Unresolved Staff Comments
+Added: SMCI | 2026 Form 10-K | 34
Cybersecurity
3 unchanged sentences
Our information security management program seeks to follow processes set forth in recognized industry standards, and we evaluate and evolve our security measures as appropriate.
−Removed: We maintain a cybersecurity incident response plan that we practice and update as needed.
+Added: The incident response plan is periodically tested through tabletop exercises, simulations, and management and operational reviews, and is updated based on lessons learned, threat intelligence, and changes in the Company's operating environment.
The identification, assessment and management of cybersecurity risk is integrated into our overall enterprise risk management program that is ultimately overseen by the Board.
1 unchanged sentence
We also use third parties to assist our risk management processes by conducting security assessments.
−Removed: SMCI | 2025 Form 10-K | 34
+Added: Third-party risk assessments are prioritized based on the nature of services provided, access to systems or data, criticality to operations, and applicable regulatory obligations.
We also have a vendor risk assessment process to oversee and identify risks from cybersecurity threats associated with our use of third-party service providers.
1 unchanged sentence
We also audit cybersecurity practices of certain third-party service providers, and take steps designed to ensure that such vendors have implemented data privacy and security controls that help mitigate the cybersecurity risks associated with these vendors, depending on the nature and sensitivity of the supplier and data it processes on our behalf.
−Removed: We routinely assess our high-risk suppliers’ conformance to industry standards and evaluate them for additional information, product, and physical security requirements.
−Removed: We employ a number of protective measures, including firewalls, endpoint detection and response technologies, regular annual training of employees with respect to cybersecurity and testing employee competence with anti-phishing policies followed up by additional remedial training as needed.
−Removed: While there have been cyber incidents in the past, none of these incidents, individually or in aggregate, had a material adverse effect on our business strategy, operations, or financial conditions.
+Added: We routinely assess our high-risk suppliers’ conformance to industry standards (e.g., ISO 27001, ISO 28001, and C-TPAT), and evaluate them for additional information, product, and physical security requirements.
+Added: Additional cybersecurity measures include security monitoring, vulnerability and patch management processes, identity and access controls, network security controls, data protection technologies, threat intelligence activities, and incident detection and response capabilities.
+Added: As of the date of this filing, we have not identified any cybersecurity threats, including as a result of prior incidents, that have materially affected or are reasonably likely to materially affect the Company, including our business strategy, results of operations, or financial conditions.
Refer to “Risk Factors” in Item 1A of this Form 10-K for additional information about cybersecurity-related risks.
1 unchanged sentence
The Audit Committee also reviews the adequacy and effectiveness of our information security policies and practices and the internal controls regarding information security risks.
−Removed: The Audit Committee and the Board receive regular information security updates relating to cybersecurity risk from management, including from our Director of Information Security.
−Removed: Cybersecurity risk is primarily managed by our Directors of Information Security and Information Technology .
+Added: The Audit Committee receives periodic updates regarding cybersecurity risks, threat trends, significant incidents, third-party risks, remediation activities, and the status of key cybersecurity initiatives.
+Added: Our cybersecurity efforts are managed by a team of executive cybersecurity, IT, engineering, and operations professionals, including senior information security and IT leadership (comprised of the Senior Director of Information Security and Senior Director of IT Security) who possess extensive experience in cybersecurity, incident response, risk management, and security operations.
These individuals have decades of experience in managing cybersecurity risk for public companies.
−Removed: Additionally, we have established a cross-functional Cybersecurity Committee, consisting of executive-level leadership, including representatives from Finance, IT, Legal, and other teams, that meets periodically to review cybersecurity risks, incidents, and assess emerging threats.
+Added: Additionally, we have established a cross-functional Cybersecurity Committee, consisting of executive-level leadership, including representatives from Finance, IT, Legal, and other teams, that meets regularly to review cybersecurity risks, incidents, and assess emerging threats.
The Cybersecurity Committee is also informed of our responses to such risks, incidents and threats.
+Added: The Company continuously evaluates emerging cybersecurity risks, including risks associated with artificial intelligence technologies, enhanced social engineering techniques, and evolving threat actor capabilities.
+Added: SMCI | 2026 Form 10-K | 35
Our cybersecurity incident response plan also contains mechanisms to notify executive management of cybersecurity incidents.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.