{"url_path":"/sec/alzn/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C ****CYBERSECURITY**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-07-22","source_url":"https://www.sec.gov/Archives/edgar/data/1677077/0001214659-26-008832-index.html","accession_number":"0001214659-26-008832","cik":"0001677077","ticker":"ALZN","issuer_name":"Alzamend Neuro, Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1677077/0001214659-26-008832-index.html","primary_entity_key":"0001677077","primary_entity_name":"Alzamend Neuro, Inc."},"word_count":771,"has_tables":true,"body_markdown":"**ITEM 1C.****CYBERSECURITY**\n\n \n\n**Information Security Program**\n\n \n\nThe mission of our information\nsecurity program is to design, implement, and maintain a comprehensive information security program that protects our systems, services,\nand data against unauthorized access, disclosure, modification, damage, and loss. Our information security program is comprised of internal\nand external security and technology professionals who work collaboratively to identify, assess, manage, and mitigate cybersecurity risks\nand threats across the Company and third-party contractors.\n\n \n\nWe recognize the importance\nof effectively managing material risks associated with cybersecurity threats, as defined in Item 106(a) of Regulation S-K. Our risk management\nprogram integrates the monitoring and management of these risks and threats and is informed by applicable laws, regulations, industry\nstandards, and best practices. We continue to invest in information security resources to mature, expand, and adapt our capabilities to\naddress emerging cybersecurity risks and threats.\n\n \n\nOur information security organization\nis committed to maintaining a robust and resilient security posture that enables us to protect our assets, maintain our stakeholders'\ntrust, and support our business's overall success.\n\n \n\n**Cybersecurity Risk Management and Strategy**\n\n \n\nOur cybersecurity risk management\nand strategy are integral components of our comprehensive information security program. They guide our continuous efforts to evaluate\nand improve the confidentiality, integrity, and availability of our critical systems, data, and operations.\n\n \n\nWe have adopted an Information\nSecurity Policy (the “Info-Sec Policy”) and an Incident Response Plan (the “Response Plan”) that establish\nadministrative, physical, and technical controls and procedures to protect sensitive data throughout the Company. These policies also\noutline processes to assess, identify, manage, and report cybersecurity risks and incidents. The Info-Sec Policy applies to all persons\nworking for the Company and any third parties working with us in any capacity.\n\n \n\nOur approach to controls and\nrisk management is informed by applicable laws and regulations, as well as industry standards and best practices. These serve as a guide\nto help us identify, assess, and manage cybersecurity controls and risks relevant to our business.\n\n \n\nOur cybersecurity risk management\nprogram includes:\n\n \n\n1.Identifying cybersecurity risks that could impact our facilities, third-party vendors/partners, operations,\ncritical systems, information, and broader enterprise information technology environment. Risks are informed by threat intelligence, current\nand historical adversarial activity, and industry-specific threats;\n\n \n\n2.Performing cybersecurity risk assessments to evaluate our readiness if the risks were to materialize;\n\n \n\n3.Ensuring risk is addressed and tracking any necessary remediation through an action plan;\n\n \n\n4.Analyzing all third-party vendors for compliance with our internal Info-Sec Policy to assess potential\nrisks associated with their security controls. We generally require third parties to maintain security controls, notify us promptly of\nany data breach or cybersecurity incident that may impact our data, and provide written assurance of corrective actions; and\n\n \n\n5.Engaging and utilizing a comprehensive suite of security solutions, including enterprise mobility management,\nendpoint protection, secure file transfer, and security information and event management to monitor and actively respond to cybersecurity\nthreats. These solutions work together to secure our endpoints, protect against malware, ensure the safe transfer of files, and provide\nour cybersecurity team with the functionality to build alerts on specific use cases that are important and unique to our business.\n\n \n\n - 43 - \n\n \n\n \n\n**Cybersecurity Governance**\n\n \n\nOur Board oversees cybersecurity\nrisk as part of its overall risk oversight function. We utilize resources from Hyperscale Data, Inc. (“HDI”) to act as our\ninformation technology department (the “IT Department”), which functions as our Information Security Advisory Team. The IT\nDepartment is responsible for managing our information security program and implementing cybersecurity risk management practices.\n\n \n\nThe IT Department collaborates\nwith various stakeholders across the organization to identify, assess, and mitigate cybersecurity risks. They regularly monitor and adapt\nour information security program to address the evolving threat landscape.\n\n \n\nIn the event of a cybersecurity\nincident, the IT Department promptly reports the matter to our Chief Financial Officer. The Chief Financial Officer is responsible for\nassessing the severity and potential impact of the incident and determining the appropriate course of action. The Chief Financial Officer\nkeeps the Board informed of significant cybersecurity incidents and provides updates on the overall status of our cybersecurity program\nas needed.\n\n \n\nThis governance structure\nensures that cybersecurity risks are effectively managed by the IT Department, with oversight from the Chief Financial Officer and the\nBoard. It maintains clear lines of communication and accountability, enabling timely decision-making and response to cybersecurity matters.\n\n \n\nDuring fiscal 2026, we did\nnot identify any cybersecurity threats that have materially affected or are reasonably likely to materially affect our business strategy,\nresults of operations or financial condition. However, despite our efforts, we may not successfully eliminate all risks from cybersecurity\nthreats and can provide no assurance that undetected cybersecurity incidents have not occurred."}