Item 4. Controls and Procedures
ITEM 4. CONTROLS AND PROCEDURES
Evaluation of Disclosure Controls and Procedures
We maintain disclosure controls and procedures (as defined in Rules 13a-15(e) and 15d-15(e) under the Exchange Act) that are designed to ensure that information required to be disclosed in our Exchange Act reports is recorded, processed, summarized and reported within the time periods specified in the SEC’s rules and forms, and that such information is accumulated and communicated to our management, including our Chief Executive Officer and Chief Financial Officer, as appropriate, to allow for timely decisions regarding required disclosure.
In designing and evaluating the disclosure controls and procedures, management recognizes that any controls and procedures, no matter how well designed and operated, can provide only reasonable assurance of achieving the desired control objectives, and management is required to apply its judgment in evaluating the cost-benefit relationship of possible controls and procedures.
As required by Rule 13a-15(b) under the Exchange Act, we carried out an evaluation, under the supervision and with the participation of our management, including our Chief Executive Officer and Chief Financial Officer, of the effectiveness of the design and operation of our disclosure controls and procedures, as of August 2, 2025, the end of the period covered by this Quarterly Report on Form 10-Q.
Based on the foregoing, our Chief Executive Officer and Chief Financial Officer concluded that, as of August 2 , 2025 , the end of the period covered by this Quarterly Report on Form 10-Q, our disclosure controls and procedures were effective and were operating at a reasonable assurance level. As part of the ongoing integration of BlueHalo, we are in
process of incorporating the disclosure controls and procedures of BlueHalo. Management’s evaluation of our disclosure
controls and procedures as of August 2, 2025 excludes an evaluation of BlueHalo’s disclosure controls and procedures
that are subsumed by its internal control over financial reporting of BlueHalo.
Acquisition of BlueHalo
On May 1, 2025, we completed the acquisition of Blue Halo, a U.S. non-public reporting company. Prior to the acquisition, in connection with the preparation of its audited consolidated financial statements for the year ended December 31, 2024, BlueHalo identified three material weaknesses in its internal control over financial reporting. A material weakness is a deficiency, or a combination of deficiencies, in internal control over financial reporting such that
35
Table of Contents
there is a reasonable possibility that a material misstatement of a company’s annual or interim financial statements will not be prevented or detected on a timely basis. First, BlueHalo did not design and maintain effective information technology (“IT”) general controls for information systems that are relevant to the preparation of its financial statements. Specifically, BlueHalo did not design and maintain: (i) program change management controls to ensure that program and data changes are identified, tested, authorized, and implemented appropriately; (ii) user access controls to ensure appropriate segregation of duties and to adequately restrict user and privileged access to appropriate personnel. Second, BlueHalo did not design and maintain an effective control environment commensurate with our financial reporting requirements. Specifically, it did not maintain a sufficient complement of personnel with an appropriate degree of internal controls and accounting knowledge, experience, and training commensurate with its accounting and financial reporting requirements. The limited personnel resulted in an inability to consistently establish appropriate authorities and responsibilities in pursuit of financial reporting objectives, as demonstrated by, among other things, insufficient segregation of duties in the finance and accounting functions. Third, BlueHalo did not design and maintain effective monitoring activities of the design and operation of controls on a timely basis, taking necessary corrective action to ensure that controls continue to operate effectively and are modified for changes in conditions as appropriate.
As of the date of this report, management’s remediation efforts are ongoing, and management has committed to a remediation plan to address the deficiencies and enhance the internal control environment. The remediation plan includes, but is not limited to:
● Reviewing and restricting administrator level access to financial systems, ensuring that elevated privileges are limited to authorized personnel with a documented business need;
● Implementing periodic user access reviews to confirm that access rights remain appropriate and promptly removing access for terminated or transferred employees;
● Implementing a process to utilize the ticketing system to document, approve, and track changes, configuration updates and data modifications;
● Implementing management review of audit logs of select data such as vendor master changes, user roles and rates;
● Implementing a process to utilize the Okta and Single Sign On (SSO) to centralize authentication, strengthen password and multi factor authentication controls, and improve monitoring of user activity;
● Enhancing segregation of duties review within key business cycles to ensure that no single individual has control over all aspects of a financial transaction;
● Providing targeted training to personnel on internal control requirements, documentation standards, and change management protocols;
● Evaluating employee’s skill set and actively recruiting experienced personnel with knowledge of internal control and accounting;
● Evaluating systems to integrate with our enterprise-wide monitoring tools, enabling real-time alerts for unauthorized access or unusual activity.
However, remedial controls must operate for a sufficient period of time for a definitive conclusion, through testing, that the deficiencies have been fully remediated and, as such, management can give no assurance that the measures it has undertaken have fully remediated the material weaknesses that it has identified or that additional material weaknesses will not arise in the future. Management will continue to monitor the effectiveness of these and other processes, procedures, and controls and will make any further changes that management determines to be appropriate.
Changes in Internal Control over Financial Reporting
On May 1, 2025, we acquired BlueHalo and, as a result, we have begun integrating certain processes, systems and controls relating to BlueHalo into our existing system of disclosure controls and procedures in accordance with our integration plans. We do not believe these represent a material change. There were no changes in our internal control over financial reporting or in other factors identified in connection with the evaluation required by paragraph (d) of Rules 13a-15 or 15d-15 under the Exchange Act that occurred during the quarter ended August 2, 2025 that have materially affected, or are reasonably likely to materially affect, our internal control over financial reporting (as defined in Rules 13a-15(f) and 15d-15(f) under the Exchange Act).
36
Table of Contents
PART II. OTHER INFORMATIO N
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.