{"url_path":"/sec/gibow/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBERSECURITY**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-05-15","source_url":"https://www.sec.gov/Archives/edgar/data/2034520/0001493152-26-023628-index.html","accession_number":"0001493152-26-023628","cik":"0002034520","ticker":"GIBO","issuer_name":"GIBO HOLDINGS Ltd","edgar_url":"https://www.sec.gov/Archives/edgar/data/2034520/0001493152-26-023628-index.html","primary_entity_key":"0002034520","primary_entity_name":"GIBO HOLDINGS Ltd"},"word_count":631,"has_tables":true,"body_markdown":"** **\n\n**ITEM\n16K. CYBERSECURITY**\n\n \n\nWe\nhave developed and implemented a cybersecurity risk management policy designed to protect the confidentiality, integrity, and availability\nof our critical systems and information.\n\n** **\n\n**Cybersecurity\nRisk Management and Strategy**\n\n \n\nTo\npreserve the confidentiality, integrity, and availability of our information systems, safeguard our assets, data and network infrastructure,\nwhile meeting regulatory requirements, it is crucial for us to effectively manage cybersecurity risks. To achieve this, we maintain a\nstrict user access control policy and only permit authorized employees to access the data on our platform, and we have implemented a\ncomprehensive cybersecurity risk management policies and measures, which is integrated in our overall enterprise risk management system\nand processes.\n\n \n\nOur\nchief executive officer and staff from IT department are tasked with assessing, identifying and managing risks related to cybersecurity\nthreats. Their responsibilities primarily include:\n\n \n\n \n●\ndevelopment\nof risk-based action plans to manage identified vulnerabilities and implementation of new protocols and infrastructure improvements;\n\n \n●\ncybersecurity\nincident investigations and threat monitoring;\n\n \n●\nsecure\naccess control measures applied to critical IT systems, equipment and devices, designed to prevent unauthorized users, processes,\nand devices from assessing IT systems and data;\n\n \n●\ndeveloping\nand executing protocols to ensure that information regarding cybersecurity incidents is promptly shared with the board of directors,\nas appropriate, to allow for risk and materiality assessments and to consider disclosure and notice requirements; and\n\n \n●\ndeveloping\nand implementing training on cybersecurity, information security and threat awareness.\n\n \n\nThere\nwere no cybersecurity incidents during the fiscal year ended December 31, 2025 that resulted in an interruption to our operations, known\nlosses of any critical data or otherwise had a material impact on our strategy, financial condition or results of operations. However,\nthe scope and impact of any future incident cannot be predicted. See “*Item 3. Key Information — D. Risk\nFactors*” for more information on how material cybersecurity attacks may impact our business.\n\n** **\n\n**Cybersecurity\nGovernance**\n\n \n\nOur\nboard of directors is ultimately responsible for overseeing risks related to cybersecurity. Our board of directors shall (i) maintain\noversight of the disclosure related to cybersecurity matters in current reports or periodic reports of our company, (ii) review updates\nto the status of any material cybersecurity incidents or material risks from cybersecurity threats to our company, and the disclosure\nissues, if any, presented by our management on a quarterly basis, and (iii) review disclosure concerning cybersecurity matters in our\nannual report on Form 20-F presented by our management.\n\n \n\nAt\nthe management level, our chief executive officer and staff under his supervision are responsible for monitoring and mitigating cybersecurity\nrisks, including those associated with third-party service providers. The team investigates and responds to any suspicious activities\nwithin our data environment. Upon detecting any material cybersecurity threat or cybersecurity incident, the relevant staff will report\nthe threat or incident to our chief technology officer, who will assume the responsibility for managing the risks from such material\ncybersecurity threat or cybersecurity incident and monitoring the prevention, mitigation and remediation measures. Our chief technology\nofficer is required to update our board of directors regarding the status of any material cybersecurity threats, material cybersecurity\nincidents or other associated risks, and also required to discuss with our board of directors with respect to disclosure of any material\ncybersecurity threat or incident, if any.\n\n \n\nIf\na cybersecurity incident occurs, our chief executive officer will promptly organize personnel for internal assessment. If it is further\ndetermined that the incident could potentially be a material cybersecurity event, our chief executive officer will promptly report the\nincident and assessment results to our board of directors, and, to the extent appropriate, involve external legal counsels to provide\nadvice. Our management shall prepare disclosure material on the cybersecurity incident for review and approval by our board of directors\nbefore it is disseminated to the public.\n\n \n\n79\n\n \n\n \n\n**PART\nIII**"}