{"url_path":"/sec/rmtg/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C **","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-05-14","source_url":"https://www.sec.gov/Archives/edgar/data/1760026/0001213900-26-056841-index.html","accession_number":"0001213900-26-056841","cik":"0001760026","ticker":"RMTG","issuer_name":"Regenerative Medical Technology Group Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1760026/0001213900-26-056841-index.html","primary_entity_key":"0001760026","primary_entity_name":"Regenerative Medical Technology Group Inc."},"word_count":557,"has_tables":true,"body_markdown":"**ITEM 1C.**\n**CYBERSECURITY**\n\n \n\nWe rely on our information technology systems,\nincluding those managed by third parties, to operate our business. These systems are critical to our manufacturing operations at the Cancún\nfacility, physician training programs through the International Society for Stem Cell Application (ISSCA), global distribution of Cellgenic\nproducts (including Peptide Pens and exosome therapies), management of sensitive clinical and research data, and coordination across our\ninternational clinic network and strategic partnerships in regions such as Latin America, Southeast Asia, the Middle East, and South Asia.\n\n \n\nCybersecurity threats, including but not limited\nto ransomware, phishing attacks, data breaches, malware, supply chain compromises, denial-of-service attacks, and insider threats, represent\nsignificant risks to our operations, intellectual property (such as proprietary protocols for mesenchymal stem cells, exosomes, and peptide-based\nproducts), patient and clinical data, financial condition, and reputation. These risks are heightened by our increasing reliance on digital\nplatforms for online education and certification programs, inventory and supply chain management, international collaborations, and the\nhandling of sensitive biological and health-related information in a global, multi-jurisdictional environment.\n\n \n\n17\n\n \n\nWe have developed and implemented policies, procedures,\nand controls designed to protect our information technology systems and to identify, assess, and respond to cybersecurity threats and\nincidents in a timely manner. Our cybersecurity risk management program is integrated into our broader enterprise risk management framework\nand is designed to protect the confidentiality, integrity, and availability of our systems and data.\n\n \n\nKey elements of our cybersecurity risk management\nprogram include:\n\n \n\n◾Regular risk assessments, vulnerability scanning, and penetration testing\nof our networks and systems;\n\n \n\n◾Implementation of technical safeguards such as firewalls, intrusion detection\nand prevention systems, endpoint detection and response tools, multi-factor authentication, encryption of sensitive data (both in transit\nand at rest), and regular security patching;\n\n \n\n◾Deployment of anti-malware and antivirus applications across endpoints and\nservers;\n\n \n\n◾Employee training programs focused on cybersecurity awareness, phishing recognition,\nsecure data handling, and incident reporting;\n\n \n\n◾Periodic quality audits, tabletop exercises, and simulated incident response\ndrills to test and improve preparedness;\n\n \n\n◾Backup systems, redundancy measures, and disaster recovery plans to minimize\nthe impact of potential incidents;\n\n \n\n◾Monitoring and detection activities to identify potential threats in real\ntime.\n\n \n\nWe engage qualified third-party consultants and\ncybersecurity service providers to support our risk management efforts. These third parties assist with independent assessments, continuous\nmonitoring, threat detection, incident response support, and enhancement of our overall cybersecurity posture. The third-party consultant\nteam is overseen by our sole officer and director on relevant matters, including the status of our cybersecurity program, emerging threats,\nand any significant incidents.\n\n \n\nAs of December 31, 2025, we have not identified\nany cybersecurity incidents that have materially affected, or are reasonably likely to materially affect, our business strategy, results\nof operations, or financial condition, including our consolidated financial statements.\n\n \n\nWe continue to monitor the evolving cybersecurity\nthreat landscape closely, particularly in light of our rapid international expansion, increasing dependence on third-party vendors for\nmanufacturing components, logistics, cloud services, and technology infrastructure, and the sensitive nature of the biological, clinical,\nand patient data we handle. While we believe our current cybersecurity measures are appropriate and proportionate to the risks we face,\nno system of safeguards can provide absolute protection. A significant cybersecurity incident in the future could result in operational\ndisruptions, loss of intellectual property, unauthorized disclosure of sensitive data, regulatory investigations, litigation, reputational\nharm, financial losses, and other adverse consequences."}