UNRESOLVED STAFF COMMENTS
−Removed: This information is not required for smaller reporting companies.
+Added: This information is not required for smaller reporting
CYBERSECURITY
Cybersecurity Risk Management and Strategy
−Removed: We rely on our information technology to operate our business.
−Removed: we have policies and processes designed to protect our information technology systems, some of which are managed by third parties, and
−Removed: resolve issues in a timely manner in the event of a cybersecurity threat or incident.
−Removed: We have designed our business applications and hosting services to minimize
−Removed: the impact that cybersecurity incidents could have on our business and have identified back-up systems where appropriate.
−Removed: We seek to further
−Removed: mitigate cybersecurity risks through a combination of monitoring and detection activities, use of anti-malware applications, employee
−Removed: training, quality audits and communication and reporting structures, among other processes.
−Removed: We engage a third-party consultant to assist
−Removed: us with our cybersecurity risk management framework, including the monitoring and detection of cybersecurity threats and responding to
−Removed: any cybersecurity threats or incidents.
+Added: We rely on our information technology to operate our
+Added: As such, we have policies and processes designed to protect our information technology systems, some of which are managed by
+Added: third parties, and resolve issues in a timely manner in the event of a cybersecurity threat or incident.
+Added: We have designed our business applications and hosting
+Added: services to minimize the impact that cybersecurity incidents could have on our business and have identified back-up systems where appropriate.
+Added: We seek to further mitigate cybersecurity risks through a combination of monitoring and detection activities, use of anti-malware applications,
+Added: employee training, quality audits and communication and reporting structures, among other processes.
+Added: We engage a third-party consultant
+Added: to assist us with our cybersecurity risk management framework, including the monitoring and detection of cybersecurity threats and responding
+Added: to any cybersecurity threats or incidents.
+Added: The Company maintains an ongoing partnership with
+Added: a third-party cybersecurity service provider, which facilitates continuous communication through regular electronic updates and periodic
+Added: onsite engagements.
+Added: This collaboration ensures alignment in key areas of cybersecurity, including threat detection, vulnerability management,
+Added: and incident response.
+Added: We have implemented internal communication protocols
+Added: designed to promptly escalate any cybersecurity incidents to the appropriate personnel responsible for evaluating their significance and
+Added: potential materiality.
+Added: Upon identification of an incident, the matter is assessed in coordination with our cybersecurity service provider.
+Added: Relevant information is then communicated to the Board of Directors, which is responsible for determining whether public disclosure is
+Added: required under applicable securities laws.
+Added: This process is intended to support timely and accurate reporting in accordance with the Company’s
+Added: disclosure obligations.
Cybersecurity Governance
−Removed: Our third-party consultant team is managed by our Chief Executive Officer
−Removed: and Independent Director.
−Removed: In addition, management updates the board, as necessary, regarding any material cybersecurity incidents, as
−Removed: well as any incidents with lesser impact potential.
−Removed: Our management team is responsible for assessing and managing our material
−Removed: risks from cybersecurity threats.
+Added: The Company’s cybersecurity program is supported
+Added: by a third-party consultant team, which provides expertise in monitoring, threat detection, and risk mitigation.
+Added: This team operates under
+Added: the oversight of senior leadership, specifically the Chief Executive Officer and an Independent Director with relevant experience.
+Added: they are responsible for managing the relationship with the cybersecurity consultants and ensuring that cybersecurity risk management
+Added: remains aligned with the Company’s overall strategic objectives and risk tolerance.
+Added: Our cybersecurity program is informed by industry-recognized
+Added: best practices, including the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF), which guides our efforts
+Added: across key domains such as risk identification, protection, threat detection, incident response, and recovery.
+Added: This framework helps ensure
+Added: consistency and effectiveness in our cybersecurity approach and supports compliance with evolving regulatory expectations.
+Added: Cybersecurity oversight is also integrated into the
+Added: Company’s broader corporate governance structure.
+Added: Management provides updates to the Board of Directors at least quarterly, or more
+Added: frequently as necessary in response to immediate threats or incidents.
+Added: These updates cover any material cybersecurity events, as well
+Added: as incidents of lesser impact that may indicate emerging risks or operational vulnerabilities.
+Added: The Board, in exercising its oversight
+Added: responsibilities, evaluates the potential impact of such incidents on the Company’s operations, financial condition, and disclosure
+Added: This governance framework is designed to ensure that
+Added: the Company remains responsive to the dynamic cybersecurity landscape, maintains regulatory compliance, and protects the integrity of
+Added: its information systems and data assets.
+Added: Our management team is responsible for assessing and
+Added: managing our material risks from cybersecurity threats.
Risks from Cybersecurity threats
−Removed: Although cybersecurity risks have not materially affected us, including
−Removed: our business strategy, results of operations or financial condition, to date, we face numerous and evolving cybersecurity threats in our
−Removed: For more information about the cybersecurity risks we face, see the risk factor entitled "The Medinotec Group of Companies
−Removed: rely on the proper function, security and availability of our IT systems and data to operate the business, and a breach, cyber-attack
−Removed: or other disruption to these systems or data could materially and adversely affect the business, results of operations, financial condition,
−Removed: cash flows, reputation, or competitive position." in Item 1A.
+Added: Although cybersecurity risks have not materially affected
+Added: us, including our business strategy, results of operations or financial condition, to date, we face numerous and evolving cybersecurity
+Added: threats in our business.
+Added: For more information about the cybersecurity risks we face, see the risk factor entitled "The Medinotec
+Added: Group of Companies rely on the proper function, security and availability of our IT systems and data to operate the business, and a breach,
+Added: cyber-attack or other disruption to these systems or data could materially and adversely affect the business, results of operations, financial
+Added: condition, cash flows, reputation, or competitive position." in Item 1A.
Risk Factors.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.