{"url_path":"/sec/jva/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C CYBERSECURITY**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-01-28","source_url":"https://www.sec.gov/Archives/edgar/data/1007019/0001493152-26-004052-index.html","accession_number":"0001493152-26-004052","cik":"0001007019","ticker":"JVA","issuer_name":"COFFEE HOLDING CO INC","edgar_url":"https://www.sec.gov/Archives/edgar/data/1007019/0001493152-26-004052-index.html","primary_entity_key":"0001007019","primary_entity_name":"COFFEE HOLDING CO INC"},"word_count":175,"has_tables":true,"body_markdown":"**ITEM\n1C. CYBERSECURITY**\n\n \n\nCybersecurity\nrisk management is part of the Company’s overall risk management. Our cybersecurity risk management is designed to provide a framework\nfor handling cybersecurity threats and incidents, including threats and incidents associated with the use of services provided by third-party\nservice provider. We rely on the cybersecurity protections of our third-party service provider. Our third-party service provider utilizes\ntwo (2) factor authorization as well as login and password protections with email verifications.\n\n \n\nOur\nBoard has overall oversight responsibility for our risk management, including our cybersecurity risk management. Management is responsible\nfor identifying, considering and assessing material cybersecurity risks on an ongoing basis, establishing processes to ensure that such\npotential cybersecurity risk exposures are monitored. We believe that we have not experienced any cybersecurity incidents in the fiscal\nyear ended October 31, 2025 that have materially affected us, including our operations, business strategy, results of operations or financial\ncondition.\n\n \n\nDespite\nour efforts, we cannot eliminate all risks from cybersecurity threats or provide assurances that we have not experienced an undetected\ncybersecurity incident.\n\n \n\n18"}