Item 1B. Unresolved Staff Comments
Item
1B. Unresolved Staff Comments
None
Item
1C. Cybersecurity
We
maintain processes for assessing, identifying and managing material risks from cybersecurity threats to our business. These processes
apply to our internal information systems, connected products, software, data, third-party service providers and certain aspects of our
supply chain and business operations. Our business involves the use of computers, mobile devices, online platforms and other information
technologies in substantially all aspects of our operations, including communications with employees, suppliers, manufacturers, distributors,
customers and consumers. As a result, cybersecurity risk is an important part of our overall risk management activities.
23
Table of Contents
Our
cybersecurity risk management processes are designed to address risks that may arise from unauthorized access to systems or data, theft,
destruction, loss, misappropriation or release of personal information or intellectual property, ransomware and other malware, phishing
and other social engineering, software vulnerabilities, misuse of credentials, failures of third-party hosted environments or applications,
and disruptions affecting the information technology systems of third parties on which we rely. These processes also reflect that security
incidents can take a variety of forms and continue to evolve as threat actors become more sophisticated.
As
part of these processes, we use a combination of safeguards and procedures that may include user access controls, monitoring and logging,
device and endpoint protections, vulnerability identification and remediation, incident response and escalation procedures, employee
awareness measures, and third-party diligence and oversight, as appropriate for our size and operations. Because we are an early-stage
company with limited personnel and resources, our cybersecurity processes are designed to be proportionate to our current business and
organizational structure. At the same time, our limited resources may affect the scope and speed of our ability to investigate, remediate
and prevent vulnerabilities and security incidents.
We
also consider cybersecurity matters in connection with the development, deployment and support of our products and products. Our business
depends in part on connected products, software functionality, wireless communications and evolving technologies,
and we may be required to expand and improve our information technologies as our business grows. These factors may increase our technological
presence and corresponding exposure to cybersecurity risk. In addition, because we rely on wireless carriers and other third-party service
providers in aspects of our business, interruptions, failures or security issues affecting those parties could adversely affect our operations,
services and reputation.
We
rely on third parties in several aspects of our business, including technology, logistics, communications and product sourcing, and we
consider third-party and supply-chain exposures as part of our cybersecurity risk management processes. Our dependence on suppliers and
other external counterparties may increase our exposure to operational disruptions, technology failures and other incidents outside our
direct control. We also consider broader business continuity risks that could affect us or the third parties on which we depend, including
natural disasters, power outages, geopolitical events, trade disputes, terrorism and other disruptions.
Our
business is also subject to privacy, data security and related laws and regulations in the United States and other jurisdictions. In
addition to breach notification requirements that may be triggered by a security incident, we may be contractually required to notify
customers or other counterparties of certain incidents. Maintaining safeguards and responding to an actual or suspected security incident
may be costly and resource-intensive and could subject us to regulatory scrutiny, litigation, fines, penalties, remediation costs, reputational
harm and business interruption. We therefore consider legal and regulatory developments relating to privacy, data security and the processing
of personal information as part of our cybersecurity risk management processes.
Because
we conduct certain operations in the PRC and have PRC-related suppliers, our cybersecurity and data-related risk management processes
also take into account certain PRC laws, regulations and regulatory developments. These include the PRC Cybersecurity Law, the PRC Data
Security Law, the Personal Information Protection Law, the Cybersecurity Review Measures and the multi-level protection scheme, or MLPS.
These laws and regulations may impose obligations relating to network security, data handling, personal information protection, classification
and protection of data, and potential cybersecurity review requirements. We monitor these developments as part of our overall compliance
and risk management activities because changes in PRC laws, regulations, interpretations or enforcement practices could impose additional
obligations on us, our subsidiaries, suppliers or business partners, or could disrupt our operations.
As
of the date of this Annual Report on Form 10-K, we have not received any notice from PRC authorities identifying us as a critical
information infrastructure operator or requiring us to undergo a cybersecurity review or network data security review by the CAC.
However, the interpretation and enforcement of PRC laws and regulations remain uncertain, and future developments could affect our
business, operations and compliance obligations.
24
Table of Contents
Cybersecurity
oversight is part of our overall risk oversight framework. Our board of directors oversees major business risks, including material cybersecurity
risks, and management is responsible for the day-to-day assessment and management of those risks. Management’s oversight involves
coordination among personnel responsible for information technology, operations, product development, finance and legal or compliance
matters, as appropriate. Material cybersecurity matters are escalated to senior management and, where appropriate, to the board of directors.
This framework reflects our size, organizational structure and stage of development.
As
of the date of this Annual Report on Form 10-K, we are not aware of any cybersecurity incident that has materially affected, or is reasonably
likely to materially affect, the Company, including our business strategy, results of operations or financial condition. However, there
can be no assurance that our processes and measures will be effective to prevent all cybersecurity threats or incidents. Any security
incident, other technology disruption, or failure to comply with privacy, data security or related laws and regulations could harm our
brand and reputation, disrupt our operations, subject us to regulatory scrutiny or legal liability, and materially adversely affect our
business, results of operations and financial condition.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.