−Removed: UNRESOLVED STAFF
+Added: Unresolved Staff Comments
Cybersecurity
Risk Management and Strategy
−Removed: We have established policies and processes for assessing,
−Removed: identifying, and managing material risks from cybersecurity threats.
−Removed: We have designed and implemented an Access Control Policy.
−Removed: and supporting procedures encompass all information systems that are owned, operated, maintained, and controlled by the Company and all
−Removed: other information systems, both internally and externally, that interact with these systems.
−Removed: Our cybersecurity program and policies is
−Removed: a collaborative effort, requiring commitment from all personnel, including management, internal employees and users of information systems,
−Removed: along with vendors, contractors, and other relevant third parties.
−Removed: Our Chief Information Security Officer (“CISO”)
−Removed: and Information System Security Officer (“ISSO”) are responsible for providing overall direction, guidance, leadership, and
−Removed: support for the entire information systems environment, while also assisting other applicable personnel in their day-to-day operations.
−Removed: The CISO and ISSO are to report to other members of senior management on a regular basis regarding all aspects of the organization’s
−Removed: information systems posture.
−Removed: Our internal employees and users are responsible for adhering to the organization’s information security
−Removed: policies, procedures, practices, and not undertaking any measure to alter such standards on any information systems.
−Removed: Additionally, end
−Removed: users are to report instances of non-compliance to senior authorities, specifically those by other users.
−Removed: End users – while undertaking
−Removed: day-to-day operations – may also notice issues that could impede the safety and security of our information systems and are to also
−Removed: report such instance immediately to senior authorities.
−Removed: Our vendors, contractor and other third-party entities are responsible for adhering
−Removed: to the organization’s information security policies, procedures, practices, and not undertaking any measure to alter such standards
−Removed: on any such system components.
−Removed: We have also implemented an IT Security Incident Response
−Removed: Incident response preparation comprises of how to respond to incidents and how to protect against and detect computer-related
−Removed: The process of providing incident response is identified by four distinct phases:
+Added: Cycurion has established policies and processes for assessing, identifying, and managing material risks from cybersecurity threats.
+Added: Cycurion has designed and implemented cybersecurity policies and procedures intended to protect its information systems and sensitive information assets.
+Added: These policies encompass information systems that are owned, operated, maintained, or controlled by Cycurion, as well as external systems and service providers that interact with Company systems.
+Added: Cycurion’s cybersecurity program includes safeguards designed to protect sensitive information, including Controlled Unclassified Information ("CUI"), where applicable.
+Added: Our cybersecurity program is a collaborative effort requiring the participation of management, employees, contractors, vendors, and other relevant third parties .
+Added: Personnel with access to Company systems are responsible for complying with Cycurion's information security policies and for reporting suspected security incidents or vulnerabilities.
+Added: Cycurion maintains a cybersecurity program designed to align with recognized industry standards and cybersecurity frameworks, including the National Institute of Standards and Technology ("NIST") cybersecurity guidance and of the CMMC framework established by the U.S.
+Added: Department of Defense for the protection of CUI.
+Added: Cycurion's cybersecurity policies, procedures, and operational safeguards incorporate security control objectives consistent with NIST and CMMC practices designed to protect sensitive information processed, stored, or transmitted within Company systems.
+Added: As part of its cybersecurity risk management processes, Cycurion performs periodic cybersecurity risk assessments designed to identify potential threats, vulnerabilities, and risks affecting the confidentiality, integrity, and availability of Company systems and data.
+Added: Identified risks are evaluated and prioritized based on potential operational and financial impact and are addressed through remediation plans, technical safeguards, or operational controls.
+Added: Cycurion maintains a vulnerability management program designed to help identify and remediate security weaknesses within its systems and infrastructure.
+Added: The Company conducts periodic vulnerability scans and security assessments and remediation activities are prioritized based on the severity of the issue and the potential impact to operations of information security.
+Added: Cycurion also employs continuous monitoring capabilities intended to detect and evaluate potential cybersecurity threats in a timely manner.
+Added: These monitoring activities may include log monitoring, endpoint detection tools, vulnerability scanning, and the analysis of security events by designated security personnel.
+Added: To help protect endpoint devices, Cycurion uses endpoint protection technologies designed to detect, prevent, and respond to malicious activity.
+Added: These tools provide monitoring and alerting capabilities that assist security personnel in identifying and responding to potential cybersecurity incidents.
+Added: Cycurion has implemented a formal Change Control Board ("CCB") process to review and approve system changes that could affect the security of Company systems.
+Added: Proposed changes are evaluated by designated personnel prior to implementation to assess potential cybersecurity risks and to help ensure that appropriate safeguards remain in place.
+Added: The Company also maintains a cybersecurity awareness and training program designed to educate employees and contractors about cybersecurity risks and their responsibilities in protecting Company systems and information.
+Added: Training topics may include phishing awareness, password security, data protection practices, and incident reporting procedures.
+Added: In addition, Cycurion may conduct periodic simulated phishing exercises to reinforce awareness and promote secure behavior.
+Added: Cycurion considers cybersecurity risks associated with third-party vendors, service providers, and contractors as part of its broader cybersecurity risk management efforts.
+Added: The Company may assess the security posture of key third parties through contractual requirements, security questionnaires, and other risk management measures designed to reduce potential exposure.
+Added: Company systems and services are hosted in secure cloud environments.
+Added: To protect these environments, Cycurion employs security controls such as identity and access management, network security protections, encryption technologies, and monitoring capabilities designed to safeguard cloud-based infrastructure and applications.
+Added: Incident Response
+Added: Cycurion has implemented an IT Security Incident Response Policy designed to support the preparation for, detection of, and response to cybersecurity incidents.
+Added: The incident response process generally includes four phases:
(i) preparation;
1 unchanged sentence
(iii) containment, eradication, and recovery;
−Removed: and (iv) post-incident activity.
−Removed: Our CISO and ISSO are responsible for developing, implementing,
−Removed: coordinating, and maintaining IT security policy and procedures.
−Removed: These individuals also fill the role of Computer Incident Response Team
−Removed: (CIRT) Leaders.
−Removed: They are responsible for the operations of the system and its applications, including reporting, responding to security
−Removed: incidents, and ensuring that adequate event logging is enabled.
−Removed: Our ISSO is responsible for the security of the system and for ensuring
−Removed: incident response (IR) policy and plan are documented, followed, that the IR plan is tested annually, updated with lessons learned from
−Removed: training exercises and on-going incident handling activities, and periodically reviewed at least on an annual basis.
−Removed: This person also
−Removed: fills the role of Deputy CIRT Leader.
−Removed: Our CISO is responsible for information security within the organization and is responsible for
−Removed: the review and approval of the incident response policy and plan.
−Removed: General end-users and non-CIRT personnel are responsible for actively
−Removed: securing their systems and notifying the CIRT of any suspected information security incident (e.g., potential virus detection, phishing
−Removed: emails, potential malware infection, etc.).
−Removed: Management considers cybersecurity risk as part of
−Removed: its overall risk oversight function and reviews policies and procedures relative to both the systems and facility to ensure all requirements
−Removed: are within the Company’s purview to meet, and that appropriate resources have been dedicated or otherwise made available to accomplish,
−Removed: these requirements.
−Removed: Our management team, including our CISO and ISSO, are responsible for day-to-day implementation, assessment, and management
−Removed: our cybersecurity risk assessment and management processes.
−Removed: The CISO and ISO have primary responsibility for our overall cybersecurity
−Removed: risk management program, including monitoring the prevention, detection, mitigation, and remediation of cybersecurity incidents, and works
−Removed: in partnership with our other business leaders.
−Removed: Our CISO and ISO supervise both our internal cybersecurity personnel and any retained
−Removed: external cybersecurity consultants.
−Removed: Our CISO and ISSO have served in various roles in information technology and information security
−Removed: for over 25 years each.
−Removed: The Board of Directors receives presentations and
−Removed: reports on cybersecurity, which address a range of topics including recent developments, evolving standards, the threat environment, cybersecurity
−Removed: systems testing and vulnerability assessments, and the Company’s practices and policies to manage risks.
−Removed: The CISO and ISSO report
−Removed: to the Board of Directors on cybersecurity matters and materials risks, if any, from cybersecurity threats.
−Removed: The Board of Directors also
−Removed: receive notice of any significant cybersecurity incidents, as well as ongoing updates regarding any such incident until it has been addressed.
−Removed: As of the date of this Annual Report, we are not aware
−Removed: of any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially affected
−Removed: the Company, its business strategy, results of operations or financial condition.
−Removed: As cybersecurity threats become more sophisticated,
−Removed: it is reasonably likely that we will be required to expend greater resources to continue to modify and enhance our protective measures.
+Added: (iv) post-incident review.
+Added: Our Chief Information Officer ("CIO") and Information System Security Officer ("ISSO") are responsible for developing, implementing, coordinating, and maintaining Cycurion's cybersecurity policies and procedures, including incident response activities.
+Added: The CIO and ISSO also serve as leaders of Cycurion's Incident Response Team ("IRT").
+Added: These individuals are responsible for overseeing the response to cybersecurity incidents, coordinating remediation efforts, and ensuring that security monitoring and logging capabilities are enabled across applicable systems.
+Added: Incident response procedures include processes for identifying, classifying, and responding to potential cybersecurity incidents.
+Added: Security personnel may investigate suspected incidents, collect, and preserve relevant evidence, and coordinate remediation actions designed to restore normal system operations.
+Added: Cycurion periodically reviews and updates its incident response procedures and may conduct internal exercises or simulations designed to evaluate incident response readiness.
+Added: Employees and system users are responsible for reporting suspected cybersecurity incidents such as malware infections, phishing attempts, unauthorized access attempts, or other suspicious activities to designated security personnel.
+Added: If a cybersecurity incident occurs, management evaluates the nature, scope, and potential impact of the incident to determine whether the incident could materially affect Cycurion's business, operations, or financial condition.
+Added: This evaluation may involve consultation with internal security personnel, senior management, and legal advisors.
+Added: Management considers cybersecurity risk as part of Cycurion's overall risk management and oversight processes.
+Added: Cycurion's management team, including the CIO and ISSO, is responsible for the day-to-day implementation, assessment, and management of Cycurion's cybersecurity risk management processes.
+Added: The CIO and ISSO oversee Cycurion's cybersecurity program and work with other members of management to implement and maintain cybersecurity policies, procedures, and safeguards designed to protect Company systems and data.
+Added: The CIO and ISSO supervise internal cybersecurity personnel and may coordinate with external cybersecurity professionals or consultants who assist with security monitoring, risk assessments, and cybersecurity program improvements.
+Added: The Board of Directors receives periodic updates regarding cybersecurity matters, including information related to cybersecurity risks, threat landscape developments, and cybersecurity program activities.
+Added: Cybersecurity risk oversight is integrated into Cycurion's broader enterprise risk management processes.
+Added: Management periodically provides the Board with updates regarding cybersecurity risk management activities and the effectiveness of cybersecurity controls.
+Added: Our Information Security team, led by our Vice President of Operations , William (Eric) Singleton, is responsible for assessing and managing material cybersecurity risks.
+Added: Certifications held by the Information Security team members include (ISC)² CISSP, (ISC)² CGRC, ISACA CISM, ISACA CRISC, CompTIA Security+, CompTIA Security X (CASP+), CompTIA PenTest+, CompTIA CNVP, EC-Council CEH, GIAC GWAPT, (ISC)² CAP, FITSI FITSP, CWAPT, IABF, and AWS Solutions Architect Associate.
+Added: Singleton's background includes over 25 years of experience in IT and Information Security spanning federal government and commercial sectors, with expertise in cybersecurity strategy, risk management, compliance frameworks, penetration testing, vulnerability assessment, security control assessment, and FISMA/RMF program oversight.
+Added: His formal education includes a Bachelor of Science in Computer Science from Northeastern University.
+Added: Certifications held by Mr.
+Added: Singleton include the (ISC)² Certified Authorization Professional (CAP), with additional specialized training in Incident Response and Threat Hunting, Offensive Operations, Penetration Testing, Red and BlueTeaming, Continuous Diagnostics and Mitigation (CDM), and Cloud Security.
+Added: Our Vice President of Operations provides reports to the Audit Committee of our Board of Directors on a standing basis at each Audit Committee meeting, and as otherwise requested by the Chair of the Audit Committee or as determined necessary by the VP of Operations or other members of senior management.
+Added: The VP of Operations is personally involved in, and responsible for, the risk assessment, identification, and management process described above.
+Added: Cybersecurity Risk Impact
+Added: As of the date of this Annual Report, Cycurion is not aware of any cybersecurity incidents that have materially affected its business strategy, results of operations, or financial condition.
+Added: However, cybersecurity threats continue to evolve in sophistication and frequency.
+Added: As a result, Cycurion may be required to devote additional resources to enhance its cybersecurity protections and maintain the effectiveness of its cybersecurity risk management processes.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.