Item 1. Business
ITEM 1. BUSINESS
General
Cycurion, Inc. (collectively with its subsidiaries,
the “Company,” “Cycurion,” “we,” “us” or “our”) was originally incorporated
as KAE Holdings, Inc., under the laws of the State of Delaware in October 2017, with the purpose of acquiring and holding operating entities
in the cybersecurity industry. On July 14, 2020, we changed our corporate name from KAE Holdings, Inc. to Cyber Secure Solutions, Inc.,
and, on February 24, 2021, to Cycurion, Inc. On February 14, 2025, the date of closing of our de-SPAC transaction, we merged into Western
Acquisition Ventures Corp. and changed that company’s name to Cycurion, Inc.
We have one first-tier wholly-owned subsidiary, Cycurion
Sub, Inc. (formerly Cycurion, Inc., until February 14, 2025), and three indirectly wholly-owned second-tier subsidiaries: (i) Axxum Technologies
LLC (“Axxum”), a Virginia limited liability company formed in December 2006, (ii) Cloudburst Security LLC (“Cloudburst”),
a Virginia limited liability company formed in January 2007, and (iii) Cycurion Innovation, Inc., a Delaware corporation formed in September
2021, in connection with our acquisition of assets from Sabres Security Ltd. (“Sabres”), a leading Israeli-based cyber security
provider.
Our Business
We provide innovative custom solutions for our clients
by adapting our superior knowledge base and government-level experience to create dynamic solutions to best serve our client’s
information technology (“IT”) and cybersecurity needs. We assess, secure and advise your organization by leveraging our government
proven, cutting edge techniques, custom tools and extensively knowledgeable personnel to revolutionize the client’s cybersecurity
posture.
We are committed to surpassing expectations and delivering
incomparable value to our clients and partners. We achieve this goal by providing Network Communications and Information Technology Security
services and solutions that are custom-tailored to your environment, as well as your level of need. We are built on a foundation of experts
in Network Communications and Information Technology who possess unrivaled security expertise and experience. We are committed to hiring
the most knowledgeable professionals in order to expand and reinforce our team of experts, leveraging world-class talent to improve and
expand upon our already vast understanding of this environment. We pride ourselves on having the capability and resources to successfully
implement a management strategy that delivers the solutions you need to stay within budget and on schedule.
We deliver high-quality, cybersecurity solutions
to federal government civilian, defense and judicial agencies in addition to commercial clients across a variety of industries. We, through
our operating subsidiaries and strategic partnerships, have numerous prime and subcontracts with key government agencies. Our growth
engine is driven by organic business solutions and strategic acquisitions of cybersecurity services and technology providers. We leverage
our highly skilled workforce to access, secure and advise our clients to improve their cyber security posture. Our ability to identify
and implement customized solutions is core to driving continued growth.
Our Services
Consulting and Advisory Services
Our consulting services perform a detailed review
of our customers’ IT security to identify and address vulnerabilities. Using advanced tools and research techniques, we enhance
our customers’ cybersecurity program to meet regulatory compliance, data confidentiality and privacy standards, and train our customers’
personnel accordingly.
Our advisory services supplement our consulting services
with a cost-effective alternative to a full-time chief information officer. Our customers gain access to our pool of experienced chief
information officers, who are backed by our resources. They deliver tailored advice and training to keep our customers’ organization
ahead in the ever-changing cybersecurity landscape.
Our consulting and advisory services include: (i)
security control assessments; (ii) security architecture and engineering; (iii) risk management and compliance audits; (iv) staff augmentation;
(v) cybersecurity awareness and training; (vi) cloud security; (vii) virtual CISO support; and (viii) digital modernization.
Managed IT Services
Our managed IT services can optimize an organization’s
IT infrastructure, reduce costs and improve operational efficiency, and it offers comprehensive IT management and support for organizations
of all sizes.
Managed IT services is a services model in which
a managed service provider (“MSP”) remotely manages the day-to-day IT offerings for a client under a service level agreement
(“SLA”). This includes remote monitoring and management of servers, disaster recovery, infrastructure as a service (“IaaS”),
platform as a service (“PaaS”), and software as a service (“SaaS”). In short, managed IT services provides businesses
with IT support and maintenance on an ongoing basis.
IT services are typically provided on a break-fix
basis, meaning that the client only calls the provider when there is a problem with its IT infrastructure. Managed IT services, on the
other hand, are provided on an ongoing basis under an SLA. This means that the MSP is responsible for the day-to-day maintenance of the
client’s IT infrastructure and is always monitoring and managing the system to ensure it is running smoothly.
For example, a company that provides cloud services
to businesses would offer managed platform services, remote monitoring and management of servers and security services. The MSP would
handle the day-to-day maintenance of the client’s IT infrastructure and offers disaster recovery services in the event of a data
breach or other catastrophe.
Our managed IT services include: (i) project and
license management; (ii) network infrastructure; (iii) systems engineering and administration; (iv) voice and data infrastructure engineering
and management; (iv) application development; (v) IT help desk support; and (vi) staff augmentation.
5
Managed Security Services
We are a professional and trusted provider of managed
security services. Our comprehensive security management solution is designed to help organizations protect their digital assets against
various cyber threats. Our managed security services include 24/7 monitoring, threat detection, incident response and remediation. Our
Security Operations Center (SOC) as a service offers organizations with a team of security professionals dedicated to monitoring and
managing their security infrastructure.
Managed security services (“MSS”) are
a crucial component of a robust security program. Managed security service providers (“MSSPs”) specialize in protecting businesses
from cyber threats and deliver a range of security services including, but not limited to, intrusion detection, vulnerability assessments
and network security services.
MSSPs offer organizations access to a dedicated team
of security professionals who use the latest security architectures and technologies to monitor their clients’ networks and systems,
identify potential threats and respond promptly to security incidents. This is especially important for small to mid-sized businesses
that may not have the in-house resources to maintain a robust security posture on their own.
MSS plays a critical role in safeguarding businesses
from cyber threats in today’s digital landscape, making them an essential partner for organizations across industries. MSSPs work
with clients ranging from small businesses to large enterprises and are often partnered with internet service providers to provide comprehensive
security solutions.
Managed security services can also help organizations
meet compliance requirements and reduce the risk of data breaches, which can be costly in terms of lost data, damaged reputation, and
regulatory penalties. Additionally, MSSPs can provide SaaS solutions, allowing businesses to access security tools and services on-demand
without having to invest in expensive hardware and software.
Our managed security services include: (i) managed
detection and response; (ii) external attack surface management; (iii) threat hunting and threat intelligence; (iv) end point detection
and response; (v) firewall management; (vi) threat and vulnerability management; (vii) vulnerability and penetration testing; (viii)
24/7/365 security monitoring; and (ix) digital forensic and incident response.
Our Industries
Enterprise Business
Enterprise level organizations face a litany of challenges
when curating and implementing a successful IT environment. Challenges generally evolve from multiple points, such as finding experienced
and deeply knowledgeable IT staff that is prepared for all security eventualities, to creating a comprehensive, functional, and compliant
interface tends to create a high cost, knowledge deficient, and overwhelmed staff that often lacks in providing a positive ROI, and at
times a cost-prohibitive scenario.
As digitization of operations becomes a necessity
in the current environment, we plan to help our customers hire the right personnel and implement proper protocols in a time- and cost-efficient
manner. We will take the responsibility from initial analysis to full spectrum implementation of our services, duly optimizing our customers’
organization and digital environment for the future.
We offer an evolutionary solution for this knowledge
gap by providing deeply knowledgeable experts and highly trained analysts directly to our customers’ organization as a service.
Our contract analysts provide more than just their individual expertise to solve specific challenges, but also will leverage Cycurion’s
entire repository of collective knowledge, techniques and methodologies to our customers’ organization, at a cost below that of
hiring an IT department, while providing highly efficient, multi-disciplined and deeply knowledgeable expert solutions to our customers.
Government
Government entities face a number of compliance and
certification challenges. With constantly changing legislation, meeting government mandate and expectations in the IT environment is
often a challenge. We leverage our historical knowledge and extensive experience on the federal level to continue to fulfill all of IT
needs across the government organization.
Bad actors attack government agencies by targeted
cyber threats, personnel exploitation and creative manipulation to gain access to critical systems and infrastructure through unperceived
vulnerabilities. Public platforms, such as social media, surface, deep and dark web, present substantial risks through knowledge gaps
in personnel training, presenting high risk and substantial possibility of security failure. We have been defending and optimizing these
environments at the federal level for over a decade and, as a result, have created a robust and predictive methodology to defend and
optimize government organizational and security gaps in order to mitigate these threats and vulnerabilities before they are compromised.
We provide the knowledge, experience and analytical understanding of this environment to evolve our services to meet current and future
needs across the IT spectrum.
Our extensive knowledge and real-world experience
with government agencies allow us to understand the operational, security and overall IT needs and challenges that such agencies must
overcome to achieve their mandate. We leverage our experience in this space allowing us to provide best-practice solutions throughout
the IT environment.
Small and Medium Businesses
We offer IT solutions for small and medium businesses
through different management plans by offering IT services and solutions with the same resources, concentrations and knowledge-based
analytical methodology that are used for our enterprise and government clients. We provide roadmaps to successful integration, streamlining
the businesses’ operation for maximum effectiveness by developing comprehensive IT solutions to navigate the modern cyber environment.
We leverage our expertise and experience from our work in the federal environment, custom tailoring these solutions to your business,
no matter the size, while focusing on our customers’ business needs and budget.
6
Healthcare
We understand that healthcare organizations must
manage a vast array of rapidly evolving complexities. Our company will lead healthcare organizations through the demands of HIPAA / HITECH
security and privacy compliance requirements. We offer healthcare IT services to augment and refine an organization through auditing
and assessment of the organization, staff, applications, compliance, risk, vulnerability and infrastructure in order to improve the entity’s
ability to better serve the healthcare needs of the organization’s clients.
We understand the key drivers of the healthcare market,
and continually create focused, innovative and repeatable solutions. We provide technology services to improve service delivery with
a focus on system integration, process reengineering, cloud/web / mobile development, solutions for coordinated community care and case
management applications. We have extensive experience providing management consulting from strategic planning, IT assessment, project
management, application rationalization, enterprise architecture, organizational change management and training.
Higher Education
We offer cybersecurity services and solutions for
universities and high education and protect our customers’ systems, information and students from cyber threats and attacks. Our
end-to-end managed cybersecurity solutions include: (i) IT and cybersecurity audit, consulting and advisory services; (ii) Security Operation
Center (SOC) Network services; (iii) virtual chief information security officers; and (iv) cyber awareness and threat intelligence training
services. We have over 150 years of experience on our management team and have served over 275,000 students.
Cycurion ARx Platform
The Cycurion ARx platform is a turnkey web application
protection and managed security solution that combines the essential cybersecurity layers in a comprehensive, customizable platform.
This platform offers: (i) Geo Gate Protection; (ii) DDoS Protection; (iii) WAF and API Protection; (iv) Endpoint Protection; and (v)
Bot Hunter Protection.
● Geo
Gate Protection . This reverse proxy server makes geographic restrictions easy, thus reducing
unwanted traffic.
● DDoS
Protection . This distributed denial-of-service (“DDOC”) protection mitigates
the threat from malicious actors attempting to flood the entry point of an application.
● WAF
and API Protection . Web Application Firewall (“WAF”) protection inspects
requests in real-time and filters out harmful traffic, while application programing interfaces
(“API”) protection is a defense mechanism involving a two-step process of authenticating
the data sender and inspecting the data to ensure no malicious data injections have occurred.
● Endpoint
Protection . This countermeasure ensures that devices follow compliance and security policies,
preventing intrusion from particular vectors.
● Bot
Hunter . Our proprietary algorithm provides detection and protection against non-human
activity. This can prevent low-level threats like unwanted scraping, and high-level threats
like attempted system breaches.
Key Performance Indicators
2024
Margin
2023
Margin
Gross Profit ($)
3,634,743
20.5 %
2,643,060
13.7 %
Operating Income ($)
2,416,113
13.6 %
326,411
1.7 %
Net Income/(Loss) ($)
1,229,601
6.9 %
(2,097,013 )
(10.8 )%
Total
Total
Number of Customers
41
38
Our Subsidiaries
Cycurion Sub, Inc.
Our operating subsidiaries are wholly owned by Cycurion
Sub., Inc., a Delaware corporation that, until the closing date of the de-SPAC, was known as “Cycurion, Inc.” We continue
to conduct our business through the three below-described entities, which are now indirectly wholly-owned second-tier subsidiaries by
virtue of the recent closing of the de-SPAC transaction.
Axxum Technologies LLC
Organized in the Commonwealth of Virginia on December
29, 2006, Axxum is a cybersecurity provider with successful assignments within the multiple sub-agencies of the Department of Homeland
Security. We acquired Axxum in November 2017. Following our acquisition, we continued Axxum’s core operations of providing contractor
services to its existing federal government customer base, while leveraging our existing processes and tools to expand its commercial
footprint.
Axxum has the specialized skills and experience
to provide a strategy and tactics to help organizations defend against cyber-attacks and implement a secure network infrastructure. Our
team has extensive experience implementing cybersecurity solutions against internal and external threats to the health of our clients’
networks. Axxum’s information security focus produces several key benefits:
● Agile
Client Focus : Axxum’s projects are overseen directly by its program managers, all
of whom have information security backgrounds and are fully authorized to promptly implement
client requirements throughout the performance life cycle.
● Streamlined
and Process Focused : Axxum’s streamlined infrastructure leverages ISO quality standards
integrated with emerging and established technologies, allowing it to engineer innovative
solutions without building in excessive overhead.
● Outstanding
Personnel : Axxum has a reputation of employing cybersecurity experts.
7
Cloudburst Security LLC
Organized in the Commonwealth of Virginia on January
12, 2007, Cloudburst specializes in providing a full spectrum of high-quality, innovative cybersecurity services to both government and
commercial organizations, such as banking and financial; education and schools; energy; critical infrastructure and supervisory control
and data acquisition; healthcare; and manufacturing. Cloudburst’s mission is to help our clients — of all sizes
and mission types — protect their integral data and information assets, so that they can focus on their core competencies.
We focus on providing tailored solutions that leverage
the industry’s best minds and technologies to predict, protect, detect, respond, and sustain our clients from the latest evolving
cyber threats. We acquired Cloudburst in April 2019.
Cycurion Innovation, Inc.
Our Cycurion Security Platform’s line of products
allows our customers to improve their cyber posture with its Multi-Dimensional Protection (“MDP”) SaaS platform. This platform
efficiently bundles and easily implements the external protection of a Web Application Firewall (WAF) and the internal protection of
Bot Mitigation. Bot Mitigation is the reduction of risk to applications, Application Program Interfaces (APIs), and backend services
from malicious bot traffic that fuels common automated attacks, such as Distributed Denial of Service (DDoS) campaigns and vulnerability
probing. The costs of single-layer security can be measured in terms of money, time, and risk, as well as the damage wrought by a data
breach, which millions of businesses experience each year. Through this interaction of the WAF and Bot Mitigation, the MDP is able to
reinforce these layers of security and generate new security layers in real time in response to emerging threats. This process is directed
by our Cycurion Security Platform’s proprietary, cloud-based artificial intelligence (“AI”) algorithm. Crucially, the
AI underpinning the MDP platform is constantly evolving to counter new threats. Through a crowdsourcing process, the cloud-based MDP
learns from every threat to any protected application and uses that newly acquired knowledge to protect all MDP clients better.
Our Subcontractor Relationship
SLG Innovation, Inc.
We are currently a subcontractor for several keystone
contracts held by SLG Innovation, Inc. (“SLG”). The SLG team has an average of over 25 years of experience in the development,
planning, implementation, and management of information systems. SLG’s leadership team offers years of combined success in answering
the needs of government agencies and healthcare organizations across the country.
The SLG team has worked nationally, as it has served
over 25 Department of Health and Human Services agencies, all 50 state governments and over 250 local governments. Since SLG’s
inception, it has primarily focused on customers in the middle of the country. The team of professionals has successfully delivered Information
Technology, Project Management, and Subject Matter Services to key health and human service projects, including, but not limited to,
state Medicaid programs in Illinois, Indiana, Nebraska, and Tennessee, the Indiana Division of Aging, Illinois Early Intervention, University
of Illinois Division of Specialized Care for Children, the Multiple Myeloma Research Foundation, and many more.
We established a subcontractor — prime
contractor relationship with SLG in fall 2019, where we serviced several government agencies and commercial customers, State of New Mexico,
Cognizant, KPMG, and University of Illinois in support of SLG.
Our Acquisitions
SLG Acquisition Agreement
On April 25, 2023, Cycurion Sub executed a Term
Sheet with SLG (the “SLG Term Sheet”), pursuant to which SLG Innovation Inc., an Illinois corporation formed in January 2010
(“SLG”), agreed to be acquired by Cycurion Sub. The Term Sheet contained all of the material terms and conditions of two
proposed interrelated transactions to be memorialized by an acquisition agreement (the “SLG Acquisition Agreement”). To effectuate
the two transactions contemplated by the SLG Term Sheet, Cycurion Sub will form two subsidiaries, which, upon formation, will initially
be wholly owned by Cycurion Sub. If, when, and as the transactions contemplated by the SLG Term Sheet are consummated, SLG would merge
with and into one of the subsidiaries and survive, thereby becoming a wholly-owned subsidiary of Cycurion Sub. Because certain of the
agreements to which SLG is the prime contractor require that the majority owner of the prime contractor be a resident of the City of
Chicago or of Cook County (depending on the contract), contemporaneously with the consummation of the first of the two transactions,
(i) SLG will divest itself of those agreements with the residency requirements, (ii) the second newly formed subsidiary will assume those
agreements, (iii) Mr. Ed Burns will become the owner of a 51% interest in that newly formed subsidiary, and (iv) we will enter into a
Management Agreement with that subsidiary (see below for a discussion of the SLG Management Agreement), the economic terms and management
/ control terms of which are intended to be the equivalent of complete ownership of the 49% owned subsidiary. Mr. Ed Burns is currently
the 51% owner of SLG and a resident of the City of Chicago. The SLG Term Sheet provides that, if, when, and as the transactions contemplated
thereby are consummated, the two current owners of SLG will be issued shares of our common stock. SLG is fully bound by the terms and
provisions of the SLG Term Sheet and the related Management Agreement structure, although Cycurion Sub is permitted to terminate the
SLG Term Sheet and to abandon the transactions contemplated thereby any time for any reason or for no reason prior to April 11, 2025,
with no further obligations on Cycurion Sub’s part. As of the date of this Annual Report, although we reserve the right to modify
the terms and provisions of the SLG Acquisition Agreement, we do not currently expect to terminate it and currently expect to close the
transactions contemplated during our current fiscal quarter. Substantially all of the agreements to which SLG is a party have a provision
that provides the counterparty to such agreement with a right to approve an assignment or change in control of SLG prior to its effectiveness.
If an approval is not forthcoming, then the provisions of the SLG Acquisition Agreement permit us to excise that specific agreement.
Upon such occurrence, we reserve that right to reduce the consideration that we would otherwise tender to the equity owners of SLG.
As amended by the parties, initially effective
as of November 29, 2023, and subsequently effective as of April 29, 2024, August 16, 2024, and December 31, 2024, the SLG Term Sheet
expires on the soonest of (i) closing of the transactions contemplated thereby, (ii) April 11, 2025, if the transactions contemplated
thereby have not closed by then, (iii) Cycurion Sub’s termination thereof, and (iv) the mutual termination by all of the parties
thereto. Notwithstanding anything to the contrary contained therein, Cycurion Sub may terminate its obligations under the SLG Term Sheet
and the transactions contemplated hereby for any reason or for no reason without any further obligations and without any liability at
any time through and including April 11, 2025. The SLG Term Sheet, as amended, consensually superseded, as noted therein, Cycurion Sub’s
previous “unidirectional” agreement with SLG.
As of March 31, 2025, and in connection with the
economic outcome contemplated by the SLG Term Sheet, we entered into a Management Services Agreement (the “SLG Management Agreement”)
with SLG to ensure SLG’s continuing commercial viability, which, indirectly, assists the commercial viability of Cycurion Sub and
us. To validate and enhance the business relationship with SLG, the parties agreed that Cycurion Sub and we shall, even more formally
than historically, manage and control all of SLG’s operations from and after such date. Accordingly, Cycurion and we shall provide
management, financing, administrative, and other services to SLG (as described in more detail on Schedule A of the SLG Management Agreement)
in exchange for the fees and/or other consideration set forth on Schedule B of the SLG Management Agreement. The relationship, as so
memorialized, results in the relationship between the parties from and after such date (if not prior thereto) results in SLG being deemed
to be a “Variable Interest Entity” of Cycurion (as such relationship is defined by the Financial Accounting Standards Board),
which will result in SLG’s financial statements being consolidated with and into our financial statements.
Our entry into the SLG Management Agreement may accomplish substantially all of SLG’s
and our business objectives and may potentially minimize certain of the risks referenced in the section entitled “Risk Factors
– Risks Related to the SLG Assignment Agreement ”. Accordingly, one or more of the parties to the SLG Term Sheet may
postpone the execution or delivery of the SLG Acquisition Agreement and the consummation of certain of the transactions specifically
contemplated thereby (as also set forth in the SLG Term Sheet), contingent, in part, on the potential agreements of the equity owners
of SLG. Nevertheless, we currently believe that the current draft of the SLG Acquisition Agreement may be executed and delivered by the
parties thereto in the first half of our current fiscal year.
8
The foregoing brief summary description of certain
terms and provisions of (i) the SLG Term Sheet does not purport to be complete and is qualified in its entirety by reference to the full
text of the SLG Term Sheet, a copy of which is attached to this Annual Report as Exhibit 10.12, (ii) the SLG Term Sheet Amendments, a
copy of each of which is attached to this Annual Report as Exhibit 10.12a, Exhibit 10.12b, Exhibit 10.12c, and Exhibit 10.12d, and (iii)
the SLG Management Agreement does not purport to be complete and is qualified in its entirety by reference to the full text of the SLG
Term Sheet, a copy of which is attached to this Annual Report as Exhibit 10.12e. Readers are encouraged to read those Exhibits in full
for a more comprehensive understanding of the transaction contemplated by the SLG Term Sheet.
RCR Acquisition Agreement
RCR Technology Corporation (“RCR”) performs
certain services for SLG in its role as an SLG subcontractor and, in that context, became a creditor of SLG. In connection with the transactions
contemplated by the SLG Term Sheet, on April 25, 2023, Cycurion Sub and RCR also entered into a term sheet (the “RCR Term Sheet”)
for a distinct, but related transaction. The RCR Term Sheet contemplates a transaction, pursuant to which RCR will sell to Cycurion all
of the accounts receivable of SLG in favor of RCR (but for those accounts that are less than 90 days old as of the date of consummation
of the contemplated transaction). The consummation of the transactions contemplated by the RCR Term Sheet is contingent upon the consummation
of the transactions contemplated by the SLG Term Sheet. Nevertheless, as a result of our entry into the SLG Management Agreement with
SLG, we still currently intend to consummate the transactions contemplated by the RCR Term Sheet in the first half of our current fiscal
year. The RCR Term Sheet provides that, if, when, and as the transactions contemplated thereby are consummated, RCR will be issued shares
of our common stock.
Further, as amended by the parties, initially effective
as of November 29, 2023, and subsequently effective as of April 29, 2024, August 16, 2024, and December 31, 2024, the RCR Term Sheet
expires on the soonest of (i) closing of the transactions contemplated thereby, (ii) April 11, 2025, if the transactions contemplated
thereby have not closed by then, (iii) Cycurion’s termination thereof, and (iv) the mutual termination by all of the parties thereto.
Notwithstanding anything to the contrary contained therein, Cycurion may terminate its obligations under the RCR Term Sheet and the transactions
contemplated hereby for any reason or for no reason without any further obligations and without any liability at any time through and
including April 11, 2025. As of the date of this Annual Report, we do not currently expect to terminate the transactions contemplated
by the RCR Term Sheet, as amended, and currently expect to close the transactions in the first half of our current fiscal year.
The foregoing brief summary description of certain
terms and provisions of the RCR Term Sheet does not purport to be complete and is qualified in its entirety by reference to the full
text of the RCR Term Sheet, a copy of which is attached to this Annual Report as Exhibit 10.13 and the full text of the RCR Term Sheet
Amendments, a copy of each of which are attached to this Annual Report as Exhibit 10.13a, 10.13b and 10.13c. Readers are encouraged to
read those Exhibits in full for a more comprehensive understanding of the transaction contemplated by the RCR Term Sheet.
Acquisition of Technology
On August 17, 2021, we entered into an asset purchase
agreement to acquire certain technology assets of Sabres, a leading Israeli-based cyber security provider. As part of the asset purchase
agreement, we acquired Multi-Dimensional Protection, Web Application Firewall and Bot Mitigation SaaS platforms, and their associated
intellectual property. The transaction closed on September 30, 2021, and we have integrated the SaaS platforms into our existing services
offerings.
Our Cycurion Security Platform’s (formerly
Sabres’) line of products allows our customers to improve their cyber posture with its MDP SaaS platform. This platform efficiently
bundles and easily implements the external protection of a Web Application Firewall (WAF) and the internal protection of Bot Mitigation.
Bot Mitigation is the reduction of risk to applications, Application Program Interfaces (APIs), and backend services from malicious bot
traffic that fuels common automated attacks, such as Distributed Denial of Service (DDoS) campaigns and vulnerability probing. The costs
of single-layer security can be measured in terms of money, time, and risk, as well as the damage wrought by a data breach, which millions
of businesses experience each year. Through this interaction of the WAF and Bot Mitigation, the MDP is able to reinforce these layers
of security and generate new security layers in real time in response to emerging threats. This process is directed by our Cycurion Security
Platform’s (formerly Sabres’) proprietary, cloud-based AI algorithm. We do not have AI processing in the production version
of the software. That version is in the testing and evaluation phase. We expect to move the production in quarter three of 2024. Through
a crowdsourcing process, the cloud-based MDP learns from every threat to any protected application and uses that newly acquired knowledge
to protect all MDP clients better.
Our Cycurion Security Platform’s (formerly
Sabres’) line of products provides solutions for substantially all web application security needs. These products provide solutions,
whether a client is in need of a web application firewall to comply with regulations and ensure it has a first line of defense against
the hazards that the internet can present or is in need of enterprise-level products that empower Security Operations Center (SOC) teams
and security management. Our Cycurion Security Platform’s constantly survey a client’s data to detect security issues in
need of attention, send automatic updates, and provide the client with a complete database of rules and threats.
● Multi-Dimensional Protection (MDP)
● On-premises option
● Dual-Layered Defense (WAF/Bot Mitigation)
● Advanced Security Information and Event
Management (SIEM) dashboard
● AI-enabled
● Ongoing reporting and alerts
● No delays for the end-user
● Can connect to any existing WAF
● Easy installation on all platforms
● Exceptional penetration testing results
● No downtime for updating
● No hardware required
● Cloud-based
● Biometric WAF
9
We have integrated the technology assets that we
acquired from Sabres (which now constitutes our Cycurion Security Platform) into our Managed Security Services Practice. We believe that
the platform will enhance our service offerings and assist with the expansion of our commercial business. The Sabres platform will be
managed by our dedicated support team, and will provide real time reporting, response to security incidents, and will manage all data
privacy needs from a single SIEM SaaS platform dashboard.
Our Growth Strategy
Our objectives are to expand our market leadership
and management and to capture large market opportunities in cloud, AI and IT. We intend to accomplish these objectives by:
● Continuing
to acquire to platforms . We believe there is substantial opportunity to increase our
platforms and have experienced growth due to expanded product capabilities and investments.
We intend to continue to pursue new customers by adding capacity and leveraging our partnerships
in the domestic and international markets.
● Expanding
platform coverage with our customers. We believe there is opportunity to develop and
expand our relationships with existing customers by targeting additional platforms and geographies,
pursuing platform expansions and expanding our coverage.
● Investing
in new technology platforms . We plan to continue to develop and broaden our exposure
and security solutions, including expanding our coverage, by entering into new contracts
focused on program management, cybersecurity, disaster recovery and business continuity.
For more information, please see “Item 1. Business – Our Acquisitions.”
● Exploring
acquisition opportunities . We intend to acquire other businesses, technology, AI platforms
and/or development personnel to enhance the functionality of our platforms. For more information,
please see “Item 1. Business – Our Acquisitions.”
Competitors
The IT and cybersecurity solutions market is fragmented,
competitive and always evolving. We compete with a range of established and emerging cybersecurity software and services vendors,
as well as organizations that choose to build their own solutions in-house. With new technologies and market entrants, we expect the
competitive environment to remain intense going forward.
Our competitors include:
● vulnerability
management and assessment vendors;
● diversified
security software and services vendors;
● endpoint
security vendors with vulnerability assessment capabilities;
● public
cloud vendors and other companies that offer solutions for cloud security; and
● providers
of point solutions that compete with some of the features present in our solutions.
The key competitive factors in our markets include:
● ability
to prepare for, detect and mitigate cybersecurity threats;
● ability
to respond to customer needs quickly;
● ability
for products to facilitate customer needs;
● total
cost and ease-of-use of our products;
● brand
awareness and reputation; and
● ability
to attract and retain employees.
We believe that the principal competitive factors
affecting the market for cybersecurity solutions include product functionality, depth of platform offerings, flexibility of
delivery models, ease of deployment and use, integration capabilities such as open APIs and scalability, uptime and performance. Some
of our competitors are more established and have greater name recognition, longer operating histories, more established customer relationships,
larger marketing budgets and significantly greater resources than we do.
Customers
We have over 41 customers across a variety of industries,
including enterprise businesses, small and medium businesses, government agencies, healthcare and higher education. Our customers include,
but are not limited to, AT&T, Smithsonian Museum, FEMA and Peraton. During the years ended December 31, 2024 and 2023, purchases
from our ten largest end-customers accounted for approximately 93% and 88% of our total revenue, respectively.
Backlog
We define backlog as contractually committed orders
to be invoiced under our existing agreements that are not included in deferred revenue on our consolidated balance sheets. We expect
the amount of backlog to change from period to period due to the timing of billings for our solutions and professional services. At December
31, 2024 and 2023, we had committed backlog of $16 million and $15 million, respectively. We expect the majority of the
backlog at December 31, 2024 to be invoiced within the following 12 months.
10
Government Regulation
Our business and operations are subject to extensive
federal and state governmental regulation and supervision. The following is a brief summary of certain statutes and rules and regulations
that affect or may affect us. This summary is not intended to be an exhaustive description of the statutes or regulations applicable
to our business.
In the ordinary course of our business, we process
personal information. Accordingly, we are, or may become, subject to numerous data privacy and security obligations, including federal,
state, local, and foreign laws, regulations, guidance, and industry standards related to data privacy and security. Such obligations
may include, without limitation, the Federal Trade Commission Act, the California Consumer Privacy Act of 2018 as amended by the California
Privacy Rights Act of 2020, or, collectively, the CCPA, the Colorado Privacy Act, Virginia’s Consumer Data Protection Act, the
Connecticut Privacy Act, the Utah Consumer Privacy Act and similar U.S. state comprehensive privacy laws, the European Union’s
General Data Protection Regulation 2016/679, or EU GDPR, the EU GDPR as it forms part of the United Kingdom law by virtue of section
3 of the European Union (Withdrawal) Act of 2018, or UK GDPR, and the ePrivacy Directive.
Human Capital
As of the date of this Annual Report, we have 46
full-time employees and 0 part-time employees. None of our U.S. employees are represented by a labor union or covered by a collective
bargaining agreement. Our senior leadership team has extensive experience with business process management, and while we have grown through
a number of acquisitions, we have retained an experienced and cohesive leadership team.
Our key human capital objectives are to attract,
retain, engage, reward and develop our highly talented existing and future employees, while cultivating an inclusive workforce and culture
to achieve exceptional business results. We are committed to fostering a community of talented individuals from all backgrounds and perspectives
by implementing the following.
● Compensation
and benefits. We continually work to provide a competitive compensation and benefits
program as this plays a key role in our ability to attract and retain a highly skilled workforce.
In addition to salaries, these programs, which vary by country/region, include long-term
equity incentive awards with certain vesting requirements, deferred compensation plans (which
are offered to certain members of executive management), a 401(k) plan, healthcare and insurance
benefits, health savings and flexible spending accounts, paid time off, paid volunteer time
off, employee assistance program and tuition assistance.
● Health,
safety and wellness. The well-being of our employees is paramount to the continued success
of our business. To this end, we are committed to each of our employees’ health, safety
and wellness. We provide our employees with access to various health and wellness benefits
designed to enable them and their family members to have affordable access to health, dental
and vision insurance.
● Talent
development. We invest significant resources to develop the talent needed to remain a
market-leading global supplier of broadband infrastructure. We offer numerous training opportunities
on both technical and professional development topics.
● Diversity
and inclusion. We believe that maintaining a diverse and inclusive workforce is important
to the success of our business. We encourage an environment where individuality is embraced
regardless of age, gender, identity, race, sexual orientation, physical or mental ability,
ethnicity and perspective and where each employee is accepted.
Research and Development
Rapidly changing technologies, evolving industry
standards, changing customer requirements, supply constraints and continuing developments in communications service offerings characterize
the markets for our products. Our on-going ability to adapt to these changes and to develop new and enhanced products that meet or anticipate
market demand is the main factor influencing our competitive position and our ability to grow.
We continue to invest substantial resources in research
and development to enhance our platform offerings by developing new features, functionality, and applications. Our engineering expertise
combines extensive security product development experience with individuals who possess deep cloud and user interface design backgrounds.
Our team is staffed by cybersecurity, cloud and data
science experts who deliver exposure management intelligence, data science insights, alerts and security advisories. Our team has developed
research tools to help improve efficiency and effectiveness in processes such as reverse engineering, code debugging, web app security
and visibility into cloud-based tools.
Intellectual Property
Not
applicable.
Recent
Developments
On
January 15, 2025, Cycurion issued a $50,000 promissory note to an unaffiliated investor for $50,000 in proceeds.
On
January 21, 2025, Cycurion issued a $75,000 promissory note to an unaffiliated investor for $75,000 in proceeds.
On
January 25, 2025, Cycurion issued a $50,000 promissory note to an unaffiliated investor for $50,000 in proceeds.
On
January 31, 2025, Cycurion issued a $125,000 promissory note to a related party for 125,000 in proceeds.
On
January 24, 2025, Western Acquisition Ventures Corp., a Delaware Corporation (“Western”), held the Special Meeting,
at which the Western stockholders considered and adopted, among other matters, a proposal to approve a business combination (“Business
Combination”) pursuant to the terms of that certain Agreement and Plan of Merger, dated April 26, 2024, as amended on December 31,
2024 and February 13, 2025 (the “Merger Agreement”), by and among Western, WAV Merger Sub, Inc., a Delaware corporation
and a wholly-owned subsidiary of Western (“Merger Sub”), and Cycurion Sub, Inc., a Delaware corporation (“Cycurion
Sub”).
On February 14, 2025, the Business Combination closed,
and, as contemplated by the Merger Agreement, Merger Sub merged with and into Cycurion Sub with Cycurion Sub surviving the merger as
a wholly-owned subsidiary of Western. In addition, in connection with the consummation of the Business Combination, Western Acquisition
Ventures Corp. was renamed “Cycurion, Inc.”
On February 18, 2025, Cycurion’s common stock
began trading on The Nasdaq Global Market and warrants began trading on The Nasdaq Capital Market under the symbols “CYCU”
and “CYCUW”, respectively.
On February 19, 2025, Cycurion announced an agreement
with iQSTEL, a multinational innovator in telecommunications, FinTech, electric vehicles and AI-driven solutions.
11
On February 24, 2025, Cycurion announced an expansion
of its partnership with a major health association, bringing its MSSP to several thousand member organizations across the country.
On March 3, 2025, Cycurion announced the availability
of its ARx Platform targeted for the corporate sector.
On March 5, 2025, Cycurion announced the award of
three new multi-year contracts focused on program management, cybersecurity and disaster and business continuity. These engagements are
secured with two government clients and one commercial client.
On March 6, 2025, Cycurion announced a nationwide
expansion of its strategic partnership with CentralSquare Technologies, LLC to deliver its IT services across the country.
On April 7, 2025, Cycurion entered into an equity
purchase agreement with Yield Point NY LLC whereby the Company has the right, but not the obligation, to direct the investor to purchase
up to $60,000,000.
On April 8, 2025, Cycurion announced an expanded
partnership with Journal Technologies. Together, the companies have been awarded a $22 million multi-year contract to deliver a criminal
justice case management system to a state police agency.
On April 9, 2025, Cycurion increased the size of
its board of directors through the appointment of Irving Minnaker.
On April 9, 2025, Cycurion received written notice
received from the Listing Qualifications Department of Nasdaq stating that, for the prior 30 consecutive business days, the closing
bid price of our common stock had been below the minimum of $1.00 per share required for continued listing on The Nasdaq Capital Market
under Nasdaq Listing Rule 5550(a)(2). The notification letter stated that we would be afforded 180 calendar days (until October
6, 2025) to regain compliance. In order to regain compliance, the closing bid price of our common stock must be at least $1.00 for a
minimum of ten consecutive business days. The notification letter also stated that, in the event that we do not regain compliance within
the initial 180-day period, we may be eligible for an additional 180-day period. If we are not eligible for the additional 180-day period,
or if it appears to the Nasdaq staff that we will not be able to cure the deficiency, the Nasdaq Listing Qualifications Department will
provide notice after the end of the initial 180-day period that our securities will be subject to delisting. Failure to regain compliance
within that 180-day period would result in the delisting of our securities from Nasdaq, although we would have the right to appeal such
a delisting to a Nasdaq hearings panel. The Nasdaq notification has no effect at this time on the listing of our common stock.
On April 11, 2025, we received two letters from
the Nasdaq Listing Qualifications Department, each addressing a separate compliance deficiency of ours under the Nasdaq Listing Rules.
The first letter notified us of our deficiency with regard to Nasdaq Listing Rule 5450(b)(2)(A), which requires a company such as ours,
whose securities are listed on The Nasdaq Global Market under the “Market Value Standard”, to maintain a minimum Market Value
of Listed Securities (an “MVLS”) of $50,000,000. The deficiency was caused by our MVLS having been below the minimum
level for the prior 30 consecutive business days. Under Nasdaq Listing Rule 5810(c)(3)(C), we are entitled to a 180-day period, ending
on October 8, 2025, to rectify the deficiency. In order to do so, we must achieve and maintain an MVLS of at least $50,000,000 or
more for a minimum of 10 consecutive business days. Failure to regain compliance within that 180-day period would result in the delisting
of our securities from Nasdaq, although we would have the right to appeal such a delisting to a Nasdaq hearings panel. The Nasdaq notification
has no effect at this time on the listing of our common stock.
The second letter notified us of our deficiency
with regard to Nasdaq Listing Rule 5450(b)(2)(C), which requires a minimum Market Value of Publicly Held Shares (an “MVPHS”)
of $15,000,000 for continued listing on the Nasdaq Global Market under the “Market Value Standard”. This deficiency was caused
by our MVPHS having been below the minimum level for the prior 30 consecutive business days. Under Nasdaq Listing Rule 5810(c)(3)(D),
we have 180 calendar days, or until October 8, 2025, to regain compliance, which we can achieve if our MVPHS is at least $15,000,000
for a minimum of 10 consecutive business days. Failure to regain compliance within that 180-day period would result in the delisting
of our securities from Nasdaq, although we would have the right to appeal such a delisting to a Nasdaq hearings panel. The Nasdaq notification
has no effect at this time on the listing of our common stock.
For more information, please see “Note 19.
Subsequent Events.”
Corporate Information
Our principal executive office is located at 1640
Boro Place, Fourth Floor, McLean, Virginia 22102, and our telephone number is (703) 854-1652. Our website address is www.cycurion.com.
Axxum’s website address is www.axxumtech.com. Cloudburst’s website address is www.cloudburstsecurity.com. The SEC maintains
an internet site that contains reports, proxy and information statements and other information regarding issuers that file electronically
with the SEC at www.sec.gov. The information contained on the websites referenced in this Annual Report is not incorporated by reference
into this filing.