{"url_path":"/sec/btcy/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C CYBERSECURITY**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-07-14","source_url":"https://www.sec.gov/Archives/edgar/data/1630113/0001493152-26-033207-index.html","accession_number":"0001493152-26-033207","cik":"0001630113","ticker":"BTCY","issuer_name":"BIOTRICITY INC.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1630113/0001493152-26-033207-index.html","primary_entity_key":"0001630113","primary_entity_name":"BIOTRICITY INC."},"word_count":572,"has_tables":true,"body_markdown":"**ITEM\n1C. CYBERSECURITY**\n\n \n\nWe\nhave established policies and processes for assessing, identifying, and managing material risk from cybersecurity threats, and have integrated\nthese processes into our overall risk management systems and processes. We routinely assess material risks from cybersecurity threats,\nincluding any potential unauthorized occurrence on or conducted through our information systems that may result in adverse effects on\nthe confidentiality, integrity, or availability of our information systems or any information residing therein.\n\n \n\nWe\nconduct periodic risk assessments to identify cybersecurity threats, as well as assessments in the event of a material change in our\nbusiness practices that may affect information systems that are vulnerable to such cybersecurity threats. These risk assessments include\nidentification of reasonably foreseeable internal and external risks, the likelihood and potential damage that could result from such\nrisks, and the sufficiency of existing policies, procedures, systems, and safeguards in place to manage such risks.\n\n \n\n32\n\n \n\n \n\nFollowing\nthese risk assessments, we re-design, implement, and maintain reasonable safeguards to minimize identified risks; reasonably address\nany identified gaps in existing safeguards; and regularly monitor the effectiveness of our safeguards. Primary responsibility for assessing,\nmonitoring and managing our cybersecurity risks rests with Vice President of Technology, who reports to our Chief Executive Officer,\nto manage the risk assessment and mitigation process.\n\n \n\nWe\nengage consultants, or other third parties in connection with our risk assessment processes. These service providers assist us to design\nand implement our cybersecurity policies and procedures, as well as to monitor and test our safeguards. We require each third-party service\nprovider to certify that it has the ability to implement and maintain appropriate security measures, consistent with all applicable laws,\nto implement and maintain reasonable security measures in connection with their work with us, and to promptly report any suspected breach\nof its security measures that may affect our company.\n\n \n\nWe\nhave not encountered cybersecurity challenges that have materially impaired our operations or financial standing.\n\n \n\n**Governance**\n\n \n\nOur\nboard of directors addresses the Company’s cybersecurity risk management as part of its general oversight function. The board of\ndirectors’ audit committee is responsible for overseeing Company’s cybersecurity risk management processes, including oversight\nand mitigation of risks from cybersecurity threats.\n\n \n\nOur\ncybersecurity risk assessment and management processes are implemented and maintained by certain Company management, including the information\ntechnology team at the direction of our Vice President of Technology. Our executive team including our Chief Executive Officer, and Chief\nFinancial Officer are responsible for hiring appropriate personnel, helping to integrate cybersecurity risk considerations into the Company’s\noverall risk management strategy, and communicating key priorities to relevant personnel. This executive team is responsible for approving\nbudgets, helping prepare for cybersecurity incidents, approving cybersecurity processes, and reviewing security assessments and other\nsecurity-related reports.\n\n \n\nOur\ncybersecurity incident response and vulnerability management policies are designed to escalate certain cybersecurity incidents to members\nof management depending on the circumstances, including our Chief Executive Officer, and Chief Financial Officer. In addition, the Company’s\nincident response and vulnerability management policies include reporting to the audit committee of the board of directors for certain\ncybersecurity incidents including significant breaches to the Company’s networks or systems. The audit committee receives regular\nreports from the information technology team concerning the Company’s significant cybersecurity threats and risk and the processes\nthe Company has implemented to address them. The audit committee also has access to the Vice President of Technology, to receive various\nreports, summaries or presentations related to cybersecurity threats, risk and mitigation."}