{"url_path":"/sec/uamy/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C Cybersecurity.**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-03-19","source_url":"https://www.sec.gov/Archives/edgar/data/101538/0001104659-26-032049-index.html","accession_number":"0001104659-26-032049","cik":"0000101538","ticker":"UAMY","issuer_name":"UNITED STATES ANTIMONY CORP","edgar_url":"https://www.sec.gov/Archives/edgar/data/101538/0001104659-26-032049-index.html","primary_entity_key":"0000101538","primary_entity_name":"UNITED STATES ANTIMONY CORP"},"word_count":599,"has_tables":true,"body_markdown":"**Item 1C. Cybersecurity.**\n\n**Risk Management and Strategy**\n\nOur cybersecurity strategy prioritizes detection, analysis and response to known, anticipated or unexpected threats, effective management of security risks, and resiliency against incidents. Our cybersecurity risk management processes include assessing and monitoring security controls, monitoring systems, tools and related services provided by third-party providers, and management oversight to assess, identify and manage material risks from cybersecurity threats.\n\nIn 2025, we established a dedicated internal leadership role by hiring a Managing Director of Information Technology to oversee the security and maintenance of our digital assets and infrastructure. The Managing Director of Information Technology is responsible for coordinating cybersecurity risk management activities across the Company, including oversight of third-party service providers engaged to support cybersecurity functions.\n\nWe implement risk-based controls to protect our information, the information of our customers, suppliers, and other third parties, our information systems, our business operations, and our products. We maintain security programs that include physical and technical safeguards. We monitor cybersecurity vulnerabilities and potential attacks, and we evaluate the potential operational and financial effects\n\n31\n\n[Table of Contents](#TOC)\n\nof any threat and of cybersecurity countermeasures made to defend against such threats, including consideration of the potential materiality of such threats to our business, results of operations, or financial condition.\n\nWe continue to integrate our cyber practices into our enterprise risk management practices, which is overseen by our Board of Directors. In addition, we assess the risks from cybersecurity threats, periodically engage third-party tools to assist us in enhancing and monitoring our cybersecurity risks, including tools designed to detect and mitigate phishing and suspicious email activity, and regularly back up company information.\n\nWe have experienced cybersecurity incidents, primarily related to phishing emails, and may in the future experience, whether directly or indirectly, cybersecurity incidents. While prior incidents have not materially affected our business strategy, results of operations, or financial condition, there is no guarantee that a future cyber incident would not materially affect our business strategy, results of operations, or financial condition. See risks related to cybersecurity and business disruptions in “Risk Factors” in this Form 10-K.\n\n**Governance**\n\nOur Board of Directors is responsible for risk oversight, including oversight of risks related to cybersecurity. Our chief executive officer and chief financial officer, with input from and participation by, as appropriate, our Managing Director of Information Technology, provide presentations to the Board of Directors regarding cybersecurity risks, incidents, and risk management practices periodically and as circumstances warrant.\n\nIn the event of a potentially material cybersecurity event, the Chairman of the Board is notified and briefed, and a meeting of the full Board of Directors would be convened, as appropriate, to review the incident, management’s response, and any required disclosures.\n\nManagement, including the Managing Director of Information Technology discuss information technology needs and activity and assess and manage material cybersecurity risks and the Company’s practices for the prevention, detection, mitigation, and remediation of cybersecurity incidents, as necessary and appropriate. The Managing Director of Information Technology reports to executive management and is responsible for day-to-day oversight of the Company’s cybersecurity risk management processes, including coordination with third-party service providers.\n\nOur Managing Director of Information Technology has approximately 20 years of experience in information technology leadership roles, including serving as Director of IT at four previous companies. Our CEO and CFO have managed information technology departments during their careers. Our CFO was trained as an auditor and an information technology auditor at the public accounting firm of Ernst & Young LLP and audited internal controls, including IT controls, of public companies, information technology departments, and third-party information technology service providers for approximately 12 years."}