{"url_path":"/sec/frgt/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBERSECURITY","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-05-14","source_url":"https://www.sec.gov/Archives/edgar/data/1687542/0001493152-26-023206-index.html","accession_number":"0001493152-26-023206","cik":"0001687542","ticker":"FRGT","issuer_name":"Freight Technologies, Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1687542/0001493152-26-023206-index.html","primary_entity_key":"0001687542","primary_entity_name":"Freight Technologies, Inc."},"word_count":432,"has_tables":true,"body_markdown":"ITEM\n16K. CYBERSECURITY\n\n \n\nWe\nemploy procedures designed to identify, protect, detect and respond to and manage reasonably foreseeable cybersecurity risks and threats.\nTo protect our information systems from cybersecurity threats, we use various security tools that help prevent, identify, escalate, investigate,\nresolve and recover from identified vulnerabilities and security incidents in a timely manner. These include, but are not limited to,\ninternal reporting, monitoring and detection tools, employee education, password encryption, frequent password change events, firewall\ndetection systems, anti-virus software in-place and frequent backups.\n\n \n\nWe\nregularly assess risks from cybersecurity and technology threats and monitor our information systems for potential vulnerabilities, including\nthose that could arise from internal sources and external sources such as third-party service providers we do business with. We use a\nwidely adopted risk quantification model to identify, measure and prioritize cybersecurity and technology risks and develop related security\ncontrols and safeguards. We conduct regular reviews and tests of our information security program and also leverage audits by our internal\naudit team, tabletop exercises, penetration and vulnerability testing, simulations, and other exercises to evaluate the effectiveness\nof our information security program and improve our security measures and planning. We may and are considering whether to further engage\nan assessor(s), consultant(s), auditor(s) or other third party(s) to supplement our processes.\n\n \n\nTo\ndate, management is only aware of an attempted cyberattack on our Waavely website, which we believe was an attempt to disrupt service\nor steal protected data. Our IT team was able to recognize the effort in real time and take defensive measures to stop the attack. Management\nis not aware of any loss, misuse or theft of personal information (of third parties, employees, and our members) and other data, confidential\ninformation or intellectual property from this incident or any other incident or event. Any significant disruption to our service or\naccess to our systems in the future could adversely affect our business and results of operation. Further, a penetration of our systems\nor a third-party’s systems or other misappropriation or misuse of personal information could subject us to business, regulatory,\nlitigation and reputation risk, which could have a negative effect on our business, financial condition and results of operations.\n\n \n\nOur\nboard of directors oversees our annual enterprise risk assessment, where we assess key risks within the Company, including security and\ntechnology risks and cybersecurity threats. The Audit Committee of the board of directors oversees our cybersecurity risk and receives\nregular reports from our management team on various cybersecurity matters, including risk assessments, mitigation strategies, areas of\nemerging risks, incidents and industry trends, and other areas of importance.\n\n \n\n**PART\nIII**"}