{"url_path":"/sec/cik-0001695963/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C Cybersecurity**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-01","source_url":"https://www.sec.gov/Archives/edgar/data/1695963/0001214659-26-006969-index.html","accession_number":"0001214659-26-006969","cik":"0001695963","ticker":null,"issuer_name":"Korth Direct Mortgage Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1695963/0001214659-26-006969-index.html","primary_entity_key":"0001695963","primary_entity_name":"Korth Direct Mortgage Inc."},"word_count":776,"has_tables":true,"body_markdown":"**Item 1C. Cybersecurity**\n\n** **\n\nOur business is highly dependent on information\ntechnology. In the ordinary course of our business, we store sensitive data, including our proprietary business information and that of\nour business partners, and non-public personally identifiable information of mortgage borrowers, on our networks. The secure maintenance,\nprocessing and transmission of this information is critical to our operations. Computer malware, viruses, ransomware and phishing attacks\nremain widespread and are increasingly sophisticated. We are frequently the target of attempted cyber threats, as are many other organizations\nwithin the financial servicing industry. We continuously monitor and develop our information technology networks and infrastructure to\nhelp prevent, detect, address and mitigate the risk of unauthorized access, misuse, computer viruses, and other events that could have\na security impact. Despite these security measures, our information technology and infrastructure may be vulnerable to attacks by hackers\nor breached due to employee error, malfeasance or other disruptions. Any such breach could compromise our networks and the information\nstored there could be accessed, publicly disclosed, lost or stolen. Such access, disclosure or other loss of information could result\nin legal claims or proceedings, liability under laws that protect the privacy of personal information, regulatory penalties, disruption\nto our operations or trading activities or damage to our reputation, all of which could have a material adverse effect on our business,\nresults of operations and financial condition. For additional information on these risks, see Item 1A, “Risk Factors”.\n\n \n\n 14 \n\n [Table of Contents](#toc)\n\n \n\nWe recognize the importance of protecting our\ninformation and our information technology systems, and assessing, identifying and managing cybersecurity-related risks have been integrated\ninto our risk management processes. We focus on information technology and cybersecurity measures at both an enterprise-wide operational\nlevel and an individual employee level. We have in place various methods and levels of information technology and cybersecurity measures\nwhich are aimed at protecting our information and information technology systems to help secure long-term value for our stockholders and\nother stakeholders. By way of example, these measures include the following:\n\n** **\n\n1.**Industry-Standard Security Frameworks:** We adhere to recognized security frameworks, including the\n**National Institute of Standards and Technology (NIST)**, and employ controls such as antivirus and anti-malware protections, multi-factor\nauthentication (MFA), complex password policies, patch management, email security solutions, and firewall protections.\n\n2.**Threat Detection and Risk Management:** We leverage advanced security technologies, including **endpoint\ndetection and response (EDR), security information and event management (SIEM), and vulnerability management tools** to proactively\nidentify and mitigate risks.\n\n3.**Incident Response Protocols:** We maintain a **formal cybersecurity incident response plan** that\nensures a structured and comprehensive response to security incidents. This plan involves senior executives, external legal and forensic\nspecialists, and includes an active **incident response retainer with our third-party Security Operations Center (SOC)**.\n\n4.**Continuous Security Assessments:** We conduct **regular cybersecurity audits, third-party risk assessments,\npenetration tests, and targeted control evaluations** to identify and remediate potential vulnerabilities. Our security program is continuously\nmonitored and assessed by an external **24/7 Security Operations Center (SOC)**.\n\n5.**Disaster Recovery and Data Resiliency:** We have robust **backup and disaster recovery processes**\nin place to ensure business continuity in the event of a security incident or system failure.\n\n6.**Employee Awareness and Training:** We implement **comprehensive cybersecurity and data privacy training\nprograms** to enhance employee awareness of cyber risks and reinforce secure operational practices.\n\n \n\nAs part of our commitment to information security and data protection,\nwe have achieved SOC 2 Type II certification in 2025 and 2024. This certification, issued by an independent third-party auditor, verifies\nthat our security controls meet the American Institute of Certified Public Accountants (AICPA) Trust Services Criteria for security, availability,\nprocessing integrity, confidentiality, and privacy. The SOC 2 Type II audit evaluates the effectiveness of our cybersecurity and IT controls\nover an extended period, further validating our commitment to safeguarding sensitive information and maintaining a secure operational\nenvironment.\n\n \n\nOur executive team is responsible for overseeing\nmatters relating to our information technology and cybersecurity risk exposures and the steps our Company takes to monitor and mitigate\nthese risks. The executive team is briefed quarterly or as needed by senior management and the Chief Information Security Officer, or\nCISO, on cybersecurity matters, or more frequently as the circumstances require. Our Vice President of Technology, who serves as our CISO,\noversees data privacy, information technology, and cybersecurity matters. Our CISO has extensive information technology and program management\nexperience, has served in this role for the Company since 2022 and has supported the Company’s information security function since\n2017.\n\n \n\nTo date, we believe that the risks from identified\ncybersecurity threats, have not materially affected and are not reasonably likely to materially affect us, including our business strategy,\nresults of operations or financial condition."}