{"url_path":"/sec/mgn/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K Cybersecurity**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-05-15","source_url":"https://www.sec.gov/Archives/edgar/data/1995075/0001213900-26-057595-index.html","accession_number":"0001213900-26-057595","cik":"0001995075","ticker":"MGN","issuer_name":"Megan Holdings Ltd.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1995075/0001213900-26-057595-index.html","primary_entity_key":"0001995075","primary_entity_name":"Megan Holdings Ltd."},"word_count":375,"has_tables":true,"body_markdown":"**ITEM\n16K. Cybersecurity**\n\n \n\nOur Board of Directors\nis responsible for reviewing the Company’s cybersecurity risk management and control systems in relation to the financial reporting\nby the Company, including the Company’s cybersecurity strategy. We maintain a process for assessing, identifying and managing material\nrisks from cybersecurity threats, including risks relating to disruption of business operations or financial reporting systems, intellectual\nproperty theft; fraud; extortion; harm to employees or customers; violation of privacy laws and other litigation\nand legal risk; and reputational risk, as part of our overall risk management system and processes. We assess and manage our cybersecurity\nrisks though our Information Technologies (“IT”) Committee, which is integrated by the Chief Executive Officer and the Chief\nFinancial Officer. The Chief Executive Officer presents to our Board of Directors, on a yearly basis, the work carried out on the identification,\ncategorization, and mitigation procedures put in place in relation to the most relevant risks of the company, including cybersecurity\nrisks. In this sense, risks related to cybersecurity have been categorized as “high relevance” for the Company.\n\n \n\nOur IT department is\nresponsible for targeted and regular monitoring of cybersecurity risks. They independently and continuously monitor cybersecurity risks\nand countermeasures to defend against such threats and, in the event of a cybersecurity threat or cybersecurity incident, inform executive\nmanagement and our Board of Directors. In addition to the regular meetings between executive management and the individual risk owners\nmainly consisting out of the various departments’ heads, a comprehensive cybersecurity risk analysis for internal and external\nrisks is carried out as appropriate.\n\n \n\nAccording to the priority\nof the cybersecurity risks as result of the risk evaluation, risks are addressed by concrete actions and, if appropriate and possible,\nnecessary countermeasures. In order to be able to react quickly and flexibly to cybersecurity risks, risk management is integrated into\nexisting processes and reporting channels. Our risk management program considers cybersecurity risks alongside other company risks, and\nour enterprise risk professionals consult with company subject matter experts to gather information necessary to identify cybersecurity\nrisks and evaluate their nature and severity, as well as identify mitigations and assess the impact of those mitigations on residual\nrisk. We may engage third parties from time to time to conduct risk assessments.\n\n \n\n121\n\n \n\n  \n\n**PART III**"}