{"url_path":"/sec/chnr/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K **","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-05-15","source_url":"https://www.sec.gov/Archives/edgar/data/793628/0001553350-26-000083-index.html","accession_number":"0001553350-26-000083","cik":"0000793628","ticker":"CHNR","issuer_name":"CHINA NATURAL RESOURCES INC","edgar_url":"https://www.sec.gov/Archives/edgar/data/793628/0001553350-26-000083-index.html","primary_entity_key":"0000793628","primary_entity_name":"CHINA NATURAL RESOURCES INC"},"word_count":241,"has_tables":true,"body_markdown":"** **\n\n \n\n \n**ITEM 16K.**\n**CYBERSECURITY**\n\n \n\nAs\nan exploration company, we have limited digital operations and our business activity to date has been identifying, acquiring, and exploring\nmineral properties, and we have not yet adopted formal cybersecurity risk management programs or formal processes for assessing cybersecurity\nrisks. We understand the importance of managing material risks from cybersecurity threats and are committed, as part of our continuing\ngrowth, to implementing and maintaining an adequate information security program to manage such risks and safeguard our systems and data.\n\n \n\nWe\ncurrently manage our cybersecurity risk through a variety of practices that are applicable to all users of our information technology\nand information assets, including our employees and contractors. We use a combination of technology, policies, training, and monitoring\nto promote security awareness and prevent security incidents.\n\n \n\nWe\nbelieve we have limited exposure to cyber threats other than emails and project data storage. Financial transactions are enabled through\nwell-established financial institutions and accounting and employee information storage are outsourced to an external accounting firm.\n\n \n\nWe\nhave not, as of the date of this annual report, experienced a cybersecurity threat or incident in the last three years, that materially\naffected or is reasonably likely to affect our business, results of operations, or financial condition. However, there can be no guarantee\nthat we will not experience such an incident in the future.\n\n \n\nOur\nboard of directors oversees cybersecurity risk as part of its role of overseeing enterprise-wide risk.\n\n \n\n \n\n**PART III**"}