Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED STAFF COMMENTS
None.
ITEM 1C. CYBERSECURITY
We maintain a structured and risk-based process for identifying, assessing, and managing material risks arising from cybersecurity threats as part of our broader enterprise risk management framework. Our cybersecurity risk management activities are integrated into the Company’s overall risk management processes and are designed to address prevention, detection, response, and recovery. We monitor security industry developments and global threat trends on an ongoing basis. Cybersecurity risk management and mitigation are overseen by dedicated privacy, safety, and security professionals, including our Information Security & Quality Manager, who has primary responsibility for overseeing cybersecurity operations. Our cybersecurity program is supported by both internal resources and external service providers with relevant expertise across multiple industries. Executive management is responsible for the Company’s enterprise risk management program and regularly considers cybersecurity risks alongside other operational, financial, and strategic risks. Cybersecurity risks are assessed for potential materiality and are incorporated into management decision-making where appropriate.
As part of our cybersecurity risk management program, we track, log, and manage privacy and security incidents across Neonode, as well as incidents involving vendors and other third-party service providers. Reported incidents are evaluated in accordance with established procedures to determine severity, potential impact, and required remediation. Significant incidents are reviewed by a cross-functional team, and any incident assessed as potentially material, or potentially becoming material, is escalated promptly to senior management for further evaluation. Where appropriate, we consult external advisors, including legal counsel, to support materiality assessments, regulatory considerations, and disclosure obligations. Senior management is responsible for making final determinations regarding materiality and related disclosure or compliance actions.
14
Table of Contents
The Board of Directors has oversight responsibility for cybersecurity risks, including oversight of material cybersecurity incidents, compliance with applicable disclosure requirements, and the potential impact of cybersecurity risks on the Company’s financial condition, results of operations, and business strategy. Senior management provides updates to the Board of Directors regarding cybersecurity risks, trends, and, if applicable, material incidents.
To date, our business strategy, results of operations, and financial condition have not been materially affected by risks arising from cybersecurity threats, including as a result of previously identified cybersecurity incidents. However, cybersecurity risks continue to evolve, and we cannot provide assurance that future incidents or emerging threats will not have a material adverse effect. For additional information regarding cybersecurity-related risks, see Item 1A – Risk Factors of this Annual Report on Form 10-K.
ITEM 2. PROPERTIES
As of December 31, 2025, we leased office facilities of approximately 6,700 square feet for our corporate headquarters in Stockholm.
We believe our facilities are adequate and suitable for our current needs and that suitable additional or alternative space will be available to accommodate our operations if needed.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.