{"url_path":"/sec/tjgc/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K Cybersecurity**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-07-22","source_url":"https://www.sec.gov/Archives/edgar/data/1969928/0001185185-26-003078-index.html","accession_number":"0001185185-26-003078","cik":"0001969928","ticker":"TJGC","issuer_name":"TJGC GROUP Ltd","edgar_url":"https://www.sec.gov/Archives/edgar/data/1969928/0001185185-26-003078-index.html","primary_entity_key":"0001969928","primary_entity_name":"TJGC GROUP Ltd"},"word_count":1021,"has_tables":true,"body_markdown":"**ITEM 16K. Cybersecurity**\n\n \n\n**Risk Management and Strategy**\n\n \n\nWe have established policies and processes for assessing, identifying,\nand managing material risks from cybersecurity threats, and plan to integrate these processes into our overall risk management\nsystems and processes.\n\n \n\nWe also implemented a set of procedures to ensure effective management\nof the cybersecurity risks associated with the use of third-party service providers, including conducting cybersecurity assessments\nand tracking the capabilities and qualifications of third-party security service providers through assessment process. vulnerabilities.\n\n \n\nWe recognize the importance of assessing, identifying, and managing\nmaterial risks associated with cybersecurity threats. These risks include, among other things, operational risks; intellectual property\ntheft; fraud; extortion; harm to employees or customers; violation of privacy or security laws and other litigation and legal risk; and\nreputational risks.\n\n \n\nTo address the increasing risks of cyber-attacks, we implemented\na robust and scalable cybersecurity strategy to protect our infrastructure, customer data, and reputation, while leveraging third-party\ncloud services. We utilize advanced security features provided by our cloud partners, including encryption, intrusion detection, and continuous\nmonitoring, to safeguard sensitive information and prevent unauthorized access. Our cybersecurity team enforces strict access controls,\nsuch as multi-factor authentication (MFA) and role-based permissions, while conducting regular vulnerability scans, penetration testing,\nand audits to identify and remediate potential weaknesses. Comprehensive employee training programs promote awareness of phishing and\nother threats, reducing human error risks. We maintain a well-defined incident response plan to swiftly contain, investigate, and resolve\nany security incidents, ensuring minimal disruption to our platform and services. By aligning with our cloud providers’ compliance\nstandards we meet regulatory requirements and protect customer trust.\n\n \n\nWe assess the impact of cybersecurity threats on our business,\nincluding our strategic direction, operational performance, and financial stability, using insights from any past cybersecurity incidents\nin the shipping industry of which we are aware.\n\n \n\nWe have implemented risk-based processes for assessing, identifying,\nand managing material risks from cybersecurity threats. These processes include access controls to organizational systems, data encryption,\nand cybersecurity training and security awareness campaigns, and are designed to systematically evaluate potential vulnerabilities and\ncybersecurity threats and minimize their potential impact on our organization’s operations, assets, and stakeholders. Accordingly,\nwe also implement processes to oversee and identify material cybersecurity risks associated with our utilization of third-party service\nproviders on whom we have a material dependency, such as conducting due diligence assessments to evaluate their cybersecurity measures,\ndata protection practices, and compliance with relevant regulatory requirements.\n\n \n\nAs we do not have a dedicated board committee solely focused on\ncybersecurity, our board of directors has oversight responsibility for risks and incidents relating to cybersecurity threats,\nincluding compliance with disclosure requirements, cooperation with law enforcement, and related effects on financial and other risks.\nSenior management regularly discusses cyber risks and trends and, should they arise, any material incidents with our board of directors.\nWe consult with outside counsel as appropriate, including on materiality analysis and disclosure matters, and in the event of an incident\nour board of directors will make the final materiality determinations and disclosure and other compliance decisions. Our external\nIT provider maintains a dedicated cybersecurity auditing team that independently tests our cybersecurity controls.\n\n \n\n75\n\n[Table of Contents](#toc)\n\n \n\nOverall, our approach to cybersecurity risk management includes\nthe following key elements:\n\n \n\n \n●\nOpen-Source Software Approval Process: All OSS intended for use in our products or platform must be reviewed and approved by a designated compliance team. This process includes evaluating the OSS license to ensure compatibility with our business model and existing obligations, documenting the software’s purpose, and verifying that it does not impose restrictive requirements, such as mandatory source code disclosure.\n\n \n \n \n\n \n●\nLicense Compliance Tracking: We maintain a centralized inventory of all OSS components used in our systems, including their versions, licenses, and associated obligations. Developers are required to log each OSS component in a software bill of materials (SBOM) and ensure that license terms, such as attribution notices or copyleft provisions, are adhered to in our codebase and distributions.\n\n \n \n \n\n \n●\nCode Review and Scanning Policy: All code, including OSS, must undergo automated scanning using tools  to detect unlicensed or non-compliant OSS components before integration. Regular code reviews ensure that OSS is used in accordance with its license terms and that any modifications or derivative works comply with applicable requirements.\n\n \n \n \n\n \n●\nDeveloper Training and Guidelines: Employees and contractors receive mandatory training on OSS licensing and compliance. Clear guidelines prohibit the use of high-risk licenses  without explicit approval and outline procedures for incorporating OSS, such as including proper license notices in our products and ensuring no proprietary code is inadvertently mixed with copyleft-licensed OSS.\n\n \n \n \n\n \n●\nThird-Party Contribution Policy: Developers are prohibited from contributing to external OSS projects on behalf of the company without prior approval. Any contributions must align with our licensing policies, and we ensure that contributions do not inadvertently incorporate our proprietary code into OSS projects under incompatible licenses.\n\n \n\nThese policies help ensure that our use of open-source software\nis compliant, minimizing legal and operational risks while maintaining the integrity of our platform and products.\n\n \n\nOur business strategy, operating results and financial condition\nhave not been materially affected by risks from cybersecurity threats, including as a result of previously identified cybersecurity incidents,\nbut we cannot provide assurance that they will not be materially affected in the future by such risks or any future material incidents.\n\n \n\nAs of the date of this Annual Report, we have not experienced\nany material cybersecurity incidents or identified any material cybersecurity threats that have affected or are reasonably likely to materially\naffect us, our business strategy, results of operations or financial condition.\n\n \n\n**Governance**\n\n \n\nOur board of directors is responsible for overseeing our cybersecurity\nrisk management. Our board of directors shall (i) maintain oversight of the disclosure related to cybersecurity matters in current\nreports or periodic reports of our company, (ii) review updates to the status of any material cybersecurity incidents or material risks\nfrom cybersecurity threats to our company, and the disclosure issues, if any, presented by our cybersecurity officer on a quarterly basis,\nand (iii) review disclosure concerning cybersecurity matters in our annual report on Form 20-F presented by our cybersecurity officer. \n\n \n\n76\n\n[Table of Contents](#toc)\n\n \n\n \n\n**PART\nIII**"}