{"url_path":"/sec/royl/10-k/2026/item-1a","section_key":"item-1a","section_title":"Item 1A Risk Factors**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-07-13","source_url":"https://www.sec.gov/Archives/edgar/data/1694617/0001185185-26-002897-index.html","accession_number":"0001185185-26-002897","cik":"0001694617","ticker":"ROYL","issuer_name":"Royale Energy, Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1694617/0001185185-26-002897-index.html","primary_entity_key":"0001694617","primary_entity_name":"Royale Energy, Inc."},"word_count":386,"has_tables":true,"body_markdown":"**Item 1A Risk Factors**\n\n \n\nAs a smaller reporting company, as defined in Rule 12b-2 of the Exchange\nAct, Royale is not required to provide the information required by this Item.\n\n \n\n**Item**  **1B**  **Unresolved Staff Comments**\n\n \n\nNone.\n\n \n\n3\n\n[Table of Contents](#toc) \n\n \n\n**Item**  **1C**  **Cybersecurity**\n\n \n\n**Risk Management and Strategy**\n\n \n\nThe Company’s cybersecurity environment is led by our third-party\ninformation technology (IT) contractor, which, in addition to cybersecurity matters, oversees the Company’s IT infrastructure. \nThe IT contractor is responsible for monitoring and managing the security of the Company’s corporate network and enterprise systems,\nincluding technical controls, and safety protocols and responding to security threats.\n\n \n\nThe Company maintains a cybersecurity risk management program that\nestablishes safeguards for protecting the confidentiality, integrity, and availability of our data, technology, and information systems.\nThe program includes general controls for managing changes in and access to the Company’s IT environment, cybersecurity awareness\nand training to help employees identify and mitigate against cybersecurity threats, cybersecurity incident response plans and third-party\nincident response retainers to help expedite the Company’s response in the event of a cybersecurity incident.\n\n \n\nThe Company’s IT contractor is primarily responsible for the\nday-to-day operation of the Company’s cybersecurity program and for identifying cybersecurity threats and incidents and managing\nthe material risks associated with the cybersecurity threats. The Company’s IT contractor engages third-party vendors and cybersecurity\nconsortiums periodically for cybersecurity-related guidance and certifications.  In the event of a cybersecurity incident, the Company’s\nprocess calls for the IT contractor, our Chief Executive Officer and our Chief Financial Officer, to work to assess and respond to the\nincident and provide briefings to the audit committee of the board of directors.\n\n \n\nThe audit committee is responsible for providing oversight over management’s\nprocesses to identify and evaluate cybersecurity risks to which the Company is exposed and to implement processes and programs to manage\ncybersecurity risks and mitigate any incidents. The Audit Committee also reports material cybersecurity risks to the board of directors.\nWe believe this risk management process provides visibility and oversight to allow the board and executive leadership team to make timely,\ndata-driven decisions ensuring that the Company, its employees, investors, and partners are adequately protected.\n\n \n\nAs of and for the year ended December 31, 2025, there have been no\ncybersecurity incidents that have materially affected the Company’s business strategy, results of operations, or financial condition."}