{"url_path":"/sec/hiho/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K Cybersecurity**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-07-14","source_url":"https://www.sec.gov/Archives/edgar/data/1026785/0001213900-26-077959-index.html","accession_number":"0001213900-26-077959","cik":"0001026785","ticker":"HIHO","issuer_name":"HIGHWAY HOLDINGS LTD","edgar_url":"https://www.sec.gov/Archives/edgar/data/1026785/0001213900-26-077959-index.html","primary_entity_key":"0001026785","primary_entity_name":"HIGHWAY HOLDINGS LTD"},"word_count":461,"has_tables":true,"body_markdown":"** **\n\n**Item 16K. Cybersecurity**\n\n** **\n\n**Cybersecurity Risk Management and Strategy**\n\n \n\nWe have developed and implemented a cybersecurity\nrisk management program intended to protect the confidentiality, integrity, and availability of our critical systems and information.\nOur cybersecurity risk management program is centered on management of risks related to our network and enterprise resource planning system,\nincluding security measures and controls to identify, protect, detect, respond to, and recover from cybersecurity risks.\n\n \n\n64\n\n \n\n \n\nOur cybersecurity risk management program is integrated\ninto our overall risk management process and shares common methodologies, reporting channels and governance processes that apply across\nthe risk management process to other risk areas.\n\n \n\nKey aspects of our cybersecurity risk management\nprogram include:\n\n \n\n \n●\nrisk assessments designed to help identify material cybersecurity risks to our critical systems and information;\n\n \n\n \n●\nour information technology department principally responsible for managing (1) our cybersecurity risk assessment processes, (2) our security controls, and (3) our response to cybersecurity incidents;\n\n \n\n \n●\nthe use of external service providers, where appropriate, to assess, test or otherwise assist with aspects of our security processes;\n\n \n\n \n●\ncybersecurity and data privacy awareness for management and employees; and\n\n \n\n \n●\na cybersecurity incident response plan and policy that includes procedures for responding to cybersecurity incidents and defines how security incidents are identified, classified, reported, remediated and mitigated.\n\n \n\nWe have not identified\nrisks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected us,\nincluding our operations, business strategy, results of operations, or financial condition. We face certain ongoing risks from cybersecurity\nthreats that, if realized, are reasonably likely to materially affect us, including our operations, business strategy, results of operations,\nor financial condition. See “*Item 3. Key Information–D. Risk Factors—Risk of Cybersecurity Breaches Could Adversely\nAffect Our Business, Revenues and Competitive Position*.”\n\n** **\n\n**Cybersecurity Governance**\n\n** **\n\nOur Board considers cybersecurity\nrisk as a critical part of its risk oversight function and is responsible for the oversight of cybersecurity and other information technology\nrisks. The Board oversees management’s implementation of our cybersecurity risk management program.\n\n \n\nThe Board receives periodic\nupdates of our cybersecurity risks and controls from our Chief Operating Officer (COO). In addition, the COO updates the Board, as necessary,\nregarding cybersecurity incidents they consider significant. The Board also monitors the cyber risk management program.\n\n \n\nOn the management team,\nour COO has overall responsibility for assessing and managing our material risks from cybersecurity threats, and the COO is assisted in\nthis regard by our information technology team.\n\n \n\nOur COO takes steps to stay informed about and\nmonitor the identification, prevention, detection, protection, mitigation, and remediation of key cybersecurity risks and incidents through\nvarious means, which may include briefings with information technology team members and external consultants, and information and alerts\nobtained from governmental, public or private sources. \n\n** **\n\n65\n\n \n\n** **\n\n**PART III**"}