{"url_path":"/sec/iehc/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C ****Cyber Security**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-12","source_url":"https://www.sec.gov/Archives/edgar/data/50292/0001213900-26-068122-index.html","accession_number":"0001213900-26-068122","cik":"0000050292","ticker":"IEHC","issuer_name":"IEH Corp","edgar_url":"https://www.sec.gov/Archives/edgar/data/50292/0001213900-26-068122-index.html","primary_entity_key":"0000050292","primary_entity_name":"IEH Corp"},"word_count":520,"has_tables":true,"body_markdown":"**Item 1C.****Cyber Security**\n\n** **\n\nAll companies utilizing technology are subject to the risk\nof breaches of or unauthorized access to their computer systems. The Company maintains a cyber risk management program designed to identify,\nassess, manage, mitigate, and respond to cybersecurity threats. The Audit Committee of our Board of Directors and our management are actively\ninvolved in the oversight of our risk management program, of which cybersecurity represents an important component. We have established\npolicies, standards, processes and practices for assessing, identifying, and managing material risks from cybersecurity threats and incidents.\nOur policies, processes and procedures include, among other things, external penetration testing using an experienced third-party company\nconducted every three years; a cybersecurity incident response and recovery plan; periodic and ongoing security awareness training for\nemployees; the use of several comprehensive vulnerability analysis systems to evaluate software vulnerabilities both internally and externally;\nand mechanisms to detect and monitor unusual network activity. The Company also requires that all third-party vendors that have access\nto or handle sensitive information undergo a risk-based vendor security assessment. We also maintain controls and procedures that are\ndesigned to promptly escalate certain cybersecurity incidents so that decisions regarding public disclosure and reporting of such incidents\ncan be made by management and our Board of Directors in a timely manner. There can be no guarantee that our policies and procedures will\nbe properly followed in every instance or that those policies and procedures will be effective.\n\n \n\nOur cyber risk management program is based on recognized best\npractices and standards for cybersecurity and information technology, including the National Institute of Standards and Technology Cybersecurity\nFramework. Our cybersecurity risks are identified and addressed through a comprehensive, cross- functional approach. The Company’s\nVice President of Engineering is primarily responsible for the implementation of defense capabilities and risk mitigation strategies in\nconnection with the Company’s information security and cybersecurity risks. The Company’s Vice President of Engineering, in\ncoordination with the Company’s senior management, works collaboratively across the Company to implement the cyber risk management\nprogram. To facilitate the success of the Company’s cybersecurity program, cross-functional teams throughout the Company address\ncybersecurity threats and respond to cybersecurity incidents. Through ongoing communications with these teams, the Company’s Vice\nPresident of Engineering and senior management are informed about and monitor the prevention, detection, mitigation and remediation of\ncybersecurity threats and incidents in real time, and report such threats and incidents to the Audit Committee of the Board of Directors\nwhen appropriate.\n\n \n\nOur Audit Committee takes the lead on behalf of our Board\nof Directors in monitoring risk management, which includes overseeing the Company’s management of its cybersecurity and data privacy.\nThe Audit Committee meets on a quarterly basis with our Vice President of Engineering, General Counsel and Chief Financial Officer, who\nprovide quarterly reports concerning the Company’s information security and cybersecurity risks.\n\n \n\nAlthough we have not been materially impacted by any cybersecurity\nincident to date, we are subject to cybersecurity threats, as discussed in Item 1A. Risk Factors, including in the risk factor entitled\n“*Our business and operations would suffer in the event of system failures, cyber-attacks or a deficiency in our cyber-security*.”\n\n \n\n 14"}