{"url_path":"/sec/ofal/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C Cybersecurity**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-07-14","source_url":"https://www.sec.gov/Archives/edgar/data/2036307/0001493152-26-033093-index.html","accession_number":"0001493152-26-033093","cik":"0002036307","ticker":"OFAL","issuer_name":"OFA Group","edgar_url":"https://www.sec.gov/Archives/edgar/data/2036307/0001493152-26-033093-index.html","primary_entity_key":"0002036307","primary_entity_name":"OFA Group"},"word_count":322,"has_tables":true,"body_markdown":"**ITEM\n1C. Cybersecurity**\n\n \n\n**Cybersecurity\nRisk Management and Strategy**\n\n \n\nThe\nmanagement of the operation and the business affairs of a Cayman Islands company lies within the power of its board of directors. Directors\nof companies incorporated under the Companies Act are subject to both statutory obligations under the Companies Act as well as fiduciary\nduties under the common law to the extent applicable to Cayman Islands companies. In addition to the statutory duties which include duties\nsuch as reporting obligations, the maintenance of internal company registers, accounting requirements, etc., directors of Cayman Islands\ncompanies owe fiduciary duties including the duty to act in good faith and in the best interests of the company as well as a duty to\nact with care, skill and diligence under English common law principles. Maintaining sufficient protection against the increasing risks\nassociated with cybercrime is one of the key challenges to the commercial world and, the overseeing of cybersecurity risks falls within\nthe duties of the Company’s board of directors, including its independent directors. The independent directors oversee cybersecurity\nrisks as of the date of this annual report.\n\n \n\nOur\nboard of directors plays an active role in monitoring cybersecurity risks and is committed to the prevention, timely detection, and mitigation\nof the effects of any such incidents on our operations. In addition to regular reports from each of the board’s committees, the\nboard receives regular reports from our management on material cybersecurity risks and the degree of our exposure to those risks. While\nthe board oversees our cybersecurity risk management, management is responsible for day-to-day risk management processes. Management\nalso works with third party service providers, i.e. software companies who provide software and antivirus supports to the Company to\nensure appropriate controls are in place and to regularly monitor network activities. We believe this division of responsibilities is\nthe most effective approach for addressing our cybersecurity risks and that our board leadership structure supports this approach.\n\n \n\n69"}