{"url_path":"/sec/cik-0001734262/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K ****CYBERSECURITY**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-04-27","source_url":"https://www.sec.gov/Archives/edgar/data/1734262/0001104659-26-048866-index.html","accession_number":"0001104659-26-048866","cik":"0001734262","ticker":null,"issuer_name":"CooTek(Cayman)Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1734262/0001104659-26-048866-index.html","primary_entity_key":"0001734262","primary_entity_name":"CooTek(Cayman)Inc."},"word_count":570,"has_tables":true,"body_markdown":"**ITEM 16K.****CYBERSECURITY**\n\n**Risk Management and Strategy**\n\nWe have implemented robust processes for assessing, identifying and managing material risks from cybersecurity threats and monitoring the prevention, detection, mitigation and remediation of material cybersecurity incident. We have also integrated cybersecurity risk management into our overall enterprise risk management system.\n\nWe have established a comprehensive information security framework that includes a dynamic and multi-layered cybersecurity defense system to effectively mitigate both internal and external cyber threats. We have implemented an information security emergency response mechanism, categorizing security incidents into four main types: cyber-attack incidents, malicious program incidents, information leakage incidents, and information security incidents, and developed emergency response plans for each type of incident. Our cybersecurity defense system spans multiple security domains, including network, host, and application layers. It integrates a range of security capabilities such as threat defense, continuous monitoring, in-depth analysis, rapid response, as well as strategic deception and countermeasures. Our approach to managing cybersecurity risks and safeguarding sensitive data is multi-faceted, involving technological safeguards, procedural protocols, a rigorous program of surveillance on our corporate network, ongoing internal and external evaluations of our security measures, a solid incident response plan, and regular cybersecurity training sessions for our employees. Furthermore, we have implemented a comprehensive information security monitoring system that forecasts and issues timely warnings regarding potential or ongoing information security emergencies, including cybersecurity threats. Our IT department is actively engaged in continuous monitoring of our application, platforms and infrastructure to ensure prompt identification and response to potential issues, including emerging cybersecurity threats.\n\nWe do not engage any assessors, consultants, auditors, or other third parties in connection with processes for assessing, identifying, and managing material risks from cybersecurity threats. As of the date of this annual report, we have not experienced any material cybersecurity incidents or identified any material cybersecurity threats that have affected or are reasonably likely to materially affect us, our business strategy, results of operations or financial condition.\n\n**Governance**\n\nOur board of directors is responsible for overseeing our cybersecurity risk management. Our board of directors shall (i) maintain oversight of the disclosure related to cybersecurity matters in current reports or periodic reports of our company, (ii) review updates to the status of any material cybersecurity incidents or material risks from cybersecurity threats to our company, and the relevant disclosure issues, if any, presented by our chief executive officer, principal financial officer and cybersecurity officer on a quarterly basis, and (iii) review disclosure concerning cybersecurity matters in our annual report on Form 20-F presented by our chief executive officer, principal financial officer and cybersecurity officer.\n\nOur disclosure committee, which is comprised of our chief executive officer, principal financial officer and cybersecurity officer, is responsible for assessing, identifying and managing material risks from cybersecurity threats to our company and monitoring the prevention, detection, mitigation and remediation of material cybersecurity incident. Our cybersecurity officer possesses extensive experience in information security risk management and compliance, particularly in the internet technology industry, and holds a data security capability maturity model assessor certification issued by the Guizhou Big Data Protection Engineering Research Center. Our disclosure committee reports to our board of directors on (i) a quarterly basis on updates to the status of any material cybersecurity incidents or material risks from cybersecurity threats to our company, and the relevant disclosure issues, if any, and (ii) on disclosure concerning cybersecurity matters in our annual report on Form 20-F.\n\n​\n\n​\n\n154\n\n[Table of Contents](#TOC)\n\n**PART III**"}