{"url_path":"/sec/ftrk/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBERSECURITY**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-06-30","source_url":"https://www.sec.gov/Archives/edgar/data/2027262/0001493152-26-031197-index.html","accession_number":"0001493152-26-031197","cik":"0002027262","ticker":"FTRK","issuer_name":"Fast Track Group","edgar_url":"https://www.sec.gov/Archives/edgar/data/2027262/0001493152-26-031197-index.html","primary_entity_key":"0002027262","primary_entity_name":"Fast Track Group"},"word_count":566,"has_tables":true,"body_markdown":"** **\n\n**Item\n16K. CYBERSECURITY**\n\n** **\n\n*Risk\nManagement and Strategy*\n\n \n\nWe\nidentify and assess material risks from cybersecurity threats to our information systems and the information residing in our information\nsystems by monitoring and evaluating our threat environment on an ongoing basis using various methods including, for example, using manual\nand automated tools, subscribing to reports and services that identify cybersecurity threats, analyzing reports of threats and threat\nactors, conducting scans of the threat environment, and conducting risk assessments.\n\n \n\nWe\nmanage material risks from cybersecurity threats to our information systems and the information residing in our information systems through\nvarious processes and procedures, including, depending on the environment, risk assessment, incident detection and response, vulnerability\nmanagement, disaster recovery and business continuity plans, internal controls within our accounting and financial reporting functions,\nencryption of data, network security controls, access controls, physical security, asset management, systems monitoring, and employee\ntraining. We engage third-party service providers to provide some of the resources used in our information systems and some third-party\nservice providers have access to information residing in our information systems. With respect to such third parties, we seek to engage\nreliable, reputable service providers that maintain cybersecurity programs. Depending on the nature and extent of the services provided,\nthe sensitivity and quantity of information processed, and the identity of the service provider, our processes may include conducting\ndue diligence on the cybersecurity practices of such provider and contractually imposing cybersecurity related obligations on the provider.\n\n \n\nWe\nare not aware of any risks from cybersecurity threats, including as a result of any cybersecurity incidents, which have materially affected\nor are reasonably likely to materially affect our Group, including our business strategy, results of operations, or financial condition.\nRefer to “Item 3. Key Information—D. Risk Factors—Risks Related to Our Business and Industry — Unauthorized disclosure,\ndestruction or modification of data, through cybersecurity breaches, computer viruses or otherwise or disruption of our services could\nexpose us to liability, protracted and costly litigation and damage our reputation” and “Item 3. Key Information—D.\nRisk Factors—Risks Related to Our Business and Industry — We could incur substantial costs as a result of data protection\nconcerns or IT systems disruption or failure .”\n\n \n\n59\n\n \n\n \n\n*Cybersecurity\nGovernance*\n\n \n\nOur\nBoard of Directors holds oversight responsibility over our Group’s risk management and strategy, including material risks related\nto cybersecurity threats. This oversight is executed directly by our board of directors and through its committees. Our audit committee\noversees the management of our Group’s major financial risk exposures, the steps management has taken to monitor and control such\nexposures, and the process by which risk assessment and management is undertaken and handled, which would include cybersecurity risks,\nin accordance with its charter. The audit committee holds regular meetings and receives periodic reports from management regarding risk\nmanagement, including major financial risk exposures from cybersecurity threats or incidents.\n\n \n\nWithin\nmanagement, the Group’s Chief Financial Officer is primarily responsible for assessing and managing our material risks from cybersecurity\nthreats and keep the senior executive officers informed on a regular basis of the identification, assessment, and management of cybersecurity\nrisks and of any cybersecurity incidents. Such management personnel have prior experience and training in managing information systems\nand cybersecurity matters and participate in ongoing training programs.\n\n \n\nAs\nof the date hereof, the Company has not encountered cybersecurity incidents that the company believes to have been material to the Company\ntaken as a whole.\n\n \n\n**PART\nIII**"}