{"url_path":"/sec/fatn/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C CYBERSECURITY**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-05-18","source_url":"https://www.sec.gov/Archives/edgar/data/1993400/0001493152-26-024184-index.html","accession_number":"0001493152-26-024184","cik":"0001993400","ticker":"FATN","issuer_name":"Fatpipe Inc/UT","edgar_url":"https://www.sec.gov/Archives/edgar/data/1993400/0001493152-26-024184-index.html","primary_entity_key":"0001993400","primary_entity_name":"Fatpipe Inc/UT"},"word_count":455,"has_tables":true,"body_markdown":"**ITEM\n1C. CYBERSECURITY**\n\n \n\n**Risk\nManagement and Strategy**\n\n \n\nFatPipe\noperates in the network and cybersecurity software industry, and the integrity, confidentiality, and availability of our information\nsystems and the networks of our customers are critical to our business. We have processes in place for assessing, identifying, and managing\nmaterial risks from cybersecurity threats, including risks that could materially adversely affect our business strategy, results of operations,\nor financial condition. These processes are designed to be integrated with our broader enterprise risk management framework and are administered\nunder the supervision of our Chief Executive Officer and our Chief Financial Officer, with technical leadership provided by our internal\ninformation technology and engineering teams.\n\n \n\nOur\ncybersecurity risk management program includes the following elements: (i) risk assessment processes designed to identify and evaluate\ncybersecurity threats and vulnerabilities; (ii) implementation of administrative, technical, and physical controls intended to safeguard\nour information systems and the data we process; (iii) ongoing monitoring of network activity and security events; (iv) an incident response\nprogram designed to detect, respond to, and recover from cybersecurity incidents; and (v) employee training on data protection and information\nsecurity practices.\n\n \n\nAs\nboth a developer and user of cybersecurity technology, we apply our internal cybersecurity capabilities to monitor and protect our own\nenterprise IT environment, including the systems used to develop and deliver our software solutions. We engage third-party providers\nfrom time to time to support our cybersecurity activities, including security testing, vulnerability assessments, and threat monitoring.\nWe also assess cybersecurity risks associated with our use of third-party service providers and the components and software incorporated\ninto our solutions.\n\n \n\nTo\ndate, we are not aware of any cybersecurity incidents that have materially affected, or are reasonably likely to materially affect, our\nbusiness strategy, results of operations, or financial condition. However, we cannot eliminate cybersecurity risk, and despite our efforts,\nour information systems and the systems we deliver to customers may be subject to attempted breaches, denial-of-service attacks, malware,\nor other intrusions, any of which could result in business interruption, reputational harm, regulatory exposure, or financial loss.\n\n \n\n**Governance**\n\n \n\nOur\nBoard of Directors has overall responsibility for risk oversight and has delegated oversight of cybersecurity risk to the Audit and Finance\nCommittee, which is comprised entirely of independent directors. The Audit and Finance Committee receives periodic updates from management\non the Company’s cybersecurity risk profile, the status of significant security initiatives, and any material cybersecurity incidents.\nManagement, including the Chief Executive Officer and the Chief Financial Officer, together with our internal technical teams, is responsible\nfor day-to-day implementation of the Company’s cybersecurity program. Our internal technical leadership has many years of experience\ndesigning, developing, and operating network and security software systems, including the cybersecurity capabilities incorporated within\nour products and services.\n\n \n\n36"}