{"url_path":"/sec/bgm/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBERSECURITY**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-07-21","source_url":"https://www.sec.gov/Archives/edgar/data/1779578/0001104659-26-085247-index.html","accession_number":"0001104659-26-085247","cik":"0001779578","ticker":"BGM","issuer_name":"BGM Group Ltd.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1779578/0001104659-26-085247-index.html","primary_entity_key":"0001779578","primary_entity_name":"BGM Group Ltd."},"word_count":374,"has_tables":true,"body_markdown":"**ITEM 16K. CYBERSECURITY**\n\n​\n\n**Cybersecurity Risk Management and Strategy**\n\n​\n\nWe have implemented comprehensive cybersecurity risk assessment procedures to ensure effectiveness in cybersecurity management, strategy and governance and reporting cybersecurity risks. We have also integrated cybersecurity risk management into our overall enterprise risk management system.\n\n​\n\nWe have developed a comprehensive cybersecurity threat defense system to address both internal and external threats. We strive to manage cybersecurity risks and protect sensitive information through various means, such as technical safeguards, procedural requirements, an intensive program of monitoring on our corporate network, frequent testing of aspects of our security posture internally and with outside vendors, a robust incident response program and regular cybersecurity awareness training for employees. Our IT department regularly monitors the performance of our platforms, apps and infrastructure to enable us to respond quickly to potential problems, including potential cybersecurity threats.\n\nAs of the date of this annual report, we have not experienced any material cybersecurity incidents or identified any material cybersecurity threats that have affected or are reasonably likely to materially affect us, our business strategy, results of operations or financial condition.\n\n**Cybersecurity Governance**\n\nOur board of directors considers cybersecurity risk as part of its risk oversight function and undertakes overall risk management, including oversight of cybersecurity and other information technology risks.\n\nOur board of directors receives quarterly reports from management on our cybersecurity risks. In addition, management updates our board of directors, as necessary, regarding any significant cybersecurity incidents. Our board of directors also receives briefings from management on our cyber risk management program.\n\nOur management has primary responsibility for our overall cybersecurity risk management program and supervises our internal cybersecurity personnel. Our management and the IT department, including our chief financial officer and chief executive officers, are responsible for assessing and managing our material risks from cybersecurity threats. Our team’s experience includes computing, management of OA system, management of ERP system, basic database management and network engineering.\n\nOur management oversees efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include briefings from internal security personnel; information obtained from governmental, public or private sources; and alerts and reports produced by security tools deployed in our IT Systems environment.\n\n​\n\n157\n\n[Table of Contents](#TOC)\n\n**PART III**"}