Item 1B. Unresolved Staff Comments
ITEM
1B. UNRESOLVED STAFF COMMENTS
None.
ITEM
1C. CYBERSECURITY
Risk
Management and Strategy
The
Company has a risk-based cybersecurity program, designed to protect the Company’s operations and information assets. The
Company constantly assesses its cybersecurity risks by evaluating the likelihood of occurrence and the potential impact on the
business. The risk identification process considers those common in the oil and gas industry and those that pertain to the technologies
within the Company’s applications and infrastructure.
We
use several key risk mitigation processes and software tools in place to prevent, detect, and respond to cybersecurity attacks.
Multi-factor authentication and privileged access are required to access the Company’s network in order to protect internal
data and ensure appropriate access. The Company utilizes security vulnerability scanning software and 24/7 monitoring in an effort
to detect and prevent significant cybersecurity threats as well as uses email and spam filtering.
The
Company also uses a backup and recovery methodology that supports the replication of data across multiple secure data centers
with the intent to prevent local and cloud backup data from accidental destruction and unavailability in the event of data loss
or a major cyber event. The Company also has contracted retainers with third party vendors in the event they are required to assist
during a major cybersecurity incident.
Security
due diligence is performed when considering purchasing third party software and utilizing third party hosted providers. This
evaluation considers the security architecture, confidentiality and criticality of data, as well as methods and practices used
by third party vendors to encrypt, transmit, store, back up, and recover data.
Governance
The
board of directors of the Company has oversight of the Company’s risk management, including cybersecurity. The
Company’s senior officers are responsible for cybersecurity risk management and regularly communicate with the board of
directors regarding risks and threats, including the status of current cybersecurity risk prevention and threat detection efforts.
Jeffery Guzy, Chief Financial Officer is the primary individual responsible for assessing and managing cybersecurity risks. He
has extensive experience managing information technology departments of oil and gas organizations. This includes responsibilities
for securing the solutions, data, and infrastructure for both corporate and field operations technology. The Company’s technology
environment is managed by an experienced team of professionals who follow an extensive set of policies and procedures related
to data security.
The
Company is not aware of any risks from cybersecurity threats that have materially affected or are reasonably likely to materially
affect the Company, including its business strategy, results of operations, or financial condition. Please see Item
1A—Risk Factors— “ Cyber-attacks targeting systems and infrastructure used by the oil and gas industry
and related regulations may adversely impact our operations and, if we are unable to obtain and maintain adequate protection for
our data, our business may be adversely affected ” in this Annual Report on Form 10-K for further discussion regarding
the Company’s cybersecurity risks.
Recognizing
the critical importance of robust cybersecurity measures, the Company is committed to developing, implementing and maintaining
measures to better safeguard our information systems and protect the confidentiality, integrity and availability of our data.
Our management team actively evaluates and addresses cybersecurity risks in alignment with our business objectives and operational
needs. The Company utilizes third party dedicated servers to protect its confidential information and has installed malware detection
applications to monitor any security breaches. To date, our operations or financial standing have not been materially impaired
by any cybersecurity challenges. Looking ahead, the Company will mandate comprehensive cybersecurity training for both the Board
and employees, covering key areas such as physical security of assets, data privacy and other information security policies and
procedures.
30