{"url_path":"/sec/gtmay/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBERSECURITY","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-09-11","source_url":"https://www.sec.gov/Archives/edgar/data/1163560/0001140361-26-036215-index.html","accession_number":"0001140361-26-036215","cik":"0001163560","ticker":"GTMAY","issuer_name":"GRUPO TMM SAB","edgar_url":"https://www.sec.gov/Archives/edgar/data/1163560/0001140361-26-036215-index.html","primary_entity_key":"0001163560","primary_entity_name":"GRUPO TMM SAB"},"word_count":940,"has_tables":true,"body_markdown":"ITEM 16K.\n\nCYBERSECURITY\n\nRisk Management, Strategy and Governance\n\nIn 2025, Grupo TMM maintained a comprehensive cybersecurity approach aimed at ensuring the confidentiality, integrity and availability of its systems\nand critical information, as an essential component of its risk management strategy and operational resilience.\n\nOur strategy is supported by a hybrid and cloud-based technology infrastructure, backed by world-class strategic partners such as Amazon Web Services, Microsoft Corporation and Fortinet, under a shared responsibility model that combines robust internal controls with internationally certified platforms.\n\nComprehensive Cyber Risk Management Framework\n\nGrupo TMM maintains a comprehensive cybersecurity framework focused on the identification, assessment and mitigation of material risks that could\naffect its operations, strategic information and digital assets. This framework includes:\n\n \n\n•\n\nCapabilities for prevention and reduction of the attack surface\n\n \n\n•\n\nContinuous monitoring of security events\n\n \n\n•\n\nEarly threat detection\n\n \n\n•\n\nAutomated incident response\n\n \n\n•\n\nComprehensive logging and traceability of events\n\nThrough this approach, access controls, network segmentation, endpoint protection, identity management and centralized monitoring of security events are strengthened, enabling operational continuity across hybrid and cloud environments.\n\nThe incident response protocol includes classification by level of criticality, timely activation of containment and mitigation measures, and comprehensive documentation within the internal help desk platform, facilitating root cause analysis, continuous improvement and regulatory compliance.\n\nIn high-severity scenarios, the Information Technology (“IT”) area is authorized to implement preventive measures, including the controlled suspension\nof operations, when necessary to protect critical assets and minimize impacts.\n\nCritical Infrastructure and Cloud Services\n\nERP Platform. The Group’s ERP system (SAP\nS/4HANA) is hosted on Amazon Web Services (AWS), which provides:\n\n \n\n•\n\nNetwork firewalls and perimeter protection\n\n \n\n•\n\nAutomated mitigation against DDoS attacks through AWS Shield Standard\n\n \n\n•\n\nIdentity and access management (IAM) with multi-factor authentication (MFA)\n\n \n\n•\n\nEncryption of data in transit and at rest\n\n \n\n•\n\nMonitoring and auditing through AWS CloudTrail\n\n \n\n•\n\nVulnerability management\n\n \n\n•\n\nDaily backups\n\n \n\n•\n\nAdvanced threat detection capabilities\n\nAWS Shield Standard provides continuous defense against distributed denial-of-service (DDoS) attacks at Layers 3 (Network) and 4 (Transport) of the OSI\nmodel, contributing to the availability and stability of the technology infrastructure.\n\n99\n\n[Table of Contents](#TABLEOFCONSENTS)\n\nCorporate Communications. Organizational\ncommunications are supported by Microsoft 365, a platform by Microsoft Corporation that integrates:\n\n•\n\nAdvanced threat protection\n\n•\n\nData encryption\n\n•\n\nData loss prevention (DLP)\n\n•\n\nMulti-factor authentication (MFA)\n\nIn emergency or high-priority situations, incidents may be escalated directly to AWS for matters related to critical infrastructure and ERP systems, or\nto Microsoft for matters related to the collaboration platform, in accordance with established protocols.\n\nSecurity in Hybrid Environments\n\nDuring 2025, the IT area strengthened its security model to address a hybrid and distributed work environment. Key capabilities implemented and\nenhanced include:\n\n \n\n1.\n\nActive protection inside and outside the office\n\n \n\n2.\n\nPreventive web filtering\n\n \n\n3.\n\nAutomated configuration standardization\n\n \n\n4.\n\nSimplified management of work profiles\n\n \n\n5.\n\nEarly detection of anomalous behavior\n\n \n\n6.\n\nReal-time digital asset inventory\n\n \n\n7.\n\nAutomated enforcement of compliance policies\n\n \n\n8.\n\nRemote diagnostics of device status\n\n \n\n9.\n\nPreventive monitoring of operational health\n\n \n\n10.\n\nEnhanced identity verification and access control\n\nSecurity updates, patches and antivirus solutions are deployed automatically, reducing risk exposure and strengthening operational resilience.\n\nCybersecurity Culture and Preventive Management\n\nOngoing training and awareness are essential components of Grupo TMM’s cybersecurity approach. Through continuous communication and training programs,\na preventive and responsible use of digital tools is promoted.\n\nDuring 2025, preventive controls and early detection mechanisms enabled the containment of attempts related to common digital threats, such as\nphishing, credential compromise, business email compromise and malware distribution. None of the detected attempts resulted in the compromise of critical assets or sensitive information. Each event was documented and managed in accordance with internal protocols, strengthening organizational learning and continuous improvement.\n\nCertifications and Compliance\n\nThe Group’s strategic providers maintain internationally recognized information security certifications, including ISO 27001, ISO 27017 and ISO 27018,\nas well as SOC 1 and SOC 2 Type II reports. This certified environment enhances the reliability and resilience of the technology infrastructure supporting Grupo TMM’s critical operations and contributes to mitigating material technology risks.\n\nGovernance and Oversight\n\nThe Chief Information Officer (“CIO”) leads Grupo TMM’s cybersecurity strategy and ensures alignment with industry best practices and the Company’s overall corporate strategy. The IT team reports continuously to the CIO on relevant threats and security events. In the event of high-priority incidents, the CIO reports to the Chief Executive Officer, the Chief Financial Officer and the Board of Directors in the corresponding sessions.\n\nWhile Grupo TMM does not have a specific Board committee or subcommittee dedicated exclusively to cybersecurity risk oversight, such risks fall within\nthe scope of the Corporate Governance Committee, which oversees the comprehensive management of the Group’s strategic, operational and technological risks. In this context, cybersecurity is\ntreated as a cross-functional strategic risk, subject to review within the overall internal control and enterprise risk management framework.\n\nESG Approach and Digital Resilience\n\nThe strategic availability of reliable information, continuous employee training and technology governance are integral components of Grupo TMM’s ESG approach,\nstrengthening operational resilience, responsible risk management and long-term sustainability.\n\nOur cybersecurity strategy continues to evolve to anticipate and mitigate emerging threats, fostering a secure digital environment that protects the Group’s assets,\npreserves business continuity and safeguards the information of our stakeholders.\n\n100\n\n[Table of Contents](#TABLEOFCONSENTS)\n\nESG Approach and Digital Resilience\n\nThe strategic availability of reliable information, continuous employee training and technology governance are integral components of Grupo TMM’s ESG\napproach, strengthening operational resilience, responsible risk management and long-term sustainability.\n\nOur cybersecurity strategy continues to evolve to anticipate and mitigate emerging threats, fostering a secure digital environment that protects the\nGroup’s assets, preserves business continuity and safeguards the information of our stakeholders.\n\nPART III"}