SURGE COMPONENTS INC 10-K Cybersecurity GRC - 2025-02-28

Page last updated on March 3, 2025

SURGE COMPONENTS INC reported their cybersecurity risk management and governance process in a yearly 10-K filed on 2025-02-28 16:00:30 EST.

Filings

10-K filed on 2025-02-28

SURGE COMPONENTS INC filed a 10-K at 2025-02-28 16:00:30 EST
Accession Number: 0001213900-25-018755

Note: filing items unformatted. Drop us a note with the above URL to help us prioritize formatting it!

Item 1C. Cybersecurity.

Item 1C. Cybersecurity We have developed and implemented a cybersecurity risk management program intended to protect the confidentiality, integrity, and availability of our critical systems and information. Our cybersecurity risk management program is integrated into our overall enterprise risk management program, and shares common methodologies, reporting channels and governance processes that apply across the enterprise risk management program to other legal, compliance, strategic, operational, and financial risk areas. Key elements of our cybersecurity risk management program include but are not limited to, ● risk assessments designed to help identify material risks from cybersecurity threats to our critical systems, information, services, and our broader enterprise IT environment; ● individuals, including employees and external third party service providers, who are responsible for managing our cybersecurity risk assessment processes, our security controls, and our response to cybersecurity incidents; cybersecurity incident response plan that includes procedures for responding to cybersecurity incidents; and ● a cybersecurity insurance policy in place to help mitigate monetary losses of a potential cybersecurity attack. Our management team is responsible for assessing and managing our material risks from cybersecurity threats. The team has primary responsibility for our overall cybersecurity risk management program and supervises both our internal cybersecurity personnel and our retained external cybersecurity consultants. Members of our management team have prior work experience in supervising and implementing cybersecurity risk mitigation efforts in highly-regulated industries. Our internal cybersecurity personnel and retained external cybersecurity consultants also have a breadth of expertise across core cybersecurity disciplines including governance, risk, compliance, and security architecture. Our management team takes steps to stay informed and monitors efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include briefings from internal security personnel; threat intelligence and other information obtained from governmental, public or private sources, including external consultants engaged by us; and alerts and reports produced by security tools deployed in the IT environment Our Board considers cybersecurity risk as part of its risk oversight function and receives regular updates from the management team on our cybersecurity risks and in addition, management updates the Board where it deems appropriate, regarding any cybersecurity incidents it considers to be significant or potentially significant.


Company Information

NameSURGE COMPONENTS INC
CIK0000747540
SIC DescriptionWholesale-Electronic Parts & Equipment, NEC
TickerSPRS - OTC
Website
CategoryNon-accelerated filer
Smaller reporting company
Fiscal Year EndNovember 29