UNRESOLVED STAFF COMMENTS
−Removed: Not applicable.
CYBERSECURITY
−Removed: At IPM, cybersecurity is at the core of our business operations and
−Removed: an integral part of our commitment to delivering secure, compliant, and resilient technology solutions to customers operating in highly
−Removed: regulated industries.
−Removed: Prior to the Transactions, the Company employed a comprehensive strategy with respect to cybersecurity, which was
−Removed: supported by both management and our Board.
−Removed: Historically, our Board was responsible for overseeing our risk management activities in general,
−Removed: and certain of our Board committees assisted the Board in the role of risk oversight.
−Removed: The operations team prior to the Transactions conducted
−Removed: manual and automated testing of our systems, with the goal of identifying vulnerabilities and proactively strengthening our defenses.
−Removed: Following the Transactions,
−Removed: in order to support our comprehensive range of IT-related services and digital infrastructure, we have embraced a multi-layered defense
−Removed: approach, which helps us recognize and address the dynamic nature of cyber threats.
−Removed: By integrating diverse security measures, we aim to
−Removed: fortify our infrastructure against a spectrum of potential risks and adapt to the ever-evolving cybersecurity landscape.
−Removed: Our cybersecurity strategy is proactively designed
−Removed: to protect our digital infrastructure, customer environments, and business continuity.
−Removed: This approach is supported by our management and
−Removed: Board, with structured oversight to ensure compliance with evolving regulatory, risk, and industry best practices.
−Removed: Proactive Security Measures and Threat Management
−Removed: We employ a multi-layered defense strategy, leveraging
−Removed: advanced threat intelligence, automation, and security analytics to proactively detect, prevent, and respond to cyber threats.
−Removed: security practices include:
−Removed: threat monitoring and response utilizing real-time security operations centers and next-generation endpoint detection and response to
−Removed: rapidly identify and neutralize threats;
−Removed: vulnerability assessments and penetration testing conducted through automated and manual assessments with prioritized remediation workflows
−Removed: to enhance security across infrastructure, applications, and client environments;
−Removed: trust security architecture, which implements strict identity verification, least privilege access and network segmentation to reduce
−Removed: attack surfaces and prevent lateral movement of threats;
−Removed: ● partnerships
−Removed: with leading cybersecurity firms for independent security audits, risk assessments, and compliance rev iews as described below.
+Added: IPM, cybersecurity is at the core of our business operations and an integral part of our commitment to delivering secure, compliant,
+Added: and resilient technology solutions to customers operating in highly regulated industries.
+Added: In order to support our comprehensive range
+Added: of IT-related services and digital infrastructure, we have embraced a multi-layered defense approach, which helps us recognize and address
+Added: the dynamic nature of cyber threats.
+Added: By integrating diverse security measures, we aim to fortify our infrastructure against a spectrum
+Added: of potential risks and adapt to the ever-evolving cybersecurity landscape.
+Added: cybersecurity strategy is proactively designed to protect our digital infrastructure, customer environments, and business continuity.
+Added: This approach is supported by our management and Board, with structured oversight to ensure compliance with evolving regulatory, risk,
+Added: and industry best practices.
+Added: Security Measures and Threat Management
+Added: employ a multi-layered defense strategy, leveraging advanced threat intelligence, automation, and security analytics to proactively detect,
+Added: prevent, and respond to cyber threats.
+Added: Our core security practices include:
+Added: ● continuous threat monitoring and response utilizing real-time security operations centers and next-generation endpoint detection and response to rapidly identify and neutralize threats;
+Added: ● regular vulnerability assessments and penetration testing conducted through automated and manual assessments with prioritized remediation workflows to enhance security across infrastructure, applications and client environments;
+Added: ● zero trust security architecture, which implements strict identity verification, least privilege access and network segmentation to reduce attack surfaces and prevent lateral movement of threats;
+Added: ● partnerships with leading cybersecurity firms for independent security audits, risk assessments and compliance reviews as described below.
Recognizing that human factors play a critical
2 unchanged sentences
quarterly security training, covering data protection, insider threat mitigation, phishing awareness, and compliance best practices.
−Removed: Additionally,
−Removed: we implement strict enforcement of multi-factor authentication, just-in-time access controls, and continuous user behavior monitoring.
−Removed: Incident Response and Business Continuity
−Removed: Our incident response framework follows a structured
−Removed: escalation and notification process focused on rapid containment, mitigation, and recovery from cybersecurity incidents.
−Removed: protocols include:
−Removed: detection and response workflows to leverage rapid assessment detection technology to detect
−Removed: breaches in real time;
−Removed: of critical incidents to our Chief Executive Officer, President, and Chief Operating Officer
−Removed: and the Board based on severity and regulatory reporting requirements;
−Removed: backup and disaster recovery, which implement immutable backups, air-gapped storage, and
−Removed: rapid failover solutions to protect data integrity and minimize downtime in case of cyber
−Removed: Both management and the Board are actively involved
−Removed: in the oversight of risks from cybersecurity threats.
−Removed: Our information security program is designed to ensure that management and the Board
−Removed: are adequately informed about, and provided with the tools necessary to monitor, (i) material risks from cybersecurity threats and (ii)
−Removed: our efforts related to the prevention, detection, mitigation, and remediation of cybersecurity incidents.
−Removed: Role of the Board
−Removed: Our Board oversees cybersecurity risk as part
−Removed: of our enterprise risk management strategy.
−Removed: The Board receives comprehensive cybersecurity updates from our President at least quarterly
−Removed: to inform our directors of evolving threats and regulatory developments.
−Removed: We undergo regular independent audits, cybersecurity risk assessments,
−Removed: and compliance reviews to validate our security posture, and our Audit Committee receives annual reports regarding our ongoing security
−Removed: Role of Management
−Removed: At the management level, our Chief Information
−Removed: Security Officer (“CISO”) leads cybersecurity initiatives and reports regularly to the President on security posture, risk
−Removed: trends, and key incidents.
−Removed: Our President is a seasoned technology and business leader with over 20 years of experience in managed IT services
−Removed: and global scale multi-site private cloud datacenter operations.
−Removed: His background and experience provide him with expertise regarding data
−Removed: privacy and security, vulnerability management, security operations, and application security.
−Removed: In addition, our Chief Operating Officer
−Removed: has many years of experience with managed IT cyber application delivery.
−Removed: We face risks from cybersecurity threats that
−Removed: could have a material adverse effect on its business, financial condition, results of operations, cash flows or reputation.
−Removed: have not experienced any risks from cybersecurity threats that have materially affected, or are reasonably likely to materially affect,
−Removed: our business strategy, financial condition, results of operations, or cash flows.
−Removed: See “ Risk Factors – Risks Related to
−Removed: Our Business – We could be adversely affected by information security breaches or cyber security attacks .”
+Added: Additionally, we implement strict enforcement of multi-factor authentication, just-in-time access controls, SOC 2 Type 1 controls, and
+Added: continuous user behavior monitoring.
+Added: In January 2026, the Company received an unqualified opinion attesting to its compliance with SOC
+Added: 2 Type 1 following an independent examination.
+Added: Response and Business Continuity
+Added: incident response framework follows a structured escalation and notification process focused on rapid containment, mitigation, and recovery
+Added: from cybersecurity incidents.
+Added: Key response protocols include:
+Added: automated detection and
+Added: response workflows to leverage rapid assessment detection technology to detect breaches in real time;
+Added: escalation of critical
+Added: incidents to our Chief Executive Officer, President, and Chief Operating Officer and the Board based on severity and regulatory reporting
+Added: requirements;
+Added: secure backup and disaster
+Added: recovery, which implement immutable backups, air-gapped storage and rapid failover solutions to protect data integrity and minimize
+Added: downtime in case of cyber incidents.
+Added: management and the Board are actively involved in the oversight of risks from cybersecurity threats.
+Added: Our information security program
+Added: is designed to ensure that management and the Board are adequately informed about, and provided with the tools necessary to monitor,
+Added: (i) material risks from cybersecurity threats and (ii) our efforts related to the prevention, detection, mitigation, and remediation
+Added: of cybersecurity incidents.
+Added: Board oversees cybersecurity risk as part of our enterprise risk management strategy.
+Added: The Board receives comprehensive cybersecurity
+Added: updates from our President at least quarterly to inform our directors of evolving threats and regulatory developments.
+Added: We undergo regular
+Added: independent audits, cybersecurity risk assessments, and compliance reviews to validate our security posture, and our Audit Committee
+Added: receives annual reports regarding our ongoing security measures.
+Added: of Management
+Added: the management level, our Chief Information Security Officer (“CISO”) leads cybersecurity initiatives and reports regularly
+Added: to the President on security posture, risk trends and key incidents.
+Added: Our President is a seasoned technology and business leader with
+Added: over 20 years of experience in managed IT services and global scale multi-site private cloud datacenter operations.
+Added: His background and
+Added: experience provide him with expertise regarding data privacy and security, vulnerability management, security operations and application
+Added: In addition, our Chief Operating Officer has many years of experience with managed IT cyber application delivery.
+Added: face risks from cybersecurity threats that could have a material adverse effect on its business, financial condition, results of operations,
+Added: cash flows or reputation.
+Added: To date, we have not experienced any risks from cybersecurity threats that have materially affected, or are
+Added: reasonably likely to materially affect, our business strategy, financial condition, results of operations or cash flows.
+Added: Factors – Risks Related to Our Business – We could be adversely affected by information security breaches or cyber security
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.