{"url_path":"/sec/ryaay/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K Cybersecurity","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-06-22","source_url":"https://www.sec.gov/Archives/edgar/data/1038683/0001104659-26-076131-index.html","accession_number":"0001104659-26-076131","cik":"0001038683","ticker":"RYAAY","issuer_name":"RYANAIR HOLDINGS PLC","edgar_url":"https://www.sec.gov/Archives/edgar/data/1038683/0001104659-26-076131-index.html","primary_entity_key":"0001038683","primary_entity_name":"RYANAIR HOLDINGS PLC"},"word_count":949,"has_tables":true,"body_markdown":"Item 16K. Cybersecurity\n\n​\n\nRISK ASSESSMENT, POLICIES AND PROCEDURES\n\n​\n\nThe Company is dependent on the use of technology and systems to run its operations. These technologies and systems include, among others, the Company's website and reservation system; flight planning and scheduling systems; flight dispatch and tracking systems; crew scheduling systems; baggage check-in kiosks; aircraft maintenance, planning, and record keeping systems; telecommunications systems; human resources systems; and financial planning, management, and accounting systems. The Company is committed to safeguarding these information systems and the information they hold, from unauthorized access, use, disclosure, disruption, modification or destruction.\n\n​\n\nThe Company’s processes for identifying, assessing and managing material risks from cybersecurity threats (including those associated with the Company’s use of third party service providers) are incorporated into its Enterprise Risk Management (\"ERM\") framework, alongside other critical business risks. The teams responsible for ERM and Information Security coordinate to review and assess these risks using a wide range of tools and services. The Company believes that integrating cybersecurity risks into its ERM framework ensures a proactive approach to cybersecurity, lessens the need for third party assistance in managing cybersecurity threats and helps safeguard the Company’s operations, financial performance and reputation.\n\n​\n\nThe Company’s cybersecurity program is designed to detect, respond to, and recover from cybersecurity threats and risks, and protect the confidentiality, integrity, and availability of its information systems, including the information residing on such systems. The program utilizes guidance drawn from the U.S. National Institute of Standards and Technology Cybersecurity Framework 2.0 to set the cybersecurity agenda and prioritise cybersecurity activities. The strategies employed by the program, among others, include:\n\n​\n\n●the application of policies and procedures designed to comply with data security and privacy obligations;\n\n●the implementation of administrative, technical, and physical controls;\n\n●the utilization of a Security Operations Center that conducts ongoing monitoring of networks and systems for potential signs of suspicious activity;\n\n●the requirement that staff complete cybersecurity training, which is updated as new technology, security and privacy issues emerge;\n\n94\n\n[Table of Contents](#TOC)\n\n●the tracking of key performance indicators and cybersecurity metrics to evaluate existing cybersecurity controls and practices;\n\n●maintaining a cybersecurity incident response plan to respond to cybersecurity incidents, which includes standard processes for reporting, escalating and recommending remediation actions for cybersecurity incidents to senior management; and\n\n●conducting periodic simulated cybersecurity scenarios to provide hands-on training and test the preparedness of the team to deal with cybersecurity threats.\n\n​\n\nCYBERSECURITY GOVERNANCE\n\n​\n\nBoard and Audit Committee\n\n​\n\nThe Board is responsible for overseeing management’s assessment of major risks, including cybersecurity, facing the Company and for reviewing options to mitigate such risks. The Board’s oversight of major risks, including cybersecurity risks, occurs at both the full Board level and at the Board committee level through the Audit Committee. The Company benefits from certain Board and Audit Committee members having considerable IT, data and cyber experience.\n\n​\n\nThe Audit Committee and Board receive updates on cybersecurity risks and the security and operations of the Company’s information technology systems from the Chief Technology Officer (“CTO”). These updates generally include any significant cybersecurity incidents, cybersecurity threats, cybersecurity program enhancements, and cybersecurity risks and related mitigation activities. This reporting helps to provide the Audit Committee with an informed understanding of the Company’s dynamic cybersecurity program and threat landscape. The Audit Committee also receives an ERM framework twice a year, in which material cybersecurity risks are identified, assessed and managed.\n\n​\n\nThe Audit Committee has opportunities to report regularly to the Board and review any major issues that arise at the committee level, which may include cybersecurity risks. Senior Management (including the CTO) also brief Board members, including new members, on cybersecurity risks. Based on this information, Board members may request additional information to address any concerns.\n\n​\n\nManagement\n\n​\n\nThe Company has a dedicated cybersecurity organization within its technology department that focuses on current and emerging cybersecurity matters. The Company’s cybersecurity function is led by the Director of Information Security, who reports to the CTO.\n\n​\n\nThe Company’s cybersecurity function engages in a range of cybersecurity activities such as threat detection, security mechanisms, and incident response. The cybersecurity function conducts vulnerability management and penetration testing to identify and mitigate vulnerabilities. Regular meetings are held with the Director of Information Security and the CTO to provide visibility of major issues and seek alignment with strategy. As noted in the “Risk assessment, policies and procedures” section above, the Company’s cybersecurity incident response plan includes standard processes for reporting, escalating and recommending remediation actions for cybersecurity incidents to Senior Management. Cybersecurity incidents that meet certain thresholds are escalated to the cybersecurity leaders and cross-functional teams on an as-needed basis for support and guidance.\n\n​\n\nThe Director of Information Security has 30 years of IT experience across manufacturing, banking and aviation, including 14 years of cybersecurity experience. He holds the following relevant qualifications:\n\n​\n\n●BSc Information Technology\n\n95\n\n[Table of Contents](#TOC)\n\n●CISSP (Certified Information Systems Security Professional)\n\n●CISM (Certified Information Security Manager)\n\n●CEH (Certified Ethical Hacker)\n\n​\n\nFor details of the CTO’s experience, please see “Item 6. Directors, Senior Management and Employees — Senior Management”.\n\n​\n\nRISKS FROM MATERIAL CYBERSECURITY THREATS\n\n​\n\nDuring FY26, the Company reported no material cybersecurity incidents affecting the confidentiality, integrity, or availability of data or systems. There are no identified risks from known cybersecurity threats, that have materially affected or are reasonably likely to materially affect the Company, including its operations, business strategy, results of operations, or financial condition. For a detailed discussion of the Company’s cybersecurity related risks, see “Item 3. Key Information—Risks related to the Company—Ryanair is subject to cyber security risks and may incur increasing costs in an effort to minimize those risks”.\n\n​\n\n**PART III**\n\n​"}