{"url_path":"/sec/lrhc/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C Cybersecurity.**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-04","source_url":"https://www.sec.gov/Archives/edgar/data/1879403/0001213900-26-065276-index.html","accession_number":"0001213900-26-065276","cik":"0001879403","ticker":"LRHC","issuer_name":"La Rosa Holdings Corp.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1879403/0001213900-26-065276-index.html","primary_entity_key":"0001879403","primary_entity_name":"La Rosa Holdings Corp."},"word_count":587,"has_tables":true,"body_markdown":"**Item\n1C. Cybersecurity.**\n\n \n\nThe\nCompany acknowledges the increasing importance of cybersecurity in today’s digital and interconnected world. Cybersecurity threats\npose significant risks to the integrity of our systems and data, potentially impacting our business operations, financial condition,\nand reputation.\n\n \n\nWe\nroutinely assess material cybersecurity risks, including potential unauthorized occurrences on, or conducted through, our information\nsystems that may compromise the confidentiality, integrity or availability of those systems or information maintained in them. We devote\nappropriate resources and designate members of our management to address the risk assessment and mitigation process.\n\n \n\nOur\nChief Technology Officer (“CTO”), reporting to the CEO, is primarily responsible for addressing cybersecurity risks. The\nCompany adopted Technology Use Policy and Procedures, pursuant to which a chief technology officer is responsible for overseeing IT infrastructure,\ncloud systems, access controls, and data protection practices, including implementation of multi-factor authentication, password management,\nand backup and recovery processes. Our CTO has respective experience. The CEO provides executive oversight, ensuring appropriate prioritization,\nresources, and alignment of cybersecurity initiatives with the Company’s overall risk management strategy. The CTO and CEO monitor\ncybersecurity risks through established processes, including system monitoring and logging, a centralized support ticketing system for\nincident tracking, mandatory reporting of suspicious activity, annual user training, third-party audits, and the use of preventative\ncontrols. The CTO leads incident response efforts and keeps the CEO informed of material developments.\n\n \n\nThe\nCTO and CEO provide updates to the Board of Directors on cybersecurity risks. These updates include assessments of the Company’s\ncybersecurity risk profile, status of mitigation efforts, results of internal and third-party audits.\n\n \n\nAs\na smaller reporting company, we are proactively leveraging AI and other resources to enhance our cybersecurity measures. While we do\nnot yet have a dedicated cybersecurity team or fully formalized protocols, we are actively developing new practices, incorporating advanced\ntechnologies to identify and mitigate risks. Our efforts include ongoing assessments and the exploration of strategic partnerships to\nstrengthen our security posture.\n\n \n\nGiven\nour current stage of cybersecurity development, we have not experienced any cybersecurity incidents to date. However, we recognize that\nthe absence of a formalized cybersecurity framework may leave us vulnerable to cyberattacks, data breaches, and other cybersecurity incidents.\nSuch events could potentially lead to unauthorized access to, or disclosure of, sensitive information, disrupt our business operations,\nresult in regulatory fines or litigation costs, and negatively impact our reputation among customers and partners.\n\n \n\nThe\nCompany is in the process of evaluating our cybersecurity needs and developing appropriate measures to enhance our cybersecurity posture.\nThis includes considering the engagement of external cybersecurity experts to advise on best practices, conducting vulnerability assessments,\nand developing an incident response strategy. Our goal is to establish a full cybersecurity framework that is commensurate with our size,\ncomplexity, and the nature of our operations, thereby reducing our exposure to cybersecurity risks.\n\n \n\nWe\nalso have a cybersecurity insurance policy in place and fully utilize its tools, guidance, and policies to ensure compliance and enhance\nour overall security posture. This coverage supports our risk management efforts by providing additional resources and expertise to help\nus identify, mitigate, and respond to potential threats effectively.\n\n \n\nDespite\nour efforts to improve our cybersecurity measures, there can be no assurance that our initiatives will fully mitigate the risks posed\nby cyber threats. The landscape of cybersecurity risks is constantly evolving, and the Company will continue to assess and update our\ncybersecurity measures in response to emerging threats.\n\n \n\nFor\na discussion of potential cybersecurity risks affecting the Company, please refer to Part I, Item 1A - “Risk Factors”."}