{"url_path":"/sec/chkp/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBERSECURITY","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-03-31","source_url":"https://www.sec.gov/Archives/edgar/data/1015922/0001178913-26-001932-index.html","accession_number":"0001178913-26-001932","cik":"0001015922","ticker":"CHKP","issuer_name":"CHECK POINT SOFTWARE TECHNOLOGIES LTD","edgar_url":"https://www.sec.gov/Archives/edgar/data/1015922/0001178913-26-001932-index.html","primary_entity_key":"0001015922","primary_entity_name":"CHECK POINT SOFTWARE TECHNOLOGIES LTD"},"word_count":1012,"has_tables":true,"body_markdown":"ITEM 16K.\nCYBERSECURITY\n\n \n\nCyber\nsecurity Risk Management and Strategy\n\n \n\nAs\na public security company, we prioritize robust cyber security measures to protect our assets, operations, and stakeholders. We have established\npolicies and processes for assessing, identifying, and managing material risks from cyber security threats (as defined below), and have\nintegrated\nthese processes into our overall risk management systems and processes. We routinely assess material risks from cyber\nsecurity threats, including any potential cyber security incidents (as defined below).\n\n \n\nWe\nconduct periodic risk assessments to identify cyber security threats, as well as additional assessments in the event of a material change\nin our business practices that may affect information systems (as defined below) that are vulnerable to such cyber security threats. These\nrisk assessments include identification of reasonably foreseeable internal and external risks, the likelihood and potential damage that\ncould result from such risks, and the sufficiency of existing policies, procedures, systems, and safeguards in place to manage such risks.\n\n \n\nFollowing\nthese risk assessments, we re-design, implement, and maintain reasonable safeguards to minimize identified risks; reasonably address any\nidentified gaps in existing safeguards; and regularly monitor the effectiveness of our safeguards. We devote significant resources and\ndesignate high-level personnel, including our Chief Security & Trust Officer, our Chief Information Security Officer (“CISO”)\nand our Chief Information Officer (“CIO”), to manage the risk assessment and mitigation process.\n\n \n\nAs\npart of our overall risk management process, we monitor and test our safeguards and train our employees on these safeguards, in collaboration\nwith human resources, IT, and management.  Personnel at all levels and departments receive training on our cyber security policies.\n\n \n\nWe\nengage our internal auditors and other third parties in connection with our risk assessment processes. These service providers assist\nus to design and implement our cyber security policies and procedures in accordance with common best practices and methodologies, as well\nas to monitor and test our security controls.\n\n \n\nWe\nmaintain a third-party\nrisk management process with regard to third-party service providers, pursuant to which third-party service providers\nthat store, process, or have access to our data, integrate with our systems, or provide certain services to us are required to undergo\na security assessment prior to approval. Approved service providers are subject to ongoing monitoring, and we conduct periodic reviews\nof critical and high-risk service providers to help ensure continued compliance with our security requirements.\n\n \n\n71\n\n \n\nWe\nhave not identified any risks from known cyber security threats, including as a result of any prior cyber security incidents, that have\nmaterially affected or are reasonably likely to materially affect us, including our operations, business strategy, results\nof operations, or financial condition.\n\n \n\nWe\nregularly experience attempts by third parties to gain unauthorized access to, or to introduce malicious software into, our information\ntechnology systems. While a limited number of these attempts have resulted in minor and isolated incidents, they were promptly identified,\ninvestigated and remediated in real time by our cyber security and information technology teams. Based on our investigations, these incidents\ndid not affect our customers, did not involve any leakage of customer or company data, and did not result in any material impact on our\noperations. For additional information regarding whether any risks from cyber security threats, including as a result of any previous\ncyber security incidents, have materially affected or are reasonably likely to materially affect our company, including our business strategy,\nresults of operations, or financial condition, please refer to Item 3D, “Key Information – Risk Factors”, in this Annual\nReport on Form 20-F, including the risk factors entitled “Other General Risks and Risks Related to the Ownership of Our Ordinary\nShares - Our\ninformation technology systems, networks and products and services have been, and may continue to be, subject to various security threats\nand cyber security incidents”.\n\n \n\nCyber\nSecurity Governance\n\n \n\nOur\nBoard of Directors considers cyber security risk as part of its risk oversight function and has delegated oversight of cyber security\nand other information technology risks to the Audit Committee. As such, the Audit Committee oversees management’s implementation\nof our cyber security risk management program.\n\n \n\nThe\nAudit Committee receives quarterly reports from our Chief Information Officer and CISO on cyber security regarding our company’s\ncyber security risks and activities, including any recent cyber security incidents and related responses, cyber security systems testing,\nactivities of third parties, as well as any incidents with lesser impact potential.\n\n \n\nOur\nAudit Committee provides updates to the board of directors on such reports.\n\n \n\nOur\nmanagement team, particularly our CIO,\noversees our cyber security policies and processes, including those described in “Cyber security Risk Management and Strategy”\nabove, and is responsible for assessing and managing our material risks from cyber security threats. Our CIO and his team\nhave primary responsibility for our overall cyber security risk management program and supervise both our internal cyber security personnel\nand our retained external cyber security consultants. Our\nmanagement team’s experience includes our  CIO’s 18 years of experience in IT services, since 2008.\n\n \n\nOur\nCIO supervises efforts to prevent, detect, mitigate, and remediate cyber security risks and incidents through various means, which may\ninclude briefings from internal security personnel; threat intelligence and other information obtained from governmental, public or private\nsources, including external consultants engaged by us; and alerts and reports produced by security tools deployed in the IT environment.\n\n \n\nFor\npurposes of this Item 16K:\n\n \n\n \n-\n\nA “cyber security\nincident” means an unauthorized occurrence, or a series of related unauthorized occurrences, on or conducted through our information\nsystems that jeopardizes the confidentiality, integrity, or availability of a registrant’s information systems or any information\nresiding therein.\n\n \n\n \n-\n\nA “cyber security\nthreat” means any potential unauthorized occurrence on or conducted through our information systems that may result in adverse effects\non the confidentiality, integrity, or availability of our information systems or any information residing therein.\n\n \n\n \n-\n\n“Information\nsystems” means electronic information resources, owned or used by us, including physical or virtual infrastructure controlled by\nsuch information resources, or components thereof, organized for the collection, processing, maintenance, use, sharing, dissemination,\nor disposition of our information to maintain or support our operations.\n\n \n\nPART\nIII"}