{"url_path":"/sec/ozsc/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C CYBERSECURITY.**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-05-14","source_url":"https://www.sec.gov/Archives/edgar/data/1679817/0001493152-26-023179-index.html","accession_number":"0001493152-26-023179","cik":"0001679817","ticker":"OZSC","issuer_name":"OZOP ENERGY SOLUTIONS, INC.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1679817/0001493152-26-023179-index.html","primary_entity_key":"0001679817","primary_entity_name":"OZOP ENERGY SOLUTIONS, INC."},"word_count":345,"has_tables":true,"body_markdown":"**ITEM\n1C. CYBERSECURITY.**\n\n \n\n**Cybersecurity\nRisk Management, Strategy, Governance, and Incident Disclosure**\n\n \n\nWe\nrecognize the importance of identifying, assessing and managing material risks associated with cybersecurity threats. We maintain an\ninformation technology and cybersecurity program appropriate for a company our size, taking into account our operations and risks.\n\n \n\n**Risk\nManagement and Strategy**\n\n \n\nOur\ncybersecurity risk management approach includes:\n\n \n\n \n●\nA\nflat network infrastructure powered by Ubiquiti (UBNT) equipment\n\n \n \n \n\n \n●\nUnified\nfirewall and security management through our UDM Pro device\n\n \n \n \n\n \n●\nRemote\naccess controlled via L2TP VPN with pre-shared key authentication\n\n \n \n \n\n \n●\nRegular\ndata backups using RoboCopy, scheduled daily at 2pm EST\n\n \n \n \n\n \n●\nPhysical\nsecurity through UniFi Access control system and ADT security cameras covering the entire building\n\n \n\nWe\nutilize third-party services for certain technology functions, including Microsoft 365 for email, GoDaddy for web hosting, and CodeTwo\nfor email signatures. While we depend on the digital technologies of these third parties, we monitor our systems to protect against unauthorized\naccess.\n\n \n\n**Governance**\n\n \n\nOur\nBoard of Directors is responsible for overseeing cybersecurity risks. Management, led by our IT department, is responsible for the operational\noversight of the company-wide cybersecurity strategy and standards. Administrative access to our critical systems is limited to authorized\npersonnel and documented in our IT inventory.\n\n \n\nGiven\nour size and operations, we maintain administrative controls including:\n\n \n\n \n●\nDefined\nadministrator accounts with appropriate access levels\n\n \n \n \n\n \n●\nDocumentation\nof system access credentials\n\n \n \n \n\n \n●\nRegular\nupdates to firmware on network infrastructure (current versions documented)\n\n \n \n \n\n \n●\nBackup\nverification and monitoring\n\n \n\n9\n\n \n\n** **\n\n**Cybersecurity\nRisks**\n\n \n\nAs\nof May 14, 2026, we are not aware of any cybersecurity threats, including as a result of any previous cybersecurity incidents, that have\nmaterially affected our business strategy, results of operations, or financial condition, or are reasonably likely to have such a material\neffect. However, like all organizations, we face potential risks from cybersecurity threats which could materially affect our operations\nor financial condition if they were to occur.\n\n \n\nAreas\nfor potential improvement in our cybersecurity posture include upgrading our WiFi access points and implementing a cloud backup solution\nto complement our current on-site backup strategy."}