4 unchanged sentences
As part of our commitment to safeguarding our operations against cybersecurity threats, we employ a comprehensive strategy for the assessment, identification, and management of cybersecurity risks.
−Removed: We engage a third-party CIO consulting firm and a managed services provider, which work together to provide wide-ranging services including risk assessments, threat detection, monitoring and response strategies, security audits and cybersecurity services, tools and training.
+Added: We engage a managed services provider (“ MSP”), which provides wide-ranging services including risk assessments, threat detection, monitoring and response strategies, security audits and cybersecurity training.
Cybersecurity Processes :
−Removed: We conduct robust cybersecurity processes aligned with NIST and CMMC protocols.
+Added: We conduct robust cybersecurity processes aligned with the National Institute of Standards Technology (“NIST”) and the Cybersecurity Maturity Model Certification (“CMMC”) protocols.
Our comprehensive approach includes:
9 unchanged sentences
These assessments are conducted using various software tools and methodologies that enable us to evaluate our systems critically and comprehensively.
−Removed: Our risk assessment process includes the analysis of:
+Added: Our risk assessment process includes, but is not limited to, the analysis of:
• Hardware and software configurations;
19 unchanged sentences
Our cybersecurity risk assessment processes are fully integrated into the broader risk management framework.
−Removed: Cybersecurity is positioned as a core component of our risk management strategy, with direct reporting to our President and COO, who is guided by our third-party CIO firm.
−Removed: The CIO firm provides strategic direction on policy, procedures and best practice.
+Added: Cybersecurity is positioned as a core component of our risk management strategy, with direct reporting to our President and COO, who is guided by our MSP firm.
+Added: The MSP firm provides strategic direction on policy, procedures and best practice.
The synergy between cybersecurity and risk management ensures a resilient posture against emerging cyber threats.
2 unchanged sentences
Third-Party Service Provider Oversight :
−Removed: Our oversight processes include comprehensive due diligence checks for any new third-party service provider and continuous monitoring of our existing managed service provider and CIO firms’ activities.
+Added: Our oversight processes include comprehensive due diligence checks for any new third-party service provider and continuous monitoring of our existing MSP firm ’ s activities.
We have established protocols for communication and incident response that align with our managed service provider's operations, and industry best practice, ensuring swift action in the face of cybersecurity threats.
10 unchanged sentences
Our executive team is actively involved in overseeing our cybersecurity operations to ensure that they meet industry standards.
−Removed: The executive team provides regular updates to the board of directors – specifically the audit committee – on the status of our cybersecurity efforts, including any potential risks, threats or incidents.
−Removed: The President and COO, with guidance from our third-party managed services provider and CIO consulting firm, manages our cybersecurity risk management and strategy process.
+Added: The executive team provides regular updates to the Board—specifically the audit committee—on the status of our cybersecurity efforts, including any potential risks, threats or incidents.
+Added: Our President and COO , with guidance from our third-party MSP, manages our cybersecurity risk management and strategy process.
Collectively, our consultants have 50+ years’ experience in the cybersecurity industry in various roles.
Processes for Informing the Board:
−Removed: The audit committee is regularly informed about cybersecurity risks through quarterly briefings from the President and COO.
−Removed: These briefings include risk assessment reports, incident response updates, changes to the cybersecurity landscape, and other relevant information.
+Added: The audit committee is regularly informed about cybersecurity risks through quarterly briefings from our President and COO.
+Added: These briefings may include risk assessment reports, incident response updates, changes to the cybersecurity landscape, and other relevant information.
In the case of a cybersecurity incident that meets reporting thresholds, the audit committee will be promptly notified and will receive continual updates until the situation is remedied.
+Added: Corporate Office
+Added: We maintain our corporate offices in Tampa, Florida where we lease approximately 6,000 square feet of office space.
+Added: We currently do not own any buildings or land.
+Added: We believe our current leased facility is adequate for our current and planned levels of operation.
+Added: ExO Phosphorite Project
+Added: We have one material mining project, the ExO Phosphorite Project, which is located in the Mexican Exclusive Economic Zone (the “Mexican EEZ”) offshore Baja California Sur, Mexico in the Pacific Ocean.
+Added: The exclusive mining concessions for the ExO
+Added: Phosphorite Project were granted to Exploraciones Oceánicas S.
+Added: de CV (“ExO”), a Mexican company in which we hold, through other subsidiaries, a 56.14% interest.
+Added: The Primary concession (concession No.
+Added: 244813) was granted in 2012, and rights for the two additional adjacent concessions (Norte concession No.
+Added: 242994 and Sur concession No.
+Added: 242995) were acquired in 2014.
+Added: Exploration has confirmed the ExO West Phosphorite Deposit lies within the Primary and Norte concessions.
+Added: The ExO Phosphorite Project currently has no reportable mineral reserves.
+Added: In October 2024, we discovered that the Mexican mining authority unlawfully cancelled ExO’s mining concessions in June and August 2024.
+Added: ExO is challenging the cancellation.
+Added: See ExO Phosphate Project in the above Part I, Item 1.
+Added: Business for additional information.
+Added: Location and Brief Description
+Added: The ExO Phosphorite Project concession area is a sedimentary marine phosphorite deposit located in the Mexican EEZ offshore Baja California Sur, Mexico in the Pacific Ocean.
+Added: The property is located using a multi-point polygonal property demarcation bounded by latitudes 26.1°, 25.4°, and longitudes -112.2°, -112.9° WGS 1984.
+Added: The property is roughly 20 to 45 kilometers from shore.
+Added: Following is a map denoting the three concessions in relation to Baja California Sur, Mexico.
+Added: Infrastructure and Access
+Added: There is no material infrastructure located on the property where the concessions are located.
+Added: Access to the site is by sea-going vessels dispatched from various nearby ports of opportunity.
+Added: Project engineering anticipates use of existing dredging technology to recover the phosphorite ore, including a trailing suction hopper dredger, and on-site mechanical beneficiation using a floating production and storage platform to produce phosphate ore concentrate, none of which introduces chemicals to the marine environment.
+Added: Description of Concessions
+Added: Total concessions encompass approximately 114,775 hectares of seafloor at a water depth of approximately 80 meters and consist of three concessions in total (see section Location and Brief Description above).
+Added: The concessions were granted to ExO by the Mexican Secretary of Economy, General Coordination of Mining, and are valid for 50 years, with an option for a 50-year extension.
+Added: The Primary concession was granted in 2012, and rights for the other two concessions (Norte and Sur) were acquired thereafter in 2014.
+Added: To commence further operations on the ExO Phosphorite Project, ExO must obtain approval of its Environmental and Social Impact Assessment ("ESIA") from the Mexican Ministry of Environment and Natural Resources ("SEMARNAT").
+Added: In October 2024, we discovered that the Mexican mining authority unlawfully cancelled ExO’s mining concessions in June and August 2024.
+Added: ExO is challenging the cancellation.
+Added: See ExO Phosphate Project in the above Part I, Item 1.
+Added: Business for additional information.
+Added: Work Completed
+Added: The ExO Phosphorite Project has sufficient data to confirm the geological continuity of the deposit and the estimation of measured, indicated and inferred resource tonnes.
+Added: ExO, through exploration operations conducted by Odyssey, explored the area, characterized the environmental baseline to enable drafting and submittal of the ESIA, and acquired approximately 200 vibracore samples for assay.
+Added: These cores were split into individual strata core units each of approximately 1 meter length.
+Added: The cores were assayed at Florida Industrial and Phosphate Research Institute ("FIPR") in Bartow, Florida under the guidance of Mr.
+Added: Related Matters
+Added: This Annual Report on Form 10-K does not include a resource estimate for the ExO Phosphorite Project because currently we do not have a technical report summary for the project that meets the requirements of Item 601(b)(96) of Regulation S-K.
+Added: LEGAL PROCEEDINGS
+Added: The information contained in “Part IV, Item 15.
+Added: Note 11, Commitments and Contingencies ” included elsewhere in this Annual Report on Form 10-K is incorporated herein by reference.
+Added: MINE SAFETY DISCLOSURES
+Added: Not applicable.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.