{"url_path":"/sec/eltp/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C CYBERSECURITY**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-29","source_url":"https://www.sec.gov/Archives/edgar/data/1053369/0001493152-26-031070-index.html","accession_number":"0001493152-26-031070","cik":"0001053369","ticker":"ELTP","issuer_name":"ELITE PHARMACEUTICALS INC /NV/","edgar_url":"https://www.sec.gov/Archives/edgar/data/1053369/0001493152-26-031070-index.html","primary_entity_key":"0001053369","primary_entity_name":"ELITE PHARMACEUTICALS INC /NV/"},"word_count":928,"has_tables":true,"body_markdown":"** **\n\n**ITEM\n1C. CYBERSECURITY**\n\n \n\n**Risk\nManagement & Strategy**\n\n \n\nElite\nmaintains a cyber risk management program designed to identify, assess, manage, mitigate and respond to cybersecurity threats. This program\naddresses cybersecurity risks to corporate information technology, or IT, environment including systems, hardware, software, data, people\nand processes.\n\n \n\nThe\nunderlying processes and controls of Elite’s cyber risk management program incorporate recognized best practices and standards\nfor cybersecurity and information technology, including principles of the National Institute of Standards and Technology (“NIST”)\nCybersecurity Framework 2.0 (“CSF”), and processes and controls supporting data protection requirements under applicable\nlaw. NIST CSF offers a thorough set of guidelines and best practices to help establish a strong cybersecurity posture. Aligning our cybersecurity\nprocesses and controls to NIST CSF enables us to systemically identify, assess, and manage cybersecurity risks most relevant and impactful\nto our business operations. It is important to note that using the NIST CSF as a guide does not imply our cybersecurity program meets\nany specific technical standards or requirements.\n\n \n\nElite\nengages a third-party specialist to perform an annual assessment of its cybersecurity risk management program against the NIST CSF. The\nannual risk assessment identifies, quantifies, and categorizes material cyber risks. Elite, in conjunction with its third-party cyber\nrisk management specialists, develops a risk mitigation plan to address such risks, and where necessary, remediate potential vulnerabilities\nidentified through the annual assessment process. In evaluating the risks identified through the annual cybersecurity risk assessment process,\nour cybersecurity specialists and partners, including but not limited to Managed Service Providers, assist Elite to assess and prioritize\nthe likelihood, severity, and impact of relevant risks, including the impact on employees, stakeholders, and vendors.\n\n \n\nIn\naddition, Elite maintains governance processes and controls designed to protect Elite’s IT assets, data, and services from threats\nand vulnerabilities. Elite employs key practices within the cybersecurity risk management program including maintaining restricted access\nto privileged accounts, intrusion prevention systems/detection systems including maintenance of protection systems such as firewalls,\nnetwork and data traffic monitoring, and critical data backups to mitigate cybersecurity risk.\n\n \n\nElite’s\ncybersecurity partners, including consultants and other third-party service providers, are a key part of Elite’s cybersecurity\nrisk management strategy and infrastructure. Elite partners with industry-recognized cybersecurity providers leveraging third-party technology\nand expertise and engages with these partners to monitor and maintain the performance and effectiveness of IT assets, data, and services\nthat are deployed in company data and technology environment. The cybersecurity partners provide services necessary to maintain Elite’s\nIT infrastructure and execute the current cybersecurity strategy, including continuous improvement and remediation efforts.\n\n \n\nElite\nmonitors service level agreements and third-party contracts as part of our efforts to monitor third-party risks associated with reliance on vendors, critical service\nproviders, and other third-parties that may lead to service disruption or an adverse cybersecurity incident.\n\n \n\nOur\ncybersecurity risk management program includes an incident response plan that includes relevant and critical members of management and\nthird-party service providers alike. This team is responsible for assessing and managing cybersecurity incident response processes, response\ntimes, and communication plans in the event corrective actions and mitigation procedures are required to isolate and eradicate an incident.\n\n \n\n**Governance\n& Oversight**\n\n \n\nElite’s\nmanagement team, with assistance from cybersecurity service providers, is responsible for oversight and administration of Elite’s\ncyber risk management program, and for informing senior management and other relevant stakeholders regarding the prevention, detection,\nmitigation, and remediation of cybersecurity incidents. Elite’s management team has prior experience selecting, deploying, and\noverseeing cybersecurity technologies, initiatives, and processes directly or via the use of strategic third-party partners. Elite’s\nmanagement team also relies on threat intelligence as well as other information obtained from governmental, public or private sources,\nincluding external consultants engaged by Elite for strategic cyber risk management, advisory and decision making.\n\n \n\nThe\nAudit Committee of the Board of Directors oversees Elite’s cybersecurity risk exposures and the steps taken by management to monitor\nand mitigate cybersecurity risks. The cybersecurity stakeholders, including members of management assigned with cybersecurity oversight\nresponsibility and/or third-party consultants providing cyber risk services, brief the Audit Committee on cyber vulnerabilities identified\nthrough the risk management process, the effectiveness of Elite’s cyber risk management program, and the emerging threat landscape\nand new cyber risks on at least an annual basis. This includes updates on processes to prevent, detect, and mitigate cybersecurity incidents.\n\n \n\nElite\nfaces risks from cybersecurity threats that could have a material adverse effect on its business, financial condition, results of operations,\ncash flows or reputation. Elite acknowledges that the risk of cyber incidents is prevalent in the current threat landscape and that a\nfuture cyber incident may occur in the normal course of its business. However, as of the date of this Annual Report on Form 10-K, Elite\nis not aware of any risks from cybersecurity threats that have materially affected or are reasonably likely to materially affect Elite’s\nbusiness strategy, financial condition, results of operations, or cash flows. Elite proactively seeks to detect and investigate unauthorized\nattempts and attacks against IT assets, data, and services, and to prevent their occurrence and recurrence where practicable through\nchanges or updates to internal processes and tools and changes or updates to Elite’s service delivery; however, potential vulnerabilities\nto known or unknown threats will still remain. Further, there are continuous regulatory considerations regarding responses to cybersecurity\nincidents, including reporting to regulators, investors, and additional stakeholders, which could subject Elite to additional liability\nand reputational harm. In response to such risks, Elite has implemented initiatives such as implementation of the cybersecurity risk\nassessment process and development of an incident response plan. See Item 1A. “*Risk Factors*” for more information\non cybersecurity risks.\n\n \n\n45"}