{"url_path":"/sec/sos/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K Cybersecurity**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-05-15","source_url":"https://www.sec.gov/Archives/edgar/data/1346610/0001213900-26-057725-index.html","accession_number":"0001213900-26-057725","cik":"0001346610","ticker":"SOS","issuer_name":"SOS Ltd","edgar_url":"https://www.sec.gov/Archives/edgar/data/1346610/0001213900-26-057725-index.html","primary_entity_key":"0001346610","primary_entity_name":"SOS Ltd"},"word_count":544,"has_tables":true,"body_markdown":"**Item\n16K. Cybersecurity**\n\n** **\n\n**Cybersecurity\nRisk Management and Strategy**\n\n \n\nTo\nmaintain a consistently high level of service experience for our customers, preserve the confidentiality, integrity, and availability\nof our information systems, safeguard our assets, data, intellectual property and network infrastructure, while meeting regulatory requirements,\nit is crucial to effectively manage cybersecurity risks. To achieve this, we have implemented a comprehensive cybersecurity risk\nmanagement framework, which is integrated in our overall enterprise risk management system and processes and is internally\nmanaged.\n\n \n\nOur\ndedicated cybersecurity staff is tasked with assessing, identifying and managing risks related to cybersecurity threats and, under the\nleadership of our head of cybersecurity, is responsible for:\n\n \n\n●risk\nassessments designed to help identify material cybersecurity risks to our critical systems,\ninformation, products, services, and our broader enterprise IT environment;\n\n \n\n●development\nof risk-based action plans to manage identified vulnerabilities and implementation of new\nprotocols and infrastructure improvements;\n\n \n\n●cybersecurity\nincident investigations;\n\n \n\n●monitoring\nthreats to sensitive data and unauthorized access to our systems;\n\n \n\n●secure\naccess control measures applied to critical IT systems, equipment and devices, designed to\nprevent unauthorized users, processes, and devices from assessing IT systems and data;\n\n \n\n●developing\nand executing protocols to ensure that information regarding cybersecurity incidents is promptly\nshared with our board of directors, as appropriate, to allow for risk and materiality assessments\nand to consider disclosure and notice requirements; and\n\n \n\n●developing\nand implementing training on cybersecurity, information security and threat awareness.\n\n \n\nThere\nwere no cybersecurity incidents during the year ended December 31, 2025, that resulted in an interruption to our operations,\nknown losses of any critical data or otherwise had a material impact on our strategy, financial condition or results of operations. However,\nthe scope and impact of any future incident cannot be predicted. See “Item 3. Key Information-D. Risk Factors” for more information\non how material cybersecurity attacks may impact our business.\n\n** **\n\n**Governance**\n\n \n\nOur\nboard of directors acknowledges the significance of robust cybersecurity management programs and actively participates in overseeing\nand reviewing our cybersecurity risk profile and exposures.\n\n \n\nOur\nboard of directors receives reports on cybersecurity risks, including recent legislative developments and evolving standards on cybersecurity,\nkey issues, priorities and challenges in our cybersecurity management, and relevant data or metrics. Our board of directors also\nreceives prompt and timely information regarding any significant cybersecurity incidents, as well as ongoing updates regarding any such\nincidents. Furthermore, in the event of any significant updates or adjustments to our cybersecurity related policies, our chief executive\nofficer will present them to our board of directors for their review and approval.\n\n \n\nOur\nchief executive officer leads the overall assessment, identification and management of risks related to cybersecurity threats. Our chief\nexecutive officer works collaboratively with us and receives regular briefings on cybersecurity matters, such as report on cybersecurity\nincidents and responses and remedial measures. Our chief executive officer has many years of relevant experience in risk management,\ncybersecurity and information technology.\n\n \n\nOur\nchief executive officer and dedicated staff are responsible for the daily management of our cybersecurity efforts. This includes updates\nand refinement of cybersecurity policies, execution and management of cybersecurity measures, and the preparation of regular reports\non cybersecurity execution. Their primary focus is to consistently update our cybersecurity programs and mitigation strategies, ensuring\nthey align with industry best practices and procedures.\n\n \n\n90\n\n \n\n \n\n**PART III**"}