{"url_path":"/sec/cik-0001566243/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C CYBERSECURITY RISK MANAGEMENT AND STRATEGY**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-10","source_url":"https://www.sec.gov/Archives/edgar/data/1566243/0001753926-26-000995-index.html","accession_number":"0001753926-26-000995","cik":"0001566243","ticker":null,"issuer_name":"Arax Holdings Corp","edgar_url":"https://www.sec.gov/Archives/edgar/data/1566243/0001753926-26-000995-index.html","primary_entity_key":"0001566243","primary_entity_name":"Arax Holdings Corp"},"word_count":323,"has_tables":true,"body_markdown":"**ITEM\n1C. CYBERSECURITY RISK MANAGEMENT AND STRATEGY**\n\n \n\n●Arax\nHoldings Corp. recognizes that cybersecurity threats pose risks to our operations, particularly given our focus on blockchain\ntechnology, digital asset infrastructure, and software development. We have implemented a cybersecurity risk management program\ndesigned to identify, assess, and manage material risks from cybersecurity threats. This program is integrated into our overall\nenterprise risk management framework and includes the following key elements:\n\n●Regular\nrisk assessments conducted by internal personnel and as needed, third-party specialists to evaluate vulnerabilities in our information\nsystems, networks, and software platforms. Technical safeguards such as firewalls, encryption, multi-factor authentication, endpoint\nprotection, and secure development practices aligned with industry standards. Employee training on cybersecurity awareness and\nincident response protocols. Monitoring of threat intelligence and periodic testing of security controls.\n\n●Engagement\nof qualified third-party providers for specialized security services, including penetration testing and vulnerability scanning.\nWhile we maintain cyber insurance as part of our overall risk mitigation strategy, we continuously evaluate and update our cybersecurity\nmeasures in response to evolving threats. To date, we have not experienced any cybersecurity incidents that have materially affected\nour business strategy, results of operations, or financial condition. However, there can be no assurance that future threats will\nnot have a material impact.\n\n●Governance\n\n●Our\nBoard of Directors oversees cybersecurity risk as part of its broader enterprise risk oversight responsibilities. Management provides\nperiodic updates to the Board on cybersecurity matters, including significant risks, mitigation efforts, and any incidents.\n\n●Day-to-day\nmanagement of cybersecurity risks is led by our Chief Technology Officer, who has substantial experience in blockchain and information\nsecurity, supported by our technical team. Management reports material cybersecurity developments to the Board as appropriate.\n\n●We\nengage qualified external cybersecurity consultants when needed to supplement internal capabilities and ensure independent assessment\nof our program.\n\n●This\ndisclosure complies with Item 106 of Regulation S-K. We continue to evaluate and enhance our cybersecurity practices in line with\nregulatory requirements and industry best practices."}