{"url_path":"/sec/ocg/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K Cybersecurity**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-05-14","source_url":"https://www.sec.gov/Archives/edgar/data/1776067/0001213900-26-056688-index.html","accession_number":"0001213900-26-056688","cik":"0001776067","ticker":"OCG","issuer_name":"Oriental Culture Holding LTD","edgar_url":"https://www.sec.gov/Archives/edgar/data/1776067/0001213900-26-056688-index.html","primary_entity_key":"0001776067","primary_entity_name":"Oriental Culture Holding LTD"},"word_count":498,"has_tables":true,"body_markdown":"** **\n\n**Item 16K. Cybersecurity**\n\n** **\n\nInformation technology (IT) and safety are critical\nto the online trading platforms and operating activities of the Company as they are subject to security threats and increasingly sophisticated\ncyber-attacks. As a result, we have policies and processes in place to assess, identify, and manage the strategic and operational\nIT-related risks as an integrated part of our overall risk management system. The Company uses layers of personnel and\nmanagement team to centralize the control of the cybersecurity management, including the board of director, executive officer, risk control\ndepartment, and cybersecurity staffs. The cybersecurity staffs use various technologies to supervise the online activities, keep a journal\nand records of the abnormal or major activities, detect and discover potential threats and bugs. The risk control department will assess\nand manage the cyber risks with make regular evaluations to understand the discoveries by the cybersecurity staffs and take appropriate\nactions to eliminate such threats to the cybersecurity of the Company. The Company has not engaged any third-party assessors,\nconsultants, auditors, or other third parties in connection with any such processes. The Company has set up the password requirement,\ncontrol of authorization on a need to know basis, categorize sensitive information so that they can be managed and transmitted at different\nsecurity levels. Other than those, the Company currently does not have processes to oversee and identify the risks from cybersecurity\nthreats associated with its use of any third-party service provider. As of date of this report, there has been no previous cybersecurity\nincidents, have materially affected the Company yet. The Board is responsible for the oversight of risks from cybersecurity threats. The\ncybersecurity staff will report any material threats, risks and incidents to the IT manager, then the IT manager will report to Chief\nExecutive Officer who will report to the Board. The Company has adopted Cybersecurity Management Policy so that suspicious activities\nor incidents can be quickly identified and reported through the system to the appropriate management team. According to the policy,\nthe cybersecurity staff will evaluate and manage the weakness, events, alerts and incidents and escalated material events to IT manager,\nthen Chief Executive Officer, or the Board if necessary. Mr. Wenyong Ding has served as our IT Manager since August 2018 and has related\ncybersecurity manage experiences and expertise. From April 2015 to July 2018, Mr. Ding was served as Software Project Manager of\nNanjing Culture and Artwork Property Exchange Co., Ltd. From September 2013 to March 2015, Mr. Ding was a Senior Software Engineer at\nShanghai Baison Software Co., Ltd. From August 2012 to September 2013, Mr. Ding was a Software Engineer at Shanghai Tansi Computer Systems\nCo., Ltd. From July 2011 to July 2012, Mr. Ding worked as a Software Engineer at Shanghai Heyi Logistics Co., Ltd. From June 2009 to June\n2011, Mr. Ding was a Software Engineer at Shanghai Shenlong Computer Technology Co., Ltd. Mr. Ding received his bachelor’s degree\nof network engineering from Yancheng Teachers University in 2009.\n\n \n\n114\n\n \n\n** **\n\n**PART III**"}