{"url_path":"/sec/glsi/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C CYBERSECURITY**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-01","source_url":"https://www.sec.gov/Archives/edgar/data/1799788/0001493152-26-026651-index.html","accession_number":"0001493152-26-026651","cik":"0001799788","ticker":"GLSI","issuer_name":"Greenwich LifeSciences, Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1799788/0001493152-26-026651-index.html","primary_entity_key":"0001799788","primary_entity_name":"Greenwich LifeSciences, Inc."},"word_count":479,"has_tables":true,"body_markdown":"**ITEM\n1C. CYBERSECURITY**\n\n \n\nWe\nbelieve cybersecurity is critical to advancing our technological developments. As a biopharmaceutical company, we face a multitude of\ncybersecurity threats that range from attacks common to most industries, such as ransomware and denial-of service. Our customers, suppliers,\nsubcontractors, and business partners face similar cybersecurity threats, and a cybersecurity incident impacting us or any of these entities\ncould materially adversely affect our business strategy, performance, and results of operations. These cybersecurity threats and related\nrisks make it imperative that we expend resources on cybersecurity.\n\n \n\n**Risk\nManagement**\n\n \n\nWe\nengage third-party services to conduct evaluations of our security controls, whether through penetration testing, independent audits,\nor consulting on best practices to address new challenges. We have established cybersecurity security awareness training and ongoing\nmonitoring.\n\n \n\nIn\nthe event of an incident, we intend to follow our cybersecurity incident response plan, which outlines the steps to be followed from\nincident detection to mitigation, and notification. We contract with external firms that have extensive information technology and program\nmanagement experience. We have implemented a governance structure and processes to assess, identify, manage, and report cybersecurity\nrisks. As a biopharmaceutical company, we must comply with extensive regulations, including requirements imposed by the Federal Drug\nAdministration related to adequately safeguarding patient information and reporting cybersecurity incidents to the SEC. We believe we\nare positioned to meet the requirements of the SEC. In addition to following SEC guidance and implementing pre-existing third party frameworks,\nwe have developed our own practices and frameworks, which we believe enhance our ability to identify and manage cybersecurity risks.\nAssessing, identifying, and managing cybersecurity related risks are factored into our overall business approach. We rely heavily on\nour supply chain to deliver our products and services, and a cybersecurity incident at a clinical site, subcontractor, or business partner\ncould materially adversely impact us. We require that our subcontractors report cybersecurity incidents to us so that we can assess the\ndirect impact of the incident.\n\n \n\n**Governance**\n\n \n\nThe\nAudit Committee has oversight responsibility for risks and incidents relating to cybersecurity threats, including compliance with disclosure\nrequirements, cooperation with law enforcement, and related effects on financial and other risks, and it reports any findings and recommendations,\nas appropriate, to the full board of directors for consideration. Senior management regularly discusses cyber risks and trends and, should\nthey arise, any material incidents with the Audit Committee.\n\n \n\nWhile\nwe have not experienced any material cybersecurity threats or incidents in recent years, there can be no guarantee that we will not be\nthe subject of future threats or incidents. Notwithstanding the extensive approach we take to cybersecurity, we may not be successful\nin preventing or mitigating a cybersecurity incident that could have a material adverse effect on us. While we maintain cybersecurity\ninsurance, the costs related to cybersecurity threats or disruptions may not be fully insured. See “Risk Factors” for a discussion\nof cybersecurity risks."}