{"url_path":"/sec/forty/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBER-SECURITY**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-05-13","source_url":"https://www.sec.gov/Archives/edgar/data/1045986/0001213900-26-055948-index.html","accession_number":"0001213900-26-055948","cik":"0001045986","ticker":"FORTY","issuer_name":"FORMULA SYSTEMS (1985) LTD","edgar_url":"https://www.sec.gov/Archives/edgar/data/1045986/0001213900-26-055948-index.html","primary_entity_key":"0001045986","primary_entity_name":"FORMULA SYSTEMS (1985) LTD"},"word_count":746,"has_tables":true,"body_markdown":"** **\n\n**ITEM 16K. CYBER-SECURITY**\n\n** **\n\n**Risk\nmanagement and strategy**\n\n \n\nWe (through our subsidiaries)\nmaintain corporate cyber-security risk assessment programs that are designed to identify and manage material risks from cyber-security\nthreats and protect the confidentiality, integrity, and availability of our critical information technology (IT) systems. These programs\nare integrated into our overall risk management systems, thereby helping to ensure that we address cyber-security risks in a comprehensive\nmanner.\n\n \n\nIn implementing the processes\nof our cyber-security risk assessment program, we have internal cyber-security teams and we also engage outside assessors, consultants,\nauditors and other third parties to help us in identifying and managing our cybersecurity risks. The degree to which our internal cyber-security\nteams, as opposed to an external party, handle the implementation of a given cyber-security project depends on the specific needs of the\nproject. We, through our subsidiaries, have processes in place to oversee and identify risks related to our outsourcing of certain portions\nof our cyber-security risks management. Those processes are designed to ensure that we utilize reliable and secure third-party vendors.\n\n \n\nWe regularly assess whether\nany risks from cyber-security threats are reasonably likely to materially affect our Group companies, and our or their business strategy,\nresults of operations or financial condition. If any such risks are identified, we take appropriate measures to mitigate them. As with\nvirtually every other public company, we believe that a potential material cybersecurity incident could potentially adversely affect our\nbusiness operations in a material manner, due to the reliance that we place on our IT systems for, among other things: effectively managing\nour accounting and financial functions, including maintaining our internal controls; managing our sales and marketing processes for our\nsolutions and services; and maintaining our proprietary rights (such as research and development, and other intellectual property- related\ndata). While we have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents,\nthat have materially affected us, including our operations, business strategy, results of operations, or financial condition, the failure\nof our IT systems to perform properly could disrupt our ability to develop, market and sell our solutions and services, which may result\nin decreased sales, increased overhead costs, and failure of our solutions to properly function, causing our business, our reputation,\nand our operating results to suffer. Please see “Item 3.D. Risk Factors-Risks Relating to Our Business, Our Industry, and Our Financing\nActivities- Significant disruptions of our information technology systems or breaches of our data security could adversely affect our\nbusiness”.\n\n \n\n**Governance**\n\n \n\nAs\npart of our (through our subsidiaries) corporate cybersecurity risk assessment program, we prioritize the identification and management\nof cybersecurity risk at several levels, including board oversight and involvement of each company’s management on an ongoing basis.\n\n \n\nOur\nboard of directors as a whole is responsible for the oversight of risks from cybersecurity threats to our subsidiaries’ operations.\nThe Formula board of directors meets annually with our Chief Financial Officer, or CFO, who updates the board regarding the latest developments\nwith respect to our subsidiaries’ cybersecurity risk assessment programs, the results of the latest risk assessments, and any material\nrisks from cybersecurity threats that have been identified. The board also receives periodic, ongoing updates on the prevention, detection,\nmitigation and remediation of cybersecurity incidents, including details concerning any incidents that have occurred for our subsidiaries,\nour subsidiaries’ response to such incidents, and any lessons learned as a result (including any recommendations for improvement\nin our subsidiaries’ response).\n\n \n\nOur\nmanagement, led by our CFO, is primarily responsible for assessing and managing material risks from cybersecurity threats to our subsidiaries.\nOur CFO directly manages our cybersecurity risk assessment program. Our CFO has general knowledge of Information Systems and Technology.\nIn handling his role, our CFO obtains information from our subsidiaries’ teams of cybersecurity professionals, which include individuals\nwith prior work experience, degrees, certification, knowledge, skills and background in cybersecurity, including with respect to cybersecurity\nrisk management, cybersecurity engineering and cybersecurity operations. Those cybersecurity teams are responsible for monitoring the\nprevention, detection, mitigation and remediation of cybersecurity incidents. That includes monitoring our subsidiaries’ IT network\nand systems for signs of cyber-attacks, responding to any cybersecurity incidents that occur, and implementing measures to prevent future\nincidents. The cybersecurity teams report information about cybersecurity risks to our CFO on a regular basis. That includes information\nabout any material risks from cybersecurity threats that have been identified, the response of the relevant company within our Group to\nthose risks, and any recommendations for improvement.\n\n \n\n178\n\n \n\n \n\n**PART III**"}