Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED STAFF COMMENTS
None.
ITEM 1C. CYBERSECURITY
Cybersecurity Risk Management and Strategy
We are dedicated to protecting the integrity, confidentiality, and availability of our data, infrastructure and operating systems. As part of our commitment to safeguarding our operations against cybersecurity threats, we employ a comprehensive strategy for the assessment, identification, and management of cybersecurity risks. We engage a managed services provider (“ MSP”), which provides wide-ranging services including risk assessments, threat detection, monitoring and response strategies, security audits and cybersecurity training.
Cybersecurity Processes : We conduct robust cybersecurity processes aligned with the National Institute of Standards Technology (“NIST”) and the Cybersecurity Maturity Model Certification (“CMMC”) protocols. Our comprehensive approach includes:
• An enterprise firewall;
• Implementation of Multi-Factor Authentication (MFA);
• Adherence to the Zero Trust model;
• Utilization of Managed Detection and Response (MDR);
• Endpoint Detection and Response (EDR) technologies;
• 24x7 Security Operations Center (SOC); and
• Employment of Security Information and Event Management (SIEM) systems to continuously monitor our network and respond to threats in real time.
Risk Assessment Procedures : We conduct periodic risk assessments to identify potential cybersecurity threats and vulnerabilities within our IT infrastructure. These assessments are conducted using various software tools and methodologies that enable us to evaluate our systems critically and comprehensively. Our risk assessment process includes, but is not limited to, the analysis of:
• Hardware and software configurations;
• Network and data access protocols;
• Encryption standards; and
• Compliance with relevant industry and regulatory standards.
Threat Identification : We utilize advanced threat detection tools and services that continuously monitor our network for signs of unauthorized access, anomalies, and potential breaches. Our third-party cybersecurity provider is equipped with sophisticated detection technologies that help to swiftly identify even the most subtle signs of compromise. We focus on:
• Real-time monitoring of our networks;
• Regularly updated intrusion detection systems (IDS);
• Deployment of endpoint detection and response (EDR) solutions; and
• Utilization of threat intelligence platforms to stay abreast of emerging threats.
Threat Management : Upon identification of a potential threat, our managed service provider’s dedicated incident response team takes immediate action to mitigate any adverse impacts. Our threat management procedures include:
• Immediate isolation of affected systems to prevent the spread of threats;
• Application of appropriate remediation measures, such as patches and software updates;
14
Table of Contents
• Conducting a thorough investigation to understand the breach's nature and scope; and
• Implementing enhancements to prevent future occurrences.
Our incident response plan provides a concise strategy of how we will respond to an incident, including who will respond and their roles and responsibilities, the facilities that are in place to help with the management of the incident, how decisions will be taken with regard to our response to an incident, how communication will be handled both internally and externally, and defining what will happen once the incident is resolved and how we can learn and improve from the situation.
Integration into Overall Risk Management : Our cybersecurity risk assessment processes are fully integrated into the broader risk management framework. Cybersecurity is positioned as a core component of our risk management strategy, with direct reporting to our President and COO, who is guided by our MSP firm. The MSP firm provides strategic direction on policy, procedures and best practice. The synergy between cybersecurity and risk management ensures a resilient posture against emerging cyber threats.
Engagement of Third Parties : These providers are selected based on stringent criteria for cybersecurity expertise, particularly their capability to implement and manage NIST and CMMC protocols.
Third-Party Service Provider Oversight : Our oversight processes include comprehensive due diligence checks for any new third-party service provider and continuous monitoring of our existing MSP firm ’ s activities. We have established protocols for communication and incident response that align with our managed service provider's operations, and industry best practice, ensuring swift action in the face of cybersecurity threats. Furthermore, a scheduled series of meetings has been established to procure updates and deliberate upon cybersecurity strategy with our contracted third-party providers.
Impact of Cybersecurity Risks
Material Effects from Cyber Threats : To date, our operations and financial condition have not been materially affected by cybersecurity threats, due in part to our proactive measures such as employee security training programs and advanced threat detection and response capabilities. Our defensive strategies have successfully mitigated the risks of cyber incidents.
Potential Risk Exposure : While we have not experienced significant disruptions from cyber threats, we recognize the evolving nature of cyber risks. We continually evaluate the likelihood of potential cybersecurity incidents that could materially impact our strategic direction, operational efficacy, and financial stability. Our investment in training, alongside our sophisticated SOC, SIEM, and Zero Trust architecture, positions us to identify and address potential cybersecurity challenges promptly.
Cybersecurity Governance
Our executive team is actively involved in overseeing our cybersecurity operations to ensure that they meet industry standards. The executive team provides regular updates to the Board—specifically the audit committee—on the status of our cybersecurity efforts, including any potential risks, threats or incidents.
Our President and COO , with guidance from our third-party MSP, manages our cybersecurity risk management and strategy process. Collectively, our consultants have 50+ years’ experience in the cybersecurity industry in various roles.
Processes for Informing the Board: The audit committee is regularly informed about cybersecurity risks through quarterly briefings from our President and COO. These briefings may include risk assessment reports, incident response updates, changes to the cybersecurity landscape, and other relevant information. In the case of a cybersecurity incident that meets reporting thresholds, the audit committee will be promptly notified and will receive continual updates until the situation is remedied.
ITEM 2. PR OPERTIES
Corporate Office
We maintain our corporate offices in Tampa, Florida where we lease approximately 6,000 square feet of office space. We currently do not own any buildings or land. We believe our current leased facility is adequate for our current and planned levels of operation.
ExO Phosphorite Project
Summary
We have one material mining project, the ExO Phosphorite Project, which is located in the Mexican Exclusive Economic Zone (the “Mexican EEZ”) offshore Baja California Sur, Mexico in the Pacific Ocean. The exclusive mining concessions for the ExO
15
Table of Contents
Phosphorite Project were granted to Exploraciones Oceánicas S. de R.L. de CV (“ExO”), a Mexican company in which we hold, through other subsidiaries, a 56.14% interest. The Primary concession (concession No. 244813) was granted in 2012, and rights for the two additional adjacent concessions (Norte concession No. 242994 and Sur concession No. 242995) were acquired in 2014. Exploration has confirmed the ExO West Phosphorite Deposit lies within the Primary and Norte concessions. The ExO Phosphorite Project currently has no reportable mineral reserves. In October 2024, we discovered that the Mexican mining authority unlawfully cancelled ExO’s mining concessions in June and August 2024. ExO is challenging the cancellation. See ExO Phosphate Project in the above Part I, Item 1. Business for additional information.
Location and Brief Description
The ExO Phosphorite Project concession area is a sedimentary marine phosphorite deposit located in the Mexican EEZ offshore Baja California Sur, Mexico in the Pacific Ocean. The property is located using a multi-point polygonal property demarcation bounded by latitudes 26.1°, 25.4°, and longitudes -112.2°, -112.9° WGS 1984. The property is roughly 20 to 45 kilometers from shore. Following is a map denoting the three concessions in relation to Baja California Sur, Mexico.
Infrastructure and Access
There is no material infrastructure located on the property where the concessions are located. Access to the site is by sea-going vessels dispatched from various nearby ports of opportunity. Project engineering anticipates use of existing dredging technology to recover the phosphorite ore, including a trailing suction hopper dredger, and on-site mechanical beneficiation using a floating production and storage platform to produce phosphate ore concentrate, none of which introduces chemicals to the marine environment.
Description of Concessions
Total concessions encompass approximately 114,775 hectares of seafloor at a water depth of approximately 80 meters and consist of three concessions in total (see section Location and Brief Description above). The concessions were granted to ExO by the Mexican Secretary of Economy, General Coordination of Mining, and are valid for 50 years, with an option for a 50-year extension. The Primary concession was granted in 2012, and rights for the other two concessions (Norte and Sur) were acquired thereafter in 2014. To commence further operations on the ExO Phosphorite Project, ExO must obtain approval of its Environmental and Social Impact Assessment ("ESIA") from the Mexican Ministry of Environment and Natural Resources ("SEMARNAT"). In October 2024, we discovered that the Mexican mining authority unlawfully cancelled ExO’s mining concessions in June and August 2024. ExO is challenging the cancellation. See ExO Phosphate Project in the above Part I, Item 1. Business for additional information.
16
Table of Contents
Work Completed
The ExO Phosphorite Project has sufficient data to confirm the geological continuity of the deposit and the estimation of measured, indicated and inferred resource tonnes. ExO, through exploration operations conducted by Odyssey, explored the area, characterized the environmental baseline to enable drafting and submittal of the ESIA, and acquired approximately 200 vibracore samples for assay. These cores were split into individual strata core units each of approximately 1 meter length. The cores were assayed at Florida Industrial and Phosphate Research Institute ("FIPR") in Bartow, Florida under the guidance of Mr. Henry Lamb.
Related Matters
This Annual Report on Form 10-K does not include a resource estimate for the ExO Phosphorite Project because currently we do not have a technical report summary for the project that meets the requirements of Item 601(b)(96) of Regulation S-K.
ITEM 3. LEGAL PROCEEDINGS
The information contained in “Part IV, Item 15. Note 11, Commitments and Contingencies ” included elsewhere in this Annual Report on Form 10-K is incorporated herein by reference.
ITEM 4. MINE SAFETY DISCLOSURES
Not applicable.
17
Table of Contents
PART II