{"url_path":"/sec/sgrp/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C Cybersecurity**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-03-31","source_url":"https://www.sec.gov/Archives/edgar/data/1004989/0001437749-26-010508-index.html","accession_number":"0001437749-26-010508","cik":"0001004989","ticker":"SGRP","issuer_name":"SPAR Group, Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1004989/0001437749-26-010508-index.html","primary_entity_key":"0001004989","primary_entity_name":"SPAR Group, Inc."},"word_count":800,"has_tables":true,"body_markdown":"**Item 1C. Cybersecurity**\n\n \n\nSPAR Group Inc. recognizes the increased cybersecurity threats and sophisticated, targeted computer crime and the risk it poses to our operations. We rely on information technology and data to operate our business and develop, market and deliver our products and services to our customers.\n\n \n\nOur cybersecurity risk management program is led by our Chief Technology Officer (“CTO”), who is directly responsible for establishing cybersecurity strategies and structures and managing ongoing cybersecurity risk management activities. Our CTO is part of the executive management team, and updates our CEO and executive management periodically on the cybersecurity enhancement and the development and implementation of our roadmap.\n\n \n\nWe have strategically embedded cybersecurity risk management within an enterprise-wide framework, ensuring that it permeates across various facets of our operations. This integrated approach encompasses administrative protocols, operational strategies, organizational structures, physical safeguards, and technical measures, all tailored to align with the scope and nature of our business.\n\n \n\n***Cybersecurity Risk Management and Strategy***\n\n \n\nWe believe this integrated approach allows cybersecurity considerations to be an integral part of our decision-making processes. Our day-to-day cybersecurity work is led by our CTO and a managed services provider with expertise in mitigating cyber risk. The CTO works closely with our executive management to continuously evaluate and address cybersecurity risks in alignment with our business and operational needs.\n\n \n\nCybersecurity risks related to our business, technical operations, privacy and compliance issues are identified and addressed through a combination of third-party assessments, internal audit, IT security, governance, risk and compliance reviews. To defend, detect and respond to cybersecurity incidents, we, among other things:\n\n \n\n \n●\nProactively review threat intelligence and other information obtained from governmental, public or private sources,\n\n \n●\n\nPerform network vulnerability scans, cyber-hygiene assessments, and continually evaluate and address perceived gaps,\n\n \n●\n\nConduct companywide cyber awareness training and on-going new employee cyber training,\n\n \n●\n\nDeploy a wide array of industry leading *3rd* party solutions to continuously monitor network and endpoints,\n\n \n●\n\nOn-going testing and evaluation of backup processes,\n\n \n●\n\nPerform disaster recovery tabletop exercises to assess readiness for possible events.\n\n \n\n*11*\n\n \n\n \n\nAs noted, to operate our business, we utilize certain *third*-party service providers to perform a variety of functions and provide certain security-related services, such as outsourced business critical functions, professional services, SaaS platforms, managed services, cloud-based infrastructure, data center facilities, content delivery to customers, encryption and authentication technology, corporate productivity services, and other functions; as well as third parties that assist us to identify, assess and manage cybersecurity risks, including professional services firms, threat intelligence service providers, cybersecurity software providers, penetration testing firms and other vendors that help to identify, assess or manage cybersecurity risks.\n\n \n\nIn addition, we have implemented an incident response and breach management plan which has *four* overarching and interconnected stages:\n\n \n\n \n●\n\nDetection of a security incident,\n\n \n●\n\nIdentification and containment,\n\n \n●\n\nResponse, eradication and recovery,\n\n \n●\n\nPost-incident analysis and future preparations.\n\n \n\nThe plan also provides the process and workflow of communication for escalation of incidents to executive leadership to determine incident classification, impact severity, and if and what further actions are warranted. Incident responses are overseen by leaders from our internal Information Technology organization and *third* party managed services provider.\n\n \n\n***Cybersecurity Governance***\n\n \n\nCybersecurity holds a significant role within our risk management procedures and remains a focal point for our Board and management. Under the Board's oversight of general risk identification and management activities, the Audit Committee monitors cybersecurity risks. Committee members engage in comprehensive discussions with management regarding these risks, as well as the measures taken to safeguard the Company's information systems and security, along with reviewing management's steps towards data privacy protection. Additionally, the Audit Committee receives annual cybersecurity updates from senior management, covering both existing and emerging risks, management's responses and mitigation efforts, any cybersecurity or data privacy incidents, and the status of key information security initiatives. Furthermore, our Board members regularly hold informal discussions with management about cybersecurity news events and any updates to our cybersecurity risk management and strategy programs.\n\n \n\nOur *third* party managed services providers offer insights and guidance to our Software, Infrastructure Engineering, and Executive teams. With backgrounds spanning: information technology, security, systems, programming, and corporate strategy, their team is equipped to oversee prevention, detection, mitigation, and remediation of cybersecurity incidents. They actively engage in managing our cybersecurity risk processes, including participating in our incident response plan, and regularly report relevant matters to the Chief Technology Officer and the Audit Committee.\n\n \n\nWe carry insurance that provides protection against the potential losses arising from a cybersecurity incident. However, there is *no* assurance that our insurance coverage will cover, or be sufficient to cover, all losses or claims that *may*result from a cybersecurity incident.\n\n \n\n***Last year***\n\n \n\nDuring the last fiscal year, *2025,* the Company did *not* encounter any material cybersecurity incidents, nor did it incur any notable expenses as a result."}