{"url_path":"/sec/okyo/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBERSECURITY**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-07-20","source_url":"https://www.sec.gov/Archives/edgar/data/1849296/0001493152-26-033847-index.html","accession_number":"0001493152-26-033847","cik":"0001849296","ticker":"OKYO","issuer_name":"OKYO Pharma Ltd","edgar_url":"https://www.sec.gov/Archives/edgar/data/1849296/0001493152-26-033847-index.html","primary_entity_key":"0001849296","primary_entity_name":"OKYO Pharma Ltd"},"word_count":480,"has_tables":true,"body_markdown":"**ITEM\n16K: CYBERSECURITY**\n\n \n\nWe\nbelieve cybersecurity is critical to advancing our technological advancements. As a biopharmaceutical company, we face a multitude of\ncybersecurity threats that range from attacks common to most industries, such as ransomware and denial-of service. Our customers, suppliers,\nsubcontractors, and business partners face similar cybersecurity threats, and a cybersecurity incident impacting us or any of these entities\ncould materially adversely affect our operations, performance, and results of operations. These cybersecurity threats and related risks\nmake it imperative that we expend resources on cybersecurity.\n\n \n\nOur\nBoard of Directors oversees management’s processes for identifying and mitigating risks, including cybersecurity risks, to help\nalign our risk exposure with our strategic objectives. Senior leadership, including our cybersecurity consultant, regularly briefs the\nBoard of Directors on our cybersecurity and information security posture and the Board of Directors is apprised of cybersecurity incidents\ndeemed to have a moderate or higher business impact, even if immaterial to us. The full Board retains oversight of cybersecurity because\nof its importance. In the event of an incident, we intend to follow our detailed incident response playbook, which outlines the steps\nto be followed from incident detection to mitigation, recovery, and notification, including notifying functional areas (e.g., legal),\nas well as senior leadership and the Board, as appropriate. Our Cybersecurity consultant has extensive information technology and program\nmanagement experience. We have implemented a governance structure and processes to assess, identify, manage, and report cybersecurity\nrisks.\n\n \n\nAs\na biopharmaceutical company, we must comply with extensive regulations, including requirements imposed by the Federal Drug Administration\nrelated to adequately safeguarding patient information and reporting cybersecurity incidents to the SEC. We work with our cybersecurity\nconsultant on assessing cybersecurity risk and on policies and practices aimed at mitigating these risks. We believe we are positioned\nto meet the requirements of the SEC. In addition to following SEC guidance and implementing pre-existing third party frameworks, we have\ndeveloped our own practices and frameworks, which we believe enhance our ability to identify and manage cybersecurity risks. Third parties\nalso play a role in our cybersecurity. We engage third-party services to conduct evaluations of our security controls, whether through\npenetration testing, independent audits, or consulting on best practices to address new challenges. Assessing, identifying, and managing\ncybersecurity related risks are factored into our overall business approach.\n\n \n\nWe\nrely heavily on our supply chain to deliver our products and services, and a cybersecurity incident at a supplier, subcontractor or business\npartner could materially adversely impact us. We require that our subcontractors report cybersecurity incidents to us so that we can\nassess the impact of the incident on us. Notwithstanding the extensive approach we take to cybersecurity, we may not be successful in\npreventing or mitigating a cybersecurity incident that could have a material adverse effect on us. While we maintain cybersecurity insurance,\nthe costs related to cybersecurity threats or disruptions may not be fully insured."}