Hour Loop, Inc 10-K Cybersecurity GRC - 2025-03-27

Page last updated on March 27, 2025

Hour Loop, Inc reported their cybersecurity risk management and governance process in a yearly 10-K filed on 2025-03-27 16:10:20 EDT.

Filings

10-K filed on 2025-03-27

Hour Loop, Inc filed a 10-K at 2025-03-27 16:10:20 EDT
Accession Number: 0001641172-25-000930

Note: filing items unformatted. Drop us a note with the above URL to help us prioritize formatting it!

Item 1C. Cybersecurity.

ITEM 1C. CYBERSECURITY Cybersecurity Risk Management and Strategy The cybersecurity risk management program, processes and strategy outlined in this section are limited to the personal and business information belonging to or maintained by the Company (collectively, “Confidential Information”), the Company’s critical third-party systems and services supporting or used by the Company (collectively, “Critical Systems”), and service providers. We will develop and implement a cybersecurity risk management program to safeguard the confidentiality, integrity, and availability of our Confidential Information and Critical Systems. Our cybersecurity risk management program will be integrated into our broader enterprise risk management framework and includes a cybersecurity incident response plan. Our cybersecurity risk management program shall include: ● risk assessments to identify material cybersecurity risks to our Confidential Information, Critical Systems and broader enterprise IT environment; ● a dedicated security team responsible for managing (1) cybersecurity risk assessment processes, (2) security controls, and (3) response to cybersecurity incidents; ● cybersecurity awareness training including spear-phishing resistance for employees, and senior management; ● a cybersecurity incident response plan outlining procedures for detecting, responding to, and mitigating cybersecurity incidents; and ● a vendor management policy to oversee cybersecurity risks associated with service providers. 35 We have no t identified any known cybersecurity threats, including prior incidents, that have materially affected or are reasonably likely to materially affect our operations, business strategy, results of operations, or financial condition. However, we recognize that cybersecurity threats pose ongoing risks which, if realized, could have a material adverse impact on our business, financial condition and results of operations. Cybersecurity Governance Our executive management team, in collaboration with our managed information technology service provider, is responsible for assessing and managing cybersecurity risks to the Company, including our Confidential Information and Critical Systems. The team holds primary responsibility for our cybersecurity risk management program and works closely with our IT service provider to ensure its effective implementation. Our management team meets regularly with our IT service provider to review current cybersecurity issues. These discussions may cover efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, including: ● threat intelligence from governmental, public private, and external sources ● alerts and reports generated by security tools deployed in the IT environment, including a spear-phishing report. Our Board incorporates cybersecurity risks into its broader risk oversight responsibility . Our Board oversees the implementation of our cybersecurity risk management program. The executive management team provides updates to the Board, as needed, on significant cybersecurity incidents. Our Board receives periodic reports from management on cybersecurity risks and the cybersecurity risk management program.


Company Information

NameHour Loop, Inc
CIK0001874875
SIC DescriptionRetail-Catalog & Mail-Order Houses
TickerHOUR - Nasdaq
Website
CategoryNon-accelerated filer
Smaller reporting company
Emerging growth company
Fiscal Year EndDecember 30