{"url_path":"/sec/akan/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBERSECURITY**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-06-09","source_url":"https://www.sec.gov/Archives/edgar/data/1888014/0001213900-26-066800-index.html","accession_number":"0001213900-26-066800","cik":"0001888014","ticker":"AKAN","issuer_name":"AKANDA CORP.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1888014/0001213900-26-066800-index.html","primary_entity_key":"0001888014","primary_entity_name":"AKANDA CORP."},"word_count":457,"has_tables":true,"body_markdown":"**ITEM 16K. CYBERSECURITY**\n\n** **\n\nWe use SaaS based information\ntechnology (IT) systems/services which are provided by reputable vendors, our IT environment is audited by third party IT auditors\nfor IT risk management regularly. The Company takes care of access management and related threats. Logs, threats, and alerts are monitored\nand dealt with by the Company on a regular basis. All system/services being used (Microsoft (email/SharePoint/teams) are all cloud-based\nprovided by reputable cloud vendors and their IT environments are audited by third party auditors for IT risk management. Information\nis analyzed on potential threats to the organization, identifying what threats each of our IT assets may face and from where those may\noriginate. All server level threats are taken care of by systems providers under SaaS model. There were no cyber-attacks, virus infection\nor security breach during the prior fiscal year. The Company is not aware of or been informed of instances of noncompliance with any\nregulatory requirements associated with IT. The information system has not experienced a significant loss of data that could not\nbe restored from backup systems.\n\n \n\nOur interim CEO is responsible\nfor assessing and managing cybersecurity risks, through her general oversight of our company and its IT service provider that manages\nour IT, but she does not have specific cybersecurity expertise. The Company does not have a specific Information Technology Policy\nthat would, among other things, govern and provide for cybersecurity policies and processes, including to define safety measures to protect\nthe Company’s confidentiality, integrity and availability of data and other intellectual property, or to define the manner\nin which information is stored, saved and routed in the Company’s network, as a result of the transition of the Company’s\nbusiness focus and lack of material day to day operations at this time. The Board and management believe cybersecurity\nrepresents an important component of the Company’s overall approach to risk management and oversight, especially as the Company\nmoves towards commercialization of its planned cannabis products and potentially the business of First Towers and Fiber Corp.\n\n ** **\n\nThe Company has not incurred\nany material expenses over the last two years relating to information security breaches. The occurrence of cyber-incidents, or a\ndeficiency in our cybersecurity or in those of any of our third-party service providers could negatively impact our business by causing\na disruption to our operations, a compromise or corruption of our confidential information and systems, or damage to our business relationships\nor reputation, all of which could negatively impact our business and results of operations. There can be no assurance that the Company’s\nthird-party vendors’ and service providers’ cybersecurity risk management processes, including their policies, controls or\nprocedures, will be fully implemented, complied with or effective in protecting the Company’s systems and information.\n\n \n\n87\n\n \n\n \n\n**PART III**"}