{"url_path":"/sec/rdcm/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBERSECURITY**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-03-31","source_url":"https://www.sec.gov/Archives/edgar/data/1016838/0001213900-26-036862-index.html","accession_number":"0001213900-26-036862","cik":"0001016838","ticker":"RDCM","issuer_name":"RADCOM LTD","edgar_url":"https://www.sec.gov/Archives/edgar/data/1016838/0001213900-26-036862-index.html","primary_entity_key":"0001016838","primary_entity_name":"RADCOM LTD"},"word_count":722,"has_tables":true,"body_markdown":"**ITEM\n16K. CYBERSECURITY**\n\n** **\n\n**Cybersecurity\nRisk Management and Strategy**\n\n \n\nWe\nhave developed and implemented a cybersecurity risk management program intended to protect the confidentiality, integrity, and availability\nof our critical systems and information. Our cybersecurity risk management program is designed to identify, assess, and manage material\nrisks from cybersecurity threats and includes a cybersecurity incident response plan. Our cybersecurity risk management program has been\ndesigned to follow our industry’s best practices and is supported by a comprehensive set of enterprise security policies and procedures.\n\n \n\n71\n\n \n\n \n\nCybersecurity\nis an important component of the Company’s overall risk management approach. The Company’s cybersecurity policies, standards\nand practices are integrated into the Company’s enterprise risk management approach, and cybersecurity risks are one of the enterprise\nrisks that are subject to oversight by the Company’s Board of Directors.\n\n \n\nOur\ncybersecurity risk management program includes the following:\n\n \n\n \n●\nrisk assessments and analysis\ndesigned to help identify material cybersecurity risks to our critical systems, information, products, services, and our broader\nenterprise IT environment;\n\n \n\n \n●\na security team principally\nresponsible for managing (i) our cybersecurity risk assessment processes, (ii) our security controls, and (iii) our response to cybersecurity\nincidents;\n\n \n\n \n●\nthe use of external service\nproviders, where appropriate, to assess, test or otherwise assist with aspects of our security controls;\n\n \n\n \n●\nperiodic cybersecurity\nawareness training of our employees;\n\n \n\n \n●\na cybersecurity incident\nresponse plan that includes procedures for responding to cybersecurity incidents; and\n\n \n\n \n●\nmaintaining ISO/IEC 27001\ncertification since 2022.\n\n \n\nWe\nalso engage our internal auditor to conduct internal reviews of our cybersecurity policies and practices. In addition, in 2025, we conducted\na business impact analysis (BIA) process and an operational and technical backup exercise as part of our business continuity management\nand disaster preparedness activity, the purpose of which was to examine the Company’s readiness for business continuity processes\nand emergency response, including preparedness, for complex and varied cyber attacks and severe disruption scenarios.\n\n \n\nDuring\n2025, we did not identify any cybersecurity threats or incidents that have materially affected or are reasonably likely to materially\naffect our business strategy, results of operations, or financial condition. However, despite our efforts, we cannot eliminate all risks\narising from cybersecurity threats or incidents nor can we provide assurances that we have not experienced an undetected cybersecurity\nincident. For more information about these risks, please see “Item 3.D—Risk Factors – Disruptions to our IT systems\ndue to system failures or cybersecurity attacks may impact our operations, result in sensitive customer information being compromised,\nwhich would negatively materially adversely affect our reputation and business” and “Item 3.D—Risk Factors –\nCyber-attacks on our customers’ networks involving our products could have an adverse effect on our business” in this Annual\nReport.\n\n \n\n**Cybersecurity\nGovernance**\n\n \n\nOur\nBoard of Directors considers cybersecurity risk as part of its risk oversight function. The Company’s Board of Directors receives\nperiodic presentations on cybersecurity risks during the year, which address a wide range of topics including, for example, recent developments,\nthird-party reviews, the threat environment, technological trends and information security considerations arising with respect to the\nCompany. The Board of Directors will receive prompt and timely information regarding any significant cybersecurity incidents, as well\nas ongoing updates regarding such incidents until they have been addressed. The Board of Directors also regularly discusses the Company’s\napproach to cybersecurity risk management with the Company’s senior management.\n\n  \n\nWe\nutilize third-party cybersecurity experts, or Third-Party Experts, for information security services. Our Third-Party Expert works with\nour IT Manager, and both are supervised by members of our senior management, including our Chief Operating Officer, Chief Technology\nOfficer, and Chief Financial Officer. Together, they oversee our cybersecurity risk management and have primary responsibility for identifying,\nassessing, remediating, and managing cybersecurity risks, threats, and incidents. Our Third-Party Experts and the dedicated personnel\nin their team are certified and experienced information systems security professionals and information security managers with over 20\nyears of cybersecurity experience. Our Third-Party Experts regularly provide our senior management team with updates on the performance\nof the cybersecurity risk management program and provides updates and presentations to our Board of Directors as necessary throughout\nthe year.\n\n** **\n\nAs\nof the date of this report, we are not aware of any material risks from cybersecurity threats that have materially affected or are reasonably\nlikely to affect us, including our business strategy, results of operations or financial condition.\n\n  \n\n72\n\n \n\n \n\n**PART\nIII**"}