{"url_path":"/sec/etst/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C CYBERSECURITY**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-18","source_url":"https://www.sec.gov/Archives/edgar/data/1538495/0001493152-26-029160-index.html","accession_number":"0001493152-26-029160","cik":"0001538495","ticker":"ETST","issuer_name":"Earth Science Tech, Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1538495/0001493152-26-029160-index.html","primary_entity_key":"0001538495","primary_entity_name":"Earth Science Tech, Inc."},"word_count":130,"has_tables":true,"body_markdown":"**ITEM\n1C. CYBERSECURITY**\n\n \n\nThe\nCompany recognizes the growing importance of cybersecurity. The company employs a dedicated IT infrastructure department led by Chris\nRose. The IT department assumes the primary responsibility for overseeing our cybersecurity risk exposure across the entire organization.\nThis includes evaluating, assessing, and enhancing cybersecurity practices.\n\n \n\nInitial\nRisk Assessment\n\n \n\nOur\ntechnology department conducts regular IT and Security risk assessments. This involves employee sit-alongs, inventorying all tech systems and assets, and\nreviewing existing practices, procedures, and policies. The findings are meticulously cataloged. Action plans are developed and addressed\nin priority ranked order. These assessments are updated quarterly, addressing new and outstanding risks and remediation plans.\n\n \n\nThird-Party\nEngagement\n\n \n\nTo\nexpedite security policy changes, active threat monitoring, infrastructure enhancements, device management, and endpoint security, the\ncompany engages additional third-party IT consultants."}