{"url_path":"/sec/wast/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C CYBERSECURITY**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-07-14","source_url":"https://www.sec.gov/Archives/edgar/data/1515139/0001493152-26-033196-index.html","accession_number":"0001493152-26-033196","cik":"0001515139","ticker":"WAST","issuer_name":"WASTE ENERGY CORP.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1515139/0001493152-26-033196-index.html","primary_entity_key":"0001515139","primary_entity_name":"WASTE ENERGY CORP."},"word_count":620,"has_tables":true,"body_markdown":"**ITEM\n1C. CYBERSECURITY**\n\n** **\n\n**Risk\nManagement and Strategy**\n\n** **\n\nWe\nrecognize the importance of protecting our information assets and of maintaining the confidentiality, integrity, and availability of\nour information technology (“IT”) systems and, as our operations develop, our operational technology (“OT”) systems.\nWe are in the early stages of building out our operating infrastructure, and our cybersecurity program is correspondingly in an early\nstage of development. Our current program and planned program elements are designed to identify, assess, and manage material cybersecurity\nrisks on a basis that is proportionate to our size, stage of development, and resources.\n\n \n\nKey\ncurrent and planned elements of our cybersecurity program include:\n\n \n\n●**Risk\nAssessment.** We conduct periodic assessments of potential cybersecurity threats and vulnerabilities\nto our IT systems, taking into account the evolving threat landscape and our operational\nfootprint. As our Midland, Texas facility is commissioned and our OT systems (including any\nindustrial control, SCADA, and distributed control systems) become operational, we intend\nto expand our assessment program to cover those systems.\n\n●**Security\nControls.** We use commercially available security tools and practices, including access\ncontrols, multi-factor authentication where supported, antivirus and endpoint protection\nsoftware, firewalls, encryption of sensitive data in transit and at rest, and regular data\nbackups. As our operations scale, we plan to adopt additional layered controls, including\nnetwork segmentation between IT and OT environments, intrusion detection, and enhanced identity\nmanagement.\n\n●**Incident\nResponse.** We are developing an incident response plan designed to provide for the detection,\ncontainment, eradication, recovery from, and post-incident review of cybersecurity incidents.\nOur executive officers are responsible for evaluating the materiality of any cybersecurity\nincident and for reporting material incidents to our Board of Directors and, as applicable,\nfor disclosure under SEC rules.\n\n●**Third-Party\nRisk Management.** We engage consultants and vendors that support our accounting, information\ntechnology, and public-reporting functions. We seek to assess the cybersecurity practices\nof material third-party providers and, where appropriate, to address cybersecurity expectations\nthrough contractual arrangements.\n\n●**Training\nand Awareness.** Given our small size, cybersecurity awareness is addressed through direct\ncommunication with our executive officers and consultants. As our workforce expands, we intend\nto adopt a formal cybersecurity awareness and training program.\n\n●**Use\nof Outside Advisors.** We expect to engage outside advisors, as needed, to support specific\ncybersecurity projects, incident response, or assessments.\n\n \n\nAs\nof the date of this Annual Report, we are not aware of any cybersecurity incident that has materially affected, or is reasonably likely\nto materially affect, our business strategy, results of operations, or financial condition. However, cybersecurity risks cannot be eliminated,\nand there can be no assurance that our program will prevent all incidents or identify all material risks. See also the risk factor titled\n“Our planned waste-to-energy facilities may represent critical infrastructure that could be targeted by cyberattacks” below.\n\n \n\n**Governance**\n\n** **\n\nOur\nBoard of Directors has general oversight responsibility for our risk management program, including cybersecurity risk. Management reports\nto the Board on cybersecurity matters on a periodic basis and in connection with material events. Given our small size and stage of development,\nwe have not yet established a separate cybersecurity committee, and we have not yet designated a dedicated chief information security\nofficer. Our Chief Financial Officer, in consultation with our President and with support from outside consultants, is primarily responsible\nfor day-to-day oversight of our cybersecurity program, including the identification and management of cybersecurity risks, the evaluation\nof cybersecurity incidents, and the reporting of material matters to the Board.\n\n \n\nAs\nour operations and resources grow — including upon the commissioning of our Midland facility and any subsequent facility deployments\n— we expect to enhance our cybersecurity governance structure, which may include the engagement of additional cybersecurity personnel,\nthe formal designation of a cybersecurity officer, and the expansion of Board-level oversight.\n\n \n\n13"}