputation
and Consulting Expertise : Our globally recognized consulting organization enhances our market credibility. By leveraging insights
derived from high-profile incident response engagements, we continuously refine our services, positioning us to deliver superior
outcomes for customers.
●
Strategic
Acquisition Strategy : As a cybersecurity consolidator, we prioritize identifying and acquiring strategic targets that align with
our commitment to service quality, technological innovation, and geographical expansion. Our track record of successful mergers and
acquisitions has enabled us to broaden our service portfolio, extend market reach, and capture operational efficiencies, positioning
us as a leading force in market consolidation.
Despite
these advantages, many of our competitors maintain substantially greater financial, technical, and operational resources, along with
broader brand recognition, larger sales and marketing infrastructures, deeper customer relationships, more extensive distribution channels,
and mature intellectual property portfolios. Additionally, cloud-based service providers introduce increased competition, transcending
geographic limitations.
We
remain committed to leveraging our core strengths, including frontline expertise, integrated solutions, and a disciplined acquisition
strategy — to expand our market presence, drive sustainable growth, and create long-term value for our stockholders.
Intellectual
Property
Our
intellectual property portfolio is a critical component of our competitive advantage and long-term business strategy. We rely on a combination
of trademarks, patents, copyrights, trade secrets, license agreements, intellectual property assignment agreements, confidentiality procedures,
non-disclosure agreements, and employee non-disclosure and invention assignment agreements to secure and enforce our proprietary rights.
While these legal protections are important, we believe our success is more significantly driven by the expertise and ingenuity of our
workforce, alongside the functionality and continuous innovation embedded in our solutions. We are committed to expanding and strengthening
our intellectual property portfolio to support our products, services, research and development efforts, and other strategic initiatives.
Where appropriate and financially prudent, we intend to pursue additional intellectual property protections to enhance our market position
and safeguard our technology.
As
we continue to grow and achieve greater market visibility, we anticipate increased competition and the potential for third parties to
develop solutions that may attempt to replicate or infringe upon our proprietary technologies. Additionally, large and established companies
within the cybersecurity sector maintain extensive patent portfolios and are frequently involved in both offensive and defensive intellectual
property litigation. From time to time, we may face allegations of intellectual property infringement from such companies or from non-practicing
entities. These claims may target us directly, or indirectly affect our business by targeting our channel partners, cloud service providers,
or customers — parties to whom we have contractual indemnification obligations. If a third party successfully asserts an intellectual
property infringement claim against us, we could face significant financial and operational consequences, including the inability to
market or deliver certain products or services, the necessity to allocate resources toward developing non-infringing alternatives, or
the obligation to pay substantial damages, including enhanced damages for willful infringement in the United States. Additionally, we
could be required to enter into costly licensing agreements or settlement arrangements. We cannot guarantee that our current or future
products and services will not be found to infringe upon third-party intellectual property rights. Defending against intellectual property-related
claims, regardless of merit, can be time-consuming, expensive, and disruptive to our business. We intend to vigorously protect and enforce
our intellectual property rights where necessary to preserve our competitive position and long-term financial performance. However, there
can be no assurance that we will succeed in these efforts or that our intellectual property protections will be sufficient to prevent
competitors from developing similar technologies or services that may diminish our market share or revenue potential.
- 13 -
Government
Regulation
We
are not aware of any specific regulations that govern cybersecurity firms or the areas in which we operate. While there are a few federal
cybersecurity regulations, they govern industries that we serve and exist to focus on specific industries.
Three
of the main cybersecurity regulations are HIPAA, the Cybersecurity Maturity Model Certification (CMMC) program, and the 2002 Homeland
Security Act, which included FISMA. These regulations mandate that healthcare organizations, financial institutions, federal contractors,
and federal agencies, should protect their systems and information. FISMA, which applies to every government agency, requires the development
and implementation of mandatory policies, principles, standards, and guidelines on information security. However, the regulations do
not address numerous computer related industries, such as Internet Service Providers and software companies. Furthermore, the regulations
do not specify what cybersecurity measures must be implemented and require only a “reasonable” level of security. In addition,
the National Cybersecurity Division is another regulatory body that is a division of the Office of Cybersecurity & Communications
within the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency.
Human
Capital Management
Our
future success relies on our ability to continually attract, hire, and retain top-tier talent, particularly within our senior management,
engineering, and technical teams. As a leader in the highly competitive cybersecurity industry, securing skilled personnel is essential
to maintaining our position at the forefront of innovation and incident response.
Competing
for Top Talent
We
recognize that the cybersecurity landscape is evolving rapidly, and the demand for specialized expertise continues to grow. To remain
competitive, we have designed comprehensive compensation and benefits programs that address the diverse needs of our global workforce.
In addition to competitive salaries, our offerings include performance-based incentive plans, pensions, healthcare and insurance coverage,
paid time off, and family leave. These benefits are tailored to meet regional requirements and employment classifications, ensuring flexibility
and relevance.
Retention
Through Recognition and Rewards
To
retain our most valuable contributors — particularly senior leaders and key technical personnel — we strategically deploy
equity-based grants with thoughtful vesting schedules. This approach aligns employee success with company performance, fostering long-term
commitment and engagement.
Prioritizing
Employee Well-being
The
success of our business is inherently tied to the well-being of our people. We are steadfast in our commitment to fostering a healthy,
safe, and supportive work environment. Our people are our greatest asset. By cultivating an environment where talent thrives, supported
by competitive rewards, opportunities for growth, and a commitment to well-being, we help ensure our continued leadership in cybersecurity
and incident response.
Environmental,
Social, and Governance Efforts
Environmental
Commitment
We
are committed to protecting the environment and attempt to mitigate any negative impact of our operations. We monitor resource use, improve
efficiency, and at the same time reduce our emissions and waste.
Social
Responsibility
We
are a trusted cybersecurity expert providing safe, efficient, and sustainable services to our existing and new communities. Our success
is the direct result of the dedication and strength of our team and promotes diversity, integrity, inclusion, reliability, and accountability.
We believe that a combination of diverse team members and an inclusive culture contributes to our success. Each member is a valued part
of our team bringing a diverse perspective to help grow business and achieve our goals. Our tradition of serving employees, customers,
and investors is at the core of our culture. For third-party vendor selection and oversight, we have standard operating procedures that
apply to employees and subcontractors who, on our behalf, oversee and conduct technical protocols.
- 14 -
Employees
As
of December 31, 2025, we had approximately 125 full-time-equivalent employees. In addition, we utilize independent contractors for projects of
short duration or where specialized knowledge or experience is needed for a complex project. We are not dependent on any independent
contractor, and we believe adequate replacements would be available in the event any such independent contractor becomes unavailable
to us. We believe our relations with our employees is good.
Available
Information
Our
Annual Report on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, our proxy and information statements and all
amendments to those reports will be available free of charge through our website at www.ciso.inc as soon as practicable after such material
is electronically filed with, or furnished to, the SEC. Except as otherwise stated in these documents, the information contained on our
website or available by hyperlink from our website is not incorporated by reference into this report or any other documents we file,
with or furnish to, the SEC.
Implications
of Being an Emerging Growth Company
We
qualify as an “emerging growth company” as the term is used in The Jumpstart Our Business Startups Act of 2012 (the “JOBS
Act”), and therefore, we may take advantage of certain exemptions from various public company reporting requirements, including:
●
a
requirement to only have two years of audited financial statements and only two years of related selected financial data and management’s
discussion and analysis;
●
exemption
from the auditor attestation requirement on the effectiveness of our internal controls over financial reporting;
●
reduced
disclosure obligations regarding executive compensation; and
●
exemptions
from the requirements of holding a nonbinding advisory stockholder vote on executive compensation and any golden parachute payments.
We
may take advantage of these provisions for up to five years after our first public equity sale or such earlier time that we are no longer
an emerging growth company. We would cease to be an emerging growth company if we have more than $1.07 billion in annual revenue, issue
more than $1.0 billion of non-convertible debt over a three-year period, or become a large accelerated filer. So long as we remain an
emerging growth company, we may choose to take advantage of some, but not all, of the available benefits of the JOBS Act. We have taken
advantage of some of the reduced reporting requirements in our filings. Accordingly, the information contained herein may be different
than the information you receive from other public companies in which you hold stock. In addition, the JOBS Act provides that an emerging
growth company can delay adopting new or revised accounting standards until such time as those standards apply to private companies.
We have elected to avail ourselves of this exemption from new or revised accounting standards and, therefore, we will not be subject
to the same new or revised accounting standards as other public companies that are not emerging growth companies.