{"url_path":"/sec/mb/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBERSECURITY**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-05-15","source_url":"https://www.sec.gov/Archives/edgar/data/2027265/0001493152-26-023479-index.html","accession_number":"0001493152-26-023479","cik":"0002027265","ticker":"MB","issuer_name":"MASTERBEEF GROUP","edgar_url":"https://www.sec.gov/Archives/edgar/data/2027265/0001493152-26-023479-index.html","primary_entity_key":"0002027265","primary_entity_name":"MASTERBEEF GROUP"},"word_count":610,"has_tables":true,"body_markdown":"**ITEM\n16K. CYBERSECURITY**\n\n \n\nThe\nCompany has adopted a Cybersecurity Policy governing the establishment and application of certain procedures and safeguards to identify\npotential cybersecurity risks and, in the event of a cybersecurity breach, the protocol for disclosing to the Securities and Exchange\nCommission, including possible remedies. We review cybersecurity risk as part of our overall risk-management program. This ensures that\ncybersecurity risk management remains a meaningful priority in our business strategy and operations. Our risk management strategy for\ncybersecurity generally includes:\n\n \n\n1.\n*Identification*:\nWe aim to proactively identify the manners in which our business could be materially impacted by cybersecurity risks including:\n\n \n\n \n(a)\nCybersecurity\nIncidents - an unauthorized occurrence on or conducted through its information system that jeopardizes the confidentiality, integrity,\nor availability of its information systems or any information residing therein\n\n \n \n \n\n \n(b)\nCybersecurity Threats -\nany potential occurrence that may result in an unauthorized effort to adversely affect the confidentiality, integrity, or availability\nof its information systems or any information residing therein.\n\n \n\n107\n\n \n\n \n\n2.\n*Assessment*:\nWe periodically assess our risks relating to cybersecurity threats, including risks relating to our reliance on third parties. In\nso doing, we consider the likelihood and impact that could result from the manifesting of such risks, together with the sufficiency\nof existing policies, procedures, systems, and safeguards in place to manage such risks, together with the sufficiency of existing\npolicies, procedures, systems, and safeguards in place to manage such risks, including evaluating and if available obtaining cyber\nliability insurance, and aligning such cyber-risk management policies with the Company’s business needs by integrating cyber-risk\nanalysis into significant business decisions.\n\n \n\n3.\n*Management*:\nIf deemed appropriate, we design and implement reasonable safeguards to address any identified gaps in our existing processes and\nprocedures, including annual cybersecurity awareness training emphasizing the use of strong passwords on all systems and aligning\ncyber-risk management policies with the Company’s needs by integrating cyber-risk analysis into significant business decisions\nand ensuring that the Company’s organization structure supports such cybersecurity goals.\n\n \n \n\n4.\n*Evaluation*: If a\ncybersecurity breach occurs, the Audit Committee will determine whether the Incident or Threat is “material” (.i.e. is\nthere a substantial likelihood that a reasonable shareholder would consider it important in making an investment decision or if it\nwould have significantly altered the “total mix” of information made available?), assessing among other factors potential\nor actual financial impacts, reputational damage, and operational disruptions.\n\n \n \n\n5.\n*Report*: Establish\nand monitor an incident response approach requiring our Chief Financial Officer to report to us, the full Board of Directors and\nlegal counsel any cybersecurity concerns or events.\n\n \n \n\n6.\n*Disclosure*: To ensure\ncompliance with SEC requirements and maintain overall stakeholder confidence in the Company, all material and known facts regarding\nthe cybersecurity breach will be recorded, including their nature, scope, and financial implications; and a Form 6-K will be prepared\nand filed within four (4) business days after the determination that a “material” cybersecurity incident has occurred.\n\n \n\nWe\npresently do not engage third parties to assist with evaluating the effectiveness of our risk-management and cybersecurity practices.\nThe Company did not have any material cybersecurity breaches during the year ended December 31, 2025.\n\n \n\nThe\nAudit Committee of our Board of Directors is the governance body involved in, and ultimately responsible for, cybersecurity oversight.\nThey will generally coordinate with our Chief Financial Officer in this regard. If needed, the full Board would be updated on cybersecurity\nrisks and incidents. None of our directors on the Audit Committee nor our Chief Financial Officer have particular experience in cybersecurity\nmatters.\n\n \n\nThe\nCybersecurity Policy has been filed as Exhibit 4.1 to our Annual Report on Form 20-F for the fiscal year ended December 31, 2024.\n\n \n\n108\n\n \n\n \n\n**PART\nIII**"}