{"url_path":"/sec/karo/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBERSECURITY**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-06-09","source_url":"https://www.sec.gov/Archives/edgar/data/1828102/0001213900-26-066795-index.html","accession_number":"0001213900-26-066795","cik":"0001828102","ticker":"KARO","issuer_name":"Karooooo Ltd.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1828102/0001213900-26-066795-index.html","primary_entity_key":"0001828102","primary_entity_name":"Karooooo Ltd."},"word_count":1093,"has_tables":true,"body_markdown":"**Item 16K. CYBERSECURITY**\n\n** **\n\n**Risk Management and Strategy**\n\n** **\n\nWhile the Board has delegated risk management\nresponsibilities to the Audit and Risk Committee, the Board remains ultimately responsible for the governance of risk, including cybersecurity\nrisk. The enterprise risk management framework defines Karooooo’s risk management philosophy and encourages a risk-conscious business\nculture through agreed internal controls and commitment to mitigating actions. Karooooo’s risk management framework implements\na bottom-up and top-down approach and has been reviewed to specifically consider the governance and management of risk to support the\nachievement of strategic objectives, including compliance and performance- related matters.\n\n \n\nThe risk management framework ensures an effective\nsystem of risk identification, analysis, evaluation and treatment throughout the Group. Major risk categories have been identified as\nfinancial risk, operational risk, business risk, legal and regulatory risk and information technology risk. A dashboard of significant\nrisks is compiled through the internal risk function from risks identified by business. Individual risk ratings are determined by the\nprobability and impact of each risk.\n\n \n\nAppropriate risk response planning is ascribed\nto each risk and mitigating actions are monitored. This report is regularly reviewed and interrogated by the Audit and Risk Committee.\n\n \n\nA system of internal controls, designed to protect\nvalue and enable business growth in a sustainable manner, encompasses financial, operational, compliance and sustainability issues. This\nsystem includes a documented organisational structure and division of responsibility, clarity of accountability, established policies\nand procedures which are communicated throughout the Group, and the careful selection, training and development of people.\n\n \n\nThe internal audit function has been outsourced\nto BDO. An annual internal audit plan, containing a programme of financial and operational audits and reviews for the Group, including\ncybersecurity, is agreed with the Audit and Risk Committee. This plan is developed by applying a risk-based approach and is reviewed\nand ultimately approved by the Board on recommendation of the Audit and Risk Committee. It is regularly revised to ensure that it remains\nrelevant to the key business priorities and changing risk environment.\n\n** **\n\n**Information Technology (IT) Governance**\n\n \n\nIn view of its importance as a key driver of\nKarooooo’s strategy and value proposition, the governance of IT, including the identification and management of risks, is managed\nthrough a separate management structure, the IT Steering Committee, that reports to the Audit and Risk Committee. Governance is achieved\nthrough the adoption and implementation of appropriate policies and procedures and the management and monitoring of compliance.\n\n \n\nThe IT Steering Committee is responsible for\nthe effective supply and use of information and technology for the Group and is composed of the Group Chief Operating Officer (“COO”),\nGroup Governance Officer (“GO”), Group Chief Information Officer (“CIO”), Group Chief Technology Officer (“CTO”),\nIT Governance and Risk Officer and other senior members of management as nominated by the Group Chief Executive Officer. The CIO has\noverall responsibility for cybersecurity in the Group, including information security risk and compliance programs, as well as cyber\nresilience and response plans. The CIO is supported by the IT Governance and Risk Officer and they work in partnership with various other\nsenior members of the business, including the COO, Group Chief Financial Officer, CTO, Legal Officer, Compliance Officer and the Data\nProtection Officer to ensure that the Group’s information security posture is fit for purpose. Both the CIO and the IT Governance\nand Risk officer hold degrees in Computer Science.\n\n \n\nThe CIO is supported by a global team of experts\nwho manage the day-to-day information and cybersecurity activities of the business. These staff hold certifications in their various\ndomains of expertise.\n\n \n\nThe IT Steering Committee presents regular reports\nto the Audit and Risk Committee, which consist of a comprehensive governance report and dedicated risk register, including information,\ncybersecurity, and information technology risks, the mitigating controls that are in place, management’s action plans to remediate\nmaterial issues, additional measures to be implemented, as well as anticipated residual risk levels. Significant risks are extracted\nand included in the enterprise risk management dashboard. At the request of the Board, the external auditors review the IT general controls\nas part of the annual audit.\n\n \n\n110\n\n \n\n \n\nThe Board reviews and discusses the Group’s technology and cybersecurity\nstrategy with the COO bi-annually.\n\n \n\nKey cybersecurity aspects include:\n\n \n\n \n●\nCybersecurity risk assessment;\n\n \n\n \n●\nInformation and cybersecurity\nincident management, including incident response timelines; materiality assessment; incident notification and communication mechanisms\nand timelines; and\n\n \n\n \n●\n  Business continuity\ntesting, including cyber incident simulations.\n\n \n\nAt an operational level, the Group has implemented\ntechnologies and systems architectures to ensure business resilience and we have adopted robust frameworks for managing threat intelligence,\nperforming vulnerability assessments and implementing appropriate technical and organizational measures to remediate identified risks.\n\n \n\nWe use the information gained through testing\nand monitoring to manage any identified vulnerabilities and further improve our cybersecurity preparedness and response infrastructure,\nincluding the actions to be taken in responding to and recovering from cybersecurity incidents, which include assessing the severity\nof incidents, escalation protocols, containment of incidents, communication protocols, remediation actions and post incident reviews.\n\n \n\nOur aim is to address cybersecurity risks by\nway of a cross-functional approach, focused on preserving the confidentiality, integrity and availability of the information that we\ncollect and store by identifying, preventing and mitigating cybersecurity threats and effectively responding to cybersecurity incidents\nwhen they occur.\n\n \n\nWe perform network and endpoint monitoring, vulnerability\nassessments, threat hunting and penetration testing on an ongoing basis. Data collected from these activities informs our response and\naction, as appropriate. This includes routinely performing incident simulations and recovery exercises at both a technical and management\nlevel.\n\n \n\nAll staff receive annual cybersecurity awareness\ntraining. Our security training, incorporates awareness of cyber threats (including but not limited to malware, ransomware, social engineering\nand AI-enabled attacks), password hygiene and incident reporting processes. We incorporate external expertise and reviews in all aspects\nof our program, which includes the ongoing certification of the Group to the ISO/IEC 27001, ISO/IEC 27017 and ISO/IEC 27018 information\nsecurity standards, third party penetration testing of the core Fleet application, as well as cybersecurity audits performed by BDO.\n\n \n\nAccess to personal data is restricted in accordance\nwith applicable Data Protection legislation and monitored in conjunction with appointed Data Protection Officers.\n\n \n\nAs at the date of this annual report, cybersecurity\nthreats, including as a result of any previous cybersecurity incidents, have not materially affected our business, results of operations\nor financial conditions. We face risks from cybersecurity threats that, if realized, could have a material adverse effect on us including\nan adverse effect on our business, financial condition and results of operations. See Also “Risks Factors – Risks Relating\nto Our Intellectual Property, Data Privacy and Cybersecurity.”"}