Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED STAFF COMMENTS.
None.
ITEM 1C. CYBERSECURITY.
RISK MANAGEMENT AND STRATEGY
Our cybersecurity program is informed by various industry frameworks, including the National Institute of Standards and Technology (NIST) Cybersecurity Framework, and our security management is ISO/IEC 27001:2022 certified. Our management, with oversight from our Board, performs an annual enterprise-wide risk assessment (ERA) to identify key existing and emerging risks. One of the main risks identified and assessed annually through this process is cybersecurity and data privacy, which remains a key focus for us and our Board.
13
Table of Contents
We maintain multiple layers of security designed to detect and block cybersecurity events, as well as employ a dedicated team of cybersecurity personnel and professionals, who assist our Vice President – Information Technology in helping to assess, identify, monitor, detect and manage cybersecurity risks, threats, vulnerabilities, and incidents. Further, we have various processes and programs designed to manage cybersecurity risks associated with our use of third-party vendors and suppliers.
When we implement significant changes to our information systems, we conduct risk-based security and privacy impact assessments and deploy technical safeguards that are designed to reasonably protect our technology and information systems from cybersecurity threats. We actively monitor and proactively research potential cybersecurity threats to our information systems, and we use what we learn to evolve our security controls over time to mitigate risks posed by such threats.
We also engage third party service providers when necessary to both expand our capabilities and capacity as well as assess the effectiveness of our cybersecurity program, including hosting regular table-top exercises meant to evaluate and improve the overall effectiveness of our cybersecurity program.
Our Incident Response Plan provides a framework for responding to cybersecurity incidents. The plan governs activities such as preparation, detection, coordination, eradication, and recovery, as well as appropriate escalations to our senior management and Board and disclosure under applicable rules and regulations. The Incident Response Plan is routinely reviewed and updated as appropriate by our Vice President – Information Technology and other senior management members.
We provide recurring mandatory information security training (which includes cybersecurity training) to our associates based on access, risk, roles, and behaviors.
Overall, we implement, develop, and maintain systems and operate programs that seek to prevent and mitigate the impact of cybersecurity incidents. Because the techniques used to obtain unauthorized access, disable or degrade service, or sabotage information systems or data on such systems, change frequently, we must continually monitor and update these systems and programs. See “Risk Factors” in Item 1A of Part I in this Annual Report for additional information on risks related to our business, including risks related to cybersecurity incidents and privacy and data protection.
GOVERNANCE
Our Vice President – Information Technology leads our assessment and management of cybersecurity risk. Reporting directly to our President & Chief Executive Officer, the incumbent is a member of our senior management team, providing cybersecurity updates to that group monthly, with more frequent updates as needed. He has more than 35 years of experience within industrial distribution, the majority of which was focused on managing and maintaining information systems. In addition, he leads a team of individuals that focus on monitoring our information systems and data for intentional and unintentional actions that could cause harm to our information systems or the data on such systems.
As indicated above, we, with oversight from the Board , perform an annual ERA and cybersecurity is among the main risks identified by the ERA for Board-level oversight. Our full Board has oversight of our efforts in cybersecurity and meets regularly with our Vice President – Information Technology (three times during 2026) on our cybersecurity risks and programs. The Board is also updated as needed on cybersecurity threats, incidents, or new developments in our cybersecurity risk profile.
14
Table of Contents