{"url_path":"/sec/pom/10-k/2026/item-16","section_key":"item-16","section_title":"Item 16 K.CYBERSECURITY","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-05-14","source_url":"https://www.sec.gov/Archives/edgar/data/1877971/0001213900-26-056576-index.html","accession_number":"0001213900-26-056576","cik":"0001877971","ticker":"POM","issuer_name":"POMDOCTOR Ltd","edgar_url":"https://www.sec.gov/Archives/edgar/data/1877971/0001213900-26-056576-index.html","primary_entity_key":"0001877971","primary_entity_name":"POMDOCTOR Ltd"},"word_count":471,"has_tables":true,"body_markdown":"ITEM 16.K.CYBERSECURITY\n\n** **\n\n**Risk Management and Strategy**\n\n \n\nWe have implemented comprehensive\ncybersecurity risk assessment procedures to ensure effectiveness in cybersecurity management, strategy and governance and reporting cybersecurity\nrisks. We have also integrated cybersecurity risk management into our overall enterprise risk management system.\n\n \n\nWe have developed a comprehensive\ncybersecurity threat defense system to address both internal and external threats. This system encompasses various levels, including\nnetwork, host and application security and incorporates systematic security capabilities for threat defense, monitoring, analysis, response,\ndeception and countermeasures. We strive to manage cybersecurity risks and protect sensitive information through various means, such\nas technical safeguards, procedural requirements, an intensive program of monitoring on our corporate network, continuous testing of\naspects of our security posture internally and with outside vendors, a robust incident response program and regular cybersecurity awareness\ntraining for employees. Our IT department regularly monitors the performance of our mobile applications, platforms and infrastructure\nto enable us to respond quickly to potential problems, including potential cybersecurity threats.\n\n \n\nAs of the date of this annual\nreport, we have not experienced any material cybersecurity incidents or identified any material cybersecurity threats that have affected\nor are reasonably likely to materially affect us, our business strategy, results of operations or financial condition.\n\n** **\n\n**Governance**\n\n \n\nThe nominating and corporate\ngovernance committee of our board of directors is responsible for overseeing the Company’s cybersecurity risk management and be\ninformed on risks from cybersecurity threats. The nominating and corporate governance committee shall review, approve and maintain oversight\nof the disclosure (i) on Form 6-K for material cybersecurity incidents (if any) and (ii) related to cybersecurity matters in the periodic\nreports (including annual report on Form 20-F) of the Company. In addition, at the management level, we have formed a data management\nteam, consisting of our head of IT and our general counsel, to oversee and manage cybersecurity related matters and formulate policies\nas necessary. Our data management team reports to our nominating and corporate governance committee on a quarterly basis regarding its\nassessment, identification and management on material risks from cybersecurity threats happened in the ordinary course of our business\noperations. If a cybersecurity incident occurs, our data management committee will promptly organize relevant personnel for internal\nassessment and, depending on the situation, seek the opinions of external experts and legal advisors. If it is determined that the incident\ncould potentially be a material cybersecurity event, our data management committee will promptly report the investigation and assessment\nresults to our nominating and corporate governance committee and our nominating and corporate governance committee will decide on the\nrelevant response measures and whether any disclosure is necessary. If such disclosure is determined to be necessary, our data management\ncommittee shall promptly prepare disclosure material for review and approval by our nominating and corporate governance committee before\nit is disseminated to the public.\n\n** **\n\n141\n\n \n\n** **\n\nPART III"}