Item 1B. Unresolved Staff Comments
ITEM
1B. UNRESOLVED STAFF COMMENTS
We
are a smaller reporting company as defined by Rule 12b-2 of the Securities Exchange Act of 1934 and are not required to provide the information
under this item.
ITEM
1C. CYBERSECURITY
Risk
Management and Strategy
The
goal of our cybersecurity risk management strategy is to protect the privacy, integrity and availability of our systems, information
and data. Our subsidiaries are required to comply with rapidly evolving and complex PRC laws and regulations with respect to cybersecurity,
data security and personal information protection. In response to the recent changes in the regulatory requirements, we have designed
a data and information protection mechanism as part of our risk management process and efforts. The measures include the following main
components: (i) enhancing data security technical measures by the introduction of an extended verification (EV) SSL certificate at the
user information security technology implementation level, offering strong encryption technology and extended verification function,
and providing security guarantee for online transactions; (ii) improving the technical level protection and the monitoring mechanism
for data use, and for the data modules related to user information in the e-commerce platform system, using MD5 irreversible encryption
for storage and display of information security sensitive fields; (iii) developing a complete personal information operating process
and system and designating personnel for information security; (iv) developing a user information collection, storage and user rules
and privacy agreement, following the “inform + express consent” model, informing users of the purpose, method and scope of
information collection and use, as well as the channels for inquiring and correcting inaccuracies in information and data; (v) conducting
assessments on technology, operational risks and system common issues, and data security governance; (vi) engaging a data security service
organization to conduct an annual data security assessment and providing disclosure and updates to all stakeholders; (vii) establishing
an emergency plan for personal information security incidents, which includes an emergency response mechanism for security incidents,
incident impact assessment and mitigation measures, and emergency response training and drills; (viii) providing periodic training to
employees; and (ix) promoting consumer data protection awareness. We have implemented and are in the process of implementing these measures.
Governance
The
Company’s board of directors has oversight responsibility for the Company’s overall risk management, including cybersecurity
risks, and has not delegated oversight authority for cybersecurity risks to any committee. Our management, led by our Chief Executive
Officer and Chief Financial Officer, is responsible for assessing cybersecurity risks and supervising relevant personnel with respect
to our efforts and measures with the aim we have an appropriate cybersecurity strategy to assess and manage those risks, including responding
to attacks or breaches. Our Chief Executive Officer and Chief Financial Officer meet periodically with the individuals charged with the
day-to-day operations supervisory responsibilities including IT operations and infrastructure regarding cybersecurity to review and assess
potential issues and any changes needed to be made related to our information technology system and cybersecurity measures. Cybersecurity
awareness trainings are provided for all employees.
In
fiscal year 2025, we did not identify any cybersecurity threats that have materially affected or are reasonably likely to materially
affect our business strategy, results of operations, or financial condition. However, we face potential cybersecurity threats that, if
realized, would materially affect us. These threats include but are not limited to ransomware and malware attacks, and compromised business
email and other social engineering threats. Our suppliers, customers, contractors and business partners also face similar cybersecurity
risks, which could have an adverse impact on our business.
ITEM
2. PROPERTIES
Our
mailing address and global operations are situated at No. 3 & 5, Jalan Hi Tech 7/7, Kawasan Perindustrian Hi Tech 7, 43500 Semenyih,
Selangor, Malaysia.
ITEM
3. LEGAL PROCEEDINGS
None
ITEM
4. MINE SAFETY DISCLOSURES
Not
applicable.
14
PART
II
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.