{"url_path":"/sec/vtix/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C Cybersecurity.","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-25","source_url":"https://www.sec.gov/Archives/edgar/data/1606242/0001213900-26-072079-index.html","accession_number":"0001213900-26-072079","cik":"0001606242","ticker":"VTIX","issuer_name":"Virtuix Holdings Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1606242/0001213900-26-072079-index.html","primary_entity_key":"0001606242","primary_entity_name":"Virtuix Holdings Inc."},"word_count":513,"has_tables":true,"body_markdown":"Item 1C. Cybersecurity.\n\n \n\nWe conduct periodic risk assessments to identify cybersecurity threats, as well as assessments in the event of a material change in our business practices that may affect information systems that are vulnerable to such cybersecurity threats. These risk assessments include identification of reasonably foreseeable internal and external risks, the likelihood and potential damage that could result from such risks, and the sufficiency of existing policies, procedures, systems, and safeguards in place to manage such risks.\n\n \n\nFollowing these risk assessments, we redesign, implement, and maintain reasonable safeguards to minimize identified risks; address any identified gaps in existing safeguards; and regularly monitor the effectiveness of our safeguards. Primary responsibility for assessing, monitoring and managing our cybersecurity risks rests with our Chief Executive Officer and Chief Financial Officer who manage the risk assessment and mitigation process.\n\n \n\nWe engage consultants, or other third parties in connection with our risk assessment processes. These service providers assist us to design and implement our cybersecurity policies and procedures, as well as to monitor and test our safeguards. We require each third-party service provider to certify that it has the ability to implement and maintain appropriate security measures, consistent with all applicable laws, to implement and maintain reasonable security measures in connection with their work with us, and to promptly report any suspected breach of its security measures that may affect our company.\n\n \n\nWe have not encountered cybersecurity incidents that have materially impaired our operations or financial standing.\n\n \n\nGovernance\n\n \n\nOur Board addresses the Company’s cybersecurity risk management as part of its general oversight function. We maintain a cybersecurity risk management program designed to identify, assess, and manage material risks from cybersecurity threats to our information systems and the digital assets and data we handle. Our program includes periodic risk assessments, control implementation, testing, and incident response processes, and it is integrated with our broader enterprise risk management framework.\n\n \n\n*Assessment and Mitigation.*\n\n \n\nWe conduct periodic and event-driven risk assessments to identify reasonably foreseeable internal and external cybersecurity risks. Following these assessments, we implement and maintain safeguards designed to minimize identified risks and remediate gaps, including multi-factor authentication, privileged access management, network segmentation, endpoint protection, vulnerability scanning, and patch management.\n\n \n\n5\n\n \n\n*Third-party Risk Management*\n\n \n\nWe assess relevant providers’ security controls during onboarding and periodically thereafter, including certifications, audit reports, incident history, and contractual commitments to notify us of security incidents that may affect our company. We incorporate cybersecurity requirements into applicable contracts.\n\n \n\n*Governance*\n\n \n\nOur Board oversees cybersecurity risk as part of its overall risk oversight. Our Chief Executive Officer and Chief Financial Officer are responsible for implementing our cybersecurity risk management program and for coordinating incident response. Management reviews significant cybersecurity assessments and reports, allocates budgets, and approves security priorities.\n\n \n\n*Incidents*\n\n \n\nTo date, we have not experienced cybersecurity incidents that have materially affected our business strategy, results of operations, or financial condition. We maintain processes to timely escalate incidents to management where appropriate, and to evaluate whether any incident is material. If we determine that a cybersecurity incident is material, we will make required disclosures consistent with applicable SEC rules."}