{"url_path":"/sec/gwav/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C CYBERSECURITY**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-15","source_url":"https://www.sec.gov/Archives/edgar/data/1589149/0001493152-26-028562-index.html","accession_number":"0001493152-26-028562","cik":"0001589149","ticker":"GWAV","issuer_name":"Greenwave Technology Solutions, Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1589149/0001493152-26-028562-index.html","primary_entity_key":"0001589149","primary_entity_name":"Greenwave Technology Solutions, Inc."},"word_count":575,"has_tables":true,"body_markdown":"**ITEM\n1C. CYBERSECURITY**\n\n \n\nCybersecurity\nrisks are a growing threat to us and other businesses, including our ERP and other third-party providers, which are vulnerable to cyberattacks,\nmalware, and other system failures that may result in unauthorized access, damage, and other harms to our business or reputation. Protecting\nthe confidentiality, integrity, and availability of our business information, intellectual property, customer, patient and employee data,\nand technology systems is critical to our business and operations, ability to comply with regulatory requirements, and reputation.\n\n \n\nAccordingly,\nCybersecurity is an important and integrated part of the Company’s enterprise risk management function that identifies, monitors,\nand mitigates business, operational, and legal risks.\n\n \n\nAccordingly,\nwe have established Cybersecurity standards, policies, and operating procedures, for the purpose of implementing information protection\nprocesses and technologies; carrying out Cybersecurity risk detection, identification, assessment, response, and monitoring; assigning\nresponsibility within our organization for risk detection and oversight; implementing Cybersecurity training; governing internal communications\nregarding Cybersecurity risks; and making required public and regulatory disclosures regarding Cybersecurity threats and incidents. We\noversee risks from Cybersecurity threats associated with our use of third-party service providers by requiring our vendors to agree that\nthey have and will maintain appropriate Cybersecurity controls, such as through standard contractual provisions, and by coordinating\nwith key vendors with respect to integration with our systems. Our Cybersecurity risk management program is based on the National Institute\nof Standards and Technology (“NIST”) framework.\n\n \n\nKey\ncomponents of our Cybersecurity risk management program include the use of third-party service providers, as appropriate, to assess,\ntest, or otherwise assist with aspects of our security processes. For example, we employed a third-party cyber risk consultant to assess\nour overall Cybersecurity risk framework against NIST standards. We have also engaged third-party experts to perform penetration testing\nof our IT systems, and we have considered the results of such tests to enhance our Cybersecurity systems and controls, as appropriate.\n\n \n\nOur\nmanagement, including leaders from our IT, information security, legal, and compliance teams, is responsible for implementing our Cybersecurity\nstandards, policies, and operating procedures, under the ultimate oversight of our Chief Financial Officer. We regularly discuss and\nassess Cybersecurity risks.\n\n \n\n18\n\n \n\n \n\nOur\nAudit Committee assists our Board in overseeing Cybersecurity risk management and the integrity of our information technology systems,\nprocesses, and data. Periodically, the Audit Committee reviews and discusses with management, and, in its discretion, third party vendors\nor other external experts, the adequacy of security for our information technology systems, processes, and data; our incident response\nand contingency plans in the event of a breakdown or security breach affecting the security of our information technology systems or\ndata or the information technology systems, processes, and data of our clients; and any new threats or incidents that have or may impact\nus. The Audit Committee receives reports on the operation of such programs from the Chief Financial Officer as appropriate. The Audit\nCommittee also reviews management reports regarding the evolving threat environment, vulnerability assessments, and specific Cybersecurity\nincidents. Periodically, the Audit Committee reports on Cybersecurity matters, incidents, and risk oversight to the Board.\n\n \n\nAlthough\nwe have not experienced a cyberattack or other Cybersecurity incident that has materially affected us, we cannot guarantee that we will\nnot experience Cybersecurity incidents that may have a material effect on us in the future. We may not be able to protect our systems\nand networks, or the confidentiality of our confidential or other information (including personal information), from cyberattacks and\nother unauthorized access, disclosure, and disruption."}