UNRESOLVED STAFF COMMENTS
−Removed: Cybersecurity
−Removed: Risk Management
−Removed: identify and assess material risks from cybersecurity threats to our information systems and the information residing in our information
−Removed: systems by monitoring and evaluating our threat environment on an ongoing basis using various methods including, for example, using manual
−Removed: and automated tools, subscribing to reports and services that identify cybersecurity threats, analyzing reports of threats and threat
−Removed: actors, conducting scans of the threat environment, and conducting risk assessments.
−Removed: manage material risks from cybersecurity threats to our information systems and the information residing in our information systems through
−Removed: various processes and procedures, including, depending on the environment, risk assessments, incident detection and response, vulnerability
−Removed: management, disaster recovery and business continuity plans, internal controls within our accounting and financial reporting functions,
−Removed: encryption of data, network security controls, access controls, physical security, asset management, systems monitoring, and employee
−Removed: We engage third-party service providers to provide some of the resources used in our information systems and some third-party
−Removed: service providers have access to information residing in our information systems.
−Removed: With respect to such third parties, we seek to engage
−Removed: reliable, reputable service providers that maintain cybersecurity programs.
−Removed: Depending on the nature and extent of the services provided,
−Removed: the sensitivity and quantity of information processed, and the identity of the service provider, our processes may include conducting
−Removed: due diligence on the cybersecurity practices of such provider and contractually imposing cybersecurity related obligations on the provider.
−Removed: development and operation of Triller’s Technology Platform is subject to physical, technological, security and other risks which
−Removed: may result in interruption in service or reduced capacity.
−Removed: These risks include physical damage, power loss, telecommunications failure,
−Removed: capacity limitation, hardware or software failures or defects and breaches of physical and cybersecurity by computer viruses, system break-ins or
−Removed: An increase in the volume of usage of Triller’s Technology Platform could strain the capacity of the software and hardware
−Removed: employed to prevent and identify such failures, breaches and attacks, which could result in slower response time or system failures.
−Removed: In particular, Triller’s industry has witnessed an increase in the number, intensity and sophistication of cybersecurity incidents
−Removed: caused by hackers and other malicious actors such as foreign governments, criminals, hacktivists, terrorists and insider threats.
−Removed: and other malicious actors may be able to penetrate Triller’s network security and misappropriate or compromise Triller’s
−Removed: confidential, sensitive, personal or proprietary information, or that of third parties, and engage in the unauthorized use or dissemination
−Removed: of such information.
−Removed: They may be able to create system disruptions, or cause shutdowns.
−Removed: Hackers and other malicious actors may be able
−Removed: to develop and deploy viruses, worms, ransomware and other malicious software programs that attack Triller’s products or otherwise
−Removed: exploit any security vulnerabilities of Triller’s systems.
−Removed: In addition, sophisticated hardware and operating system software
−Removed: and applications that Triller procures from third parties may contain defects in design or manufacture, including “bugs,”
−Removed: cybersecurity vulnerabilities and other problems that could unexpectedly interfere with the operation or security of its systems.
−Removed: example, in 2022, as a result of a bug introduced in the application, Triller estimated that potentially 504 accounts may have been compromised.
+Added: Not applicable.
Cybersecurity
−Removed: Board of Directors holds oversight responsibility over Triller’s risk management and strategy, including material risks related
−Removed: to cybersecurity threats.
−Removed: This oversight is executed directly by our board of directors and through its committees.
−Removed: Our audit committee
−Removed: oversees the management of Triller’s major financial risk exposures, the steps management has taken to monitor and control such
−Removed: exposures, and the process by which risk assessment and management is undertaken and handled, which would include cybersecurity risks,
−Removed: in accordance with its charter.
−Removed: The audit committee holds regular meetings and receives periodic reports from management regarding risk
−Removed: management, including major financial risk exposures from cybersecurity threats or incidents.
−Removed: management, the Group Chief Information Officer of our business units are primarily responsible for assessing and managing our material
−Removed: risks from cybersecurity threats on a day-to-day basis and keep the senior executive officers informed on a regular basis of the identification,
−Removed: assessment, and management of cybersecurity risks and of any cybersecurity incidents.
−Removed: Such management personnel have prior experience
−Removed: and training in managing information systems and cybersecurity matters and participate in ongoing training programs.
−Removed: of the date hereof, the Company has not encountered cybersecurity incidents that the Company believes to have been material to the Company
−Removed: taken as a whole.
+Added: Risk Management and Strategy
+Added: We identify and assess material risks from cybersecurity
+Added: threats to our information systems and the information residing in our information systems by monitoring and evaluating our threat environment
+Added: on an ongoing basis using various methods including, for example, using manual and automated tools, subscribing to reports and services
+Added: that identify cybersecurity threats, analyzing reports of threats and threat actors, conducting scans of the threat environment, and conducting
+Added: risk assessments.
+Added: We manage material risks from cybersecurity threats
+Added: to our information systems and the information residing in our information systems through various processes and procedures, including,
+Added: depending on the environment, risk assessments, incident detection and response, vulnerability management, disaster recovery and business
+Added: continuity plans, internal controls within our accounting and financial reporting functions, encryption of data, network security controls,
+Added: access controls, physical security, asset management, systems monitoring, and employee training.
+Added: We engage third-party service providers
+Added: to provide some of the resources used in our information systems and some third-party service providers have access to information residing
+Added: in our information systems.
+Added: With respect to such third parties, we seek to engage reliable, reputable service providers that maintain
+Added: cybersecurity programs.
+Added: Depending on the nature and extent of the services provided, the sensitivity and quantity of information processed,
+Added: and the identity of the service provider, our processes may include conducting due diligence on the cybersecurity practices of such provider
+Added: and contractually imposing cybersecurity related obligations on the provider.
+Added: The development and operation of Triller’s Technology Platform
+Added: is subject to physical, technological, security and other risks which may result in interruption in service or reduced capacity.
+Added: risks include physical damage, power loss, telecommunications failure, capacity limitation, hardware or software failures or defects and
+Added: breaches of physical and cybersecurity by computer viruses, system break-ins or otherwise.
+Added: An increase in the volume of usage
+Added: of Triller’s Technology Platform could strain the capacity of the software and hardware employed to prevent and identify such failures,
+Added: breaches and attacks, which could result in slower response time or system failures.
+Added: In particular, Triller’s industry has witnessed
+Added: an increase in the number, intensity and sophistication of cybersecurity incidents caused by hackers and other malicious actors such as
+Added: foreign governments, criminals, hacktivists, terrorists and insider threats.
+Added: Hackers and other malicious actors may be able to penetrate
+Added: Triller’s network security and misappropriate or compromise Triller’s confidential, sensitive, personal or proprietary information,
+Added: or that of third parties, and engage in the unauthorized use or dissemination of such information.
+Added: They may be able to create system disruptions,
+Added: or cause shutdowns.
+Added: Hackers and other malicious actors may be able to develop and deploy viruses, worms, ransomware and other malicious
+Added: software programs that attack Triller’s products or otherwise exploit any security vulnerabilities of Triller’s systems.
+Added: sophisticated hardware and operating system software and applications that Triller procures from third parties may contain defects in
+Added: design or manufacture, including “bugs,” cybersecurity vulnerabilities and other problems that could unexpectedly interfere
+Added: with the operation or security of its systems.
+Added: The Company has not experienced any cybersecurity incidents during the year ended December
+Added: 31, 2025 that it believes to have been material to the Company taken as a whole.
+Added: Cybersecurity Governance
+Added: Our Board of Directors holds oversight responsibility
+Added: over Triller’s risk management and strategy, including material risks related to cybersecurity threats.
+Added: This oversight is executed
+Added: directly by our board of directors and through its committees.
+Added: Our audit committee oversees the management of Triller’s major financial
+Added: risk exposures, the steps management has taken to monitor and control such exposures, and the process by which risk assessment and management
+Added: is undertaken and handled, which would include cybersecurity risks, in accordance with its charter.
+Added: The audit committee holds regular
+Added: meetings and receives periodic reports from management regarding risk management, including major financial risk exposures from cybersecurity
+Added: threats or incidents.
+Added: Within management, the Group Chief Information
+Added: Officer of our business units are primarily responsible for assessing and managing our material risks from cybersecurity threats on a
+Added: day-to-day basis and keep the senior executive officers informed on a regular basis of the identification, assessment, and management
+Added: of cybersecurity risks and of any cybersecurity incidents.
+Added: Such management personnel have prior experience and training in managing information
+Added: systems and cybersecurity matters and participate in ongoing training programs.
+Added: As of the date hereof, the Company has not encountered
+Added: cybersecurity incidents that the Company believes to have been material to the Company taken as a whole.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.