{"url_path":"/sec/cik-0001138724/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C CYBERSECURITY","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-08-11","source_url":"https://www.sec.gov/Archives/edgar/data/1138724/0001493152-26-037140-index.html","accession_number":"0001493152-26-037140","cik":"0001138724","ticker":null,"issuer_name":"Global Arena Holding, Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1138724/0001493152-26-037140-index.html","primary_entity_key":"0001138724","primary_entity_name":"Global Arena Holding, Inc."},"word_count":274,"has_tables":true,"body_markdown":"ITEM\n1C. CYBERSECURITY\n\n \n\nRisk\nManagement and Strategy\n\n \n\nGES\nrelies heavily on information technology systems to operate our election registration, tabulation and online voting business. GES in\nadministering elections manages proprietary and personal data list from its clients. Despite our ongoing investments in cybersecurity\nmeasures, we are subject to increasing risks associated with cyberattacks, ransomware, phishing, and other malicious activities.\n\n \n\nInadequate\naccount security or organizational security practices, including those of companies of third parties GES utilizes, may result in unauthorized\naccess to our systems and data, and cause irrevocable damage to the Company.\n\n \n\nCyberthreats\nin the election industry are constantly evolving and becoming increasingly difficult in detecting and successfully defending against\nthem. Threat actors, including individual and groups of hackers and sophisticated organizations, including nation-states, state-sponsored\norganizations, or cybercriminal groups, can pose a threat to GES customers and GES election software infrastructure. Threat actors may\nalso utilize emerging technologies, such as AI and machine learning. Our current capabilities may not detect certain vulnerabilities\nor new attack methods.\n\n \n\nA\nsuccessful cyber intrusion could result in significant business disruption, reputational damage, regulatory penalties, and financial\nloss. GES maintains cybersecurity insurance, employs robust monitoring tools, and conducts employee training, but these safeguards may\nnot prevent all incidents. Failure to effectively prevent or respond to such incidents could materially and adversely affect the Company\nand businesses operations and financial condition.\n\n \n\nGovernance\n\n \n\nOur\nBoard of Directors considers cybersecurity risk as part of its oversight function. Management is responsible for assessing and managing\nour material risks from cybersecurity threats. Management has primary responsibility for overall cybersecurity risk management and is\nresponsible for updating the Board, as necessary regarding significant cybersecurity incidents."}