Cycurion, Inc.
−Removed: (collectively with its subsidiaries,
−Removed: the “Company,” “Cycurion,” “we,” “us” or “our”) was originally incorporated
−Removed: as KAE Holdings, Inc., under the laws of the State of Delaware in October 2017, with the purpose of acquiring and holding operating entities
−Removed: in the cybersecurity industry.
+Added: (collectively with its subsidiaries, the "Company," "Cycurion," "we," "us" or "our") is a publicly traded, cybersecurity and artificial intelligence ("AI")-powered IT solutions provider headquartered in McLean, Virginia.
+Added: We were originally incorporated as KAE Holdings, Inc.
+Added: under the laws of the State of Delaware in October 2017, with the purpose of acquiring and holding operating entities in the cybersecurity industry.
On July 14, 2020, we changed our corporate name from KAE Holdings, Inc.
−Removed: to Cyber Secure Solutions, Inc.,
−Removed: and, on February 24, 2021, to Cycurion, Inc.
−Removed: On February 14, 2025, the date of closing of our de-SPAC transaction, we merged into Western
−Removed: Acquisition Ventures Corp.
−Removed: and changed that company’s name to Cycurion, Inc.
−Removed: We have one first-tier wholly-owned subsidiary, Cycurion
−Removed: (formerly Cycurion, Inc., until February 14, 2025), and three indirectly wholly-owned second-tier subsidiaries:
−Removed: (i) Axxum Technologies
−Removed: LLC (“Axxum”), a Virginia limited liability company formed in December 2006, (ii) Cloudburst Security LLC (“Cloudburst”),
−Removed: a Virginia limited liability company formed in January 2007, and (iii) Cycurion Innovation, Inc., a Delaware corporation formed in September
−Removed: 2021, in connection with our acquisition of assets from Sabres Security Ltd.
−Removed: (“Sabres”), a leading Israeli-based cyber security
−Removed: We provide innovative custom solutions for our clients
−Removed: by adapting our superior knowledge base and government-level experience to create dynamic solutions to best serve our client’s
−Removed: information technology (“IT”) and cybersecurity needs.
−Removed: We assess, secure and advise your organization by leveraging our government
−Removed: proven, cutting edge techniques, custom tools and extensively knowledgeable personnel to revolutionize the client’s cybersecurity
−Removed: We are committed to surpassing expectations and delivering
−Removed: incomparable value to our clients and partners.
−Removed: We achieve this goal by providing Network Communications and Information Technology Security
−Removed: services and solutions that are custom-tailored to your environment, as well as your level of need.
−Removed: We are built on a foundation of experts
−Removed: in Network Communications and Information Technology who possess unrivaled security expertise and experience.
−Removed: We are committed to hiring
−Removed: the most knowledgeable professionals in order to expand and reinforce our team of experts, leveraging world-class talent to improve and
−Removed: expand upon our already vast understanding of this environment.
−Removed: We pride ourselves on having the capability and resources to successfully
−Removed: implement a management strategy that delivers the solutions you need to stay within budget and on schedule.
−Removed: We deliver high-quality, cybersecurity solutions
−Removed: to federal government civilian, defense and judicial agencies in addition to commercial clients across a variety of industries.
−Removed: our operating subsidiaries and strategic partnerships, have numerous prime and subcontracts with key government agencies.
−Removed: engine is driven by organic business solutions and strategic acquisitions of cybersecurity services and technology providers.
−Removed: our highly skilled workforce to access, secure and advise our clients to improve their cyber security posture.
−Removed: Our ability to identify
−Removed: and implement customized solutions is core to driving continued growth.
+Added: to Cyber Secure Solutions, Inc., and, on February 24, 2021, to Cycurion, Inc.
+Added: On February 14, 2025, Cycurion completed the business combination and transactions (the "Business Combination") as set forth in an Agreement and Plan of Merger, dated November 21, 2022, as amended on April 26, 2024, December 31, 2024 and February 13, 2025 (the "Merger Agreement"), by and among Western Acquisition Ventures Corp.
+Added: ("Western"), Western Acquisition Merger Inc., a Delaware corporation and a wholly-owned subsidiary of Western ("Merger Sub"), and Cycurion Sub, Inc., a Delaware corporation formerly known as Cycurion, Inc.
+Added: ("Cycurion Sub").
+Added: As contemplated by the Merger Agreement, Merger Sub merged with and into Cycurion Sub with Cycurion Sub as surviving the merger as a wholly-owned subsidiary of Western.
+Added: In addition, in connection with the consummation of the Business Combination, Western was renamed "Cycurion, Inc."
+Added: Following the closing of the Business Combination, our shares of common stock and warrants commenced trading on The Nasdaq Stock Market LLC ("Nasdaq") under the ticker symbols "CYCU" and "CYCUW," respectively.
+Added: We have two first-tier wholly-owned subsidiaries, Cycurion Sub (formerly Cycurion, Inc., until February 14, 2025) and Cycurion Crypto Inc., a Delaware corporation formed in July 2025, and three indirectly wholly-owned second-tier subsidiaries:
+Added: (i) Axxum Technologies LLC ("Axxum"), a Virginia limited liability company formed in December 2006, (ii) Cloudburst Security LLC ("Cloudburst"), a Virginia limited liability company formed in January 2007, and (iii) Cycurion Innovation, Inc., a Delaware corporation formed in September 2021, in connection with our acquisition of assets from Sabres Security Ltd.
+Added: ("Sabres"), a leading Israeli-based cybersecurity provider.
+Added: In addition, we also integrated SLG Innovation, Inc.
+Added: ("SLG"), which provides data modernization and technology services to state and local government agencies, expanding our footprint in public-sector IT modernization.
+Added: We provide innovative custom solutions for our clients by adapting our knowledge base and government-level experience to create dynamic solutions to best serve our client's IT and cybersecurity needs.
+Added: We assess, secure and advise your organization by leveraging our government proven, cutting edge techniques, custom tools and extensively knowledgeable personnel to revolutionize the client’s cybersecurity posture.
+Added: We are committed to surpassing expectations and delivering incomparable value to our clients and partners.
+Added: We achieve this goal by providing network communications and information technology security services and solutions that are custom-tailored to your environment, as well as your level of need.
+Added: We are built on a foundation of experts in network communications and information technology who possess unrivaled security expertise and experience.
+Added: We are committed to hiring the most knowledgeable professionals in order to expand and reinforce our team of experts, leveraging world-class talent to improve and expand upon our already vast understanding of this environment.
+Added: We pride ourselves on having the capability and resources to successfully implement a management strategy that delivers the solutions you need to stay within budget and on schedule.
+Added: We deliver high-quality, cybersecurity solutions to federal government civilian, defense and judicial agencies in addition to commercial clients across a variety of industries.
+Added: We, through our operating subsidiaries and strategic partnerships, have numerous prime and subcontracts with key government agencies.
+Added: Our growth engine is driven by organic business solutions and strategic acquisitions of cybersecurity services and technology providers.
+Added: We leverage our highly skilled workforce to access, secure and advise our clients to improve their cybersecurity posture.
+Added: Our ability to identify and implement customized solutions is core to driving continued growth.
Consulting and Advisory Services
−Removed: Our consulting services perform a detailed review
−Removed: of our customers’ IT security to identify and address vulnerabilities.
−Removed: Using advanced tools and research techniques, we enhance
−Removed: our customers’ cybersecurity program to meet regulatory compliance, data confidentiality and privacy standards, and train our customers’
−Removed: personnel accordingly.
−Removed: Our advisory services supplement our consulting services
−Removed: with a cost-effective alternative to a full-time chief information officer.
−Removed: Our customers gain access to our pool of experienced chief
−Removed: information officers, who are backed by our resources.
−Removed: They deliver tailored advice and training to keep our customers’ organization
−Removed: ahead in the ever-changing cybersecurity landscape.
+Added: Our consulting services perform a detailed review of our customers' IT security to identify and address vulnerabilities.
+Added: Using advanced tools and research techniques, we enhance our customers' cybersecurity program to meet regulatory compliance, data confidentiality and privacy standards, and train our customers' personnel accordingly.
+Added: Our advisory services supplement our consulting services with a cost-effective alternative to a full-time chief information officer.
+Added: Our customers gain access to our pool of experienced chief information officers, who are backed by our resources.
+Added: They deliver tailored advice and training to keep our customers’ organization ahead in the ever-changing cybersecurity landscape.
Our consulting and advisory services include:
−Removed: security control assessments;
+Added: (i) security control assessments;
(ii) security architecture and engineering;
6 unchanged sentences
Managed IT Services
−Removed: Our managed IT services can optimize an organization’s
−Removed: IT infrastructure, reduce costs and improve operational efficiency, and it offers comprehensive IT management and support for organizations
−Removed: of all sizes.
−Removed: Managed IT services is a services model in which
−Removed: a managed service provider (“MSP”) remotely manages the day-to-day IT offerings for a client under a service level agreement
−Removed: This includes remote monitoring and management of servers, disaster recovery, infrastructure as a service (“IaaS”),
−Removed: platform as a service (“PaaS”), and software as a service (“SaaS”).
−Removed: In short, managed IT services provides businesses
−Removed: with IT support and maintenance on an ongoing basis.
−Removed: IT services are typically provided on a break-fix
−Removed: basis, meaning that the client only calls the provider when there is a problem with its IT infrastructure.
−Removed: Managed IT services, on the
−Removed: other hand, are provided on an ongoing basis under an SLA.
−Removed: This means that the MSP is responsible for the day-to-day maintenance of the
−Removed: client’s IT infrastructure and is always monitoring and managing the system to ensure it is running smoothly.
−Removed: For example, a company that provides cloud services
−Removed: to businesses would offer managed platform services, remote monitoring and management of servers and security services.
−Removed: The MSP would
−Removed: handle the day-to-day maintenance of the client’s IT infrastructure and offers disaster recovery services in the event of a data
−Removed: breach or other catastrophe.
+Added: Our managed IT services can optimize an organization's IT infrastructure, reduce costs and improve operational efficiency, and it offers comprehensive IT management and support for organizations of all sizes.
+Added: Managed IT services is a services model in which a managed service provider ("MSP") remotely manages the day-to-day IT offerings for a client under a service level agreement ("SLA").
+Added: This includes remote monitoring and management of servers, disaster recovery, infrastructure as a service ("IaaS"), platform as a service ("PaaS"), and software as a service ("SaaS").
+Added: In short, managed IT services provides businesses with IT support and maintenance on an ongoing basis.
+Added: IT services are typically provided on a break-fix basis, meaning that the client only calls the provider when there is a problem with its IT infrastructure.
+Added: Managed IT services, on the other hand, are provided on an ongoing basis under an SLA.
+Added: This means that the MSP is responsible for the day-to-day maintenance of the client’s IT infrastructure and is always monitoring and managing the system to ensure it is running smoothly.
+Added: For example, a company that provides cloud services to businesses would offer managed platform services, remote monitoring and management of servers and security services.
+Added: The MSP would handle the day-to-day maintenance of the client’s IT infrastructure and offers disaster recovery services in the event of a data breach or other catastrophe.
Our managed IT services include:
−Removed: (i) project and
−Removed: license management;
+Added: (i) project and license management;
(ii) network infrastructure;
(iii) systems engineering and administration;
−Removed: (iv) voice and data infrastructure engineering
−Removed: and management;
+Added: (iv) voice and data infrastructure engineering and management;
(iv) application development;
2 unchanged sentences
Managed Security Services
−Removed: We are a professional and trusted provider of managed
−Removed: security services.
−Removed: Our comprehensive security management solution is designed to help organizations protect their digital assets against
−Removed: various cyber threats.
+Added: We are a professional and trusted provider of managed security services.
+Added: We have designed comprehensive security management solution to help organizations protect their digital assets against various cyber threats.
Our managed security services include 24/7 monitoring, threat detection, incident response and remediation.
−Removed: Security Operations Center (SOC) as a service offers organizations with a team of security professionals dedicated to monitoring and
−Removed: managing their security infrastructure.
−Removed: Managed security services (“MSS”) are
−Removed: a crucial component of a robust security program.
−Removed: Managed security service providers (“MSSPs”) specialize in protecting businesses
−Removed: from cyber threats and deliver a range of security services including, but not limited to, intrusion detection, vulnerability assessments
−Removed: and network security services.
−Removed: MSSPs offer organizations access to a dedicated team
−Removed: of security professionals who use the latest security architectures and technologies to monitor their clients’ networks and systems,
−Removed: identify potential threats and respond promptly to security incidents.
−Removed: This is especially important for small to mid-sized businesses
−Removed: that may not have the in-house resources to maintain a robust security posture on their own.
−Removed: MSS plays a critical role in safeguarding businesses
−Removed: from cyber threats in today’s digital landscape, making them an essential partner for organizations across industries.
−Removed: with clients ranging from small businesses to large enterprises and are often partnered with internet service providers to provide comprehensive
−Removed: security solutions.
−Removed: Managed security services can also help organizations
−Removed: meet compliance requirements and reduce the risk of data breaches, which can be costly in terms of lost data, damaged reputation, and
−Removed: regulatory penalties.
−Removed: Additionally, MSSPs can provide SaaS solutions, allowing businesses to access security tools and services on-demand
−Removed: without having to invest in expensive hardware and software.
−Removed: Our managed security services include:
−Removed: detection and response;
+Added: Our Security Operations Center ("SOC") as a service offers organizations with a team of security professionals dedicated to monitoring and managing their security infrastructure.
+Added: Managed security services ("MSS") are a crucial component of a robust security program.
+Added: Managed security service providers ("MSSPs") specialize in protecting businesses from cyber threats and deliver a range of security services including, but not limited to, intrusion detection, vulnerability assessments and network security services.
+Added: MSSPs offer organizations access to a dedicated team of security professionals who use the latest security architectures and technologies to monitor their clients’ networks and systems, identify potential threats and respond promptly to security incidents.
+Added: This is especially important for small to mid-sized businesses that may not have the in-house resources to maintain a robust security posture on their own.
+Added: MSS plays a critical role in safeguarding businesses from cyber threats in today's digital landscape, making them an essential partner for organizations across industries.
+Added: MSSPs work with clients ranging from small businesses to large enterprises and are often partnered with internet service providers to provide comprehensive security solutions.
+Added: Managed security services can also help organizations meet compliance requirements and reduce the risk of data breaches, which can be costly in terms of lost data, damaged reputation, and regulatory penalties.
+Added: Additionally, MSSPs can provide SaaS solutions, allowing businesses to access security tools and services on-demand without having to invest in expensive hardware and software.
+Added: Our MSS include:
+Added: (i) managed detection and response;
(ii) external attack surface management;
(iii) threat hunting and threat intelligence;
−Removed: (iv) end point detection
−Removed: and response;
+Added: (iv) end point detection and response;
(v) firewall management;
1 unchanged sentence
(vii) vulnerability and penetration testing;
−Removed: 24/7/365 security monitoring;
+Added: (viii) 24/7/365 security monitoring;
and (ix) digital forensic and incident response.
−Removed: Our Industries
−Removed: Enterprise Business
−Removed: Enterprise level organizations face a litany of challenges
−Removed: when curating and implementing a successful IT environment.
−Removed: Challenges generally evolve from multiple points, such as finding experienced
−Removed: and deeply knowledgeable IT staff that is prepared for all security eventualities, to creating a comprehensive, functional, and compliant
−Removed: interface tends to create a high cost, knowledge deficient, and overwhelmed staff that often lacks in providing a positive ROI, and at
−Removed: times a cost-prohibitive scenario.
−Removed: As digitization of operations becomes a necessity
−Removed: in the current environment, we plan to help our customers hire the right personnel and implement proper protocols in a time- and cost-efficient
−Removed: We will take the responsibility from initial analysis to full spectrum implementation of our services, duly optimizing our customers’
−Removed: organization and digital environment for the future.
−Removed: We offer an evolutionary solution for this knowledge
−Removed: gap by providing deeply knowledgeable experts and highly trained analysts directly to our customers’ organization as a service.
−Removed: Our contract analysts provide more than just their individual expertise to solve specific challenges, but also will leverage Cycurion’s
−Removed: entire repository of collective knowledge, techniques and methodologies to our customers’ organization, at a cost below that of
−Removed: hiring an IT department, while providing highly efficient, multi-disciplined and deeply knowledgeable expert solutions to our customers.
−Removed: Government entities face a number of compliance and
−Removed: certification challenges.
−Removed: With constantly changing legislation, meeting government mandate and expectations in the IT environment is
−Removed: often a challenge.
−Removed: We leverage our historical knowledge and extensive experience on the federal level to continue to fulfill all of IT
−Removed: needs across the government organization.
−Removed: Bad actors attack government agencies by targeted
−Removed: cyber threats, personnel exploitation and creative manipulation to gain access to critical systems and infrastructure through unperceived
−Removed: vulnerabilities.
−Removed: Public platforms, such as social media, surface, deep and dark web, present substantial risks through knowledge gaps
−Removed: in personnel training, presenting high risk and substantial possibility of security failure.
−Removed: We have been defending and optimizing these
−Removed: environments at the federal level for over a decade and, as a result, have created a robust and predictive methodology to defend and
−Removed: optimize government organizational and security gaps in order to mitigate these threats and vulnerabilities before they are compromised.
−Removed: We provide the knowledge, experience and analytical understanding of this environment to evolve our services to meet current and future
−Removed: needs across the IT spectrum.
−Removed: Our extensive knowledge and real-world experience
−Removed: with government agencies allow us to understand the operational, security and overall IT needs and challenges that such agencies must
−Removed: overcome to achieve their mandate.
−Removed: We leverage our experience in this space allowing us to provide best-practice solutions throughout
−Removed: the IT environment.
+Added: Industries We Serve
+Added: Government entities face a number of compliance and certification challenges.
+Added: With constantly changing legislation, meeting government mandate and expectations in the IT environment is often a challenge.
+Added: We leverage our historical knowledge and extensive experience on the federal level to continue to fulfill all of IT needs across the government organization.
+Added: Bad actors attack government agencies by targeted cyber threats, personnel exploitation and creative manipulation to gain access to critical systems and infrastructure through unperceived vulnerabilities.
+Added: Public platforms, such as social media, surface, deep and dark web, present substantial risks through knowledge gaps in personnel training, presenting high risk and substantial possibility of security failure.
+Added: We have been defending and optimizing these environments at the federal level for over a decade and, as a result, have created a robust and predictive methodology to defend and optimize government organizational and security gaps in order to mitigate these threats and vulnerabilities before they are compromised.
+Added: We provide the knowledge, experience and analytical understanding of this environment to evolve our services to meet current and future needs across the IT spectrum.
+Added: Our extensive knowledge and real-world experience with government agencies allow us to understand the operational, security and overall IT needs and challenges that such agencies must overcome to achieve their mandate.
+Added: We leverage our experience in this space allowing us to provide best-practice solutions throughout the IT environment.
Small and Medium Businesses
−Removed: We offer IT solutions for small and medium businesses
−Removed: through different management plans by offering IT services and solutions with the same resources, concentrations and knowledge-based
−Removed: analytical methodology that are used for our enterprise and government clients.
−Removed: We provide roadmaps to successful integration, streamlining
−Removed: the businesses’ operation for maximum effectiveness by developing comprehensive IT solutions to navigate the modern cyber environment.
−Removed: We leverage our expertise and experience from our work in the federal environment, custom tailoring these solutions to your business,
−Removed: no matter the size, while focusing on our customers’ business needs and budget.
−Removed: We understand that healthcare organizations must
−Removed: manage a vast array of rapidly evolving complexities.
−Removed: Our company will lead healthcare organizations through the demands of HIPAA / HITECH
−Removed: security and privacy compliance requirements.
−Removed: We offer healthcare IT services to augment and refine an organization through auditing
−Removed: and assessment of the organization, staff, applications, compliance, risk, vulnerability and infrastructure in order to improve the entity’s
−Removed: ability to better serve the healthcare needs of the organization’s clients.
−Removed: We understand the key drivers of the healthcare market,
−Removed: and continually create focused, innovative and repeatable solutions.
−Removed: We provide technology services to improve service delivery with
−Removed: a focus on system integration, process reengineering, cloud/web / mobile development, solutions for coordinated community care and case
−Removed: management applications.
−Removed: We have extensive experience providing management consulting from strategic planning, IT assessment, project
−Removed: management, application rationalization, enterprise architecture, organizational change management and training.
+Added: We offer IT solutions for small and medium businesses through different management plans by offering IT services and solutions with the same resources, concentrations and knowledge-based analytical methodology that are used for our enterprise and government clients.
+Added: We provide roadmaps to successful integration, streamlining the businesses’ operation for maximum effectiveness by developing comprehensive IT solutions to navigate the modern cyber environment.
+Added: We leverage our expertise and experience from our work in the federal environment, custom tailoring these solutions to your business, no matter the size, while focusing on our customers’ business needs and budget.
+Added: We understand that healthcare organizations must manage a vast array of rapidly evolving complexities.
+Added: Our company will lead healthcare organizations through the demands of HIPAA / HITECH security and privacy compliance requirements.
+Added: We offer healthcare IT services to augment and refine an organization through auditing and assessment of the organization, staff, applications, compliance, risk, vulnerability and infrastructure in order to improve the entity’s ability to better serve the healthcare needs of the organization’s clients.
+Added: We understand the key drivers of the healthcare market, and continually create focused, innovative and repeatable solutions.
+Added: We provide technology services to improve service delivery with a focus on system integration, process reengineering, cloud/web/mobile development, solutions for coordinated community care and case management applications.
+Added: We have extensive experience providing management consulting from strategic planning, IT assessment, project management, application rationalization, enterprise architecture, organizational change management and training.
+Added: Enterprise Business
+Added: Enterprise level organizations face a litany of challenges when curating and implementing a successful IT environment.
+Added: Challenges generally evolve from multiple points, such as finding experienced and deeply knowledgeable IT staff that is prepared for all security eventualities, to creating a comprehensive, functional, and compliant interface tends to create a high cost, knowledge deficient, and overwhelmed staff that often lacks in providing a positive return on investment, and at times a cost-prohibitive scenario.
+Added: As digitization of operations becomes a necessity in the current environment, we plan to help our customers hire the right personnel and implement proper protocols in a time- and cost-efficient manner.
+Added: We will take the responsibility from initial analysis to full spectrum implementation of our services, duly optimizing our customers’ organization and digital environment for the future.
+Added: We offer an evolutionary solution for this knowledge gap by providing deeply knowledgeable experts and highly trained analysts directly to our customers' organization as a service.
+Added: Our contract analysts provide more than just their individual expertise to solve specific challenges, but also will leverage Cycurion's entire repository of collective knowledge, techniques and methodologies to our customers' organization, at a cost below that of hiring an IT department, while providing highly efficient, multi-disciplined and deeply knowledgeable expert solutions to our customers.
Higher Education
−Removed: We offer cybersecurity services and solutions for
−Removed: universities and high education and protect our customers’ systems, information and students from cyber threats and attacks.
−Removed: end-to-end managed cybersecurity solutions include:
+Added: We offer cybersecurity services and solutions for universities and higher education and protect our customers' systems, information and students from cyber threats and attacks.
+Added: Our end-to-end managed cybersecurity solutions include:
(i) IT and cybersecurity audit, consulting and advisory services;
−Removed: (ii) Security Operation
−Removed: Center (SOC) Network services;
+Added: (ii) SOC network services;
(iii) virtual chief information security officers;
−Removed: and (iv) cyber awareness and threat intelligence training
+Added: and (iv) cyber awareness and threat intelligence training services.
We have over 150 years of experience on our management team and have served over 275,000 students.
Cycurion ARx Platform
−Removed: The Cycurion ARx platform is a turnkey web application
−Removed: protection and managed security solution that combines the essential cybersecurity layers in a comprehensive, customizable platform.
+Added: The Cycurion ARx platform is a turnkey web application protection and managed security solution that combines the essential cybersecurity layers in a comprehensive, customizable platform.
This platform offers:
(i) Geo Gate Protection;
−Removed: (ii) DDoS Protection;
−Removed: (iii) WAF and API Protection;
+Added: (ii) DoS Protection (defined below);
+Added: (iii) WAF (defined below) and API (defined below) Protection;
(iv) Endpoint Protection;
+Added: and (v) Bot Hunter Protection.
+Added: • Geo Gate Protection .
+Added: This reverse proxy server makes geographic restrictions easy, thus reducing unwanted traffic.
+Added: • DoS Protection .
+Added: This denial-of-service ("DoS") protection mitigates the threat from malicious actors attempting to flood the entry point of an application.
+Added: • WAF and API Protection .
+Added: Web Application Firewall ("WAF") protection inspects requests in real-time and filters out harmful traffic, while application programming interfaces ("API") protection is a defense mechanism involving a two-step process of authenticating the data sender and inspecting the data to ensure no malicious data injections have occurred.
+Added: • Endpoint Protection .
+Added: This countermeasure ensures that devices follow compliance and security policies, preventing intrusion from particular vectors.
• Bot Hunter Protection .
−Removed: Gate Protection .
−Removed: This reverse proxy server makes geographic restrictions easy, thus reducing
−Removed: unwanted traffic.
−Removed: This distributed denial-of-service (“DDOC”) protection mitigates
−Removed: the threat from malicious actors attempting to flood the entry point of an application.
−Removed: and API Protection .
−Removed: Web Application Firewall (“WAF”) protection inspects
−Removed: requests in real-time and filters out harmful traffic, while application programing interfaces
−Removed: (“API”) protection is a defense mechanism involving a two-step process of authenticating
−Removed: the data sender and inspecting the data to ensure no malicious data injections have occurred.
−Removed: This countermeasure ensures that devices follow compliance and security policies,
−Removed: preventing intrusion from particular vectors.
−Removed: Our proprietary algorithm provides detection and protection against non-human
−Removed: This can prevent low-level threats like unwanted scraping, and high-level threats
−Removed: like attempted system breaches.
−Removed: Key Performance Indicators
−Removed: Gross Profit ($)
−Removed: Operating Income ($)
−Removed: Net Income/(Loss) ($)
−Removed: Number of Customers
−Removed: Our Subsidiaries
−Removed: Cycurion Sub, Inc.
−Removed: Our operating subsidiaries are wholly owned by Cycurion
−Removed: Sub., Inc., a Delaware corporation that, until the closing date of the de-SPAC, was known as “Cycurion, Inc.” We continue
−Removed: to conduct our business through the three below-described entities, which are now indirectly wholly-owned second-tier subsidiaries by
−Removed: virtue of the recent closing of the de-SPAC transaction.
−Removed: Axxum Technologies LLC
−Removed: Organized in the Commonwealth of Virginia on December
−Removed: 29, 2006, Axxum is a cybersecurity provider with successful assignments within the multiple sub-agencies of the Department of Homeland
−Removed: We acquired Axxum in November 2017.
−Removed: Following our acquisition, we continued Axxum’s core operations of providing contractor
−Removed: services to its existing federal government customer base, while leveraging our existing processes and tools to expand its commercial
−Removed: Axxum has the specialized skills and experience
−Removed: to provide a strategy and tactics to help organizations defend against cyber-attacks and implement a secure network infrastructure.
−Removed: team has extensive experience implementing cybersecurity solutions against internal and external threats to the health of our clients’
−Removed: Axxum’s information security focus produces several key benefits:
−Removed: Client Focus :
−Removed: Axxum’s projects are overseen directly by its program managers, all
−Removed: of whom have information security backgrounds and are fully authorized to promptly implement
−Removed: client requirements throughout the performance life cycle.
−Removed: ● Streamlined
−Removed: and Process Focused :
−Removed: Axxum’s streamlined infrastructure leverages ISO quality standards
−Removed: integrated with emerging and established technologies, allowing it to engineer innovative
−Removed: solutions without building in excessive overhead.
−Removed: ● Outstanding
−Removed: Axxum has a reputation of employing cybersecurity experts.
−Removed: Cloudburst Security LLC
−Removed: Organized in the Commonwealth of Virginia on January
−Removed: 12, 2007, Cloudburst specializes in providing a full spectrum of high-quality, innovative cybersecurity services to both government and
−Removed: commercial organizations, such as banking and financial;
−Removed: education and schools;
−Removed: critical infrastructure and supervisory control
−Removed: and data acquisition;
−Removed: and manufacturing.
−Removed: Cloudburst’s mission is to help our clients — of all sizes
−Removed: and mission types — protect their integral data and information assets, so that they can focus on their core competencies.
−Removed: We focus on providing tailored solutions that leverage
−Removed: the industry’s best minds and technologies to predict, protect, detect, respond, and sustain our clients from the latest evolving
−Removed: cyber threats.
−Removed: We acquired Cloudburst in April 2019.
−Removed: Cycurion Innovation, Inc.
−Removed: Our Cycurion Security Platform’s line of products
−Removed: allows our customers to improve their cyber posture with its Multi-Dimensional Protection (“MDP”) SaaS platform.
−Removed: This platform
−Removed: efficiently bundles and easily implements the external protection of a Web Application Firewall (WAF) and the internal protection of
−Removed: Bot Mitigation.
−Removed: Bot Mitigation is the reduction of risk to applications, Application Program Interfaces (APIs), and backend services
−Removed: from malicious bot traffic that fuels common automated attacks, such as Distributed Denial of Service (DDoS) campaigns and vulnerability
−Removed: The costs of single-layer security can be measured in terms of money, time, and risk, as well as the damage wrought by a data
−Removed: breach, which millions of businesses experience each year.
−Removed: Through this interaction of the WAF and Bot Mitigation, the MDP is able to
−Removed: reinforce these layers of security and generate new security layers in real time in response to emerging threats.
−Removed: This process is directed
−Removed: by our Cycurion Security Platform’s proprietary, cloud-based artificial intelligence (“AI”) algorithm.
−Removed: Crucially, the
−Removed: AI underpinning the MDP platform is constantly evolving to counter new threats.
−Removed: Through a crowdsourcing process, the cloud-based MDP
−Removed: learns from every threat to any protected application and uses that newly acquired knowledge to protect all MDP clients better.
−Removed: Our Subcontractor Relationship
−Removed: SLG Innovation, Inc.
−Removed: We are currently a subcontractor for several keystone
−Removed: contracts held by SLG Innovation, Inc.
−Removed: The SLG team has an average of over 25 years of experience in the development,
−Removed: planning, implementation, and management of information systems.
−Removed: SLG’s leadership team offers years of combined success in answering
−Removed: the needs of government agencies and healthcare organizations across the country.
−Removed: The SLG team has worked nationally, as it has served
−Removed: over 25 Department of Health and Human Services agencies, all 50 state governments and over 250 local governments.
−Removed: inception, it has primarily focused on customers in the middle of the country.
−Removed: The team of professionals has successfully delivered Information
−Removed: Technology, Project Management, and Subject Matter Services to key health and human service projects, including, but not limited to,
−Removed: state Medicaid programs in Illinois, Indiana, Nebraska, and Tennessee, the Indiana Division of Aging, Illinois Early Intervention, University
−Removed: of Illinois Division of Specialized Care for Children, the Multiple Myeloma Research Foundation, and many more.
−Removed: We established a subcontractor — prime
−Removed: contractor relationship with SLG in fall 2019, where we serviced several government agencies and commercial customers, State of New Mexico,
−Removed: Cognizant, KPMG, and University of Illinois in support of SLG.
−Removed: Our Acquisitions
−Removed: SLG Acquisition Agreement
−Removed: On April 25, 2023, Cycurion Sub executed a Term
−Removed: Sheet with SLG (the “SLG Term Sheet”), pursuant to which SLG Innovation Inc., an Illinois corporation formed in January 2010
−Removed: (“SLG”), agreed to be acquired by Cycurion Sub.
−Removed: The Term Sheet contained all of the material terms and conditions of two
−Removed: proposed interrelated transactions to be memorialized by an acquisition agreement (the “SLG Acquisition Agreement”).
−Removed: To effectuate
−Removed: the two transactions contemplated by the SLG Term Sheet, Cycurion Sub will form two subsidiaries, which, upon formation, will initially
−Removed: be wholly owned by Cycurion Sub.
−Removed: If, when, and as the transactions contemplated by the SLG Term Sheet are consummated, SLG would merge
−Removed: with and into one of the subsidiaries and survive, thereby becoming a wholly-owned subsidiary of Cycurion Sub.
−Removed: Because certain of the
−Removed: agreements to which SLG is the prime contractor require that the majority owner of the prime contractor be a resident of the City of
−Removed: Chicago or of Cook County (depending on the contract), contemporaneously with the consummation of the first of the two transactions,
−Removed: (i) SLG will divest itself of those agreements with the residency requirements, (ii) the second newly formed subsidiary will assume those
−Removed: agreements, (iii) Mr.
−Removed: Ed Burns will become the owner of a 51% interest in that newly formed subsidiary, and (iv) we will enter into a
−Removed: Management Agreement with that subsidiary (see below for a discussion of the SLG Management Agreement), the economic terms and management
−Removed: / control terms of which are intended to be the equivalent of complete ownership of the 49% owned subsidiary.
−Removed: Ed Burns is currently
−Removed: the 51% owner of SLG and a resident of the City of Chicago.
−Removed: The SLG Term Sheet provides that, if, when, and as the transactions contemplated
−Removed: thereby are consummated, the two current owners of SLG will be issued shares of our common stock.
−Removed: SLG is fully bound by the terms and
−Removed: provisions of the SLG Term Sheet and the related Management Agreement structure, although Cycurion Sub is permitted to terminate the
−Removed: SLG Term Sheet and to abandon the transactions contemplated thereby any time for any reason or for no reason prior to April 11, 2025,
−Removed: with no further obligations on Cycurion Sub’s part.
−Removed: As of the date of this Annual Report, although we reserve the right to modify
−Removed: the terms and provisions of the SLG Acquisition Agreement, we do not currently expect to terminate it and currently expect to close the
−Removed: transactions contemplated during our current fiscal quarter.
−Removed: Substantially all of the agreements to which SLG is a party have a provision
−Removed: that provides the counterparty to such agreement with a right to approve an assignment or change in control of SLG prior to its effectiveness.
−Removed: If an approval is not forthcoming, then the provisions of the SLG Acquisition Agreement permit us to excise that specific agreement.
−Removed: Upon such occurrence, we reserve that right to reduce the consideration that we would otherwise tender to the equity owners of SLG.
−Removed: As amended by the parties, initially effective
−Removed: as of November 29, 2023, and subsequently effective as of April 29, 2024, August 16, 2024, and December 31, 2024, the SLG Term Sheet
−Removed: expires on the soonest of (i) closing of the transactions contemplated thereby, (ii) April 11, 2025, if the transactions contemplated
−Removed: thereby have not closed by then, (iii) Cycurion Sub’s termination thereof, and (iv) the mutual termination by all of the parties
−Removed: Notwithstanding anything to the contrary contained therein, Cycurion Sub may terminate its obligations under the SLG Term Sheet
−Removed: and the transactions contemplated hereby for any reason or for no reason without any further obligations and without any liability at
−Removed: any time through and including April 11, 2025.
−Removed: The SLG Term Sheet, as amended, consensually superseded, as noted therein, Cycurion Sub’s
−Removed: previous “unidirectional” agreement with SLG.
−Removed: As of March 31, 2025, and in connection with the
−Removed: economic outcome contemplated by the SLG Term Sheet, we entered into a Management Services Agreement (the “SLG Management Agreement”)
−Removed: with SLG to ensure SLG’s continuing commercial viability, which, indirectly, assists the commercial viability of Cycurion Sub and
−Removed: To validate and enhance the business relationship with SLG, the parties agreed that Cycurion Sub and we shall, even more formally
−Removed: than historically, manage and control all of SLG’s operations from and after such date.
−Removed: Accordingly, Cycurion and we shall provide
−Removed: management, financing, administrative, and other services to SLG (as described in more detail on Schedule A of the SLG Management Agreement)
−Removed: in exchange for the fees and/or other consideration set forth on Schedule B of the SLG Management Agreement.
−Removed: The relationship, as so
−Removed: memorialized, results in the relationship between the parties from and after such date (if not prior thereto) results in SLG being deemed
−Removed: to be a “Variable Interest Entity” of Cycurion (as such relationship is defined by the Financial Accounting Standards Board),
−Removed: which will result in SLG’s financial statements being consolidated with and into our financial statements.
−Removed: Our entry into the SLG Management Agreement may accomplish substantially all of SLG’s
−Removed: and our business objectives and may potentially minimize certain of the risks referenced in the section entitled “Risk Factors
−Removed: – Risks Related to the SLG Assignment Agreement ”.
−Removed: Accordingly, one or more of the parties to the SLG Term Sheet may
−Removed: postpone the execution or delivery of the SLG Acquisition Agreement and the consummation of certain of the transactions specifically
−Removed: contemplated thereby (as also set forth in the SLG Term Sheet), contingent, in part, on the potential agreements of the equity owners
−Removed: Nevertheless, we currently believe that the current draft of the SLG Acquisition Agreement may be executed and delivered by the
−Removed: parties thereto in the first half of our current fiscal year.
−Removed: The foregoing brief summary description of certain
−Removed: terms and provisions of (i) the SLG Term Sheet does not purport to be complete and is qualified in its entirety by reference to the full
−Removed: text of the SLG Term Sheet, a copy of which is attached to this Annual Report as Exhibit 10.12, (ii) the SLG Term Sheet Amendments, a
−Removed: copy of each of which is attached to this Annual Report as Exhibit 10.12a, Exhibit 10.12b, Exhibit 10.12c, and Exhibit 10.12d, and (iii)
−Removed: the SLG Management Agreement does not purport to be complete and is qualified in its entirety by reference to the full text of the SLG
−Removed: Term Sheet, a copy of which is attached to this Annual Report as Exhibit 10.12e.
−Removed: Readers are encouraged to read those Exhibits in full
−Removed: for a more comprehensive understanding of the transaction contemplated by the SLG Term Sheet.
−Removed: RCR Acquisition Agreement
−Removed: RCR Technology Corporation (“RCR”) performs
−Removed: certain services for SLG in its role as an SLG subcontractor and, in that context, became a creditor of SLG.
−Removed: In connection with the transactions
−Removed: contemplated by the SLG Term Sheet, on April 25, 2023, Cycurion Sub and RCR also entered into a term sheet (the “RCR Term Sheet”)
−Removed: for a distinct, but related transaction.
−Removed: The RCR Term Sheet contemplates a transaction, pursuant to which RCR will sell to Cycurion all
−Removed: of the accounts receivable of SLG in favor of RCR (but for those accounts that are less than 90 days old as of the date of consummation
−Removed: of the contemplated transaction).
−Removed: The consummation of the transactions contemplated by the RCR Term Sheet is contingent upon the consummation
−Removed: of the transactions contemplated by the SLG Term Sheet.
−Removed: Nevertheless, as a result of our entry into the SLG Management Agreement with
−Removed: SLG, we still currently intend to consummate the transactions contemplated by the RCR Term Sheet in the first half of our current fiscal
−Removed: The RCR Term Sheet provides that, if, when, and as the transactions contemplated thereby are consummated, RCR will be issued shares
−Removed: of our common stock.
−Removed: Further, as amended by the parties, initially effective
−Removed: as of November 29, 2023, and subsequently effective as of April 29, 2024, August 16, 2024, and December 31, 2024, the RCR Term Sheet
−Removed: expires on the soonest of (i) closing of the transactions contemplated thereby, (ii) April 11, 2025, if the transactions contemplated
−Removed: thereby have not closed by then, (iii) Cycurion’s termination thereof, and (iv) the mutual termination by all of the parties thereto.
−Removed: Notwithstanding anything to the contrary contained therein, Cycurion may terminate its obligations under the RCR Term Sheet and the transactions
−Removed: contemplated hereby for any reason or for no reason without any further obligations and without any liability at any time through and
−Removed: including April 11, 2025.
−Removed: As of the date of this Annual Report, we do not currently expect to terminate the transactions contemplated
−Removed: by the RCR Term Sheet, as amended, and currently expect to close the transactions in the first half of our current fiscal year.
−Removed: The foregoing brief summary description of certain
−Removed: terms and provisions of the RCR Term Sheet does not purport to be complete and is qualified in its entirety by reference to the full
−Removed: text of the RCR Term Sheet, a copy of which is attached to this Annual Report as Exhibit 10.13 and the full text of the RCR Term Sheet
−Removed: Amendments, a copy of each of which are attached to this Annual Report as Exhibit 10.13a, 10.13b and 10.13c.
−Removed: Readers are encouraged to
−Removed: read those Exhibits in full for a more comprehensive understanding of the transaction contemplated by the RCR Term Sheet.
−Removed: Acquisition of Technology
−Removed: On August 17, 2021, we entered into an asset purchase
−Removed: agreement to acquire certain technology assets of Sabres, a leading Israeli-based cyber security provider.
−Removed: As part of the asset purchase
−Removed: agreement, we acquired Multi-Dimensional Protection, Web Application Firewall and Bot Mitigation SaaS platforms, and their associated
−Removed: intellectual property.
−Removed: The transaction closed on September 30, 2021, and we have integrated the SaaS platforms into our existing services
−Removed: Our Cycurion Security Platform’s (formerly
−Removed: Sabres’) line of products allows our customers to improve their cyber posture with its MDP SaaS platform.
−Removed: This platform efficiently
−Removed: bundles and easily implements the external protection of a Web Application Firewall (WAF) and the internal protection of Bot Mitigation.
−Removed: Bot Mitigation is the reduction of risk to applications, Application Program Interfaces (APIs), and backend services from malicious bot
−Removed: traffic that fuels common automated attacks, such as Distributed Denial of Service (DDoS) campaigns and vulnerability probing.
−Removed: of single-layer security can be measured in terms of money, time, and risk, as well as the damage wrought by a data breach, which millions
−Removed: of businesses experience each year.
−Removed: Through this interaction of the WAF and Bot Mitigation, the MDP is able to reinforce these layers
−Removed: of security and generate new security layers in real time in response to emerging threats.
−Removed: This process is directed by our Cycurion Security
−Removed: Platform’s (formerly Sabres’) proprietary, cloud-based AI algorithm.
−Removed: We do not have AI processing in the production version
−Removed: of the software.
−Removed: That version is in the testing and evaluation phase.
−Removed: We expect to move the production in quarter three of 2024.
−Removed: a crowdsourcing process, the cloud-based MDP learns from every threat to any protected application and uses that newly acquired knowledge
−Removed: to protect all MDP clients better.
−Removed: Our Cycurion Security Platform’s (formerly
−Removed: Sabres’) line of products provides solutions for substantially all web application security needs.
−Removed: These products provide solutions,
−Removed: whether a client is in need of a web application firewall to comply with regulations and ensure it has a first line of defense against
−Removed: the hazards that the internet can present or is in need of enterprise-level products that empower Security Operations Center (SOC) teams
−Removed: and security management.
−Removed: Our Cycurion Security Platform’s constantly survey a client’s data to detect security issues in
−Removed: need of attention, send automatic updates, and provide the client with a complete database of rules and threats.
−Removed: ● Multi-Dimensional Protection (MDP)
−Removed: ● On-premises option
−Removed: ● Dual-Layered Defense (WAF/Bot Mitigation)
−Removed: ● Advanced Security Information and Event
−Removed: Management (SIEM) dashboard
−Removed: ● Ongoing reporting and alerts
−Removed: ● No delays for the end-user
−Removed: ● Can connect to any existing WAF
−Removed: ● Easy installation on all platforms
−Removed: ● Exceptional penetration testing results
−Removed: ● No downtime for updating
−Removed: ● No hardware required
−Removed: ● Cloud-based
−Removed: ● Biometric WAF
−Removed: We have integrated the technology assets that we
−Removed: acquired from Sabres (which now constitutes our Cycurion Security Platform) into our Managed Security Services Practice.
−Removed: We believe that
−Removed: the platform will enhance our service offerings and assist with the expansion of our commercial business.
−Removed: The Sabres platform will be
−Removed: managed by our dedicated support team, and will provide real time reporting, response to security incidents, and will manage all data
−Removed: privacy needs from a single SIEM SaaS platform dashboard.
−Removed: Our Growth Strategy
−Removed: Our objectives are to expand our market leadership
−Removed: and management and to capture large market opportunities in cloud, AI and IT.
−Removed: We intend to accomplish these objectives by:
−Removed: to acquire to platforms .
−Removed: We believe there is substantial opportunity to increase our
−Removed: platforms and have experienced growth due to expanded product capabilities and investments.
−Removed: We intend to continue to pursue new customers by adding capacity and leveraging our partnerships
−Removed: in the domestic and international markets.
−Removed: platform coverage with our customers.
−Removed: We believe there is opportunity to develop and
−Removed: expand our relationships with existing customers by targeting additional platforms and geographies,
−Removed: pursuing platform expansions and expanding our coverage.
−Removed: in new technology platforms .
−Removed: We plan to continue to develop and broaden our exposure
−Removed: and security solutions, including expanding our coverage, by entering into new contracts
−Removed: focused on program management, cybersecurity, disaster recovery and business continuity.
−Removed: For more information, please see “Item 1.
−Removed: Business – Our Acquisitions.”
−Removed: acquisition opportunities .
−Removed: We intend to acquire other businesses, technology, AI platforms
−Removed: and/or development personnel to enhance the functionality of our platforms.
−Removed: For more information,
−Removed: please see “Item 1.
−Removed: Business – Our Acquisitions.”
−Removed: The IT and cybersecurity solutions market is fragmented,
−Removed: competitive and always evolving.
−Removed: We compete with a range of established and emerging cybersecurity software and services vendors,
−Removed: as well as organizations that choose to build their own solutions in-house.
−Removed: With new technologies and market entrants, we expect the
−Removed: competitive environment to remain intense going forward.
+Added: Our proprietary algorithm provides detection and protection against non-human activity.
+Added: This can prevent low-level threats like unwanted scraping, and high-level threats like attempted system breaches.
+Added: The IT and cybersecurity solutions market is fragmented, competitive and always evolving.
+Added: We compete with a range of established and emerging cybersecurity software and services vendors, as well as organizations that choose to build their own solutions in-house.
+Added: With new technologies and market entrants, we expect the competitive environment to remain intense going forward.
Our competitors include:
−Removed: ● vulnerability
−Removed: management and assessment vendors;
−Removed: ● diversified
−Removed: security software and services vendors;
−Removed: security vendors with vulnerability assessment capabilities;
−Removed: cloud vendors and other companies that offer solutions for cloud security;
−Removed: of point solutions that compete with some of the features present in our solutions.
+Added: • vulnerability management and assessment vendors;
+Added: • diversified security software and services vendors;
+Added: • endpoint security vendors with vulnerability assessment capabilities;
+Added: • public cloud vendors and other companies that offer solutions for cloud security;
+Added: • providers of point solutions that compete with some of the features present in our solutions.
The key competitive factors in our markets include:
−Removed: to prepare for, detect and mitigate cybersecurity threats;
−Removed: to respond to customer needs quickly;
−Removed: for products to facilitate customer needs;
−Removed: cost and ease-of-use of our products;
−Removed: awareness and reputation;
−Removed: to attract and retain employees.
−Removed: We believe that the principal competitive factors
−Removed: affecting the market for cybersecurity solutions include product functionality, depth of platform offerings, flexibility of
−Removed: delivery models, ease of deployment and use, integration capabilities such as open APIs and scalability, uptime and performance.
−Removed: of our competitors are more established and have greater name recognition, longer operating histories, more established customer relationships,
−Removed: larger marketing budgets and significantly greater resources than we do.
−Removed: We have over 41 customers across a variety of industries,
−Removed: including enterprise businesses, small and medium businesses, government agencies, healthcare and higher education.
−Removed: Our customers include,
−Removed: but are not limited to, AT&T, Smithsonian Museum, FEMA and Peraton.
−Removed: During the years ended December 31, 2024 and 2023, purchases
−Removed: from our ten largest end-customers accounted for approximately 93% and 88% of our total revenue, respectively.
−Removed: We define backlog as contractually committed orders
−Removed: to be invoiced under our existing agreements that are not included in deferred revenue on our consolidated balance sheets.
−Removed: the amount of backlog to change from period to period due to the timing of billings for our solutions and professional services.
−Removed: 31, 2024 and 2023, we had committed backlog of $16 million and $15 million, respectively.
−Removed: We expect the majority of the
−Removed: backlog at December 31, 2024 to be invoiced within the following 12 months.
+Added: • ability to prepare for, detect and mitigate cybersecurity threats;
+Added: • ability to respond to customer needs quickly;
+Added: • ability for products to facilitate customer needs;
+Added: • total cost and ease-of-use of our products;
+Added: • brand awareness and reputation;
+Added: • ability to attract and retain employees.
+Added: We believe that the principal competitive factors affecting the market for cybersecurity solutions include product functionality, depth of platform offerings, flexibility of delivery models, ease of deployment and use, integration capabilities such as open APIs and scalability, uptime and performance.
+Added: Some of our competitors are more established and have greater name recognition, longer operating histories, more established customer relationships, larger marketing budgets and significantly greater resources than we do.
+Added: We have customers in a variety of industries, including enterprise businesses, small and medium businesses, government agencies, healthcare and higher education.
+Added: During the years ended December 31, 2025 and 2024, purchases from our four largest end-customers accounted for approximately 64.5% and 63.8% of our total revenue, respectively.
+Added: We define backlog as contractually committed orders to be invoiced under our existing agreements that are not included in deferred revenue on our consolidated balance sheets.
+Added: We expect the amount of backlog to change from period to period due to the timing of billings for our solutions and professional services.
+Added: As of December 31, 2025 and 2024, we had committed backlog of approximately $80.0 million and $16.0 million, respectively.
Government Regulation
−Removed: Our business and operations are subject to extensive
−Removed: federal and state governmental regulation and supervision.
−Removed: The following is a brief summary of certain statutes and rules and regulations
−Removed: that affect or may affect us.
−Removed: This summary is not intended to be an exhaustive description of the statutes or regulations applicable
−Removed: to our business.
−Removed: In the ordinary course of our business, we process
−Removed: personal information.
−Removed: Accordingly, we are, or may become, subject to numerous data privacy and security obligations, including federal,
−Removed: state, local, and foreign laws, regulations, guidance, and industry standards related to data privacy and security.
−Removed: Such obligations
−Removed: may include, without limitation, the Federal Trade Commission Act, the California Consumer Privacy Act of 2018 as amended by the California
−Removed: Privacy Rights Act of 2020, or, collectively, the CCPA, the Colorado Privacy Act, Virginia’s Consumer Data Protection Act, the
−Removed: Connecticut Privacy Act, the Utah Consumer Privacy Act and similar U.S.
−Removed: state comprehensive privacy laws, the European Union’s
−Removed: General Data Protection Regulation 2016/679, or EU GDPR, the EU GDPR as it forms part of the United Kingdom law by virtue of section
−Removed: 3 of the European Union (Withdrawal) Act of 2018, or UK GDPR, and the ePrivacy Directive.
+Added: Our business and operations are subject to extensive federal and state governmental regulation and supervision.
+Added: The following is a brief summary of certain statutes and rules and regulations that affect or may affect us.
+Added: This summary is not intended to be an exhaustive description of the statutes or regulations applicable to our business.
+Added: In the ordinary course of our business, we process personal information.
+Added: Accordingly, we are, or may become, subject to numerous data privacy and security obligations, including federal, state, local, and foreign laws, regulations, guidance, and industry standards related to data privacy and security.
+Added: Such obligations may include, without limitation, the Federal Trade Commission Act, the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020, or, collectively, the CCPA, the Colorado Privacy Act, Virginia's Consumer Data Protection Act, the Connecticut Privacy Act, the Utah Consumer Privacy Act and similar U.S.
+Added: state comprehensive privacy laws, the European Union’s General Data Protection Regulation 2016/679, or EU GDPR, the EU GDPR as it forms part of the United Kingdom law by virtue of section 3 of the European Union (Withdrawal) Act of 2018, or UK GDPR, and the ePrivacy Directive.
Human Capital
−Removed: As of the date of this Annual Report, we have 46
−Removed: full-time employees and 0 part-time employees.
+Added: As of December 31, 2025, we have 74 employees, of which 66 were full-time employees.
None of our U.S.
−Removed: employees are represented by a labor union or covered by a collective
−Removed: bargaining agreement.
−Removed: Our senior leadership team has extensive experience with business process management, and while we have grown through
−Removed: a number of acquisitions, we have retained an experienced and cohesive leadership team.
−Removed: Our key human capital objectives are to attract,
−Removed: retain, engage, reward and develop our highly talented existing and future employees, while cultivating an inclusive workforce and culture
−Removed: to achieve exceptional business results.
−Removed: We are committed to fostering a community of talented individuals from all backgrounds and perspectives
−Removed: by implementing the following.
−Removed: ● Compensation
−Removed: and benefits.
−Removed: We continually work to provide a competitive compensation and benefits
−Removed: program as this plays a key role in our ability to attract and retain a highly skilled workforce.
−Removed: In addition to salaries, these programs, which vary by country/region, include long-term
−Removed: equity incentive awards with certain vesting requirements, deferred compensation plans (which
−Removed: are offered to certain members of executive management), a 401(k) plan, healthcare and insurance
−Removed: benefits, health savings and flexible spending accounts, paid time off, paid volunteer time
−Removed: off, employee assistance program and tuition assistance.
−Removed: safety and wellness.
−Removed: The well-being of our employees is paramount to the continued success
−Removed: of our business.
−Removed: To this end, we are committed to each of our employees’ health, safety
−Removed: and wellness.
−Removed: We provide our employees with access to various health and wellness benefits
−Removed: designed to enable them and their family members to have affordable access to health, dental
−Removed: and vision insurance.
−Removed: We invest significant resources to develop the talent needed to remain a
−Removed: market-leading global supplier of broadband infrastructure.
−Removed: We offer numerous training opportunities
−Removed: on both technical and professional development topics.
−Removed: and inclusion.
−Removed: We believe that maintaining a diverse and inclusive workforce is important
−Removed: to the success of our business.
−Removed: We encourage an environment where individuality is embraced
−Removed: regardless of age, gender, identity, race, sexual orientation, physical or mental ability,
−Removed: ethnicity and perspective and where each employee is accepted.
+Added: employees are represented by a labor union or covered by a collective bargaining agreement.
+Added: Our senior leadership team has extensive experience with business process management, and while we have grown through a number of acquisitions, we have retained an experienced and cohesive leadership team.
+Added: Our key human capital objectives are to attract, retain, engage, reward and develop our highly talented existing and future employees, while cultivating an inclusive workforce and culture to achieve exceptional business results.
+Added: We are committed to fostering a community of talented individuals from all backgrounds and perspectives by implementing the following.
Research and Development
−Removed: Rapidly changing technologies, evolving industry
−Removed: standards, changing customer requirements, supply constraints and continuing developments in communications service offerings characterize
−Removed: the markets for our products.
−Removed: Our on-going ability to adapt to these changes and to develop new and enhanced products that meet or anticipate
−Removed: market demand is the main factor influencing our competitive position and our ability to grow.
−Removed: We continue to invest substantial resources in research
−Removed: and development to enhance our platform offerings by developing new features, functionality, and applications.
−Removed: Our engineering expertise
−Removed: combines extensive security product development experience with individuals who possess deep cloud and user interface design backgrounds.
−Removed: Our team is staffed by cybersecurity, cloud and data
−Removed: science experts who deliver exposure management intelligence, data science insights, alerts and security advisories.
−Removed: Our team has developed
−Removed: research tools to help improve efficiency and effectiveness in processes such as reverse engineering, code debugging, web app security
−Removed: and visibility into cloud-based tools.
−Removed: Intellectual Property
−Removed: January 15, 2025, Cycurion issued a $50,000 promissory note to an unaffiliated investor for $50,000 in proceeds.
−Removed: January 21, 2025, Cycurion issued a $75,000 promissory note to an unaffiliated investor for $75,000 in proceeds.
−Removed: January 25, 2025, Cycurion issued a $50,000 promissory note to an unaffiliated investor for $50,000 in proceeds.
−Removed: January 31, 2025, Cycurion issued a $125,000 promissory note to a related party for 125,000 in proceeds.
−Removed: January 24, 2025, Western Acquisition Ventures Corp., a Delaware Corporation (“Western”), held the Special Meeting,
−Removed: at which the Western stockholders considered and adopted, among other matters, a proposal to approve a business combination (“Business
−Removed: Combination”) pursuant to the terms of that certain Agreement and Plan of Merger, dated April 26, 2024, as amended on December 31,
−Removed: 2024 and February 13, 2025 (the “Merger Agreement”), by and among Western, WAV Merger Sub, Inc., a Delaware corporation
−Removed: and a wholly-owned subsidiary of Western (“Merger Sub”), and Cycurion Sub, Inc., a Delaware corporation (“Cycurion
−Removed: On February 14, 2025, the Business Combination closed,
−Removed: and, as contemplated by the Merger Agreement, Merger Sub merged with and into Cycurion Sub with Cycurion Sub surviving the merger as
−Removed: a wholly-owned subsidiary of Western.
−Removed: In addition, in connection with the consummation of the Business Combination, Western Acquisition
−Removed: Ventures Corp.
−Removed: was renamed “Cycurion, Inc.”
−Removed: On February 18, 2025, Cycurion’s common stock
−Removed: began trading on The Nasdaq Global Market and warrants began trading on The Nasdaq Capital Market under the symbols “CYCU”
−Removed: and “CYCUW”, respectively.
−Removed: On February 19, 2025, Cycurion announced an agreement
−Removed: with iQSTEL, a multinational innovator in telecommunications, FinTech, electric vehicles and AI-driven solutions.
−Removed: On February 24, 2025, Cycurion announced an expansion
−Removed: of its partnership with a major health association, bringing its MSSP to several thousand member organizations across the country.
−Removed: On March 3, 2025, Cycurion announced the availability
−Removed: of its ARx Platform targeted for the corporate sector.
−Removed: On March 5, 2025, Cycurion announced the award of
−Removed: three new multi-year contracts focused on program management, cybersecurity and disaster and business continuity.
−Removed: These engagements are
−Removed: secured with two government clients and one commercial client.
−Removed: On March 6, 2025, Cycurion announced a nationwide
−Removed: expansion of its strategic partnership with CentralSquare Technologies, LLC to deliver its IT services across the country.
−Removed: On April 7, 2025, Cycurion entered into an equity
−Removed: purchase agreement with Yield Point NY LLC whereby the Company has the right, but not the obligation, to direct the investor to purchase
−Removed: up to $60,000,000.
−Removed: On April 8, 2025, Cycurion announced an expanded
−Removed: partnership with Journal Technologies.
−Removed: Together, the companies have been awarded a $22 million multi-year contract to deliver a criminal
−Removed: justice case management system to a state police agency.
−Removed: On April 9, 2025, Cycurion increased the size of
−Removed: its board of directors through the appointment of Irving Minnaker.
−Removed: On April 9, 2025, Cycurion received written notice
−Removed: received from the Listing Qualifications Department of Nasdaq stating that, for the prior 30 consecutive business days, the closing
−Removed: bid price of our common stock had been below the minimum of $1.00 per share required for continued listing on The Nasdaq Capital Market
−Removed: under Nasdaq Listing Rule 5550(a)(2).
−Removed: The notification letter stated that we would be afforded 180 calendar days (until October
−Removed: 6, 2025) to regain compliance.
−Removed: In order to regain compliance, the closing bid price of our common stock must be at least $1.00 for a
−Removed: minimum of ten consecutive business days.
−Removed: The notification letter also stated that, in the event that we do not regain compliance within
−Removed: the initial 180-day period, we may be eligible for an additional 180-day period.
−Removed: If we are not eligible for the additional 180-day period,
−Removed: or if it appears to the Nasdaq staff that we will not be able to cure the deficiency, the Nasdaq Listing Qualifications Department will
−Removed: provide notice after the end of the initial 180-day period that our securities will be subject to delisting.
−Removed: Failure to regain compliance
−Removed: within that 180-day period would result in the delisting of our securities from Nasdaq, although we would have the right to appeal such
−Removed: a delisting to a Nasdaq hearings panel.
−Removed: The Nasdaq notification has no effect at this time on the listing of our common stock.
−Removed: On April 11, 2025, we received two letters from
−Removed: the Nasdaq Listing Qualifications Department, each addressing a separate compliance deficiency of ours under the Nasdaq Listing Rules.
−Removed: The first letter notified us of our deficiency with regard to Nasdaq Listing Rule 5450(b)(2)(A), which requires a company such as ours,
−Removed: whose securities are listed on The Nasdaq Global Market under the “Market Value Standard”, to maintain a minimum Market Value
−Removed: of Listed Securities (an “MVLS”) of $50,000,000.
−Removed: The deficiency was caused by our MVLS having been below the minimum
−Removed: level for the prior 30 consecutive business days.
−Removed: Under Nasdaq Listing Rule 5810(c)(3)(C), we are entitled to a 180-day period, ending
−Removed: on October 8, 2025, to rectify the deficiency.
−Removed: In order to do so, we must achieve and maintain an MVLS of at least $50,000,000 or
−Removed: more for a minimum of 10 consecutive business days.
−Removed: Failure to regain compliance within that 180-day period would result in the delisting
−Removed: of our securities from Nasdaq, although we would have the right to appeal such a delisting to a Nasdaq hearings panel.
−Removed: The Nasdaq notification
−Removed: has no effect at this time on the listing of our common stock.
−Removed: The second letter notified us of our deficiency
−Removed: with regard to Nasdaq Listing Rule 5450(b)(2)(C), which requires a minimum Market Value of Publicly Held Shares (an “MVPHS”)
−Removed: of $15,000,000 for continued listing on the Nasdaq Global Market under the “Market Value Standard”.
−Removed: This deficiency was caused
−Removed: by our MVPHS having been below the minimum level for the prior 30 consecutive business days.
−Removed: Under Nasdaq Listing Rule 5810(c)(3)(D),
−Removed: we have 180 calendar days, or until October 8, 2025, to regain compliance, which we can achieve if our MVPHS is at least $15,000,000
−Removed: for a minimum of 10 consecutive business days.
−Removed: Failure to regain compliance within that 180-day period would result in the delisting
−Removed: of our securities from Nasdaq, although we would have the right to appeal such a delisting to a Nasdaq hearings panel.
−Removed: The Nasdaq notification
−Removed: has no effect at this time on the listing of our common stock.
−Removed: For more information, please see “Note 19.
−Removed: Subsequent Events.”
+Added: Rapidly changing technologies, evolving industry standards, changing customer requirements, supply constraints and continuing developments in communications service offerings characterize the markets for our products.
+Added: Our on-going ability to adapt to these changes and to develop new and enhanced products that meet or anticipate market demand is the main factor influencing our competitive position and our ability to grow.
+Added: We continue to invest substantial resources in research and development to enhance our platform offerings by developing new features, functionality, and applications.
+Added: Our engineering expertise combines extensive security product development experience with individuals who possess deep cloud and user interface design backgrounds.
+Added: Our team is staffed by cybersecurity, cloud and data science experts who deliver exposure management intelligence, data science insights, alerts and security advisories.
+Added: Our team has developed research tools to help improve efficiency and effectiveness in processes such as reverse engineering, code debugging, web app security and visibility into cloud-based tools.
+Added: 2025 Developments
+Added: On April 8, 2025, Cycurion announced an expanded partnership with Journal Technologies.
+Added: Together, the companies have been awarded a $22 million multi-year contract to deliver a criminal justice case management system to a state police agency.
+Added: On April 9, 2025, Cycurion increased the size of its board of directors through the appointment of Irving Minnaker.
+Added: On April 29, 2025, Cycurion issued a press release announcing that the Company has been awarded a $6 million contract by a major municipal agency.
+Added: From April 1 to May 30, 2025, otherwise unaffiliated persons converted 2,999.3 shares of the Company's Series B Preferred Stock into 200,000 shares of the Company’s common stock and 5,000 shares of the Company’s Series D Preferred Stock into 5,000 shares of the Company's common stock.
+Added: On July 2, 2025,the Company issued a press release announcing that the Company had partnered with AgileBlue, an AI-powered security operations platform provider.
+Added: On July 10, 2025,the Company issued a press release announcing its diamond level partnership with the National Association of County and City Officials ("NACCHO").
+Added: On July 23, 2025,the Company issued a press release announcing its attendance at the NACCHO Annual Conference as a Diamond Affiliate Partner, showcasing its Cyber Shield solution.
+Added: On August 7, 2025,the Company issued a press release announcing that it had entered into a memorandum of understanding with iQSTEL Inc.
+Added: ("iQSTEL") for a stock-for-stock exchange.
+Added: On September 2, 2025,the Company entered into a stock-for-stock exchange agreement (the "Stock-for-Stock Exchange Agreement") with iQSTEL.
+Added: Under the terms of the agreement, Cycurion and iQSTEL will issue $1,000,000 worth of its common stock to the other company, with the number of shares being calculated by dividing $1,000,000 by the applicable per-share price of the issuing company's common stock.
+Added: On September 26, 2025,the Company entered into an amendment to the Stock-for-Stock Exchange Agreement with iQSTEL to, among other things, (i) allow each party, at its sole discretion, to satisfy the $500,000 dividend obligation to its shareholders by distributing either (a) up to 50% of the shares received from the other party (i.e., up to 75,529 shares of iQSTEL common stock for Cycurion, based on 151,058 shares issued to Cycurion, and up to 1,933,488 shares of Cycurion Common Stock for iQSTEL, based on 3,866,976 shares issued to iQSTEL), or (b) an equivalent value of its own authorized common stock, calculated using the valuation methodology set forth in the Stock-for-Stock Exchange Agreement;
+Added: and (ii) extend the timeline for the issuance and delivery of shares from 30 business days to 60 business days following the effective date of the Stock-for-Stock Exchange Agreement (September 2, 2025) and establish a firm deadline of December 15, 2025 to complete all necessary regulatory filings (e.g., SEC filings, FINRA submissions, and Nasdaq notifications) to facilitate the dividend distribution by December 31, 2025.
+Added: On November 25, 2025, the Company and iQSTEL announced that each company plans to distribute $500,000 worth of its own shares as a one-time, pro-rata dividend to its own respective shareholders and security holders, while preserving the full $1,000,000 in cross-ownership shares.
+Added: On December 5, 2025, the Company announced that it plans to distribute a special dividend valued at $500,000 in the form of its shares of Common Stock shares to all of its shareholders of record as of December 15, 2025 on a pro-rata basis.
+Added: The dividend is payable on or about December 30, 2025.
+Added: On December 11, 2025, the Company announced an updated dividend distribution ratio of 0.0180 per share of Common Stock to its shareholders and security holders.
+Added: On August 20, 2025,the Company issued a press release providing additional information regarding its then current $69 million backlog.
+Added: On August 28, 2025,the Company's board of directors amended and restated the Amended and Restated Bylaws, effective immediately, to conform them to the provisions in the Second Amended and Restated Certificate of Incorporation and certain provisions of the Delaware General Corporation Law with respect to the election of directors.
+Added: On September 10, 2025,the Company issued a press release announcing an additional $4.6 million in new contracts to be earned over the next year, building on the previously announced $69 million in contracts for a then current total of $73.6 million in AI-powered growth across multiple sectors.The Company announced several key initiatives beginning in September 2025 driving the expanded growth including delivering AI-powered IT and cybersecurity assessment services for a major county government.
+Added: On September 25, 2025,the Company's board of directors waived the Series A Convertible Preferred Stock lock-up restrictions.
+Added: The holders of the Company's Series A Convertible Preferred Stock (and the underlying securities for which the holders have conversion rights) were previously subject to a one-year lock-up of their securities that commenced on the closing of the Business Combination with Western on February 14, 2025, subject to release from the lock-up after six months from the closing if, thereafter, the daily trading value of shares of the Company's common stock is greater than $150,000 for 30 consecutive trading days and the 30-day VWAP for shares of the Company's common stock is greater than $5.00.
+Added: As the Company's common stock does not meet the conditions set forth above to release the holders of the Series A Convertible Preferred Stock from the lock-up restrictions after six months from the closing of the Business Combination,the Company's board of directors deemed it in the best interests to waive such lock-up restrictions as the Series A Convertible Preferred Stock accrues approximately $120,000 per year in stock or cash payments.
+Added: If the holders of the Series A Convertible Preferred Stock convert such preferred stock into common stock,the Company could save approximately $120,000 in costs on its income statement, which is part of its strategic recapitalization to strengthen its balance sheet and support growth initiatives.
+Added: On October 29, 2025,the Company announced its selection as an approved vendor under the Florida State Term Contract for Information Technology Staff Augmentation Services.
+Added: On October 30, 2025,the Company announced a comprehensive three-part webinar series with NACCHO designed to empower healthcare organizations with critical threat intelligence and defensive strategies.
+Added: On November 5, 2025, the Company announced that the Company's wholly-consolidated VIE, SLG Innovation, Inc., had been awarded a $1.1 million contract to modernize legacy data systems for one of America’s largest county-level public guardian offices.
+Added: On November 10, 2025, the Company announced that it had been awarded a contract by a telecommunication company to deliver network deployment services supporting a critical modernization initiative for one of the federal government’s agencies.
+Added: On November 14, 2025, the Company's board of directors amended and restated the Company’s Insider Trading Policy (the "Amended and Restated Insider Trading Policy"), effective immediately, to clarify language around the Company’s trading windows and blackout periods.
+Added: Recent Developments
+Added: On January 22, 2026, the Company announced that it had entered into a Memorandum of Understanding to acquire the video-solutions division of Kustom Entertainment, Inc., a pioneer in mobile video surveillance technologies, including body-worn cameras, in-car video systems, and digital evidence management solutions for law enforcement, public safety, and commercial sectors.
+Added: On February 3, 2026, the Company announced that Litchfield Hills Research had initiated coverage on Cycurion.
+Added: On February 11, 2026, the Company announced a strategic business reorganization that will streamline operations, enhance organizational agility, and position the Company for long-term growth.
+Added: On March 19, 2026, the Company held a special meeting of stockholders (the "Special Meeting") to vote on the proposals identified in the proxy statement filed with the U.S.
+Added: Securities and Exchange Commission (the "SEC") and mailed to stockholders on February 2, 2026.
+Added: As of the record date on January 21, 2026, there were a total of 5,148,411 shares of Voting Stock (as defined below) issued and outstanding, consisting of 4,188,187 shares of common stock, par value $0.0001 per share (the "common stock"), and 960,224 shares of preferred stock, par value $0.0001 per share, having voting rights on as as-if-converted-to- common stock basis (the "Preferred Voting Stock", and together with the common stock, the "Voting Stock"), each of which is entitled to one vote.
+Added: A total of 2,611,518 shares of the Company's Voting Stock were represented at the Special Meeting either in person or by proxy.
+Added: At the Special Meeting, the Company's stockholders voted on the following matters and approved the proposal to approve, pursuant to Nasdaq Listing Rule 5635(d), the issuance of up to an aggregate of 3,314,920 shares of common stock upon the exercise of certain common stock purchase warrants issued in connection with our private placement that closed on December 5, 2025, that may be equal to or exceed 20% of our outstanding shares of common stock immediately prior to such offering.
+Added: On March 17, 2026, the Company issued a press release in response to an unauthorized press release.
+Added: On March 25, 2026, the Company announced two new contract awards which are expected to generate approximately $1.35 million in combined revenue in 2026, including $1.165 million in new annual recurring revenue.
+Added: The awards include a multi-year engagement with a large healthcare government agency and an expanded relationship with the National Association of County and City Health Officials.
Corporate Information
−Removed: Our principal executive office is located at 1640
−Removed: Boro Place, Fourth Floor, McLean, Virginia 22102, and our telephone number is (703) 854-1652.
−Removed: Our website address is www.cycurion.com.
+Added: Our principal executive office is located at 1640 Boro Place, Suite 420C, McLean, Virginia 22102.
+Added: Our telephone number is (703) 854-1652 and our website address is www.cycurion.com.
Axxum's website address is www.axxumtech.com.
Cloudburst's website address is www.cloudburstsecurity.com.
−Removed: The SEC maintains
−Removed: an internet site that contains reports, proxy and information statements and other information regarding issuers that file electronically
−Removed: with the SEC at www.sec.gov.
−Removed: The information contained on the websites referenced in this Annual Report is not incorporated by reference
−Removed: into this filing.
+Added: The SEC maintains an internet site that contains reports, proxy and information statements and other information that we file electronically with the SEC at www.sec.gov.
+Added: The information contained on the websites referenced in this Annual Report is not incorporated by reference into this filing.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.