{"url_path":"/sec/afriw/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBERSECURITY**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-05-15","source_url":"https://www.sec.gov/Archives/edgar/data/1903870/0001493152-26-023781-index.html","accession_number":"0001493152-26-023781","cik":"0001903870","ticker":"AFRI","issuer_name":"Forafric Global PLC","edgar_url":"https://www.sec.gov/Archives/edgar/data/1903870/0001493152-26-023781-index.html","primary_entity_key":"0001903870","primary_entity_name":"Forafric Global PLC"},"word_count":426,"has_tables":true,"body_markdown":"**ITEM\n16K. CYBERSECURITY**\n\n \n\nWe\nare developing a cybersecurity risk management program, consisting of cybersecurity policies, procedures, compliance and awareness programs\nto mitigate risk and to ensure compliance with security, availability and confidentiality trust principles. The aforementioned policies\nare substantially in place, but not yet committed to writing or formally approved. The\ncybersecurity process has been integrated into our overall risk management system and process, and is solely internally managed.\nManagement\nis responsible for identifying risks that threaten achievement of the control activities stated in the management’s description\nof the services organizations systems. Management has implemented a process for identifying relevant risks that could affect the organization’s\nability to provide secure and reliable service to its users. The\nrisk assessment occurs annually, or as business needs change, and covers identification of risks that could act against the company’s\nobjectives as well as specific risks related to a compromise to the security of data. See “*Item 3.D — Risk Factors Related\nto our Business* — *Our\nbusiness and operations would suffer in the event of IT system failures, cybersecurity attacks, data breaches, or vulnerabilities in\nour or our third-party vendors’ information security program or defenses*.”\n\n \n\nThe\nlevel of each identified risk is determined by considering the impact of the risk itself and the likelihood of the risk materializing\nand high scoring risks are actioned upon. Risks are analyzed to determine whether the risk meets company risk acceptance criteria to\nbe accepted or whether a mitigation plan will be applied. Mitigation plans include both the individual or department responsible for\nthe plan and may include budget considerations.\n\n \n\nThe\noversight of cybersecurity threats is undertaken by our Chief Information Officer, who holds over two decades of experience in information\ntechnology and the design and architecture of information systems, and is supported by management. Our audit committee is responsible\nfor cybersecurity oversight and monitoring risk. Management informs the audit and investment committee of such risk by committee meetings.\n\n \n\nWe\nhave not, to our knowledge, experienced any material IT system failures or any material cybersecurity attacks to date. See “*Item\n3.D — Risk Factors Risks Related to our Business — Our business and operations would suffer in the event of IT system failures,\ncybersecurity attacks, data breaches, or vulnerabilities in our or our third-party vendors’ information security program or defenses*.”\n\n \n\nAs\nof the date of this report, we are not aware of any material risks from cybersecurity threats that have materially affected or are reasonably\nlikely to materially affect us, including our business strategy, results of operations or financial condition.\n\n \n\n**Part\nIII**"}