{"url_path":"/sec/feim/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C Cybersecurity","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-07-17","source_url":"https://www.sec.gov/Archives/edgar/data/39020/0001185185-26-002997-index.html","accession_number":"0001185185-26-002997","cik":"0000039020","ticker":"FEIM","issuer_name":"FREQUENCY ELECTRONICS INC","edgar_url":"https://www.sec.gov/Archives/edgar/data/39020/0001185185-26-002997-index.html","primary_entity_key":"0000039020","primary_entity_name":"FREQUENCY ELECTRONICS INC"},"word_count":651,"has_tables":true,"body_markdown":"Item\n1C. Cybersecurity\n\n \n\n*Risk\nManagement and Strategy*\n\n* *\n\nWe\nbelieve cybersecurity is critical to our mission to ensure uninterrupted business continuity and enables us to deliver superior services\nwhile safeguarding our customers’ sensitive information.\n\n \n\nOur\ncybersecurity risk management processes are integrated into our overall risk management strategy. As part of our risk management strategy,\nour cybersecurity framework encompasses the following key processes:\n\n \n\n●Risk-Based\nControls for Information Systems: We maintain an Information Technology (IT) infrastructure with physical, administrative, and technical\ncontrols tailored to protect the confidentiality, integrity, and availability of our information and systems.\n\n \n\n●Cybersecurity\nIncident Response Plan and Testing: We have an incident response plan supported by a dedicated team to address cybersecurity incidents.\nThis incident response plan includes vulnerability identification, initial assessment, and engagement of external experts as needed.\n\n \n\n●Training\nInitiatives: We provide security awareness training to help our employees understand their information protection and cybersecurity responsibilities\nat the Company. We also provide additional role-based training to employees based on customer requirements, regulatory obligations and\nindustry risks, as needed.\n\n \n\n●Third-Party\nAssessments: We engage cybersecurity firms to regularly evaluate our cybersecurity posture, helping identify and mitigate risks posed\nby evolving threats.\n\n \n\nWe\nseek to continually strengthen our cybersecurity defenses through significant investments in resources and maintaining comprehensive\ncybersecurity insurance coverage. We maintain an insider threat detection program to proactively identify and mitigate both external\nand internal threats in a timely manner.\n\n \n\nWe\nrely on certain third-party service providers to assist us with the delivery of our products to our customers. A cybersecurity incident\nat a supplier or subcontractor could materially adversely impact us. Therefore, we evaluate third party providers from a cybersecurity\nrisk perspective, which may include an assessment of that service provider’s cybersecurity posture through a questionnaire. However,\nwe rely on the third parties we use to implement security programs commensurate with their risk, and we cannot ensure in all circumstances\nthat their efforts will be successful.\n\n \n\nOur\nadherence to Defense Federal Acquisition Regulation Supplement (DFARS) and Cybersecurity Maturity Model Certification (CMMC) requirements\nseeks to ensure strict protection of Controlled Unclassified Information (CUI), as mandated by the U.S. Department of War. These efforts\nunderscore our commitment to maintaining the highest cybersecurity resilience standards and regulatory compliance.\n\n \n\nAs\na U.S. Government defense industry contractor, we have experienced cybersecurity attacks and may be subject to significant cybersecurity\nattacks in the future. To date, we are not aware of any cybersecurity threats that have materially affected or are reasonably likely\nto affect us, including our business strategy, results of operations or financial condition. For additional information, see “Our\nbusiness could be adversely impacted by significant cybersecurity attacks” in Item 1A. Risk Factors above.\n\n \n\n*Governance*\n\n* *\n\nThe\nfull Board of Directors has overall responsibility for overseeing the cybersecurity processes of identifying and mitigating cybersecurity\nrisks. The Board of Directors has not delegated this responsibility to any one Committee, as its structure and size allows for the entire\nBoard of Directors to oversee this responsibility. Periodically, our management provides updates to the Board of Directors regarding\nour internal control program, including any significant changes to its IT infrastructure and/or cybersecurity program. Management also\ncommunicates directly with the Board of Directors to report any material risks from cybersecurity threats.\n\n \n\n11\n\n[Table of Contents](#TableOfContents)\n\n \n\nOur Chief Information Officer\n(CIO) leads our cybersecurity program and reports directly to our Chief Executive Officer. Our CIO is supported by our internal IT team\nthat assists our CIO in the day-to-day management of the cybersecurity program, including the cybersecurity incident response plan, training\ninitiatives and third-party assessments. Our CIO has over two decades of experience in various cybersecurity functions, including implementing\nstringent cybersecurity measures to protect sensitive information and meet established security standards, extensive work in IT governance\nand operations, network intrusion and critical systems protection, Enterprise Resource Planning (ERP) systems, and data analytics. He\nhas a B.S. in Computer Information Systems, and additional training in Risk Management Framework 2, COMSEC, and APICS."}