{"url_path":"/sec/rct/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBERSECURITY**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-05-15","source_url":"https://www.sec.gov/Archives/edgar/data/2027360/0001493152-26-023944-index.html","accession_number":"0001493152-26-023944","cik":"0002027360","ticker":"RCT","issuer_name":"RedCloud Holdings plc","edgar_url":"https://www.sec.gov/Archives/edgar/data/2027360/0001493152-26-023944-index.html","primary_entity_key":"0002027360","primary_entity_name":"RedCloud Holdings plc"},"word_count":894,"has_tables":true,"body_markdown":"**ITEM\n16K. CYBERSECURITY**\n\n \n\nRisk\nManagement\n\n \n\nWe\nunderstand the importance of preventing, assessing, identifying, and managing material risks associated with cybersecurity threats. Processes\nto manage risks from cybersecurity threats have been incorporated as a part of our overall risk assessment process. Our cybersecurity\nrisks include theft of business data, fraud or extortion, lack of access to our information systems, harm to employees, harm to business\npartners, violation of privacy laws, potential reputational damage, and litigation or other legal risk if a cybersecurity incident were\nto occur. It is difficult to assign a monetary materiality assessment to these risks or to the impact if we were to sustain a breach\nof our systems. Our approach is based on the premise that any cybersecurity incident could result in material harm to our company.\n\n \n\nThreats\nto security, confidentiality, and availability are identified and assessed as part of our annual and routine risk assessments. Our annual\nrisk assessment is performed by using the ISO27001 risk assessment as a basis for risk identification, which is conducted by a trusted\nthird-party provider to test our enterprise and product security controls. Additionally, our employees go through cybersecurity awareness\ntraining as part of their onboarding procedures. We also try to stay ahead of emerging cyber threats by continuously updating our security\nmeasures and investing in the latest technologies. We believe this proactive approach will help us be prepared to defend against new\ntypes of attacks, keeping our customers’ data secure.\n\n \n\nMatters\ndetermined to present potential material impacts to our financial results, operations, and/or reputation would immediately be reported\nby our cybersecurity team and escalated, as appropriate. In relation to security incident levels P0 - P4, the following escalation framework\nwill be evoked, as outlined in the table below:\n\n \n\n \n\nWe\nmanage significant and persistent cybersecurity risks due to the need to protect our business, including our intellectual property and\nintellectual property of others that is licensed for our use, our confidential information and information concerning our personnel and\nothers with whom we conduct business. As other technology companies we occasionally face threats from actors who seek to disrupt our\nbusiness as well as others who are engaging in malicious activities or for reputation damage. Disclose of certain information as a result\nof a cybersecurity breach may result in a breach of privacy laws. The substantial level of harm that could occur to us and our suppliers\nand customers were we to suffer impacts of a material cybersecurity incident; and our use of third-party products, services and components\nrequires us to maintain robust governance and oversight of these risks and to implement mechanisms, technologies and processes designed\nto help us assess, identify, and eliminate these risks.\n\n \n\nWhile\nwe have not, as of the date of this annual report, experienced a cybersecurity threat or incident that resulted in a material adverse\nimpact to our business or operations, we cannot assure you that we will not experience such an incident in the future. We have seen an\nincrease in cyberattack volume, frequency, and sophistication. We seek to detect and investigate unauthorized attempts and attacks against\nour network, products, and services, and to prevent their occurrence and recurrence where practicable through changes or updates to our\ninternal processes and tools and changes or updates to our products and services; however, while diligently taking actions to eliminate\nand reduce cyber risks, we remain potentially vulnerable to known or unknown threats. In some instances, we, our suppliers, our customers,\nand the users of our products and services can be unaware of a threat or incident or its magnitude and effects. Further, there are increasing\nregulation requirements regarding responses to cybersecurity incidents, including reporting to regulators, which could subject us to\nadditional liability and reputational harm.\n\n \n\nGovernance\n\n \n\nWe\naim to incorporate industry best practices throughout our cybersecurity program. Our cybersecurity strategy focuses on implementing effective\nand efficient controls, technologies, and other processes to assess, identify, and manage material cybersecurity risks.\n\n \n\nOur\ncybersecurity program is designed to be aligned with applicable industry standards, and we have engaged outside sources to assist in\nthis effort. We have processes in place to assess, identify, manage, and address material cybersecurity threats and incidents.\n\n \n\nWe\nmonitor issues that are internally discovered or externally reported that may affect our products and have processes to assess those\nissues for potential cybersecurity impact or risk. We also have a process in place to manage cybersecurity risks associated with third-party\nservice providers. We are in the process of implementing additional technical and organizational security measures to follow our information\nsecurity program.\n\n \n\nUnder\nour cybersecurity governance framework, the Audit Committee, in its charter, is empowered to implement and oversee our cybersecurity\nand information security policies and periodically review their compliance and mitigate potential cybersecurity threats.\n\n \n\nOur\nCISO, who is a third party engaged by us, leads the strategy and guidelines, and works with senior management and IT engineering, to\noperate and implement cybersecurity of the Company. The CISO is responsible for handling the risk management by assessment, analysis,\nreporting, managing the cyber protection following the relevant requirements, the work with the Information Technology team, implementing\ninformation security awareness among the employees, and updating the company’s security policies. Our CISO provides annual analysis\nand updates to the management on our cybersecurity and information security policies and programs, as well as ad hoc updates on information\nsecurity and cybersecurity matters.\n\n \n\n74\n\n \n\n \n\n**PART\nIII**"}