{"url_path":"/sec/lud/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K **","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-05-15","source_url":"https://www.sec.gov/Archives/edgar/data/1984124/0001213900-26-057512-index.html","accession_number":"0001213900-26-057512","cik":"0001984124","ticker":"LUD","issuer_name":"Luda Technology Group Ltd","edgar_url":"https://www.sec.gov/Archives/edgar/data/1984124/0001213900-26-057512-index.html","primary_entity_key":"0001984124","primary_entity_name":"Luda Technology Group Ltd"},"word_count":419,"has_tables":true,"body_markdown":"**ITEM 16K.**\n**CYBERSECURITY**\n\n \n\n**Risk Management and Strategy**\n\n \n\nWe adhere to the definitions provided in Item\n16K, recognizing the critical significance of implementing strong cybersecurity measures to safeguard our information systems and the\nsensitive data they hold. Our priority is to protect our information and systems from unauthorized access, use, disclosure, disruption,\nmodification, or destruction. We identify and assess material risks from cybersecurity threats to our information systems and the information\nresiding in our information systems by monitoring and evaluating our threat environment on an ongoing basis using various methods including,\nfor example, using manual and automated tools that identify cybersecurity threats, conducting scans of the threat environment, and conducting\nrisk assessments.\n\n \n\nWe manage material risks\nfrom cybersecurity threats to our information systems and the information residing in our information systems through various processes\nand procedures, including, depending on the environment, risk assessment, incident detection and response, vulnerability management, disaster\nrecovery and business continuity plans, internal controls within our accounting and financial reporting functions, encryption of data,\nnetwork security controls, access controls, physical security, asset management, systems monitoring, and employee training.\n\n \n\nAs of the date of this\nannual report, we are not aware of any risks from cybersecurity threats, including as a result of any cybersecurity incidents, which have\nmaterially affected or are reasonably likely to materially affect our Group, including our business strategy, results of operations, or\nfinancial condition.\n\n \n\n**Cybersecurity Governance**\n\n \n\nOur board of directors holds oversight responsibility\nover our Group’s risk management and strategy, including material risks related to cybersecurity threats. This oversight is executed\ndirectly by our board of directors and through its committees. Our audit committee oversees the management of our Group’s major\nfinancial risk exposures, the steps management has taken to monitor and control such exposures, and the process by which risk assessment\nand management is undertaken and handled, which would include cybersecurity risks, in accordance with its charter. The audit committee\nholds regular meetings and receives periodic reports from management regarding risk management, including major financial risk exposures\nfrom cybersecurity threats or incidents.\n\n \n\nAs we do not have a dedicated board committee\nexclusively focused on cybersecurity, our full board is primarily responsible for overseeing the implementation of our cybersecurity strategy.\nThis includes assessing and managing material risks arising from cybersecurity threats, as well as identifying, evaluating, and addressing\nany cybersecurity incidents.\n\n \n\nAs of the date of this annual report, the Company\nhas not encountered cybersecurity incidents that the company believes to have been material to the Company taken as a whole.\n\n \n\n93\n\n \n\n**PART III**"}