{"url_path":"/sec/ibatf/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C Cybersecurity.","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-18","source_url":"https://www.sec.gov/Archives/edgar/data/1786318/0001193125-26-274679-index.html","accession_number":"0001193125-26-274679","cik":"0001786318","ticker":"IBATF","issuer_name":"INTERNATIONAL BATTERY METALS LTD.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1786318/0001193125-26-274679-index.html","primary_entity_key":"0001786318","primary_entity_name":"INTERNATIONAL BATTERY METALS LTD."},"word_count":341,"has_tables":true,"body_markdown":"Item 1C. Cybersecurity.\n\nCybersecurity Risk Management and Strategy\n\nWe maintain a cybersecurity risk management program designed to identify, assess, manage, mitigate, and respond to cybersecurity threats affecting the information systems we own or use. Our information systems are cloud-based and delivered through software-as-a-service platforms. We rely on third-party providers for system availability, security, data backup, and related services.\n\nOur cybersecurity program is supported by an outsourced information technology service provider, which assists with user account administration, security monitoring, and general IT maintenance, in coordination with senior management. Cybersecurity risks are considered through management’s oversight of IT operations and periodic risk assessment activities, including assessments performed in connection with cybersecurity insurance renewals.\n\n23\n\n[Table of Contents](#toc_page)\n\n \n\nIncident Assessment and Response\n\nOur cybersecurity processes include monitoring and detection activities, procedures to assess the nature and potential impact of cybersecurity events, escalation protocols for senior management and the Board of Directors where appropriate, and incident response procedures intended to support containment, recovery, and communications. If management determines that a cybersecurity incident is material, the incident would be escalated to executive management and the Board, and the company would make public disclosure as required by applicable SEC or Canadian rules and regulations.\n\nThird-Party Risk Management\n\nWe use third-party service providers to support key functions, including cloud-based enterprise systems and hosted platforms. We perform diligence when selecting critical service providers and review available SOC reports or other security attestations where applicable. We have not implemented a formal third-party IT vendor risk management framework, but management relies on contractual commitments, available third-party attestations, and oversight by our outsourced IT provider to help manage cybersecurity risks associated with these providers.\n\nGovernance\n\nThe Board of Directors oversees cybersecurity risk as part of its broader risk oversight responsibilities. Senior management is responsible for oversight of the cybersecurity risk management program and coordination with third-party service providers supporting IT and cybersecurity functions.\n\nMaterial Incidents\n\nWe have not identified any cybersecurity incidents that have materially affected, or are reasonably likely to materially affect, our business strategy, results of operations, or financial condition."}