Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED STAFF COMMENTS
None.
ITEM 1C. CYBERSECURITY
The Company has adopted processes to assess, identify, and manage material risks posed by cybersecurity threats. These processes are integrated into the Company’s overall enterprise risk management framework.
Cybersecurity risk management is overseen by the Company’s Managed Service Provider (MSP), Computer Doctoring Inc., which provides structured cybersecurity oversight , monitoring, and incident response services. The MSP has significant experience designing and implementing layered cybersecurity programs aligned with recognized frameworks, including NIST and ISO 27001 best practices.
The Company employs a multi-layered security model that includes:
▪ Advanced endpoint detection and response (EDR)
▪ Centralized monitoring and logging
▪ Multi-Factor Authentication (MFA) and role-based access control
▪ Third-party AI-driven email threat protection
▪ Continuous patch management and vulnerability remediation
▪ Dark web credential monitoring
▪ Independent SaaS backup and disaster recovery controls
These controls are centrally monitored using the full Kaseya security and management suite, enabling proactive threat detection, system visibility, and operational oversight across the Company’s environment.
During the year ended December 31, 2025 , the Company did not experience any risks from cybersecurity threats that materially affected or were reasonably likely to materially affect the Company’s business strategy, results of operations, or financial condition.
The Company’s Board of Directors, through its Audit Committee (the “Committee”), oversees cybersecurity risks. The MSP provides ongoing reporting to management regarding cybersecurity posture, threat activity, and incident response readiness. Any material cybersecurity risks or incidents are escalated to executive management and reported to the Committee as appropriate.
22
Table of Contents
While the Company does not maintain an internal employee dedicated solely to cybersecurity risk management, it relies on its external MSP for specialized cybersecurity expertise, monitoring, and incident response.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.