{"url_path":"/sec/vcig/10-k/2026/item-16k","section_key":"item-16k","section_title":"Item 16K CYBERSECURITY**","topic":"sec","document":{"doc_type":"20-F","doc_date":"2026-07-15","source_url":"https://www.sec.gov/Archives/edgar/data/1930510/0001213900-26-078044-index.html","accession_number":"0001213900-26-078044","cik":"0001930510","ticker":"VCIG","issuer_name":"VCI Global Ltd","edgar_url":"https://www.sec.gov/Archives/edgar/data/1930510/0001213900-26-078044-index.html","primary_entity_key":"0001930510","primary_entity_name":"VCI Global Ltd"},"word_count":308,"has_tables":true,"body_markdown":"** **\n\n**Item\n16K. CYBERSECURITY**\n\n** **\n\n*Cybersecurity\nRisk Management and Strategy*. We maintain a cyber-risk management program which is intended to assist in assessing, identifying,\nand managing material risks from cybersecurity threats to our data and information systems. This program is to ensure that cybersecurity\nconsiderations are included in decision-making processes throughout the Company.\n\n \n\nOur\napproach consists of, among other things, cybersecurity threat and vulnerability prevention, detection, mitigation and remediation of\npotential cybersecurity risks. We employ cybersecurity intrusion detection systems and continuous monitoring, in order to help defend\nagainst unauthorized access. We also employ identity-based access controls and identity authentication requirements. Access to the Company’s\ndata is monitored and controlled according to access control policies. Data protection and privacy practices, including data loss prevention,\nhelp to safeguard sensitive information. We have also outsourced significant elements of our information technology infrastructure; as\na result, we manage independent vendor relationships with third parties who are responsible for maintaining significant elements of our\ninformation technology systems and infrastructure.\n\n \n\nOur\nBoard of Directors is responsible for oversight of our cyber-risk management program and management’s role is to assist the Board\nof Directors in identifying and considering material cybersecurity risks, ensure implementation of management and employee level cybersecurity\npractices and training and provide the Board of Directors with regular reports regarding any cybersecurity attacks or vulnerabilities.\n\n \n\nAs of the date of this annual report, we have not experienced any significant\ncybersecurity attacks and, to date, the risks from cybersecurity threats have not materially affected, or are reasonably likely to materially\naffect, our business strategy, results of operations, or financial condition. For more information regarding the risks the Company faces\nfrom cybersecurity threats, see “Item 3D. Risk Factors––Risks Related to Our Business and Operations––We\nare increasingly dependent on information technology, and our systems and infrastructure face certain risks, including cybersecurity and\ndata leakage risks.”\n\n \n\n79\n\n \n\n \n\n**Part\nIII**"}