{"url_path":"/sec/ambr/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K ****CYBERSECURITY**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-05-13","source_url":"https://www.sec.gov/Archives/edgar/data/1697818/0001104659-26-060362-index.html","accession_number":"0001104659-26-060362","cik":"0001697818","ticker":"AMBR","issuer_name":"Amber International Holding Ltd","edgar_url":"https://www.sec.gov/Archives/edgar/data/1697818/0001104659-26-060362-index.html","primary_entity_key":"0001697818","primary_entity_name":"Amber International Holding Ltd"},"word_count":504,"has_tables":true,"body_markdown":"**ITEM 16K.****CYBERSECURITY**\n\n**Cybersecurity Risk Management and Strategy**\n\nWe have implemented processes for assessing, identifying and managing material risks from cybersecurity threats. These processes mainly include:\n\n●\n\nconducting risk assessments to identify material cybersecurity risks to our critical systems, information, products and services, as well as broader enterprise IT environment;\n\n●\n\ndeveloping risk-based action plans to manage identified vulnerabilities and implementing new protocols and infrastructure improvements;\n\n114\n\n[Table of Contents](#TOC)\n\n●\n\ninvestigating cybersecurity incidents, if any;\n\n●\n\nmonitoring cybersecurity threats to sensitive data and unauthorized access to our systems;\n\n●\n\nimplementing secure access control measures to our critical IT systems, equipment, and devices to prevent unauthorized access; and\n\n●\n\nbased on the severity of the cybersecurity risk and the potential impact of such risk on our business operations, developing and executing protocols to promptly report material cybersecurity incidents to our board of directors.\n\nWe have also integrated cybersecurity risk management into our overall enterprise risk management system. In addition, our policies require regular cybersecurity, information security, and threat awareness training for relevant personnel.\n\nThe assessment, identification, and management of cybersecurity risks are conducted internally, without reliance on outsourced personnel, and are supported by the use of mature, reputable, and industry-recognized security tools. In 2025, we did not have any cybersecurity incidents that have materially affected or are reasonably likely to materially affect our business, results of operations, or financial condition. However, despite our efforts, we cannot eliminate all risks from cybersecurity threats, or provide assurances that we have not experienced an undetected cybersecurity incident. For more information about these risks, please see “Item 3.D. Key Information—Risk Factors—Risks Related to Our Business and Industry.”\n\n**Governance**\n\nOur board of directors oversees our cybersecurity risk profile and exposures. Specifically, our board of directors (i) maintains oversight of the disclosure related to cybersecurity matters in our current reports or periodic reports (including annual reports on Form 20-F); (ii) reviews and approves material cybersecurity policies, and (iii) reviews updates to the status of any material cybersecurity incidents or material risks from cybersecurity threats, and the disclosure issues, if any, presented by our IT department.\n\nOur board of directors delegates its authorities and powers in managing risks associated with cybersecurity threats to our IT department.\n\n●\n\nour IT department consists of seven members, who have relevant experience in information security, compliance and risk management. Our IT department is responsible for the daily security operation and maintenance of our information systems and monitoring and coordinating our cybersecurity risk management processes, including preparing internal policies and remediation plans with respect to cybersecurity risk assessment and management, and promptly reporting material cybersecurity risk or incidents to our board of directors.\n\n●\n\nIn addition, our IT department is responsible for implementing our cybersecurity risk management plans, regularly monitoring the prevention, detection, mitigation, and remediation of cybersecurity incidents, and reporting information about our cybersecurity risk and assessments results to a senior member of the IT department. This senior member has approximately eight years of experience in cybersecurity management.\n\n​\n\n​\n\n115\n\n[Table of Contents](#TOC)\n\n**PART III**"}