{"url_path":"/sec/airi/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C CYBERSECURITY**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-03-27","source_url":"https://www.sec.gov/Archives/edgar/data/1009891/0001213900-26-035731-index.html","accession_number":"0001213900-26-035731","cik":"0001009891","ticker":"AIRI","issuer_name":"AIR INDUSTRIES GROUP","edgar_url":"https://www.sec.gov/Archives/edgar/data/1009891/0001213900-26-035731-index.html","primary_entity_key":"0001009891","primary_entity_name":"AIR INDUSTRIES GROUP"},"word_count":412,"has_tables":true,"body_markdown":"** **\n\n**ITEM 1C. CYBERSECURITY**\n\n \n\nWe regularly review our cybersecurity defenses\nto assess our vulnerability to cybersecurity attacks from viruses, malware and more sophisticated and targeted cyber-related attacks such\nas hackers looking to demand ransomware or access our systems to obtain information and data, as well as our vulnerability to cybersecurity\nfailures resulting from human error and technological errors.  We rely upon internal information technology (“IT”) personnel\nworking in conjunction with specialized outside security consultants on a day-to-day basis to conduct reviews and upgrade our systems\nwhen determined to be necessary.\n\n \n\nOur overall strategy in combatting cybersecurity\nrisks includes a variety of measures, including:\n\n \n\n \n●\nthe use of antivirus software, virtual private networks, email security, as well as other software and system-wide measures such as multi-factor authorization to prevent and detect data intrusions;\n\n \n\n \n●\ndeployment of updates and patches as they become available from our software suppliers and consultants and maintaining the current versions of major software to reduce the exposure to vulnerabilities;\n\n \n\n \n●\nthe use of third-party services to conduct mandatory online training for all employees regarding identifying and avoiding cyber-security risks;\n\n \n\n \n●\nthe review of the security procedures used by third parties that may host or otherwise have access to our systems;\n\n \n\n \n●\nthe deployment of third-party cybersecurity experts to perform penetration testing on our internal and external networks and systems in an effort to identify potential vulnerabilities; and\n\n \n\n \n●\nconsideration of the cybersecurity risks posed by interacting with current and potential third-party service providers, suppliers and customers.\n\n \n\nWe are not aware of any vulnerability inherent in our systems or malware\nembedded in our systems that are likely to materially affect, or are reasonably likely to materially affect, our operations. We are in\nthe process of implementing additional training and are in the process of engaging third parties to perform various testing as indicated\nabove.\n\n \n\nDay-to-day management of cybersecurity threats\nis conducted by our IT department in conjunction with outside service providers, which is charged with identifying and reporting threats\nto senior management. On a quarterly basis, cybersecurity is reviewed by our Chief Executive Officer and Chief Financial Officer, who\nare expected to report to the Audit Committee.\n\n \n\n**Board Oversight**\n\n \n\nThe Audit Committee of our Board of Directors,\nwhich is composed of all non-employee directors, is responsible for oversight of our efforts to eliminate cybersecurity risks. The Audit\nCommittee meets regularly with our Chief Executive Officer and Chief Financial Officer and, in turn, reports its findings to the Board\nof Directors.\n\n** **\n\n24"}