{"url_path":"/sec/xair/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C CYBERSECURITY**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-26","source_url":"https://www.sec.gov/Archives/edgar/data/1641631/0001493152-26-030287-index.html","accession_number":"0001493152-26-030287","cik":"0001641631","ticker":"XAIR","issuer_name":"Beyond Air, Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1641631/0001493152-26-030287-index.html","primary_entity_key":"0001641631","primary_entity_name":"Beyond Air, Inc."},"word_count":944,"has_tables":true,"body_markdown":"**ITEM\n1C. CYBERSECURITY**\n\n \n\nWe\nrely on sophisticated information technology systems and network infrastructure to operate and manage our business. We also maintain\npersonally identifiable information (“PII”) about our employees, and given the nature of our business, we have access to\nprotected health information (“PHI”). Our business therefore depends on the continuous, effective, reliable, and secure operation\nof our computer hardware, software, networks, Internet servers, and related infrastructure. To the extent that our hardware or software\nmalfunctions or access to our data by internal personnel, suppliers or customers through the Internet is interrupted or compromised,\nour business could suffer.\n\n \n\nThe\nintegrity and protection of our customer, personnel, financial, research and development, and other confidential data is critical to\nour business, and our customers and employees have a high expectation that we will adequately protect their personal information. The\nregulatory environment governing information, security and privacy laws is increasingly demanding and continues to evolve and a number\nof states have adopted laws and regulations that may affect our privacy and data security practices regarding the use, disclosure and\nprotection of PII. For example, the California Consumer Privacy Act (“the CCPA”), among other things, creates individual\nprivacy rights and imposes increased obligations on companies handling PII.\n\n \n\nAlthough\nour computer and communications hardware are protected through physical and software safeguards, they are still vulnerable to system\nmalfunction, computer viruses, malware and ransomware, and other cybersecurity threats such as phishing and social engineering attacks.\nThese events could lead to unauthorized access to our information technology systems and result in financial loss and the misappropriation\nor unauthorized disclosure of confidential information belonging to us, our employees, partners, customers, or suppliers. The techniques\nused by criminal elements to attack computer systems are sophisticated, change frequently and may originate from less regulated and remote\nareas of the world. As a result, we may not be able to address these techniques proactively or implement adequate preventative measures.\nIf our information technology systems are compromised, we could be subject to fines, damages, litigation and enforcement actions, incur\nfinancial losses, suffer reputational damage, and lose trade secrets or other confidential information, each of which could significantly\nharm our business.\n\n \n\n*Cybersecurity\nProgram*\n\n \n\nGiven\nthe importance of cybersecurity to our business, we maintain a robust cybersecurity program to support both the effectiveness of our\nsystems and our preparedness for information security risks. This program includes a number of administrative, physical, and technical\nsafeguards with regular evaluations of our cybersecurity program, including periodic internal and external audits, penetration tests,\nand incident response simulations. We also require cybersecurity training when onboarding new employees and contractors, as well as required\ncybersecurity awareness training for our employees and contractors/other workforce members. Our program leverages industry frameworks,\nincluding the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) to strengthen our program effectiveness\nand reduce cybersecurity risks.\n\n \n\nWe\nuse a risk-based approach with respect to our use and oversight of third-party service providers. We use a number of means to assess\ncyber risks related to our third-party service providers, including maintaining vendor questionnaires/conducting due diligence in connection\nwith onboarding new vendors and engaging in periodic reviews thereafter as appropriate.\n\n \n\n*Process\nfor Assessing, Identifying and Managing Material Risks from Cybersecurity Threats*\n\n \n\nIn\nthe event of a cybersecurity incident, we maintain a regularly tested incident response program. Pursuant to the program and its escalation\nprotocols, designated personnel are responsible for assessing the severity of an incident and associated threat, and handling it in accordance\nwith that severity level. We have relationships with a number of third-party service providers to assist with cybersecurity containment\nand remediation efforts.\n\n \n\n*Governance*\n\n \n\nUpon\na notification of concerning factors which may be indicative that a notable cybersecurity incident has occurred, the Cyber Security Subcommittee\n(Cyber Security Subcommittee) consisting of General Counsel, Head of HR & Chief Technical Officer (CTO) meets to make an initial\nassessment. If the Cyber Security Subcommittee determines there is a reasonable likelihood a notable cybersecurity incident has occurred,\nthen notice will promptly be given to certain members of the Company Executive Team including our Chief Executive Officer, Chief Operating\nOfficer, Chief Commercial Officer & Chief Financial Officer.\n\n \n\nOur\nteam leverages over 25 years of experience in various cyber security functions. Our CTO, and their team, are responsible for the day-to-day\nmanagement of the cybersecurity program.\n\n \n\n69\n\n \n\n \n\nThe\nCTO provides periodic briefings for our senior management team on cybersecurity matters, including the prevention, detection, mitigation,\nand remediation of cybersecurity incidents and cybersecurity threats.\n\n \n\n*Board\nOversight*\n\n \n\nWhile\nthe Board of Directors has overall responsibility for risk oversight, our Audit Committee oversees cybersecurity risk matters. The Audit\nCommittee is responsible for reviewing, discussing with management, and overseeing the Company’s cybersecurity and privacy risk\nexposures and policies. On a quarterly basis, the CTO reports to the Audit Committee on information technology and cybersecurity matters,\nincluding key information technology risks. The CTO also apprises the Audit Committee and full Board of cyber security incidents consistent\nwith our incident response program, promptly.\n\n \n\n*Cybersecurity\nRisks*\n\n \n\nOur\ncybersecurity risk management processes are integrated into our overall Enterprise Risk Management (“ERM”) process. As part\nof our ERM process, department leaders identify, assess, and evaluate risks impacting our operations across the Company, including those\nrisks related to cybersecurity. Department leaders are asked to consider the severity and likelihood of certain risk factors, drawing\nupon their company knowledge and past business experience. While we maintain a robust cybersecurity program, the techniques used to infiltrate\ninformation technology systems continue to evolve. Accordingly, we may not be able to timely detect threats or anticipate and implement\nadequate security measures. For additional information, see “Item 1A—Risk Factors.” To date, we have not experienced\nany material cybersecurity incidents or threats."}