20-F/A: Polyrizon Amends 20-F, Confirms Controls Effective
Annual Report Amendment
Polyrizon Ltd. filed an amendment to its 2025 annual report to confirm the effectiveness of its disclosure controls and procedures, while also detailing past cybersecurity incidents.
Summary
- Polyrizon Ltd. filed an Amendment No. 1 on Form 20-F/A to its annual report for the fiscal year ended December 31, 2025, originally filed on March 25, 2026.
- The amendment primarily revises management's conclusion regarding the effectiveness of the company's disclosure controls and procedures (Item 15(a)).
- Management, including the Chief Executive Officer and Chief Financial Officer, concluded that disclosure controls and procedures were effective as of December 31, 2025.
- Management also concluded that internal control over financial reporting was effective as of December 31, 2025, based on the COSO (2013) framework.
- The company was a victim of Business Email Compromise (BEC) fraud in October 2025, resulting in a fraudulent wire transfer of approximately $464,000.
- A subsequent attempted fraud in December 2025 led to the discovery of unauthorized access to a management member's email account, including unauthorized mail-forwarding rules.
- Remedial actions included re-securing the impacted email account, removing unauthorized mail-forwarding rules, and implementing new wire transfer verification policies.
- The cybersecurity incidents did not have a material impact on the company's business, financial condition, or results of operations as of the report date, though additional costs may be incurred.
- Audit fees for 2025 were $100,000, audit-related fees were $50,000, and tax fees were $20,154, totaling $170,154.
- As a foreign private issuer, Polyrizon follows Israeli corporate governance practices instead of certain Nasdaq rules regarding quorum, officer compensation, shareholder approval, related party transactions, annual meetings, report distribution, equity compensation plans, and director nominations.
Sentiment
Score: 4
Explanation: StockSavvy.ai views this filing with caution. While the company has corrected its disclosure controls assessment and implemented remediation for cybersecurity incidents, the actual financial loss and the initial failure to detect email account compromise are significant concerns, partially offset by the non-material impact on overall financials.
Positives
- Management concluded that disclosure controls and procedures were effective as of December 31, 2025, correcting a prior oversight.
- Management concluded that internal control over financial reporting was effective as of December 31, 2025.
- The company successfully identified and prevented a second attempted fraudulent transfer in December 2025.
- Remedial actions, including enhanced wire transfer verification policies and re-securing email accounts, have been implemented following the cybersecurity incidents.
- The cybersecurity incidents did not have a material impact on the company's business, financial condition, or results of operations as of the report date.
Negatives
- The company was a victim of Business Email Compromise (BEC) fraud in October 2025, resulting in a loss of approximately $464,000.
- Unauthorized access to a management member's email account, including unauthorized mail-forwarding rules, was discovered following the second attempted fraud in December 2025.
- The initial assessment in October 2025 incorrectly determined there had been no third-party access to the email account.
- The company may incur additional costs in connection with the investigation, remediation efforts, and any related recovery actions from the cybersecurity incidents.
Risks
- Risk of computer system failures, cyber attacks, or deficiencies in cybersecurity, as referenced in Item 3.D Risk Factors.
- Potential for future financial losses or operational disruptions due to sophisticated cyber threats.
- Incurrence of additional costs for investigation, remediation, and recovery actions related to cybersecurity incidents.
- Reliance on third-party providers for IT systems and cybersecurity monitoring introduces vendor risk.
- Inherent limitations of internal controls over financial reporting, which may not prevent or detect all misstatements.
Future Outlook
The company anticipates potential additional costs related to the investigation, remediation efforts, and recovery actions stemming from the cybersecurity incidents, but does not expect a material impact on its business, financial condition, or results of operations as of the report date.
Management Comments
- "Our management, with the participation of our Chief Executive Officer and Chief Financial Officer, has evaluated the effectiveness of our disclosure controls and procedures... and concluded that... our disclosure controls and procedures are effective."
- "Our management concluded that our internal control over financial reporting was effective as of December 31, 2025."
- "The incident did not have a material impact on our business, financial condition or results of operations as of the date of this annual report; however, we may incur additional costs in connection with the investigation, remediation efforts and any related recovery actions."
Industry Context
StockSavvy.ai notes that cybersecurity threats, particularly Business Email Compromise (BEC) attacks, remain a pervasive and evolving risk across all industries, especially for companies handling financial transactions. Polyrizon's experience highlights the critical need for robust internal controls and continuous vigilance, a challenge many smaller and emerging growth companies face in allocating sufficient resources compared to larger, more established industry players.
Comparison to Industry Standards
- Polyrizon's audit fees of $100,000 for 2025 are within the typical range for an emerging growth company, though specific comparisons would require detailed revenue and asset size data. For instance, a small biotech firm like Aytu BioPharma reported audit fees of $150,000 in a recent 10-K, while a larger firm like Moderna reported audit fees in the millions.
- The company's adoption of Israeli corporate governance practices as a foreign private issuer is standard for companies incorporated in Israel and listed on Nasdaq, such as Teva Pharmaceutical Industries Ltd. or Check Point Software Technologies Ltd., which also utilize these exemptions.
- The cybersecurity incidents, particularly the BEC fraud resulting in a $464,000 loss, are unfortunately common across industries. For example, the FBI's Internet Crime Report consistently shows BEC as one of the costliest cybercrimes, with reported losses in the billions annually across various sectors. Polyrizon's swift remediation and engagement with authorities align with best practices for incident response.
Corporate Governance
| Change Type | Description | Effective Date | Impact Assessment |
|---|---|---|---|
| Disclosure Controls and Procedures Evaluation | Management revised its conclusion, now stating that disclosure controls and procedures were effective as of December 31, 2025, correcting an inadvertent omission in the original filing. | 2025-12-31 | Enhances confidence in the accuracy and timeliness of financial reporting, addressing a prior oversight. |
| Internal Control over Financial Reporting Evaluation | Management concluded that internal control over financial reporting was effective as of December 31, 2025, based on the COSO (2013) framework. | 2025-12-31 | Indicates a sound framework for reliable financial reporting, crucial for investor confidence. |
| Cybersecurity Policy Enhancement | Implemented a new wire transfer verification policy requiring out-of-band authentication and reconfirmation of supplier banking details, along with bank confirmation for wire transfers, following fraud incidents. | 2025-10-01 | Strengthens financial security and reduces the risk of future fraudulent transfers, protecting company assets. |
| Email Account Security Remediation | Re-secured an impacted management email account, including removal of unauthorized mail-forwarding rules, after discovering unauthorized access. | 2025-12-01 | Mitigates the risk of further email-based fraud and unauthorized information access. |
| Audit Committee Composition | Audit Committee is comprised of Mr. Yehonatan Zalman Vinokur, Mr. Assaf Itzhaik (Chair), and Ms. Liat Sidi, all determined to be financially literate, independent, financially sophisticated, and financial experts. | NA | Ensures robust oversight of financial reporting and internal controls, meeting high governance standards. |
| Code of Business Conduct and Ethics Adoption | Adopted a Code of Business Conduct and Ethics applicable to all directors and employees, including executive officers. | NA | Establishes clear ethical guidelines and promotes a culture of integrity within the company. |
| Foreign Private Issuer Governance Practices | The company elects to follow Israeli corporate governance practices instead of certain Nasdaq rules regarding quorum, officer compensation, shareholder approval, related party transactions, annual meetings, report distribution, equity compensation plans, and director nominations. | NA | Aligns governance with home country regulations, potentially offering flexibility but requiring investors to understand differences from U.S. domestic issuer standards. |
Stakeholder Impact
- Shareholders: The correction of disclosure controls and the detailed cybersecurity incidents provide greater transparency, but the financial loss from fraud and the initial oversight could raise concerns about internal controls and risk management. The adherence to Israeli corporate governance practices may differ from expectations of U.S. investors.
- Employees: The implementation of enhanced cybersecurity protocols may require additional training or adherence to new procedures.
- Customers/Business Partners: The company's commitment to cybersecurity and data protection, despite the incidents, aims to maintain trust and confidence.
- Creditors: The $464,000 loss, while not deemed material to overall financials, represents a reduction in assets that could be a minor concern, but the overall effectiveness of internal controls should reassure them.
Next Steps
- Continue to monitor and address cybersecurity risks through a comprehensive, cross-functional approach.
- Ongoing engagement with third-party IT providers for system maintenance and monitoring.
- Further investigation, remediation efforts, and potential recovery actions related to the cybersecurity incidents.
- Maintain compliance with Israeli corporate governance practices and applicable U.S. securities laws.
Key Dates
| Date | Description |
|---|---|
| 2020-07-15 | Share Purchase Agreement with XYLO TECHNOLOGIES LTD. |
| 2021-12-15 | First Addendum to Share Purchase Agreement with XYLO TECHNOLOGIES LTD. |
| 2021-12-23 | Second Addendum to Share Purchase Agreement with XYLO TECHNOLOGIES LTD. |
| 2022-08-10 | Form of Simple Agreement for Future Equity and Compensation Policy filed. |
| 2022-10-06 | Form of Indemnification Agreement, Collaboration Agreement with Nurexone Biologic Inc., and Collaboration Agreement with SciSparc Ltd. filed. |
| 2023-02-04 | Convertible Loan Agreement with Certain Shareholders. |
| 2023-06-20 | Share Purchase Agreement. |
| 2023-11-21 | Third Addendum to Share Purchase Agreement with XYLO TECHNOLOGIES LTD. |
| 2023-12-19 | Share Purchase Agreement. |
| 2024-04-10 | Convertible Loan Agreement with L.I.A Pure Capital Ltd. |
| 2024-05-07 | Fourth Addendum to Share Purchase Agreement with XYLO TECHNOLOGIES LTD. |
| 2024-05-12 | Share Purchase Agreement. |
| 2024-08-13 | Convertible Loan Agreement with L.I.A Pure Capital Ltd. and Reuven Srugo Construction Company Ltd. |
| 2024-08-14 | License Agreement with SciSparc Ltd., Form of Pre-Funded Warrant, and Form of Warrant Agent Agreement filed. |
| 2024-09-09 | Form of Warrant filed. |
| 2025-01-22 | Amended and Restated Equity Incentive Plan filed. |
| 2025-04-01 | Form of Securities Purchase Agreement, Form of Series A Warrant, Form of Pre-Funded Warrant, Form of Placement Agent Agreement, Form of Registration Rights Agreement, and Form of Exchange Agreement furnished to SEC. |
| 2025-04-17 | Amended and Restated Articles of Association filed. |
| 2025-10-01 | Approximate date of Business Email Compromise (BEC) fraud incident. |
| 2025-12-01 | Approximate date of second attempted fraud incident. |
| 2025-12-05 | Form of Securities Purchase Agreement furnished to SEC. |
| 2025-12-31 | Fiscal year end; Evaluation Date for disclosure controls and internal control over financial reporting; Number of outstanding shares: 1,608,266 Ordinary Shares. |
| 2026-03-25 | Original filing date of the annual report on Form 20-F. |
| 2026-03-27 | Filing date of this Amendment No. 1 on Form 20-F/A. |
Recommendation
holdThe filing presents a mixed picture. While Polyrizon has addressed an oversight in its disclosure controls and implemented corrective measures following significant cybersecurity incidents, the actual financial loss of $464,000 and the initial failure to fully identify the scope of the breach are concerning. The company's assertion that the impact is not material to its overall financial condition is noted, but investors should monitor the effectiveness of the new controls and any further costs. Given the proactive remediation but also the demonstrated vulnerabilities, a 'hold' recommendation is appropriate as investors await further financial results and evidence of sustained control effectiveness.
Keywords
Polyrizon, 20-F/A, SEC filing, disclosure controls, internal controls, cybersecurity, Business Email Compromise, fraud, corporate governance, foreign private issuer, Nasdaq, Israel, financial reporting, audit fees
Disclaimer:The information provided here is for general informational purposes only and does not constitute financial advice, recommendation, or endorsement of any kind. It may contain errors or omissions. You should not rely on this information to make financial decisions. Always seek the advice of a qualified financial professional before making any investment or financial decisions. Use of this information is at your own risk.