VIP Play, Inc. 10-K Cybersecurity GRC - 2025-09-29

Page last updated on September 29, 2025

VIP Play, Inc. reported their cybersecurity risk management and governance process in a yearly 10-K filed on 2025-09-29 17:05:14 EDT.

Filings

10-K filed on 2025-09-29

VIP Play, Inc. filed a 10-K at 2025-09-29 17:05:14 EDT
Accession Number: 0001493152-25-016043

Note: filing items unformatted. Drop us a note with the above URL to help us prioritize formatting it!

Item 1C. Cybersecurity.

Item 1C. Cybersecurity Risk Management and Strategy The Company maintains policies, procedures, and technical safeguards designed to protect its network infrastructure, segregate environments, and monitor for potential cybersecurity threats. Our approach aligns with ISO/IEC 27001:2022 standards and includes: ● Intrusion Detection and Monitoring - We utilize cloud-native IDS/IPS services and firewall-based alerting to monitor traffic for suspicious activity. Alerts are reviewed daily, and high-risk alerts trigger immediate escalation under our Incident Response procedures. IDS/IPS configurations are reviewed and tuned on a quarterly basis. ● Firewall Rule Management - All ingress and egress traffic is filtered through firewalls or security groups, following a default-deny principle. Firewall rule changes require approval by the Security team and are documented. Rules are reviewed at least annually and following major system changes. ● Network Segmentation - Logical separation is maintained between production, staging, development, and internal environments through VPCs, VLANs, or subnet segmentation. Administrative access is segregated from user-facing systems, with restricted access to shared infrastructure. These measures are designed to reduce the risk of unauthorized access and support the confidentiality, integrity, and availability of our systems and customer data. We maintain documentation of firewall changes, alert logs, network segmentation diagrams, and annual testing to evidence compliance. Governance Oversight of cybersecurity is integrated into our enterprise risk management program. The Company’s Chief Technology Officer (CTO) serves as the control owner for network security and provides regular updates to senior management. The Security team, in coordination with IT and Infrastructure administrators, is responsible for: ● Configuring and maintaining intrusion detection/prevention systems and firewall monitoring tools. ● Reviewing alerts daily and investigating potential incidents. ● Approving firewall changes and overseeing segmentation enforcement. ● Conducting annual reviews of network security controls. The Board of Directors receives updates regarding the Company’s cybersecurity posture and material risks, including matters relating to network protection, firewall management, and incident response readiness. Assessment and Oversight The Company performs annual reviews and penetration testing of network controls, with results shared with senior management. Third-party connections (e.g., payment processors, monitoring tools) are subject to access restrictions through IP allowlisting or VPN requirements. The Company will continue to monitor and enhance its network security controls and allocate resources to mitigate future risk.


Company Information

NameVIP Play, Inc.
CIK0001832161
SIC DescriptionRetail-Miscellaneous Retail
TickerVIPZ - OTC
Website
Category
Emerging growth company
Fiscal Year EndJune 29