1 unchanged sentence
CYBERSECURITY
−Removed: Management and Board Oversight
−Removed: In the ordinary course of our business, we collect, use, store, and digitally transmit confidential, sensitive, proprietary, and personal information.
−Removed: The secure maintenance of this information and our information technology systems are important to our operations and business strategy.
−Removed: The Audit Committee , which is composed solely of independent directors, has been designated by our Board to review and discuss with management the Company’s risk assessment and risk management policies, including the steps that management has taken to monitor and control related cybersecurity risks and exposures.
−Removed: Management updates the Audit Committee and the Board as necessary about significant cybersecurity occurrences and measures the Company is taking to prevent the same.
+Added: the ordinary course of our business, we collect, use, store, and digitally transmit confidential, sensitive, proprietary, and personal
+Added: information, including customer identities, financial data, transaction histories, private key management data, and personally identifiable
+Added: information (“PII”).
+Added: As a digital asset trading and payment services platform, the secure maintenance of this information
+Added: and our information technology systems is fundamental to the trust our customers place in us, to the continued operation of our business,
+Added: and to our compliance with applicable laws and regulations.
+Added: operate in an industry that is a high-value target for sophisticated and well-funded threat actors, including nation-state actors, organized
+Added: criminal groups, and individual hackers who may seek to compromise customer assets, disrupt our platform operations, or steal sensitive
+Added: We take this threat environment seriously and are in the process of developing a cybersecurity risk management program designed
+Added: to protect the confidentiality, integrity, and availability of our critical systems and information.
+Added: Item 1C is organized into three principal sections as required by the SEC’s cybersecurity disclosure rules:
+Added: (1) Risk Management
+Added: and Strategy;
+Added: (2) Governance;
+Added: and (3) Material Incidents.
+Added: For a discussion of the risks that cybersecurity threats pose to our business
+Added: strategy, operations, and financial condition, including the risk of private key loss, platform disruption, and regulatory penalties,
+Added: see “Item 1A — Risk Factors,” which is incorporated by reference herein.
+Added: Cybersecurity
Risk Management and Strategy
−Removed: We rely on our subsidiary-level information technology professionals to continuously monitor and update our IT networks and infrastructure.
−Removed: Their role is to prevent, detect, address, and mitigate risks related to unauthorized access, misuse,
−Removed: malware, and other security threats.
−Removed: To safeguard our data and business processes, as well as those of our subsidiaries, we invest in industry-standard security technologies to defend against cyber risks.
−Removed: To further strengthen our cybersecurity efforts, with our subsidiary’s assistance, we are establishing an “IT Steering Committee” composed of IT professionals from our subsidiary.
−Removed: This committee will meet quarterly to discuss cybersecurity threats, emerging attack methods, and best practices.
−Removed: In fiscal year 2024, our crypto-processing subsidiary engaged an external consultant to conduct a cybersecurity risk assessment of our business operations.
−Removed: This assessment examined both internal and external threats to our systems and data handling processes, providing a structured framework for evaluating, prioritizing, and enhancing our cybersecurity initiatives.
−Removed: On a going-forward basis, in collaboration with our Audit Committee, management will determine and implement appropriate measures based on these findings.
−Removed: As part of our cybersecurity risk management program, we are working with our crypto-processing subsidiary to develop a cyber training curriculum for our employees.
−Removed: The training may cover topics such as phishing awareness, cybersecurity best practices, and e-mail security.
−Removed: Despite our commitment to cybersecurity, no system can fully eliminate technology risks.
−Removed: As of now, we are unaware of any cybersecurity incidents that have had, or are reasonably likely to have, a material impact on our business or operations.
−Removed: However, the increasing volume and sophistication of cyberattacks—including data breaches, ransomware, and similar threats—pose ongoing risks.
−Removed: Incidents that occur could result in reputational, competitive, operational, or financial harm, as well as regulatory consequences.
−Removed: For a more detailed discussion of how cybersecurity threats may affect our business strategy, operations, or financial condition, see Item 1A, “Risk Factors,” which is incorporated by reference into Item 1C.
+Added: are in the process of developing a cybersecurity risk management program intended to protect the confidentiality, integrity, and availability
+Added: of our critical systems and information.
+Added: We are evaluating alignment of this program with the National Institute of Standards and Technology
+Added: Cybersecurity Framework (“NIST CSF”) and intend to integrate it into our overall enterprise risk management (“ERM”)
+Added: program so that cybersecurity risks are evaluated alongside operational, financial, legal, and strategic risks facing the Company.
+Added: cybersecurity risk management program is being developed around the NIST CSF core functions — Identify, Protect, Detect, Respond,
+Added: and Recover — and is expected to include the following key elements, which are currently under review for future implementation:
+Added: Identify — Risk Assessment and Asset Management
+Added: are evaluating the development of processes to maintain an inventory of information assets, systems, and data, and to conduct periodic
+Added: cybersecurity risk assessments to identify threats, vulnerabilities, and the potential impact of cybersecurity incidents on our operations.
+Added: During fiscal year 2024, management performed
+Added: an internal review focused on identifying key cybersecurity risks associated with our business operations and continues to assess the
+Added: need for more formalized risk assessment processes.
+Added: Management is evaluating potential remediation measures and enhancements to its cybersecurity
+Added: risk management program for future implementation on a prioritized basis, including the possible engagement of third-party resources.
+Added: are also evaluating the use of threat intelligence feeds and participation in information-sharing forums relevant to the digital asset
+Added: and financial technology sectors to monitor emerging cybersecurity developments, including threats specifically targeting digital asset
+Added: platforms and companies similar to ours.
+Added: No formal threat intelligence program has been implemented to date.
+Added: Protect — Technical and Administrative Controls
+Added: are reviewing the adoption of a defense-in-depth security architecture to protect our systems, data, and customer assets.
+Added: The technical
+Added: and administrative controls we are evaluating for future implementation include:
+Added: Firewalls, intrusion detection and prevention systems (IDS/IPS), and network segmentation
+Added: to isolate sensitive systems and limit lateral movement in the event of a breach.
+Added: Endpoint detection and response (EDR) tools to detect, contain, and remediate
+Added: malicious activity across company devices.
+Added: and Access Management:
+Added: Multi-factor authentication (MFA) across critical systems;
+Added: access controls (RBAC) based on the principle of least privilege;
+Added: and privileged access management
+Added: (PAM) controls for administrative accounts.
+Added: ● Encryption:
+Added: Encryption of data at rest and in transit using industry-standard protocols, and hardware-based
+Added: controls for the management of private keys and other cryptographically sensitive materials.
+Added: A managed 24/7 Security Operations Center (SOC) staffed by a managed security
+Added: service provider (“MSSP”), supported by Security Information and Event Management
+Added: (SIEM) technology to aggregate and correlate log data across our environment.
+Added: ● Vulnerability
+Added: Regular vulnerability scanning and patching protocols, supplemented by periodic
+Added: penetration testing conducted by qualified third-party security firms.
+Added: Cloud-native security controls for our cloud-hosted infrastructure, including configuration
+Added: management, access logging, and continuous posture monitoring.
+Added: Formal internal policies governing the classification, handling, retention, and
+Added: disposal of sensitive data, including customer PII, financial data, and proprietary information.
+Added: are evaluating investment in industry-standard security technologies commensurate with the size and risk profile of our business.
+Added: formal implementation of the above controls has occurred to date.
+Added: We intend to prioritize and implement these controls on a phased basis,
+Added: informed by the findings of our FY2024 external risk assessment.
+Added: Detect — Threat Detection and Monitoring
+Added: are evaluating the engagement of a managed 24/7 Security Operations Center (SOC) to provide continuous threat monitoring across our IT
+Added: Under this model, the SOC team would monitor security alerts generated by a SIEM platform, endpoint protection tools, network
+Added: security devices, and other detection capabilities, with alerts triaged and escalated to senior management in accordance with incident
+Added: response procedures.
+Added: No managed SOC has been engaged to date.
+Added: are also reviewing subscriptions to industry threat intelligence services and, where appropriate, participation in information-sharing
+Added: forums relevant to the digital asset and financial technology sectors, to stay current on threat actor tactics, techniques, and procedures
+Added: (TTPs) targeting companies similar to ours.
+Added: These capabilities are under consideration for future implementation.
+Added: Respond and Recover — Incident Response Planning
+Added: are in the process of developing a written cybersecurity incident response plan (“IRP”) designed to provide a structured
+Added: approach to detecting, containing, eradicating, and recovering from cybersecurity incidents.
+Added: The IRP, when completed, is intended to
+Added: establish defined procedures for:
+Added: detection, triage, and classification of potential security incidents, including a materiality
+Added: analysis framework to evaluate incidents for potential disclosure obligations under SEC rules
+Added: and applicable securities laws;
+Added: and notification protocols to senior management and the Audit Committee, including escalation
+Added: timelines tied to incident severity;
+Added: ● Containment
+Added: and eradication activities designed to limit the impact of an incident and prevent recurrence;
+Added: ● Communication
+Added: procedures for notifying affected customers, regulators, law enforcement, and other stakeholders
+Added: as required by applicable law;
+Added: ● Post-incident
+Added: review and remediation to identify root causes and implement corrective measures.
+Added: IRP has not yet been finalized.
+Added: We intend to review and update the plan at least annually once adopted, to reflect changes in our threat
+Added: environment, business operations, and regulatory requirements.
+Added: We are also evaluating the conduct of tabletop exercises to test our incident
+Added: response capabilities once the IRP is in place.
+Added: Workforce Training and Security Awareness
+Added: recognize that human error is one of the most significant risk factors in cybersecurity, and we are committed to building a security-aware
+Added: organizational culture.
+Added: We are currently evaluating the development of a formal cybersecurity training curriculum in collaboration with
+Added: our crypto-processing subsidiary.
+Added: The program under consideration is expected to cover:
+Added: awareness and identification of social engineering attacks;
+Added: hygiene and secure credential management;
+Added: handling of sensitive customer data and PII;
+Added: security best practices, including how to identify and report suspicious messages;
+Added: data protection policies and compliance obligations.
+Added: formal training program has been implemented to date.
+Added: We intend, once a curriculum is developed, to require all employees to complete
+Added: cybersecurity awareness training on at least an annual basis, with role-specific training for personnel with access to particularly sensitive
+Added: systems or data.
+Added: We are also evaluating the use of periodic phishing simulation exercises to test employee awareness and identify areas
+Added: for additional training.
+Added: Third-Party and Supply Chain Risk Management
+Added: recognize that our security posture is affected not only by our own controls but also by the security practices of the third-party vendors ,
+Added: service providers, and partners with whom we share data or on whom we rely for critical services.
+Added: We are evaluating the development of
+Added: a formal third-party risk management program.
+Added: The elements under consideration include:
+Added: evaluation of third-party vendors and service providers prior to onboarding, including assessment
+Added: of their cybersecurity controls, certifications, and compliance posture;
+Added: ● Contractual
+Added: requirements for third-party vendors to maintain appropriate technical, administrative, and
+Added: physical cybersecurity controls, including requirements for prompt notification of security
+Added: incidents that may affect our data or systems;
+Added: monitoring of key third-party relationships to assess any changes in their security posture
+Added: or risk profile;
+Added: reassessment of vendor risk as part of our overall enterprise risk management process.
+Added: formal third-party cybersecurity risk management program has been implemented to date.
+Added: We intend to apply any such program, once developed,
+Added: to all significant vendors, including any managed security service providers engaged to supplement our internal IT capabilities.
+Added: Cybersecurity Incidents
+Added: of the date of this Annual Report, we are not aware of any cybersecurity incidents that have had, or are reasonably likely to have, a
+Added: material impact on our business, operations, results of operations, or financial condition.
+Added: As a company operating in the digital asset
+Added: sector, we are subject to ongoing cybersecurity threats and may experience security events from time to time.
+Added: To date, any incidents
+Added: we have experienced have been addressed through our security operations capabilities without material impact.
+Added: note that the digital asset industry has experienced a number of high-profile cybersecurity incidents at other companies, some of which
+Added: have resulted in material losses of customer assets or sensitive data and significant regulatory and legal consequences.
+Added: to monitor the evolving threat landscape and invest in our cybersecurity defenses in light of these industry developments.
+Added: provide assurance that future cybersecurity incidents will not occur or that any future incidents will not have a material effect on
+Added: our business.
+Added: a detailed discussion of cybersecurity-related risks facing our business, including risks related to private key loss, platform disruption,
+Added: data breaches, regulatory exposure, and the security of third-party blockchain networks, see Item 1A, “Risk Factors,” which
+Added: is incorporated by reference into this Item 1C.
+Added: Cybersecurity
+Added: of Directors and Audit Committee Oversight
+Added: Board considers cybersecurity risk as an integral component
+Added: of its overall risk oversight function.
+Added: Our Board has designated the Audit Committee — which is composed solely of independent directors — as the body primarily
+Added: responsible for assisting the Board in fulfilling its oversight responsibilities with respect to cybersecurity and other information
+Added: technology risks.
+Added: Audit Committee oversees management’s implementation of our cybersecurity risk management program, including the processes and
+Added: policies for determining risk tolerance, and reviews management’s strategies for adequately mitigating and managing identified
+Added: cybersecurity risks.
+Added: The Audit Committee receives updates from management regarding cybersecurity risks, the status of our cybersecurity
+Added: program, significant emerging threats, and the results of risk assessments and security testing, at least quarterly and more frequently
+Added: as significant matters warrant.
+Added: Audit Committee reports its cybersecurity-related findings and recommendations to the full Board on a periodic basis.
+Added: Management updates
+Added: the Audit Committee and the Board as necessary regarding material cybersecurity occurrences and the measures the Company is taking to
+Added: prevent, contain, and remediate the same.
+Added: As our cybersecurity program matures, the Board will consider developing additional specific
+Added: cybersecurity oversight functions and protocols commensurate with the size and complexity of our business.
+Added: Responsibility
+Added: cybersecurity risk management responsibility rests with our subsidiary-level IT professionals, who work in collaboration with our external
+Added: managed security service providers and, as appropriate, our outsourced virtual CISO (“vCISO”).
+Added: Our management team is responsible
+Added: for assessing and managing material cybersecurity risks and for our overall cybersecurity risk management program on a day-to-day basis,
+Added: including supervising both our internal IT personnel and the relationship with our retained external security consultants.
+Added: subsidiary-level IT professionals are responsible for overseeing the security of our IT networks and infrastructure, with a focus on
+Added: preventing, detecting, addressing, and mitigating risks related to unauthorized access, misuse, malware, ransomware, social engineering,
+Added: and other security threats.
+Added: We intend to supplement these internal efforts with managed security service providers as our program matures.
+Added: escalates significant cybersecurity matters to senior management and the Audit Committee in accordance with defined escalation protocols,
+Added: including any matters that may require disclosure under the SEC’s cybersecurity reporting rules or other applicable law.
+Added: also ensures that the Audit Committee receives prompt notification of any cybersecurity incidents that have, or are reasonably likely
+Added: to have, a material effect on the Company.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.