VITASPRING BIOMEDICAL CO. LTD. 10-K Cybersecurity GRC - 2025-12-01

Page last updated on December 1, 2025

VITASPRING BIOMEDICAL CO. LTD. reported their cybersecurity risk management and governance process in a yearly 10-K filed on 2025-12-01 14:06:02 EST.

Filings

10-K filed on 2025-12-01

VITASPRING BIOMEDICAL CO. LTD. filed a 10-K at 2025-12-01 14:06:02 EST
Accession Number: 0001640334-25-002237

Note: filing items unformatted. Drop us a note with the above URL to help us prioritize formatting it!

Item 1C. Cybersecurity.

Item 1C. Cybersecurity. As of the date of this Annual Report, we have not yet adopted a formal, written cybersecurity risk management policy or enterprise-wide cybersecurity governance framework. However, we are aware of the growing risks associated with cybersecurity threats and are in the early stages of assessing and developing appropriate controls to identify and mitigate such risks in proportion to our size, scale, and operational complexity. We intend to implement a formal cybersecurity risk assessment and governance policy by Q1 2026. This process will include third-party vendor risk assessment, incident response protocols, and reporting mechanisms to management and the sole director. Risk management and strategy While we do not currently have dedicated cybersecurity personnel or a Chief Information Security Officer (CISO), responsibility for cybersecurity-related matters currently resides with our senior management team. Management oversees the implementation of basic safeguards, including secure login credentials, limited network access, and offsite data backups. We rely on third-party cloud-based software and IT vendors for the majority of our infrastructure and data storage, and we depend on their built-in security protocols. We have not yet experienced any known material cybersecurity incidents. However, the lack of a formal cybersecurity risk management framework may expose us to vulnerabilities that could have an adverse effect on our operations, financial position, or reputation if not appropriately addressed in the future. We are currently evaluating the need for a more structured cybersecurity program and anticipate allocating resources to strengthen our risk management processes as we grow. Governance Cybersecurity oversight is provided by our executive officers, who periodically review cybersecurity considerations as part of their general oversight of business operations and IT needs. The Board of Directors has not yet established a dedicated cybersecurity committee or delegated specific oversight responsibility to an existing committee. Cybersecurity risks, to the extent material, are discussed by management with the Board on an ad hoc basis. Our management team is responsible for monitoring industry trends, consulting with outside IT vendors, and taking basic steps to protect company systems and data. Although none of our executive officers have formal cybersecurity credentials, we recognize the importance of increasing our capabilities in this area as we scale our operations and infrastructure.


Company Information

NameVITASPRING BIOMEDICAL CO. LTD.
CIK0001697884
SIC DescriptionServices-Commercial Physical & Biological Research
Ticker
Website
Category
Emerging growth company
Fiscal Year EndJanuary 30