LENDWAY, INC. 10-K Cybersecurity GRC - 2025-03-27

Page last updated on March 27, 2025

LENDWAY, INC. reported their cybersecurity risk management and governance process in a yearly 10-K filed on 2025-03-27 16:15:33 EDT.

Filings

10-K filed on 2025-03-27

LENDWAY, INC. filed a 10-K at 2025-03-27 16:15:33 EDT
Accession Number: 0001558370-25-003816

Note: filing items unformatted. Drop us a note with the above URL to help us prioritize formatting it!

Item 1C. Cybersecurity.

Item 1C. Cybersecurity We recognize the importance of safeguarding our business operations, sensitive data, and intellectual property from cyber threats and other technological risks. Our operations involve the use of various information technology systems, including those for production management, customer order management, and financial reporting. As such, we are exposed to a range of cyber risks, including but not limited to data breaches, ransomware attacks, unauthorized access to proprietary data, and disruptions to our operations due to system failures. We are committed to maintaining an appropriate level of cybersecurity to mitigate these risks. Lendway’s cyber environment at December 31, 2024 consisted primarily of outsourced information technology (“IT”) operations. The outsourced providers have a cybersecurity framework which includes multiple products implemented to ensure the security of Lendway’s and Bloomia’s environments. Our third-party service providers alert management, specifically the CFO and CEO of Bloomia , to incidents or other concerns. Management reports significant incidents or concerns to the Audit Committee . Annual internal and external vulnerability scans are completed to ensure we mitigate any risks proactively. The Company’s internal operations are PC based and the PCs have up to date security software. Regular phishing exercises are conducted, and employee awareness training is conducted annually by our outsourced provider . The Company relies on third-party service providers for services such as IT management and payroll . These third-parties are also vulnerable to cybersecurity threats. Management actively assesses its third-parties policies related to cyber risks, including obtaining System and Organization Controls (SOC) reports, when available. Our full Board of Directors and our Audit Committee provide oversight of our risk management program, which includes cybersecurity and monitoring the performance of our third-party IT providers. The Audit Committee, as part of its charter to review the Company’s practices with respect to risk assessment and risk management, receives updates on internal control, including those relating to IT general controls and cybersecurity. Management’s Role As of the date of this report, we did not identify any cybersecurity threats, including as a result of previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect, the Company, including our business strategy, results of operations, or financial condition. However, despite our efforts, we cannot eliminate all risks from cybersecurity threats, or provide assurances that we have not experienced an undetected cybersecurity incident.


Company Information

NameLENDWAY, INC.
CIK0000875355
SIC DescriptionAgricultural Production-Crops
TickerLDWY - Nasdaq
Website
CategoryNon-accelerated filer
Smaller reporting company
Fiscal Year EndJune 29