{"url_path":"/sec/iotr/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBERSECURITY**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-07-07","source_url":"https://www.sec.gov/Archives/edgar/data/1997637/0001213900-26-075976-index.html","accession_number":"0001213900-26-075976","cik":"0001997637","ticker":"IOTR","issuer_name":"iOThree Ltd","edgar_url":"https://www.sec.gov/Archives/edgar/data/1997637/0001213900-26-075976-index.html","primary_entity_key":"0001997637","primary_entity_name":"iOThree Ltd"},"word_count":535,"has_tables":true,"body_markdown":"**ITEM 16K. CYBERSECURITY**\n\n** **\n\n**Risk Management and Strategy**\n\n** **\n\nThe Company recognizes the critical importance\nof developing, implementing, and maintaining robust cybersecurity measures to safeguard our information systems and protect the confidentiality,\nintegrity, and availability of our data. In an increasingly complex and evolving threat environment, we are committed to proactively addressing\ncybersecurity risks that could impact our operations, customers, and stakeholders.\n\n \n\nWe have established a comprehensive cybersecurity\nand risk management framework, designed to identify, assess, mitigate, and monitor cyber threats and vulnerabilities. This framework includes:\n\n \n\n \n●\n*Regular Cybersecurity Risk Assessments*: We conduct ongoing assessments to evaluate potential cyber-attack vectors, information security weaknesses, and emerging threats that may affect our business operations.\n\n \n\n \n●\n*Data Encryption and Protection*: We employ advanced data encryption protocols to ensure the secure transmission and storage of sensitive information. Confidential data is encrypted based on risk level, and encryption methodologies are applied in accordance with best practices and regulatory standards.\n\n \n\n \n●\n*Internal Security Policies and Access Controls*: The Company has implemented stringent internal policies and procedures governing data security and access control. Access to sensitive systems and information is restricted to authorized personnel on a need-to-know basis, and all employees are required to comply strictly with our cybersecurity policies.\n\n \n\n \n●\n*Employee Training and Awareness*: We provide regular training and awareness programs to educate employees on cybersecurity best practices, threat awareness, and their individual responsibilities in information management. These initiatives are designed to foster a strong security culture across the organization.\n\n \n\n \n●\n*Incident Response and Monitoring*: Our cybersecurity infrastructure includes real-time monitoring tools and an incident response plan to detect, respond to, and recover from security incidents in a timely manner, minimizing potential disruption and loss.\n\n  \n\nWe have not identified risks from known\ncybersecurity threats, or experienced any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially\naffect us, including our operations, business strategy, results of operations, or financial condition. In the event of any significant\ncybersecurity incidents, we will publicly disclose the nature, scope, and impact of the incident, as well as the remediation measures\nwe implement. \n\n \n\n84\n\n \n\n  \n\n**Risk Governance**\n\n** **\n\nOur board of directors oversees the management\nof risks associated with cybersecurity threats.\n\n \n\n**Management’s Role in Managing Risk**\n\n* *\n\nThe Company’s Chief Executive Officer is\nprimarily responsible for assessing, monitoring and managing our cybersecurity risks. Management must ensure that all industry standard\ncybersecurity measures are functioning as required to prevent or detect cybersecurity threats and related risks. Management oversees and\ntests our compliance with standards, remediates known risks, and leads our employee training program.\n\n \n\n**Monitoring Cybersecurity Incidents**\n\n** **\n\nThe Company’s management is continually\ninformed about the latest developments in cybersecurity, including potential threats and innovative risk management techniques. Management\nimplements and oversees processes for the regular monitoring of our information systems. This includes the deployment of industry-standard\nsecurity measures and regular system audits to identify potential vulnerabilities. In the event of a cybersecurity incident, management\nwill implement the cybersecurity crisis management plan.\n\n \n\n**Reporting to Board of Directors**\n\n* *\n\nSignificant cybersecurity matters, and strategic\nrisk management decisions, will be escalated to the board of directors.\n\n \n\nFor additional information on our cybersecurity\nrisks, please see “*Item 3.D. Risk Factors — Risks Related to Intellectual Property, Information Technology, Data Privacy\nand Cybersecurity*.”\n\n \n\n85\n\n \n\n \n\n**PART III**"}