{"url_path":"/sec/pets/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C CYBERSECURITY","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-02","source_url":"https://www.sec.gov/Archives/edgar/data/1040130/0001040130-26-000019-index.html","accession_number":"0001040130-26-000019","cik":"0001040130","ticker":"PETS","issuer_name":"PETMED EXPRESS INC","edgar_url":"https://www.sec.gov/Archives/edgar/data/1040130/0001040130-26-000019-index.html","primary_entity_key":"0001040130","primary_entity_name":"PETMED EXPRESS INC"},"word_count":744,"has_tables":true,"body_markdown":"ITEM 1C. CYBERSECURITY\n\nPetMeds and PetCareRx maintain an enterprise-wide cybersecurity program designed to identify, assess, manage, and mitigate information security risks across the organization. Our program covers governance, policy, prevention, detection, incident response, and recovery, aligned with industry standards.\n\nCybersecurity Risk Management and Oversight\n\nOur cybersecurity risk management program is designed to protect our systems, data, and customers from a wide range of cyber threats. Our cybersecurity practices are guided by the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework (“CSF”), which categorizes cybersecurity activities into five key functions: identify, protect, detect, respond, and recover.\n\nDuring fiscal 2026, we enhanced our governance structure by establishing two internal risk committees, an enterprise-wide management risk committee and an executive risk committee, to identify, assess, and manage enterprise risks, including cybersecurity risks, in a coordinated and timely manner. This committee improves cross-functional alignment and helps us proactively manage risk across the organization.\n\nOur management team includes individuals with relevant expertise in information technology and cybersecurity. During fiscal 2026, cybersecurity oversight responsibilities were led by our Chief Digital and Technology Officer and Chief Information Security Officer, both of whom served through the end of the fiscal year and had significant experience in cybersecurity and risk management, including more than two decades of combined experience in these areas. Following their departures in the first quarter of fiscal 2027, these responsibilities have been assigned to other members of management and are supported by internal personnel and an external third-party specialist with relevant cybersecurity expertise.\n\nIn addition, we implemented Drata, a governance, risk, and compliance (“GRC”) platform, to automate and streamline risk management, control monitoring, and compliance processes. This investment strengthens our ability to maintain continuous visibility into our control environment and enhances our overall cybersecurity maturity.\n\nThe Audit Committee of our Board of Directors oversees cybersecurity risk and receives quarterly updates from management on cybersecurity strategy, threat landscape, incident trends, remediation activities, and other relevant developments.\n\nIncident Detection and Response\n\nWe maintain an Incident Response Policy and supporting procedures that define how potential cybersecurity events are identified, escalated, investigated, contained, and remediated. The objectives of our incident response program include:\n\n23\n\n•Timely investigation and validation of incidents\n\n•Minimization of data loss or service disruption\n\n•Evidence preservation in accordance with legal and regulatory requirements\n\n•Restoration of affected systems and services\n\n•Post-incident review and implementation of corrective actions\n\n•Notification to affected parties and regulators, where appropriate\n\nThese procedures are periodically tested and updated to ensure effectiveness and readiness.\n\nSecurity Measures and Monitoring\n\nWe use a layered, defense-in-depth approach with industry-standard tools and our own processes for threat detection, monitoring, and response. Our security measures include:\n\n•Regular system scans, vulnerability assessments, and penetration testing\n\n•Ongoing compliance with the Payment Card Industry Data Security Standard (“PCI DSS”)\n\n•Deployment of endpoint detection and response (“EDR”) tools and real-time monitoring solutions\n\n•Secure development practices are integrated into our digital platforms\n\nDuring fiscal 2026, we conducted both internal and external penetration testing, which identified certain minor vulnerabilities. These findings were promptly remediated, and no threats were identified in these assessments.\n\nAs part of our vendor management and procurement processes, we conduct cybersecurity due diligence, including reviewing SOC reports and validating data privacy and security practices for vendors with access to our systems or sensitive data.\n\nAs we modernize our technology platforms and phase out legacy systems, we're strengthening security across identity management, access governance, and software development.\n\nTraining and Awareness\n\nCybersecurity awareness is a foundational element of our risk management approach. We conduct recurring cybersecurity training for employees across the Company, with targeted modules addressing common threat vectors such as phishing, ransomware, and social engineering. Additional training is provided for employees in roles with elevated access to systems or sensitive data\n\nCybersecurity Incidents\n\nWe maintain processes to detect and respond to cybersecurity incidents as part of normal operations. While we have experienced routine threats and minor incidents, to date, we have not identified any cybersecurity incidents that have materially impacted our business, operations, or financial condition.\n\nCybersecurity risks continue to evolve, and we cannot provide assurance that future incidents will not materially impact our business, financial condition, or results of operations. For additional information, see Item 1A, “Risk Factors,” including the risk titled: “Our failure or the failure of third-party service providers to protect our websites, networks, and systems against cybersecurity incidents, or otherwise to protect our confidential information, could damage our reputation and brands and substantially harm our business, financial condition, and results of operations.\""}