{"url_path":"/sec/ifbd/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBERSECURITY**","topic":"sec","document":{"doc_type":"20-F/A","doc_date":"2026-06-12","source_url":"https://www.sec.gov/Archives/edgar/data/1815566/0001731122-26-000847-index.html","accession_number":"0001731122-26-000847","cik":"0001815566","ticker":"IFBD","issuer_name":"Infobird Co., Ltd","edgar_url":"https://www.sec.gov/Archives/edgar/data/1815566/0001731122-26-000847-index.html","primary_entity_key":"0001815566","primary_entity_name":"Infobird Co., Ltd"},"word_count":577,"has_tables":true,"body_markdown":"**ITEM 16K CYBERSECURITY**\n\n \n\nWe identify and assess material\nrisks from cybersecurity threats to our information systems and the information residing in our information systems by monitoring and\nevaluating our threat environment on an ongoing basis using various methods including, for example, using manual and automated tools,\nsubscribing to reports and services that identify cybersecurity threats, analyzing reports of threats and threat actors, conducting scans\nof the threat environment, and conducting risk assessments.\n\n \n\nWe manage material risks from\ncybersecurity threats to our information systems and the information residing in our information systems through various processes and\nprocedures, including, depending on the environment, risk assessment, incident detection and response, vulnerability management, disaster\nrecovery and business continuity plans, internal controls within our accounting and financial reporting functions, encryption of data,\nnetwork security controls, access controls, physical security, asset management, systems monitoring, and employee training. We engage\nthird-party service providers to provide some of the resources used in our information systems and some third-party service providers\nhave access to information residing in our information systems. With respect to such third parties, we seek to engage reliable, reputable\nservice providers that maintain cybersecurity programs. Depending on the nature and extent of the services provided, the sensitivity and\nquantity of information processed, and the identity of the service provider, our processes may include conducting due diligence on the\ncybersecurity practices of such provider and contractually imposing cybersecurity related obligations on the provider. In light of the\nNational Cybersecurity Incident Reporting Measures effective November 1, 2025, we have enhanced our incident detection and reporting procedures\nto ensure compliance with the strict one-hour (for CII operators) and four-hour (for general network operators) reporting timelines for\nmajor incidents .\n\n \n\nWe are not aware of any risks\nfrom cybersecurity threats, including as a result of any cybersecurity incidents, which have materially affected or are reasonably likely\nto materially affect our Group, including our business strategy, results of operations, or financial condition. Refer to “Item\n3. Key Information—D. Risk Factors—Risks Related to Our Business and Industry — Unauthorized disclosure, destruction\nor modification of data, through cybersecurity breaches, computer viruses or otherwise or disruption of our services could expose us\nto liability, protracted and costly litigation and damage our reputation.”\n\n \n\n*Cybersecurity Governance*\n\n \n\nOur Board of Directors holds\noversight responsibility over our Group’s risk management and strategy, including material risks related to cybersecurity threats.\nThis oversight is executed directly by our board of directors and through its committees. Our audit committee oversees the management\nof our Group’s major financial risk exposures, the steps management has taken to monitor and control such exposures, and the process\nby which risk assessment and management is undertaken and handled, which would include cybersecurity risks, in accordance with its charter.\nThe audit committee holds regular meetings and receives periodic reports from management regarding risk management, including major financial\nrisk exposures from cybersecurity threats or incidents.\n\n \n\n121\n\n \n\n \n\nWithin management, the Group’s\nChief Executive Officer are primarily responsible for assessing and managing our material risks from cybersecurity threats on a day-to-day\nbasis and keep the senior executive officers informed on a regular basis of the identification, assessment, and management of cybersecurity\nrisks and of any cybersecurity incidents. Such management personnel have prior experience and training in managing information systems\nand cybersecurity matters and participate in ongoing training programs.\n\n \n\nAs of the date hereof, the Company has not encountered\ncybersecurity incidents that the company believes to have been material to the Company taken as a whole.\n\n \n\n**PART III**"}