{"url_path":"/sec/zcar/10-k/2026/item-1c","section_key":"item-1c","section_title":"Item 1C Cybersecurity**","topic":"sec","document":{"doc_type":"10-K","doc_date":"2026-07-14","source_url":"https://www.sec.gov/Archives/edgar/data/1854275/0001213900-26-078029-index.html","accession_number":"0001213900-26-078029","cik":"0001854275","ticker":"ZCAR","issuer_name":"Zoomcar Holdings, Inc.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1854275/0001213900-26-078029-index.html","primary_entity_key":"0001854275","primary_entity_name":"Zoomcar Holdings, Inc."},"word_count":1018,"has_tables":true,"body_markdown":"**Item\n1C. Cybersecurity**\n\n \n\nCybersecurity\nattacks impact businesses and organizations of all sizes and sectors on a global basis. At Zoomcar, we recognize the importance of developing,\nimplementing and maintaining a cybersecurity risk management program. Our customers rely on our solutions to store, use and protect their\nfiles, which may include confidential or personally identifiable information, critical business information, photographs, and other meaningful\ncontent. A successful cybersecurity attack could adversely affect the confidentiality, integrity, and availability of our information\nsystems or any data residing therein. We dedicate significant effort and resources to protect our systems and data, as well as the data\nof our customers from cybersecurity threats. We are dependent on internal and external information technology systems and infrastructure\nto securely process, transmit, and store critical information. Our Internal Security team is responsible for overseeing our cybersecurity.\nWe seek to reduce cybersecurity risks through a variety of cybersecurity risk management activities that are designed to identify, assess,\nmanage and mitigate cybersecurity threats.\n\n \n\n69\n\n \n\n**Risk\nManagement Strategy**\n\n \n\nThe\nCompany’s cybersecurity risk management program is focused on the following key areas:\n\n \n\n \n●\n**Governance:**The cybersecurity risk management program is led by Mr. Vishal Ramrakhyani, Head of Engineering and Product, with the Internal\nSecurity team and the policies therein are reviewed from time to time by Mr. Vishal Ramrakhyani.\n\n \n\nOur\nBoard of Directors, through its Audit Committee, provide oversight of our cybersecurity risk management. The Audit Committee periodically\nreviews and receives updates from the management and the Internal Security Team, including briefings on recent developments, key initiatives\nto strengthen our systems, applicable industry standards, incident response preparedness, compliance with regulatory requirements, vulnerability\nassessments, third-party and independent reviews, and other information security considerations. Our Internal Security Team also\nfrequently engages with key vendors, industry groups, and law enforcement communities as part of our continuing efforts to improve our\ncybersecurity program.\n\n \n\n  ● **Approach:**We use a cross-functional approach to identifying, preventing, assessing, and mitigating cybersecurity threats and incidents, while also implementing controls and procedures that are designed to provide for the prompt escalation of cybersecurity incidents and support appropriate public disclosure and reporting of incidents as required in a timely manner. Our cybersecurity efforts include the use of risk-based administrative, technical, and physical controls. Zoomcar has implemented an extensive set of policies, procedures, systems and tools designed to help safeguard our systems and data, including firewalls, intrusion detection systems, access controls including multi-factor authentication, vulnerability scanning, penetration testing, independent third-party control audits, an internal bug bounty program, and other systems and processes.\n\n \n\n \n●\n**Incident\nResponse Planning:**We maintain a breach reporting and resolution plan that includes defined processes, roles, communications,\nresponsibilities and procedures for responding to cybersecurity incidents and other events that impact our operations. Our incident\nresponse plans are tested and evaluated on a regular basis.\n\n \n\n  ● **Third-Party Risk Management:**Our business relies on various services from third party service providers that could adversely impact the security of our systems and business. We have implemented processes designed to identify and assess cybersecurity risks associated with our use of third-party service providers.\n\n \n\n \n●\n**Education\nand Awareness:**We have established a security and privacy awareness program that runs throughout the year and includes training\nfor all company personnel to enhance employee awareness of how to detect and respond to cybersecurity threats as well as more targeted\ntraining for company personnel that have increased responsibility for mitigating certain potential cybersecurity risks.\n\n \n\nWe\nregularly review and update our policies, procedures, processes and practices to address changes in the threat landscape and as a result\nof lessons learned from suspected, actual or simulated incidents. We also conduct tabletop exercises, and engage third party services\nto conduct evaluations of our security controls through penetration testing and independent audits. We also review industry best practices\nto assist in evaluating responses to new challenges and risks. These evaluations include testing both the design and operational effectiveness\nof security controls. \n\n \n\n**Experience:**\n\n** **\n\nVishal\nRamrakhyani, our Head of Engineering, has over 15 years of experience as a seasoned technology leader and operator with expertise in\napplication development, IT, cybersecurity, data protection and governance. He has been associated with Zoomcar for more than 9\nyears and has led strategic initiatives to build robust cybersecurity practices that align with long-term business objectives. Vishal\nhas also worked with internal DevSecOps and external security consultants to build policies around disaster recovery and incident response\nkeeping business continuity as the core objective. Before Zoomcar, Vishal worked as an engineering leader in multiple startups in India. \n\n \n\n70\n\n \n\n**Cybersecurity\nRisks**\n\n \n\nWhile\nwe dedicate significant efforts and resources to our cybersecurity program, we may be unable to successfully identify threats, prevent\nattacks, satisfactorily resolve cybersecurity incidents, or implement adequate mitigating controls. On June 9, 2025, we identified a\ncybersecurity incident involving unauthorized access to our information systems, which is described in our Current Report on Form 8-K\nfiled with the SEC on June 13 2025 (the “Cybersecurity Incident”). After the incident, we have also completed our external\nsecurity assessment and have enhanced our internal controls. Any future cybersecurity incident, or any failure to adequately detect,\nrespond to, contain, or remediate such an incident, could adversely affect our business, operations, financial condition, reputation,\nand brand, and could result in litigation, regulatory scrutiny, fines, penalties, or other liabilities.. To date and except as otherwise\nmay be noted in this Annual Report on Form 10-K, we do not believe that any cybersecurity threats, including as a result of any previous\ncybersecurity incidents have materially affected, or are reasonably likely to materially affect the Company, including its business strategy,\nresults of operations or financial condition. For more information relating to cybersecurity risks and uncertainties, please see the\nrisk factor entitled “**Breaches and other types of security incidents of our networks or systems similar to the recent Cybersecurity\nIncident, or those of our third-party service providers, could negatively impact our business, our brand and reputation, our ability\nto retain existing Hosts and Guests and attract new Hosts and Guests, may cause us to incur significant liabilities and adversely affect\nour business, results of operations, financial condition, and future prospects**.” in Part I, Item 1A, and other risk factors\nin this 10-K."}