{"url_path":"/sec/tmcr/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K Cybersecurity.**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-04-27","source_url":"https://www.sec.gov/Archives/edgar/data/2087398/0001104659-26-049527-index.html","accession_number":"0001104659-26-049527","cik":"0002087398","ticker":"TMCR","issuer_name":"Metals Royalty Co Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/2087398/0001104659-26-049527-index.html","primary_entity_key":"0002087398","primary_entity_name":"Metals Royalty Co Inc."},"word_count":224,"has_tables":true,"body_markdown":"**Item 16K. Cybersecurity.**\n\nWe employ procedures designed to identify, protect, detect and respond to and manage reasonably foreseeable cybersecurity risks and threats. To protect our information systems from cybersecurity threats, we use various security tools that help prevent, identify, escalate, investigate, resolve and recover from identified vulnerabilities and security incidents in a timely manner. These include, but are not limited to, internal reporting, monitoring and detection tools, employee education, password encryption, frequent password change events, firewall detection systems, anti-virus software and frequent backups.\n\nWe regularly assess risks from cybersecurity and technology threats and monitor our information systems for potential vulnerabilities. We conduct regular reviews and tests of our information security program and also utilize other exercises to evaluate the effectiveness of our information security program and improve our security measures and planning. Any significant disruption to our service or access to our systems in the future could adversely affect our business and results of operation.\n\nOur board of directors oversees our enterprise risk assessment, where we assess key risks within the Company, including security and technology risks and cybersecurity threats. The Audit Committee oversees our cybersecurity risk and receives regular reports from our management team on various cybersecurity matters, including risk assessments, mitigation strategies, areas of emerging risks, incidents and industry trends, and other areas of importance.\n\n​\n\n96\n\n[Table of Contents](#TOC)\n\n**PART III**"}