{"url_path":"/sec/cik-0002071489/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C CYBERSECURITY**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-25","source_url":"https://www.sec.gov/Archives/edgar/data/2071489/0001493152-26-030051-index.html","accession_number":"0001493152-26-030051","cik":"0002071489","ticker":null,"issuer_name":"Yellowstone Group Ltd.","edgar_url":"https://www.sec.gov/Archives/edgar/data/2071489/0001493152-26-030051-index.html","primary_entity_key":"0002071489","primary_entity_name":"Yellowstone Group Ltd."},"word_count":362,"has_tables":true,"body_markdown":"**ITEM\n1C. CYBERSECURITY**\n\n \n\n**Risk\nmanagement and strategy**\n\n \n\nWe\nrecognize the critical importance of developing, implementing, and maintaining robust cybersecurity measures to safeguard our information\nsystems and protect the confidentiality, integrity, and availability of our data.\n\n \n\n**Managing\nMaterial Risks & Integrated Overall Risk Management**\n\n \n\nWe\nhave strategically integrated cybersecurity risk management into our broader risk management framework to promote a company-wide culture\nof cybersecurity risk management. This integration ensures that cybersecurity considerations are an integral part of our decision-making\nprocesses at every level. Our management team continuously evaluates and addresses cybersecurity risks in alignment with our business\nobjectives and operational needs.\n\n \n\n**Oversee\nThird-Party Risk**\n\n \n\nBecause\nwe are aware of the risks associated with third-party service providers, we have implemented stringent processes to oversee and manage\nthese risks. We conduct thorough security assessments of all third-party providers before engagement and maintain ongoing monitoring\nto ensure compliance with our cybersecurity standards. The monitoring includes annual assessments of the system and organization controls\n(SOC) reports of our providers and implementing complementary controls. This approach is designed to mitigate risks related to data breaches\nor other security incidents originating from third parties.\n\n \n\n**Risks\nfrom Cybersecurity Threats**\n\n \n\nWe\nhave not encountered cybersecurity challenges that have materially impaired our operations or financial standing during the financial\nyear ended March 31, 2026. We will continue to monitor and assess our cybersecurity risk management program as well as invest in and\nseek to improve such systems and processes as appropriate. If we were to experience a material cybersecurity incident in the future,\nsuch an incident may have a material effect, including on our operations, business strategy, operating results, or financial condition.\nFor more information regarding cybersecurity risks that we face and potential impacts on our business related thereto, see the section\ntitled “*Risk Factors*” in Part I, Item 1A of this Annual Report on Form 10-K.\n\n \n\n9\n\n \n\n \n\n**Governance**\n\n \n\nOur\nboard of directors is responsible for monitoring and assessing strategic risk exposure.\n\n \n\nOur\ncybersecurity coordinator is responsible for assessing and managing our material risks from cybersecurity threat and reports to our CEO. This ensures that the senior management are kept abreast of the cybersecurity posture and potential\nrisks faced by our group."}