{"url_path":"/sec/ug/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C **","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-03-27","source_url":"https://www.sec.gov/Archives/edgar/data/101295/0001171843-26-001973-index.html","accession_number":"0001171843-26-001973","cik":"0000101295","ticker":"UG","issuer_name":"UNITED GUARDIAN INC","edgar_url":"https://www.sec.gov/Archives/edgar/data/101295/0001171843-26-001973-index.html","primary_entity_key":"0000101295","primary_entity_name":"UNITED GUARDIAN INC"},"word_count":521,"has_tables":true,"body_markdown":"**Item 1C.**\n\n**Cybersecurity.**\n\n \n\n \n\nWe continue to augment the capabilities of our people, processes, and technologies to address our cybersecurity risks. Our cybersecurity risks, and the controls designed to mitigate those risks, are integrated into our overall risk management governance and are reviewed yearly by our Board of Directors.\n\n \n\nWe take steps to protect our data and third-party data we receive through the implementation of technological and organizational measures designed to reduce the risk from cybersecurity threats, including data theft or destruction.\n\n \n\nWe have undertaken a program of annual enterprise-wide cybersecurity risk assessments and have implemented policies, procedures, and programs designed to help manage the risks to which we are exposed in our business. As part of our risk management process, we have implemented a risk-based approach to identify and assess the cybersecurity threats that could affect our business and information systems, as well as the systems of third parties on whom we rely, such as any cloud hosting partners. Our cybersecurity program is designed to assess, identify, and manage material risks and vulnerabilities to our security posture, including prioritizing and remediating cybersecurity risks.\n\n \n\nOur program includes, among other things:\n\n \n\n• Incorporation of cybersecurity in our overall enterprise risk management processes, including periodic risk assessments and tools used to track and monitor risks.\n\n \n\n• Regular reviews of cybersecurity risks and mitigation efforts.\n\n \n\n• Use of software and hardware tools and services to help safeguard our systems, information, and data.\n\n \n\n• Assessments designed to help identify cybersecurity risks to our critical systems, information, products, services, and our broader enterprise IT environment.\n\n \n\n• An employee information security training program to educate employees on various cybersecurity risks and mitigation strategies.\n\n \n\n• Policies and processes governing our third-party security risks.\n\n \n\n**Risk Management and Strategy**\n\n \n\nWe have implemented a set of comprehensive cybersecurity and data protection policies and procedures. Risks from cybersecurity threats are regularly evaluated as a part of our broader risk management activities and as a fundamental component of our internal control system. Our employees receive ongoing cybersecurity awareness training, including specific topics related to social engineering and email fraud. We utilize an outsourced information technology firm and consultants with significant expertise in cybersecurity. We invest in advanced technologies for continuous cybersecurity monitoring across our information technology environment which are designed to prevent, detect, and minimize cybersecurity attacks, as well as alert management of such attacks.\n\n \n\n16\n\n \n\n \n\nOur Information Technology General Controls are firmly established based on the National Institute of Standards and Technology (“NIST”) cybersecurity framework and cover areas such as risk management, data backup, and disaster recovery. We have utilized an outsourced information technology consultant to reduce and monitor security threats and vulnerabilities.  As part of our gap analysis, identified vulnerabilities have been, and will continue to be, promptly addressed with our senior business leadership and our Board of Directors. \n\n \n\n \n\n**Governance**\n\n \n\nOur Board of Directors is responsible for overseeing our cybersecurity risk management and strategy. Our President regularly meets with and provides periodic briefings to our Board of Directors regarding our cybersecurity risks and activities, including any recent cybersecurity incidents and related responses, cybersecurity systems testing, activities of third parties, and the like."}