{"url_path":"/sec/nwgl/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K **","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-04-27","source_url":"https://www.sec.gov/Archives/edgar/data/1948294/0001493152-26-019023-index.html","accession_number":"0001493152-26-019023","cik":"0001948294","ticker":"NWGL","issuer_name":"CL Workshop Group Ltd","edgar_url":"https://www.sec.gov/Archives/edgar/data/1948294/0001493152-26-019023-index.html","primary_entity_key":"0001948294","primary_entity_name":"CL Workshop Group Ltd"},"word_count":576,"has_tables":true,"body_markdown":"**ITEM\n16K.**\n**CYBERSECURITY**\n\n \n\n**Risk\nManagement and strategy**\n\n \n\nThe\ndata processed in our business does not have a bearing on national security, economy operation, social stability or public health and\nsecurity and thus may not be classified as being sensitive. Nevertheless, we have implemented and maintained information security processes\ndesigned to identify, assess and manage material risks from cybersecurity threats to our information systems and critical data, including\nintellectual property and confidential information that is proprietary, strategic or competitive in nature. We also maintain critical\ninternal computer networks, as well as third-party hosted services, communications systems, hardware and software.\n\n \n\nWe\nmaintain various cybersecurity measures and protocols to safeguard our systems and data and continuously monitor and assess potential\nthreats to pre-emptively address any emerging cyber risks. We have implemented various processes for assessing, identifying, and managing\nmaterial risks from cybersecurity threats, which are integrated into our overall risk management framework. These processes include access\ncontrols to organizational systems, data encryption and security awareness campaigns, and are designed to systematically evaluate potential\nvulnerabilities and cybersecurity threats and minimize their potential impact on our organization’s operations, assets and stakeholders.\nOur cybersecurity risk management processes share common methodologies, reporting channels and governance processes with our broader\nrisk management processes. By embedding cybersecurity risk management into and aligning it with our broader risk management processes,\nwe aim to ensure a comprehensive and proactive approach to safeguarding our assets and operations.\n\n \n\nWe\nengage third-party consultants and specialists to enhance the effectiveness of our cybersecurity processes, augment our internal capabilities,\nvalidate our controls, and stay abreast of evolving cybersecurity risks and best practices.\n\n \n\nFor\nthe year ended December 31, 2025, we did not detect any cybersecurity incidents that have materially affected or are reasonably likely\nto materially affect us, including our business strategy, results of operations, or financial condition.\n\n \n\nResponsibility\nfor overseeing cybersecurity risks is integrated into our management team, which includes our directors and chief financial officer.\nWe also utilize third-party service providers who are responsible for monitoring, detecting and assessing cybersecurity risks and incidents.\nThese third-party service providers are also used for certain IT-related services, where appropriate, to assess, test or otherwise assist\nwith aspects of our security controls. Accordingly, we also implement processes to oversee and identify material cybersecurity risks\nassociated with our utilization of third-party service providers on whom we have a material dependency.\n\n \n\nOur\nthird-party service providers currently comprise IT professionals with expertise in risk management, cybersecurity, and information technology.\nThese individuals have, and any future individuals are expected to have credentials relevant to their role, which includes prior experience\nworking in similar roles and formal education. The third-party service providers are also expected to keep abreast of cybersecurity best\npractices and procedures. The third-party service providers are responsible for assessing, identifying and mitigating material cybersecurity\nrisks, including at a strategic level, monitoring for, defending against and remediating cybersecurity incidents and implementing and\nmaking improvements to our overall cybersecurity strategy.\n\n \n\nDespite\nthese measures, we may not be successful in preventing, mitigating or recovering from a cybersecurity incident, which could have a material\nadverse effect on our operations or financial results or reputation. For a description of the primary risks from cybersecurity threats\nthat may materially affect our business and how they may do so, see Part I, Item 1A. Risk Factors in this Annual Report on Form 10-K,\nincluding “— Our networks and those of our third-party service providers may be vulnerable to cybersecurity risks.”\n\n \n\n76\n\n \n\n \n\n**PART\nIII**"}