BLUE DOLPHIN ENERGY CO 10-K Cybersecurity GRC - 2025-04-01

Page last updated on April 1, 2025

BLUE DOLPHIN ENERGY CO reported their cybersecurity risk management and governance process in a yearly 10-K filed on 2025-04-01 16:39:27 EDT.

Filings

10-K filed on 2025-04-01

BLUE DOLPHIN ENERGY CO filed a 10-K at 2025-04-01 16:39:27 EDT
Accession Number: 0001437749-25-010478

Note: filing items unformatted. Drop us a note with the above URL to help us prioritize formatting it!

Item 1C. Cybersecurity.

ITEM 1C. CYBERSECURITY We depend on information technology and systems for various operations (including refinery processes and refined product loading) and for capturing accounting, technical, and regulatory data for reporting, analysis, and archiving. Our primary business systems mostly consist of purchased and licensed software programs that integrate with our internal solutions. As of the filing date of this report, our risk monitoring process related to cybersecurity includes conducting periodic vulnerability assessments using a combination of internal and third-party capabilities to perform technical assessments, vulnerability scanning, and incident and event monitoring. We are working to: (i) identify and assess threats and (ii) establish a thorough, risk-based cybersecurity program, including the potential adoption of a formal cybersecurity policy if deemed necessary by the Board, aimed at safeguarding our data, along with the data of our customers and partners. We anticipate that such a program will follow well-organized cybersecurity frameworks and be managed by a central control figure with Board oversight. We did not experience a significant cybersecurity breach or associated expenses, penalties, or settlements for the twelve months ended December 31, 2024 and 2023.


Company Information

NameBLUE DOLPHIN ENERGY CO
CIK0000793306
SIC DescriptionCrude Petroleum & Natural Gas
TickerBDCO - OTC
Website
CategoryNon-accelerated filer
Smaller reporting company
Fiscal Year EndDecember 30