{"url_path":"/sec/essi/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C CYBERSECURITY**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-09","source_url":"https://www.sec.gov/Archives/edgar/data/1490873/0001477932-26-003725-index.html","accession_number":"0001477932-26-003725","cik":"0001490873","ticker":"ESSI","issuer_name":"ECO SCIENCE SOLUTIONS, INC.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1490873/0001477932-26-003725-index.html","primary_entity_key":"0001490873","primary_entity_name":"ECO SCIENCE SOLUTIONS, INC."},"word_count":303,"has_tables":true,"body_markdown":"**ITEM 1C. CYBERSECURITY**\n\n \n\n**Risk Management and Strategy**\n\n \n\nThe Company utilizes various processes and procedures intended to identify, assess, and manage cybersecurity risks affecting its systems, operations, data, and third-party service providers. The Company relies substantially on third-party cloud-based software, payment processors, hosting providers, communication systems, and external technology vendors in connection with its operations and platform development activities.\n\n \n\n \n\n9\n\n*Table of Contents*\n\n \n\nCybersecurity risks considered by the Company include unauthorized access to systems or data, ransomware, phishing attempts, business interruption, payment processing disruptions, loss of confidential information, and vulnerabilities involving third-party vendors or hosted infrastructure.\n\n \n\nThe Company’s cybersecurity processes currently include periodic review of system access controls, use of third-party security features and monitoring tools where available, password and authentication controls, vendor oversight activities, data backup procedures, and periodic evaluation of technology-related operational risks. Due to the Company’s size and limited personnel, the Company relies significantly on third-party service providers and external consultants to support certain technology, hosting, payment processing, and cybersecurity-related functions.\n\n \n\nAs of the date of this Annual Report on Form 10-K, the Company is not aware of any cybersecurity incident that has materially affected, or is reasonably likely to materially affect, the Company’s business strategy, results of operations, or financial condition.\n\n \n\n**Governance**\n\n \n\nManagement is responsible for assessing and managing cybersecurity risks as part of the Company’s broader operational and financial risk management activities. Cybersecurity and technology-related matters may be reviewed periodically by management and the Board of Directors, including risks associated with third-party service providers, operational systems, payment processing activities, data security, and business continuity.\n\n \n\nDue to the Company’s limited personnel and early-stage operations, the Company does not currently maintain a dedicated internal cybersecurity department or formalized enterprise cybersecurity program. The Company intends to continue evaluating and enhancing its cybersecurity processes, policies, and oversight procedures as operations and resources expand."}