{"url_path":"/sec/jxg/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K Cybersecurity**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-05-15","source_url":"https://www.sec.gov/Archives/edgar/data/1546383/0001213900-26-057231-index.html","accession_number":"0001213900-26-057231","cik":"0001546383","ticker":"JXG","issuer_name":"JX Luxventure Group Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1546383/0001213900-26-057231-index.html","primary_entity_key":"0001546383","primary_entity_name":"JX Luxventure Group Inc."},"word_count":1011,"has_tables":true,"body_markdown":"** **\n\n**ITEM 16K. Cybersecurity**\n\n** **\n\n**Risk\nManagement and Strategy**\n\n** **\n\nWe have\nestablished policies and processes for assessing, identifying, and managing material risks from cybersecurity threats, and plan to integrate\nthese processes into our overall risk management systems and processes.\n\n \n\nWe also implemented a\nset of procedures to ensure effective management of the cybersecurity risks associated with the use of third-party service providers,\nincluding conducting cybersecurity assessments and tracking the capabilities and qualifications of third-party security service providers\nthrough assessment process. vulnerabilities.\n\n \n\nWe recognize the importance\nof assessing, identifying, and managing material risks associated with cybersecurity threats. These risks include, among other things,\noperational risks; intellectual property theft; fraud; extortion; harm to employees or customers; violation of privacy or security laws\nand other litigation and legal risk; and reputational risks.\n\n \n\nTo address the increasing\nrisks of cyber-attacks, we implemented a robust and scalable cybersecurity strategy to protect our infrastructure, customer data, and\nreputation, while leveraging third-party cloud services. We utilize advanced security features provided by our cloud partners, including\nencryption, intrusion detection, and continuous monitoring, to safeguard sensitive information and prevent unauthorized access. Our cybersecurity\nteam enforces strict access controls, such as multi-factor authentication (MFA) and role-based permissions, while conducting regular vulnerability\nscans, penetration testing, and audits to identify and remediate potential weaknesses. Comprehensive employee training programs promote\nawareness of phishing and other threats, reducing human error risks. We maintain a well-defined incident response plan to swiftly contain,\ninvestigate, and resolve any security incidents, ensuring minimal disruption to our platform and services. By aligning with our cloud\nproviders’ compliance standards we meet regulatory requirements and protect customer trust.\n\n \n\nWe assess the impact of cybersecurity\nthreats on our business, including our strategic direction, operational performance, and financial stability, using insights from any\npast cybersecurity incidents in the shipping industry of which we are aware.\n\n \n\nWe have implemented risk-based processes for assessing,\nidentifying, and managing material risks from cybersecurity threats. These processes include access controls to organizational systems,\ndata encryption, and cybersecurity training and security awareness campaigns, and are designed to systematically evaluate potential vulnerabilities\nand cybersecurity threats and minimize their potential impact on our organization’s operations, assets, and stakeholders. Accordingly,\nwe also implement processes to oversee and identify material cybersecurity risks associated with our utilization of third-party service\nproviders on whom we have a material dependency, such as conducting due diligence assessments to evaluate their cybersecurity measures,\ndata protection practices, and compliance with relevant regulatory requirements.\n\n \n\nAs we do not have a dedicated board committee\nsolely focused on cybersecurity, our board of directors has oversight responsibility for risks and incidents relating to cybersecurity\nthreats, including compliance with disclosure requirements, cooperation with law enforcement, and related effects on financial and other\nrisks. Senior management regularly discusses cyber risks and trends and, should they arise, any material incidents with our board of directors.\nWe consult with outside counsel as appropriate, including on materiality analysis and disclosure matters, and in the event of an incident\nour board of directors will make the final materiality determinations and disclosure and other compliance decisions. Our external IT provider\nmaintains a dedicated cybersecurity auditing team that independently tests our cybersecurity controls.\n\n \n\n118\n\n \n\n \n\nOverall, our approach to cybersecurity risk management\nincludes the following key elements:\n\n \n\n \n●\nOpen-Source Software Approval Process: All OSS intended for use in our products or platform must be reviewed and approved by a designated compliance team. This process includes evaluating the OSS license to ensure compatibility with our business model and existing obligations, documenting the software’s purpose, and verifying that it does not impose restrictive requirements, such as mandatory source code disclosure.\n\n \n \n \n\n \n●\nLicense Compliance Tracking: We maintain a centralized inventory of all OSS components used in our systems, including their versions, licenses, and associated obligations. Developers are required to log each OSS component in a software bill of materials (SBOM) and ensure that license terms, such as attribution notices or copyleft provisions, are adhered to in our codebase and distributions.\n\n \n\n \n●\nCode Review and Scanning Policy: All code, including OSS, must undergo automated scanning using tools  to detect unlicensed or non-compliant OSS components before integration. Regular code reviews ensure that OSS is used in accordance with its license terms and that any modifications or derivative works comply with applicable requirements.\n\n \n \n \n\n \n●\nDeveloper Training and Guidelines: Employees and contractors receive mandatory training on OSS licensing and compliance. Clear guidelines prohibit the use of high-risk licenses  without explicit approval and outline procedures for incorporating OSS, such as including proper license notices in our products and ensuring no proprietary code is inadvertently mixed with copyleft-licensed OSS.\n\n \n \n \n\n \n●\nThird-Party Contribution Policy: Developers are prohibited from contributing to external OSS projects on behalf of the company without prior approval. Any contributions must align with our licensing policies, and we ensure that contributions do not inadvertently incorporate our proprietary code into OSS projects under incompatible licenses.\n\n \n\nThese policies help ensure\nthat our use of open-source software is compliant, minimizing legal and operational risks while maintaining the integrity of our platform\nand products.\n\n \n\nOur business strategy,\noperating results and financial condition have not been materially affected by risks from cybersecurity threats, including as a result\nof previously identified cybersecurity incidents, but we cannot provide assurance that they will not be materially affected in the future\nby such risks or any future material incidents.\n\n \n\nAs of the date of this\nAnnual Report, we have not experienced any material cybersecurity incidents or identified any material cybersecurity threats that have\naffected or are reasonably likely to materially affect us, our business strategy, results of operations or financial condition.\n\n** **\n\n**Governance**\n\n \n\nOur Board is responsible for overseeing our cybersecurity risk management.\nOur Board shall (i) maintain oversight of the disclosure related to cybersecurity matters in current reports or periodic reports of our\ncompany, (ii) review updates to the status of any material cybersecurity incidents or material risks from cybersecurity threats to our\ncompany, and the disclosure issues, if any, presented by our cybersecurity officer on a quarterly basis, and (iii) review disclosure concerning\ncybersecurity matters in our annual report on Form 20-F presented by our cybersecurity officer.\n\n \n\n119\n\n \n\n  \n\n**PART III**"}