{"url_path":"/sec/mlab/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C Cybersecurity**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-03","source_url":"https://www.sec.gov/Archives/edgar/data/724004/0000724004-26-000047-index.html","accession_number":"0000724004-26-000047","cik":"0000724004","ticker":"MLAB","issuer_name":"MESA LABORATORIES INC /CO/","edgar_url":"https://www.sec.gov/Archives/edgar/data/724004/0000724004-26-000047-index.html","primary_entity_key":"0000724004","primary_entity_name":"MESA LABORATORIES INC /CO/"},"word_count":702,"has_tables":true,"body_markdown":"**Item 1C. Cybersecurity**\n\n \n\n \n\n**Governance Related to Cybersecurity Risks**\n\n \n\nWe recognize the importance of developing, implementing, and maintaining robust cybersecurity measures to safeguard our information systems and protect the confidentiality, integrity, and availability of our data.\n\n \n\nOur Board of Directors has delegated oversight of cybersecurity risks to our Audit Committee. In accordance with its charter, our Audit Committee is responsible for overseeing management’s review and assessment of our cybersecurity and other information technology risks, controls and procedures. Management's Business Information Services team provides the Audit Committee with quarterly updates on our cybersecurity program, including monitoring activities and mitigation efforts. The Audit Committee has two members with prior work experience overseeing or assessing cybersecurity functions, and the Audit Committee informs the full Board of pertinent cybersecurity matters regularly. We have established policies and procedures to keep management and the Audit Committee informed about cybersecurity incidents that could significantly impact our business.\n\n \n\nOur information security program is led by our Information Security Manager, who has over ten years of cybersecurity experience and reports to our Vice President of Business Information Services, who has over 25 years of experience in the information technology industry. The Information Security Manager regularly meets with our Business Information Services team, and as appropriate, with other executives and directors to review our cybersecurity posture, developments in the cybersecurity landscape, any identified cybersecurity incidents, continuous risk mitigation activities, and any anticipated enhancements to our policies, procedures and controls.\n\n \n\n \n\n**Cybersecurity Risk Management and Strategy**\n\n \n\nOur cybersecurity program, guided by industry standards, encompasses processes for the identification, assessment, and management of cybersecurity risks. Cybersecurity risks are considered as part of our enterprise risk management processes and are evaluated alongside other operational and strategic risks. We conduct regular risk assessments, supported by external vendors, to evaluate our cybersecurity program, identify areas for enhancement and develop strategies to mitigate cybersecurity risks. Internally, we perform ongoing security testing and maintain a vulnerability management process to address identified security risks based on severity. An external vendor provides us with periodic vulnerability scans, annual penetration tests, security tabletop exercises, and an enterprise-wide annual security assessment to evaluate and validate our physical, technical, external, and administrative controls.\n\n \n\nPage\n*23*\n\n[Table of Contents](#toc)\n\n \n\nWe rely on third parties to provide, host, or support certain information technology systems. Cybersecurity considerations are incorporated into Mesa’s processes for selecting and onboarding third‑party vendors that access our information systems or data, and such vendors *may*be required to maintain information security measures appropriate to the nature of the services they provide. However, we do *not* control the security practices of *third* parties, and their failure to maintain adequate security could adversely affect us. Third parties that access, process, store or transmit our information or that have access to our systems *may*have and be subject to additional cybersecurity controls.\n\n \n\nWe maintain cybersecurity policies that articulate Mesa’s expectations and requirements with respect to topics such as acceptable use of technology and data, data privacy, risk management, education and awareness, and incident management. Consistent with our position that cybersecurity is the responsibility of every Mesa team member, we regularly educate and share best practices to raise awareness of cybersecurity threats. Employees in applicable job categories are required to complete annual information security and data protection training, and we conduct ongoing simulated phishing exercises to reinforce awareness for all employees. \n\n \n\nOur Information Security Manager and Business Information Services team oversee the day-to-day prevention, detection, mitigation, and resolution of cybersecurity risks, utilizing *third*-party security software and services. We deploy processes and technologies to monitor security alerts from both internal and external sources, including information security research. In the event of a confirmed security incident, we maintain a full incident response plan that includes engaging an incident handling team, guidance for determining materiality, and steps to respond to, remediate, and recover from the security incident. We maintain a cybersecurity insurance policy and a retainer for third-party incident response services, which *may*mitigate certain financial impacts of a cybersecurity incident, should *one* occur.\n\n \n\nTo date, risks from cybersecurity threats have not materially affected our business, results of operations or financial condition. We can provide no assurance that cybersecurity incidents will not occur in the future or that such incidents will not materially affect us."}