Mag Mile Capital, Inc. 10-K Cybersecurity GRC - 2024-04-16

Page last updated on July 16, 2024

Mag Mile Capital, Inc. reported their cybersecurity risk management and governance process in a yearly 10-K filed on 2024-04-16 18:04:05 EDT.

Filings

10-K filed on 2024-04-16

Mag Mile Capital, Inc. filed a 10-K at 2024-04-16 18:04:05 EDT
Accession Number: 0001493152-24-014911

Note: filing items unformatted. Drop us a note with the above URL to help us prioritize formatting it!

Item 1C. Cybersecurity.

ITEM 1C. CYBERSECURITY We use, store and process data for and about our customers, employees, partners and suppliers. We have implemented a cybersecurity risk management program that is designed to identify, assess, and mitigate risks from cybersecurity threats to this data, our systems and business operations. Cyber Risk Management and Strategy Under the oversight of the Board of Directors since we do not currently have an Audit Committee, we have implemented and maintain a risk management program that includes processes for the systematic identification, assessment, management, and treatment of cybersecurity risks. Our cybersecurity oversight and operational processes are integrated into our overall risk management processes, and cybersecurity is one of our designated risk categories. We use the National Institute of Standards and Technology Cybersecurity Framework to guide our approach, ensuring a structured and comprehensive strategy for managing cybersecurity risks. We implement a risk-based approach to the management of cyber threats, supported by cybersecurity technologies, including automated tools, designed to monitor, identify, and address cybersecurity risks. In support of this approach, our IT security team implements processes to assess, identify, and manage security risks to the company, including in the pillar areas of security and compliance, application security, infrastructure security, and data privacy. This process includes regular compliance and critical system access reviews. In addition, we conduct application security assessments, vulnerability management, penetration testing, security audits, and ongoing risk assessments as part of our risk management process. We also maintain an incident response plan to guide our processes in the event of an incident. We also have a process to require corporate employees to undertake cybersecurity training and compliance programs annually. 16 We utilize third parties and consultants to assist in the identification and assessment of risks, including to support tabletop exercises and to conduct security testing. We utilize well-known cloud-based technologies and service providers such as GoDaddy, Microsoft Office, and DropBox enterprise to provide protection against cybersecurity threats. We have a special email encryption from GoDaddy that protect against cyberthreats. Further, we have processes in place to evaluate potential risks from cybersecurity threats associated with our use of third-party service providers that will have access to our data, including a review process for such providers’ cybersecurity practices, risk assessments, contractual requirement, and system monitoring. We continue to evaluate and enhance our systems, controls, and processes where possible, including in response to actual or perceived threats specific to us or experienced by other companies. Although risks from cybersecurity threats have to date not materially affected us, our business strategy, results of operations or financial condition, we have, from time to time, experienced threats to and breaches of our and our third-party vendors’ data and systems. For more information, please see Item 1A. Risk Factors, the section titled “Risk Factors-Risks Related to our Information Technology, Cybersecurity and Data Protection- Failure to maintain the security of our information and technology networks, including personal information and other client information, intellectual property and proprietary business information could materially adversely affect us .” Risk Management Oversight and Governance The Board of Directors has oversight of the Company’s cybersecurity program. Our IT Administrator oversees our information security program and leads our information security team. Our IT Administrator has primary responsibility for assessing and managing our cybersecurity threat management program, informed by over five years of experience leading cross-functional organizations in the development and operation of large-scale systems. Our IT Administrator reports quarterly to our Board of Directors on the information security program and related cyber risks and provides an annual update to the Board of Directors on our overall risk management strategy, which includes addressing cybersecurity risks. Any cybersecurity incidents at the Company are reported to the Board of Directors by the IT Administrator.


Company Information

NameMag Mile Capital, Inc.
CIK0001879293
SIC DescriptionIndustrial Process Furnaces & Ovens
TickerMMCP - OTC
Website
CategoryNon-accelerated filer
Smaller reporting company
Emerging growth company
Fiscal Year EndDecember 30