{"url_path":"/sec/fedu/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBERSECURITY","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-06-17","source_url":"https://www.sec.gov/Archives/edgar/data/1709819/0001193125-26-273350-index.html","accession_number":"0001193125-26-273350","cik":"0001709819","ticker":"FEDU","issuer_name":"Four Seasons Education (Cayman) Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1709819/0001193125-26-273350-index.html","primary_entity_key":"0001709819","primary_entity_name":"Four Seasons Education (Cayman) Inc."},"word_count":348,"has_tables":true,"body_markdown":"ITEM 16k. CYBERSECURITY\n\nRisk Management and Strategy\n\nWe have implemented comprehensive cybersecurity risk assessment processes to ensure effectiveness in cybersecurity management, strategy and governance and reporting cybersecurity risks. We have also integrated cybersecurity risk management into our overall enterprise risk management system.\n\n \n\n154\n\n \n\n[Table of Contents](#toc_page)\n\n \n\n \n\nWe have developed a comprehensive cybersecurity threat defense system to address both internal and external threats. This system encompasses various levels, including network, host and application security and incorporates systematic security capabilities for threat defense, monitoring, analysis, response, deception and countermeasures. We strive to manage cybersecurity risks and protect sensitive information through various means, such as technical safeguards, procedural requirements, an intensive program of monitoring on our corporate network, continuous testing of aspects of our security posture internally and with outside vendors, a robust incident response program and regular cybersecurity awareness training for employees. Our IT department regularly monitors the performance of our apps, platforms and infrastructure to enable us to respond quickly to potential problems, including potential cybersecurity threats.\n\nAs of the date of this annual report, we have not experienced any material cybersecurity incidents or identified any risks from cybersecurity threats that have materially affected or are reasonably likely to materially affect us, our business strategy, results of operations, or financial condition.\n\nGovernance\n\nOur board of directors is responsible for overseeing cybersecurity risks. When appropriate, periodic reviews are held to discuss the landscape of cybersecurity, potential threats, and our preparedness for potential cybersecurity threats and risks to our company. In case a material cybersecurity occurs, our board of directors is responsible for reviewing the information and issues involved, disclosures to be made, and the procedures followed. Our Director of Technology, and his team, who have many years of experience in the field, are primarily responsible for assessing and managing cybersecurity risks and monitoring the prevention, detection, mitigation, and remediation of cybersecurity incidents. The Director of Technology reports to our CEO and provides periodic updates to our CEO and the board of directors on any material cybersecurity incidents or material risks arising from cybersecurity threats.\n\n \n\n155\n\n \n\n[Table of Contents](#toc_page)\n\n \n\n \n\nPART III"}