{"url_path":"/sec/oesx/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C CYBERSECURITY","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-04","source_url":"https://www.sec.gov/Archives/edgar/data/1409375/0001193125-26-257468-index.html","accession_number":"0001193125-26-257468","cik":"0001409375","ticker":"OESX","issuer_name":"ORION ENERGY SYSTEMS, INC.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1409375/0001193125-26-257468-index.html","primary_entity_key":"0001409375","primary_entity_name":"ORION ENERGY SYSTEMS, INC."},"word_count":198,"has_tables":true,"body_markdown":"ITEM 1C. CYBERSECURITY\n\nOur Board and Audit and Finance Committee oversee risks from cybersecurity threats. Our Audit and Finance Committee reviews cybersecurity risks on a quarterly basis and our Board periodically reviews cybersecurity risks as part of its overall risk management oversight and specifically reviews cybersecurity in detail at least annually. Our Board relies on management and its use of third-party consultants for expertise for assessing and managing our risks from cybersecurity threats. In conjunction with management, our Board considers the nature of the work provided by our operations, the potential impact of a cybersecurity event, costs, potential likelihood of an event, prior events, and benefits in its general oversight of the cybersecurity risk management.\n\nWe have experienced targeted and non-targeted cybersecurity attacks and incidents in the past that have resulted in unauthorized persons gaining limited access to our information and systems, and we could in the future experience similar attacks. To date, no cybersecurity incident or attack, or any risk from cybersecurity threats, has materially affected or has been determined to be reasonably likely to materially affect us or our business strategy, results of operations, or financial condition.\n\nSee also “Item 1A. Risk Factors — Operational Risks.”"}