5 unchanged sentences
risk is the risk of harm or loss resulting from misuse or abuse of technology or the unauthorized disclosure of data.
−Removed: Cybersecurity risk is an important and evolving focus for the Company, due to its small size and limited resources, the Company is unable
−Removed: to devote any internal resources to cybersecurity and relies entirely on its vendors, for email, e-commerce, order management, purchasing/direct
−Removed: shipping, financials, inventory, warranty and returns and remote access, for assessing, identifying and managing material risks from
−Removed: cybersecurity threats whose collective security efforts are designed to protect against, among other things, cybersecurity attacks that
−Removed: can result in unauthorized access to confidential information, the destruction of data, disruptions to or degradations of service, the
−Removed: sabotaging of systems or other damage.
−Removed: Company’s vendors have implemented measures and controls reasonably designed to address cyber attacks, including enhanced threat
−Removed: ERP software is made accessible, controlled and monitored through an extensive list of policies and procedures.
−Removed: These include protocols
−Removed: dictating acceptable use, management of confidential data, application monitoring, secure access policies and application access strategies.
−Removed: Operating System updates and security patches as well as application software updates released by the vendors are reviewed, tested and
−Removed: implemented on a regular basis.
−Removed: Data backup is achieved through hourly incremental backups with replications to off-site locations.
−Removed: access is secured through industry standard encryption and supports accessibility rules including two factor authentication and VPNs.
−Removed: data center where our ERP software is hosted achieves some of the highest compliance certifications including:
−Removed: Certification for information security management systems.
−Removed: Compliance with the AICPA’s Trust Service Criteria, demonstrating security, availability, processing integrity, confidentiality,
−Removed: and privacy controls.
−Removed: Compliance with the Health Insurance Portability and Accountability Act for handling protected health information (PHI).
−Removed: Compliance with the General Data Protection Regulation for protecting the privacy and rights of EU citizens’ data.
−Removed: Compliance with the Payment Card Industry Data Security Standard for secure handling of payment card data.
−Removed: addition, the data center where our ERP software is hosted achieves cybersecurity compliance through a multifaceted approach that encompasses
−Removed: various security measures and controls including:
−Removed: The data centers are highly secure facilities with strict access controls, surveillance systems, and perimeter fencing.
−Removed: Access to data centers is limited to authorized personnel only.
−Removed: Advanced network security measures are implemented to protect against unauthorized access and malicious activities.
−Removed: includes firewalls, DDoS (Distributed Denial of Service) protection, and encryption for data in transit.
−Removed: Data is encrypted both at rest and in transit using industry-standard encryption algorithms.
−Removed: This ensures that data remains
−Removed: secure even if it’s intercepted or compromised.
−Removed: Identity and Access Management (IAM) allows us to manage access to our resources securely.
−Removed: IAM enables granular control
−Removed: over permissions, roles, and access policies, reducing the risk of unauthorized access.
−Removed: Monitoring and Logging.
−Removed: The data centers support robust monitoring and logging capabilities, allowing us to track and analyze security-related
−Removed: events in real-time.
−Removed: This includes audit logging, activity tracking, and integration with security information and event management
−Removed: (SIEM) systems.
−Removed: The data centers have established incident response procedures to detect, investigate, and mitigate security incidents
−Removed: This includes a dedicated security incident response team (SIRT) that coordinates response efforts and communicates with
−Removed: Audits and Reviews.
−Removed: The data centers undergo regular third-party audits and reviews to validate its security controls and compliance
−Removed: with industry standards and regulations.
−Removed: These audits provide independent verification of the security posture and help build trust
−Removed: with customers.
−Removed: parties with which the Company does business, that facilitate the Company’s business activities (e.g., vendors, supply chain, exchanges,
−Removed: distributors and service providers) or that the Company has acquired are also sources of cybersecurity risk to the Company.
−Removed: incidents such as system breakdowns or failures, misconduct by the employees of such parties, or cyber-attacks, including ransomware
−Removed: and supply-chain compromises, could have a material adverse effect on the Company, including in circumstances in which an affected third
−Removed: party is unable to deliver a product or service to the Company or where the incident delivers compromised software to the Company or
−Removed: results in lost or compromised information of the Company or its clients or customers.
−Removed: The Company does not have processes in place to
−Removed: oversee and identify risks from cybersecurity threats associated with its use of third-party service providers and vendors.
−Removed: are also sources of cybersecurity risk to the Company and its information assets, particularly when their activities and systems are
−Removed: beyond the Company’s own security and control systems.
−Removed: from cybersecurity threats, including any previous cybersecurity events, to-date have not materially affected and are not likely to materially
−Removed: affect the Company or its business strategy, results of operations or financial condition.
−Removed: Notwithstanding the approach that the Company
−Removed: takes to address cybersecurity risk via its vendors, the Company may not be successful in preventing or mitigating a future cybersecurity
−Removed: incident that could have a material adverse effect on the Company or its business strategy, results of operations or financial condition.
−Removed: Company has not and, for the foreseeable future, does not intend to engage third-party assessors or auditing firms with industry-recognized
−Removed: expertise on cybersecurity matters to review specific aspects of the Company’s or its vendors’ cybersecurity risk management
−Removed: framework, processes and controls.
+Added: preserve the confidentiality, integrity , and availability of our information systems, and to safeguard our assets, data, intellectual
+Added: property, and network infrastructure, while meeting regulatory requirements, it is crucial to effectively manage cybersecurity risk.
+Added: To achieve this, we have implemented a comprehensive cybersecurity risk management framework, which is integrated into our overall enterprise
+Added: risk management system and processes and is internally managed.
+Added: IT staff is tasked with assessing, identifying, and managing cybersecurity threats and is responsible for:
+Added: assessments designed to help identify material cybersecurity risks to our critical systems, information, products, and services and
+Added: to our broader enterprise IT environment;
+Added: of risk-based action plans to manage identified vulnerabilities and implementation of new protocols and infrastructure improvements;
+Added: cybersecurity
+Added: incident investigations;
+Added: threats to sensitive data and unauthorized access to our systems;
+Added: access control measures to critical IT systems, equipment, and devices, which measures are designed to prevent unauthorized users,
+Added: processes, and devices from accessing IT systems and data;
+Added: and executing protocols to ensure that information regarding cybersecurity incidents is shared promptly with the Board, as appropriate,
+Added: to allow for risk and materiality assessments and to consider disclosure and notice requirements;
+Added: and implementing training on cybersecurity, information security, and threat awareness.
+Added: were no cybersecurity incidents during the financial year ended April 30, 2025, that resulted in an interruption to our operations or
+Added: known losses of any critical data or that otherwise had a material impact on our business strategy, financial condition, or results of
+Added: However, the scope and impact of any future incident cannot be predicted.
+Added: See Item 1A, “Risk Factors,” for more
+Added: information on how material cybersecurity attacks might impact our business.
and oversight
−Removed: Company’s board of directors has not to-date exercised any oversight of risks from cybersecurity threats and none of its committees
−Removed: is tasked with or responsible for oversight of risks from cybersecurity threats.
−Removed: The Company’s board of directors will review its
−Removed: cybersecurity oversight going forward on a periodic basis and, if the Company makes adequate resources available, effect changes therein.
−Removed: of the date of this report, we do not own any properties.
−Removed: Our principal office is located at 2709 N.
−Removed: Rolling Road, Suite 138, Windsor
−Removed: Mill, Maryland 21244.
−Removed: We entered into a lease for use of office space at this location effective September 1, 2019.
−Removed: This location is
−Removed: owned by Zeek Logistics.
−Removed: We do not pay any rent or fee to use this location.
+Added: Board acknowledges the significance of robust cybersecurity management programs and actively participates in overseeing and reviewing
+Added: our cybersecurity risk profile and exposures.
+Added: Our Board receives prompt and timely information regarding any significant cybersecurity
+Added: incidents, as well as ongoing updates regarding any such incidents.
+Added: Furthermore, in the event of any significant updates or adjustments
+Added: to our cybersecurity related policies, our IT staff will present them to the Board for their review and approval.
+Added: IT staff are responsible for the daily management of our cybersecurity efforts.
+Added: This includes updates and refinement of cybersecurity
+Added: policies, execution and management of cybersecurity measures, and the preparation of regular reports on cybersecurity execution.
+Added: primary focus is to consistently update our cybersecurity programs and mitigation strategies, ensuring they align with industry best
+Added: practices and procedures.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.