{"url_path":"/sec/adxn/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K Cybersecurity","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-05-15","source_url":"https://www.sec.gov/Archives/edgar/data/1574232/0001104659-26-062447-index.html","accession_number":"0001104659-26-062447","cik":"0001574232","ticker":"ADXN","issuer_name":"Addex Therapeutics Ltd.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1574232/0001104659-26-062447-index.html","primary_entity_key":"0001574232","primary_entity_name":"Addex Therapeutics Ltd."},"word_count":640,"has_tables":true,"body_markdown":"Item 16K. Cybersecurity\n\n**Risk Management and Strategy**\n\nSafeguarding the Company’s information systems, assets, data, intellectual property and network infrastructure and ensuring that risks related to cybersecurity threats are appropriately managed is essential to maintaining a consistently high level of confidentiality, integrity and availability of our information systems; and the trust of our stakeholders, as well as meeting applicable regulatory requirements. We have implemented a multi-faceted cybersecurity risk management framework, which is integrated in our overall enterprise risk management system and processes.\n\nOur cybersecurity team is tasked with assessing, identifying and managing risks related to cybersecurity threats and, is responsible for:\n\n●proactive detection and assessment of threats and vulnerabilities through vulnerability testing, penetration testing and attack simulation;\n\n●development of risk-based action plans to manage identified vulnerabilities and implementation of new protocols and infrastructure improvements;\n\n●cybersecurity incident investigations, with the assistance of third-party experts as required;\n\n●monitoring threats to sensitive data and unauthorized access to Company systems, with assistance of third-party data loss prevention software and a third-party security operations center;\n\n●developing and executing protocols to ensure that information regarding cybersecurity incidents is promptly shared with our chief information officer, executive leadership team, Audit Committee and Board, as appropriate, to allow for risk and materiality assessments and to consider disclosure and notice requirements;\n\n●developing and implementing periodic training on cybersecurity, information security and threat awareness; and\n\n●collaborating with law enforcement and other companies on cybersecurity incidents and best practices.\n\nWe also use third - party service providers to perform a variety of functions throughout our business such as hosting companies and contract research organizations. We manage cybersecurity risks associated with our use of these providers using several approaches, as deemed necessary, including security questionnaires, review of compliance reports, audits and the imposition of information security contractual obligations on vendors.\n\nFor a description of the risks from cybersecurity threats that may materially affect us and how they may do so, see our risk factors under Item 3.D “Risk Factors” in this Annual Report on Form 20 - F.\n\n**Role of Management**\n\nOur chief information officer leads management’s assessment, identification and management of risks related to cybersecurity threats and reports directly to our Chief Executive Officer. The chief information officer receives regular briefings on cybersecurity matters including results of vulnerability testing and remediation, cyber incident response and progress on cybersecurity infrastructure initiatives.\n\n**Role of the Board of Directors**\n\nOur Board recognizes the importance of robust cybersecurity management programs and is actively engaged in overseeing and reviewing the Company’s cybersecurity risk profile and exposures.\n\nThe responsibilities of the Board include reviewing the cybersecurity threat landscape facing the Company, as well as our strategy, policies and procedures to mitigate cybersecurity risks and any significant cybersecurity incidents. The Board also considers the impact of emerging cybersecurity developments and regulations that may affect the Company.\n\n101\n\n[Table of Contents](#TOC)\n\nThe Board meets periodically with relevant members of management, who provide reports on cybersecurity matters including, among others: recent external cybersecurity threats and attack trends; updates to threat monitoring processes; the composition of our cybersecurity team; cybersecurity awareness training and stress testing; cybersecurity strategy; cybersecurity metrics, assessments and peer ratings; and cybersecurity programs. The Board has also directed management to be informed promptly and of any investigation of a material cybersecurity incident. The Board may, from time to time, engage third party advisors and experts, and meet with the Company’s external advisors on cybersecurity matters, as appropriate.\n\nThere were no cybersecurity incidents during the year ended December 31, 2025, that resulted in an interruption to our operations, known losses of any critical data or otherwise had a material impact on the Company’s strategy, financial condition or results of operations. However, the scope and impact of any future incident cannot be predicted. See “Item 3D—Risk Factors” for more information on how material cybersecurity attacks may impact our business.\n\nPART III"}