{"url_path":"/sec/qdmi/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C Cybersecurity.**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-06-29","source_url":"https://www.sec.gov/Archives/edgar/data/1094032/0001213900-26-073119-index.html","accession_number":"0001213900-26-073119","cik":"0001094032","ticker":"QDMI","issuer_name":"QDM International Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1094032/0001213900-26-073119-index.html","primary_entity_key":"0001094032","primary_entity_name":"QDM International Inc."},"word_count":511,"has_tables":true,"body_markdown":"**Item 1C. Cybersecurity.**\n\n \n\n**Risk Management**\n\n \n\nWe may face significant\nand persistent cybersecurity risks due to the need to protect our business, our confidential information and information concerning our\npersonnel and others with whom we conduct business. As with other insurance brokerage companies, we occasionally face threats from actors\nwho seek to disrupt our business as well as others who are engaging in malicious activities for profit, to make a political point or for\nno particular reason other than creating disruption. Disclosure of certain information as a result of a cybersecurity breach may result\nin a breach of privacy laws. The substantial level of harm that could occur to us and our business partners and customers were we to suffer\nimpacts of a material cybersecurity incident; and our use of third-party products, services and components requires us to maintain robust\ngovernance and oversight of these risks and to implement mechanisms, technologies and processes designed to help us assess, identify,\nand eliminate these risks.\n\n \n\nWhile we have not, as\nof the date of this Report, experienced a cybersecurity threat or incident that resulted in a material adverse impact to our business\nor operations, we cannot assure you that we will not experience such an incident in the future. Any cybersecurity incidents, whether or\nnot successful, could result in our incurring additional costs related to, for example, rebuilding our internal systems, implementing\nadditional threat protection measures, responding to regulatory inquiries or actions, paying damages or making payments to obtain access\nto our computer systems, or taking other remedial steps with respect to third parties, as well as incurring significant reputational harm.\nWe seek to detect and investigate unauthorized attempts and attacks against our network, products, and services, and to prevent their\noccurrence and recurrence where practicable through changes or updates to our internal processes and tools and changes or updates to our\nproducts and services; however, we remain potentially vulnerable to known or unknown threats. In some instances, we, our business partners\nand our customers can be unaware of a threat or incident or its magnitude and effects. Further, there are increasing regulation requirements\nregarding responses to cybersecurity incidents, including reporting to regulators, which could subject us to additional liability and\nreputational harm. \n\n \n\n45\n\n \n\n \n\n**Governance**\n\n \n\nFollowing these risk\nassessments, we evaluate whether and how to re-design, implement, and maintain reasonable safeguards to mitigate identified risks and\nreasonably address any identified gaps in existing safeguards. Our responsible offer is directly supervising our employees’ compliance\nof our internal safeguards and she reports to our Chief Executive Officer periodically and on an as-needed basis to manage our risk assessment\nand mitigation process. We monitor and test our safeguards and regularly conduct training for our employees on these safeguards, in collaboration\nwith human resources, IT, and management. We are committed to promoting a company-wide culture of cybersecurity risk management.\n\n \n\nWe have not encountered\ncybersecurity risks, threats or incidents that have materially affected or are reasonably likely to materially affect the Company, our\nbusiness strategy, results of operations, or financial condition during the fiscal year ended March 31, 2026."}