{"url_path":"/sec/cchh/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K Cybersecurity**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-05-15","source_url":"https://www.sec.gov/Archives/edgar/data/2074123/0001213900-26-057844-index.html","accession_number":"0001213900-26-057844","cik":"0002074123","ticker":"CCHH","issuer_name":"CCH Holdings Ltd","edgar_url":"https://www.sec.gov/Archives/edgar/data/2074123/0001213900-26-057844-index.html","primary_entity_key":"0002074123","primary_entity_name":"CCH Holdings Ltd"},"word_count":466,"has_tables":true,"body_markdown":"** **\n\n**Item\n16K. Cybersecurity**\n\n** **\n\n**Risk\nManagement and Strategy**\n\n \n\nWe\nhave implemented processes for assessing, identifying and managing material risks from cybersecurity threats and monitoring the prevention,\ndetection, mitigation and remediation of material cybersecurity incident. We have also integrated cybersecurity risk management into\nour overall risk management system.\n\n \n\nWe\nhave developed a cybersecurity threat defense system to address both internal and external threats. This system encompasses various levels,\nincluding network, host and application security and incorporates systematic security capabilities for threat defense, monitoring, analysis,\nresponse, deception and countermeasures. We strive to manage cybersecurity risks and protect sensitive information through various means,\nsuch as technical safeguards, procedural requirements, a program of monitoring our network, testing of aspects of our security posture,\nan incident response program, and cybersecurity awareness training for employees. We regularly monitors the performance of our apps,\nplatform, and infrastructure to enable us to respond quickly to potential problems, including potential cybersecurity threats.\n\n \n\nWe\ndo not engage any third parties in connection with the processes for assessing, identifying, and managing material risks from cybersecurity\nthreats. As of the date of this annual report, we have not experienced any material cybersecurity incidents or identified any material\ncybersecurity threats that have affected or are reasonably likely to materially affect us, our business strategy, results of operations\nor financial condition.\n\n \n\n**Governance**\n\n** **\n\nOur\nboard of directors is responsible for overseeing our cybersecurity risk management. Our board of directors shall review, approve and\nmaintain oversight of the disclosure (i) on Form 6-K for material cybersecurity incidents (if any) and (ii) related to cybersecurity\nmatters in the periodic reports (including annual report on Form 20-F) of our Company.\n\n \n\nAt\nmanagement level, our Co-Chief Executive Officers and Chief Financial Officer are responsible for assessing, identifying and managing\nmaterial risks from cybersecurity threats to our Company and monitoring the prevention, detection, mitigation and remediation of material\ncybersecurity incident. Our executive officers shall meet with the board of directors (i) in connection with each current report to furnish\ninformation concerning any material cybersecurity incident, report the status of any material cybersecurity incidents or material risks\nfrom cybersecurity threats to our Company, if any, and the relevant disclosure issue, and (ii) in connection with each annual report,\npresent the disclosure concerning cybersecurity matters in Form 20-F.\n\n \n\nIf\na cybersecurity incident occurs, our executive officers will promptly organize relevant personnel for internal assessment and if it is\ndetermined that the incident could potentially be a material cybersecurity event, our executive officers will promptly report the incident\nand assessment results to our board of directors and external legal counsel, to the extent appropriate. Our executive officers shall\nprepare disclosure material on the cybersecurity incident for review and approval by the board of directors, and external legal counsel\n(if necessary), before it is disseminated to the public.\n\n \n\n77\n\n** **\n\n**PART\nIII**"}