{"url_path":"/sec/ivf/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C Cybersecurity.**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-02","source_url":"https://www.sec.gov/Archives/edgar/data/1417926/0001493152-26-026775-index.html","accession_number":"0001493152-26-026775","cik":"0001417926","ticker":"IVF","issuer_name":"INVO Fertility, Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1417926/0001493152-26-026775-index.html","primary_entity_key":"0001417926","primary_entity_name":"INVO Fertility, Inc."},"word_count":362,"has_tables":true,"body_markdown":"**Item\n1C. Cybersecurity.**\n\n \n\n*Risk\nmanagement and strategy*\n\n \n\nWe\nhave not formally developed and implemented a cybersecurity risk management program. However, we generally follow operating practices\ndesigned to help prevent cybersecurity risk to protect the confidentiality, integrity, and availability of our data and systems and any\npersonal health information (“PHI”) that we maintain.\n\n \n\nOur\ngeneral operating procedures for cybersecurity risk management are incorporated into our overall enterprise risk management programs,\nand share common methodologies, reporting channels and governance processes, including the following:\n\n \n\n \n●\nGeneral\nprocedures designed to help identify material cybersecurity risks to our critical systems, information, services, and our broader\nenterprise IT environment; and\n\n \n \n \n\n \n●\nAn\noutsourced IT security team to assist with managing (1) our cybersecurity procedures, (2) our security controls, and (3) our response\nto cybersecurity interests.\n\n \n\nAs\nof the date of this filing, we have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity\nincidents that have materially affected us, including our operations, business strategy, results of operations, or financial condition.\nWe may face risks from cybersecurity threats that, if realized, are likely to materially affect us, including our operations, business\nstrategy, results of operations, or financial condition. For additional information, see Part I, Item 1A: *Risk Factors— Risks\nRelating to our Business: We are susceptible to cybersecurity breaches and cyber-related fraud.*\n\n \n\n*Cybersecurity:\nGovernance*\n\n \n\nOur\nexecutive team evaluates our cybersecurity risk and reports any findings, recommendations, or material impacts to the Board, which provides\nan oversight function. The Board has charged management with the responsibility for oversight of cybersecurity risks and incidents and\nany other risks and incidents relevant to our computerized information system controls and security.\n\n \n\nOur\nIT consultant reviews the efficacy of our cybersecurity procedures from time to time as circumstances make it appropriate and\nannually in connection with the annual audit of our financial statements. Our IT consultant reports to our CEO and CFO on matters\nof cybersecurity, and together they carry responsibility for our overall cybersecurity risk management procedures. Our CEO and\nCFO provide prompt reports to the Board regarding cybersecurity risks and incidents as they are revealed, as well as periodic reports,\nas appropriate, regarding our cybersecurity activities."}