Item 1B. Unresolved Staff Comments
ITEM
1B. UNRESOLVED STAFF COMMENTS
None.
ITEM
1C. CYBERSECURITY
Overview
In
the ordinary course of our business, we collect, use, store, and digitally transmit confidential, sensitive, proprietary, and personal
information, including customer identities, financial data, transaction histories, private key management data, and personally identifiable
information (“PII”). As a digital asset trading and payment services platform, the secure maintenance of this information
and our information technology systems is fundamental to the trust our customers place in us, to the continued operation of our business,
and to our compliance with applicable laws and regulations.
We
operate in an industry that is a high-value target for sophisticated and well-funded threat actors, including nation-state actors, organized
criminal groups, and individual hackers who may seek to compromise customer assets, disrupt our platform operations, or steal sensitive
data. We take this threat environment seriously and are in the process of developing a cybersecurity risk management program designed
to protect the confidentiality, integrity, and availability of our critical systems and information.
This
Item 1C is organized into three principal sections as required by the SEC’s cybersecurity disclosure rules: (1) Risk Management
and Strategy; (2) Governance; and (3) Material Incidents. For a discussion of the risks that cybersecurity threats pose to our business
strategy, operations, and financial condition, including the risk of private key loss, platform disruption, and regulatory penalties,
see “Item 1A — Risk Factors,” which is incorporated by reference herein.
Cybersecurity
Risk Management and Strategy
We
are in the process of developing a cybersecurity risk management program intended to protect the confidentiality, integrity, and availability
of our critical systems and information. We are evaluating alignment of this program with the National Institute of Standards and Technology
Cybersecurity Framework (“NIST CSF”) and intend to integrate it into our overall enterprise risk management (“ERM”)
program so that cybersecurity risks are evaluated alongside operational, financial, legal, and strategic risks facing the Company.
21
Table of Contents
Our
cybersecurity risk management program is being developed around the NIST CSF core functions — Identify, Protect, Detect, Respond,
and Recover — and is expected to include the following key elements, which are currently under review for future implementation:
1.
Identify — Risk Assessment and Asset Management
We
are evaluating the development of processes to maintain an inventory of information assets, systems, and data, and to conduct periodic
cybersecurity risk assessments to identify threats, vulnerabilities, and the potential impact of cybersecurity incidents on our operations. During fiscal year 2024, management performed
an internal review focused on identifying key cybersecurity risks associated with our business operations and continues to assess the
need for more formalized risk assessment processes. Management is evaluating potential remediation measures and enhancements to its cybersecurity
risk management program for future implementation on a prioritized basis, including the possible engagement of third-party resources.
We
are also evaluating the use of threat intelligence feeds and participation in information-sharing forums relevant to the digital asset
and financial technology sectors to monitor emerging cybersecurity developments, including threats specifically targeting digital asset
platforms and companies similar to ours. No formal threat intelligence program has been implemented to date.
2.
Protect — Technical and Administrative Controls
We
are reviewing the adoption of a defense-in-depth security architecture to protect our systems, data, and customer assets. The technical
and administrative controls we are evaluating for future implementation include:
● Network
Security: Firewalls, intrusion detection and prevention systems (IDS/IPS), and network segmentation
to isolate sensitive systems and limit lateral movement in the event of a breach.
● Endpoint
Protection: Endpoint detection and response (EDR) tools to detect, contain, and remediate
malicious activity across company devices.
● Identity
and Access Management: Multi-factor authentication (MFA) across critical systems; role-based
access controls (RBAC) based on the principle of least privilege; and privileged access management
(PAM) controls for administrative accounts.
● Encryption:
Encryption of data at rest and in transit using industry-standard protocols, and hardware-based
controls for the management of private keys and other cryptographically sensitive materials.
● Continuous
Monitoring: A managed 24/7 Security Operations Center (SOC) staffed by a managed security
service provider (“MSSP”), supported by Security Information and Event Management
(SIEM) technology to aggregate and correlate log data across our environment.
● Vulnerability
Management: Regular vulnerability scanning and patching protocols, supplemented by periodic
penetration testing conducted by qualified third-party security firms.
● Cloud
Security: Cloud-native security controls for our cloud-hosted infrastructure, including configuration
management, access logging, and continuous posture monitoring.
● Data
Governance: Formal internal policies governing the classification, handling, retention, and
disposal of sensitive data, including customer PII, financial data, and proprietary information.
We
are evaluating investment in industry-standard security technologies commensurate with the size and risk profile of our business. No
formal implementation of the above controls has occurred to date. We intend to prioritize and implement these controls on a phased basis,
informed by the findings of our FY2024 external risk assessment.
3.
Detect — Threat Detection and Monitoring
We
are evaluating the engagement of a managed 24/7 Security Operations Center (SOC) to provide continuous threat monitoring across our IT
environment. Under this model, the SOC team would monitor security alerts generated by a SIEM platform, endpoint protection tools, network
security devices, and other detection capabilities, with alerts triaged and escalated to senior management in accordance with incident
response procedures. No managed SOC has been engaged to date.
22
Table of Contents
We
are also reviewing subscriptions to industry threat intelligence services and, where appropriate, participation in information-sharing
forums relevant to the digital asset and financial technology sectors, to stay current on threat actor tactics, techniques, and procedures
(TTPs) targeting companies similar to ours. These capabilities are under consideration for future implementation.
4.
Respond and Recover — Incident Response Planning
We
are in the process of developing a written cybersecurity incident response plan (“IRP”) designed to provide a structured
approach to detecting, containing, eradicating, and recovering from cybersecurity incidents. The IRP, when completed, is intended to
establish defined procedures for:
● Initial
detection, triage, and classification of potential security incidents, including a materiality
analysis framework to evaluate incidents for potential disclosure obligations under SEC rules
and applicable securities laws;
● Escalation
and notification protocols to senior management and the Audit Committee, including escalation
timelines tied to incident severity;
● Containment
and eradication activities designed to limit the impact of an incident and prevent recurrence;
● Communication
procedures for notifying affected customers, regulators, law enforcement, and other stakeholders
as required by applicable law; and
● Post-incident
review and remediation to identify root causes and implement corrective measures.
The
IRP has not yet been finalized. We intend to review and update the plan at least annually once adopted, to reflect changes in our threat
environment, business operations, and regulatory requirements. We are also evaluating the conduct of tabletop exercises to test our incident
response capabilities once the IRP is in place.
5.
Workforce Training and Security Awareness
We
recognize that human error is one of the most significant risk factors in cybersecurity, and we are committed to building a security-aware
organizational culture. We are currently evaluating the development of a formal cybersecurity training curriculum in collaboration with
our crypto-processing subsidiary. The program under consideration is expected to cover:
● Phishing
awareness and identification of social engineering attacks;
● Password
hygiene and secure credential management;
● Safe
handling of sensitive customer data and PII;
● Email
security best practices, including how to identify and report suspicious messages; and
● Applicable
data protection policies and compliance obligations.
No
formal training program has been implemented to date. We intend, once a curriculum is developed, to require all employees to complete
cybersecurity awareness training on at least an annual basis, with role-specific training for personnel with access to particularly sensitive
systems or data. We are also evaluating the use of periodic phishing simulation exercises to test employee awareness and identify areas
for additional training.
6.
Third-Party and Supply Chain Risk Management
We
recognize that our security posture is affected not only by our own controls but also by the security practices of the third-party vendors ,
service providers, and partners with whom we share data or on whom we rely for critical services. We are evaluating the development of
a formal third-party risk management program. The elements under consideration include:
● Security
evaluation of third-party vendors and service providers prior to onboarding, including assessment
of their cybersecurity controls, certifications, and compliance posture;
23
Table of Contents
● Contractual
requirements for third-party vendors to maintain appropriate technical, administrative, and
physical cybersecurity controls, including requirements for prompt notification of security
incidents that may affect our data or systems;
● Ongoing
monitoring of key third-party relationships to assess any changes in their security posture
or risk profile; and
● Periodic
reassessment of vendor risk as part of our overall enterprise risk management process.
No
formal third-party cybersecurity risk management program has been implemented to date. We intend to apply any such program, once developed,
to all significant vendors, including any managed security service providers engaged to supplement our internal IT capabilities.
Material
Cybersecurity Incidents
As
of the date of this Annual Report, we are not aware of any cybersecurity incidents that have had, or are reasonably likely to have, a
material impact on our business, operations, results of operations, or financial condition. As a company operating in the digital asset
sector, we are subject to ongoing cybersecurity threats and may experience security events from time to time. To date, any incidents
we have experienced have been addressed through our security operations capabilities without material impact.
We
note that the digital asset industry has experienced a number of high-profile cybersecurity incidents at other companies, some of which
have resulted in material losses of customer assets or sensitive data and significant regulatory and legal consequences. We continue
to monitor the evolving threat landscape and invest in our cybersecurity defenses in light of these industry developments. We cannot
provide assurance that future cybersecurity incidents will not occur or that any future incidents will not have a material effect on
our business.
For
a detailed discussion of cybersecurity-related risks facing our business, including risks related to private key loss, platform disruption,
data breaches, regulatory exposure, and the security of third-party blockchain networks, see Item 1A, “Risk Factors,” which
is incorporated by reference into this Item 1C.
Cybersecurity
Governance
Board
of Directors and Audit Committee Oversight
Our
Board considers cybersecurity risk as an integral component
of its overall risk oversight function. Our Board has designated the Audit Committee — which is composed solely of independent directors — as the body primarily
responsible for assisting the Board in fulfilling its oversight responsibilities with respect to cybersecurity and other information
technology risks.
The
Audit Committee oversees management’s implementation of our cybersecurity risk management program, including the processes and
policies for determining risk tolerance, and reviews management’s strategies for adequately mitigating and managing identified
cybersecurity risks. The Audit Committee receives updates from management regarding cybersecurity risks, the status of our cybersecurity
program, significant emerging threats, and the results of risk assessments and security testing, at least quarterly and more frequently
as significant matters warrant.
The
Audit Committee reports its cybersecurity-related findings and recommendations to the full Board on a periodic basis. Management updates
the Audit Committee and the Board as necessary regarding material cybersecurity occurrences and the measures the Company is taking to
prevent, contain, and remediate the same. As our cybersecurity program matures, the Board will consider developing additional specific
cybersecurity oversight functions and protocols commensurate with the size and complexity of our business.
Management
Responsibility
Day-to-day
cybersecurity risk management responsibility rests with our subsidiary-level IT professionals, who work in collaboration with our external
managed security service providers and, as appropriate, our outsourced virtual CISO (“vCISO”). Our management team is responsible
for assessing and managing material cybersecurity risks and for our overall cybersecurity risk management program on a day-to-day basis,
including supervising both our internal IT personnel and the relationship with our retained external security consultants.
24
Table of Contents
Our
subsidiary-level IT professionals are responsible for overseeing the security of our IT networks and infrastructure, with a focus on
preventing, detecting, addressing, and mitigating risks related to unauthorized access, misuse, malware, ransomware, social engineering,
and other security threats. We intend to supplement these internal efforts with managed security service providers as our program matures.
Management
escalates significant cybersecurity matters to senior management and the Audit Committee in accordance with defined escalation protocols,
including any matters that may require disclosure under the SEC’s cybersecurity reporting rules or other applicable law. Management
also ensures that the Audit Committee receives prompt notification of any cybersecurity incidents that have, or are reasonably likely
to have, a material effect on the Company.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.