CXApp's 10-K Item 1C disclosure describes its cybersecurity risk management and governance framework, including ISO 27001 and SOC 2 alignment, annual risk assessments, and Board oversight. The Company explicitly states that as of December 31, 2025, it was not aware of any cybersecurity threats that have materially affected or are reasonably likely to materially affect its business, results of operations, or financial condition. No specific incident, breach, or material impact is reported.