Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments.
None.
Item 1C. Cybersecurity
We rely on information technology systems to operate our business and store and process data, including confidential business information and personal information of our customers and employees. Generally, these systems are maintained by third parties, who assume responsibility for data security. We are, however, subject to cybersecurity risks, including unauthorized access to our systems, data breaches, service disruptions, and other incidents.
20
Table of Contents
Cybersecurity Risk Management and Strategy
We maintain processes to identify, assess, manage, and mitigate material risks posed by cybersecurity threats. These processes are integrated into our overall risk management framework and include, among other things, risk assessments, monitoring of information technology systems, employee training, and the use of third-party service providers and security tools. We also maintain incident response and business continuity processes designed to address cybersecurity incidents, including incidents involving third-party service providers.
Cybersecurity risks are evaluated in the context of potential operational, financial, legal, and reputational impacts. While we seek to manage these risks, cybersecurity threats continue to evolve, and there can be no assurance that our processes will prevent all cybersecurity incidents.
Governance
Responsibility for oversight of cybersecurity risks resides with our management team, which regularly assesses cybersecurity risks and the effectiveness of related processes and controls. Senior management is informed of material cybersecurity risks and incidents, as appropriate, and is responsible for implementing and maintaining our cybersecurity risk management practices.
The Board of Directors oversees the Company’s risks, including cybersecurity risks, and receives information from management on material risks and related mitigation efforts as part of its overall risk oversight function.
Cybersecurity Incidents
As of the date of this Annual Report, we have not experienced a cybersecurity incident that has materially affected our business, operating results, or financial condition. However, we may experience cybersecurity incidents in the future that could have such effects.
Cybersecurity risks are described in more detail under Item 1A, “Risk Factors—Cybersecurity incidents or security breaches involving customer or employee information could adversely affect our business.”
21
Table of Contents
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.