{"url_path":"/sec/mbai/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K Cybersecurity.**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-04-27","source_url":"https://www.sec.gov/Archives/edgar/data/1610590/0001213900-26-048090-index.html","accession_number":"0001213900-26-048090","cik":"0001610590","ticker":"MBAI","issuer_name":"Check-Cap Ltd","edgar_url":"https://www.sec.gov/Archives/edgar/data/1610590/0001213900-26-048090-index.html","primary_entity_key":"0001610590","primary_entity_name":"Check-Cap Ltd"},"word_count":735,"has_tables":true,"body_markdown":"** **\n\n**Item\n16K. Cybersecurity.**\n\n \n\nThe Board of Directors is\nresponsible for overseeing our risk management program and cybersecurity is a critical element of this program. Management is responsible\nfor the day-to-day administration of our risk management program and our cybersecurity policies, processes, and practices. Our cybersecurity\npolicies, standards, processes, and practices are based on recognized frameworks and other applicable industry standards are standalone\nfrom our overall risk management system and processes. In general, we seek to address material cybersecurity threats through a company-wide\napproach that addresses the confidentiality, integrity, and availability of our information systems or the information that the Company\ncollects and stores, by assessing, identifying and managing cybersecurity issues as they occur.\n\n**  **\n\n**Cybersecurity Risk Management and Strategy**\n\n \n\nOur cybersecurity risk management\nstrategy focuses on several areas:\n\n \n\n \n●\n*Identification and Reporting*: We have implemented a comprehensive, cross-functional approach to assessing, identifying and managing material cybersecurity threats and incidents. Our program includes controls and procedures to properly identify, classify and escalate certain cybersecurity incidents to provide management visibility and obtain direction from management as to the public disclosure and reporting of material incidents in a timely manner.\n\n \n\n \n●\n*Technical Safeguards*: We implements technical safeguards that are designed to protect the our information systems from cybersecurity threats, including firewalls, intrusion prevention and detection systems, anti-malware functionality, and access controls, which are evaluated and improved through vulnerability assessments and cybersecurity threat intelligence, as well as outside audits and certifications.\n\n \n\n131\n\n \n\n \n\n \n●\n*Incident Response and Recovery Planning*: We have established and maintains comprehensive incident response, business continuity, and disaster recovery plans designed to address our response to a cybersecurity incident. We conduct regular tabletop exercises to test these plans and ensure personnel are familiar with their roles in a response scenario.\n\n \n\n  ● *Third-Party Risk Management*: We maintain a comprehensive, risk-based approach to identifying and overseeing material cybersecurity threats presented by third parties, including vendors, service providers, and other external users of our systems, as well as the systems of third parties that could adversely impact our business in the event of a material cybersecurity incident affecting those third-party systems, including any outside auditors or consultants who advise on our cybersecurity systems.\n\n \n\n \n●\n*Education and Awareness*: We provide regular, mandatory training for all levels of employees regarding cybersecurity threats as a means to equip our employees with effective tools to address cybersecurity threats, and to communicate our evolving information security policies, standards, processes, and practices.\n\n \n\nWe conduct periodic assessment\nand testing of our policies, standards, processes, and practices in a manner intended to address cybersecurity threats and events. The\nresults of such assessments, audits, and reviews are evaluated by management and reported to the Audit Committee and the Board, and we\nadjust our cybersecurity policies, standards, processes, and practices as necessary based on the information provided by these assessments,\naudits, and reviews.\n\n** **\n\n**Governance**\n\n \n\nThe Board, in coordination\nwith the Audit Committee, oversees our risk management program, including the management of cybersecurity threats. The Board and the Audit\nCommittee each receive regular presentations and reports on developments in the cybersecurity space, including risk management practices,\nrecent developments, evolving standards, vulnerability assessments, third-party and independent reviews, the threat environment, technological\ntrends, and information security issues encountered by our peers and third parties. The Board and the Audit Committee also receive prompt\nand timely information regarding any cybersecurity risk that meets pre-established reporting thresholds, as well as ongoing updates regarding\nany such risk. On an annual basis, the Board and the Audit Committee discuss our approach to overseeing cybersecurity threats with members\nof senior management.\n\n \n\nSenior management works collaboratively\nacross the Company to implement a program designed to protect our information systems from cybersecurity threats and to promptly respond\nto any material cybersecurity incidents in accordance with our incident response and recovery plans. To facilitate the success of our\ncybersecurity program, cross-functional teams throughout the Company address cybersecurity threats and respond to cybersecurity incidents.\nThrough ongoing communications with these teams, our outsourced information technology team and senior management are informed about and\nmonitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time, and report such threats\nand incidents to the Audit Committee when appropriate.\n\n** **\n\n**Material Effects of Cybersecurity Incidents**\n\n \n\nRisks from cybersecurity\nthreats, including as a result of any previous cybersecurity incidents, have not materially affected and are not reasonably likely to\nmaterially affect us, including our business strategy, results of operations, or financial condition.\n\n \n\n132\n\n \n\n \n\n**Part\nIII**"}