Unresolved Staff Comments
−Removed: The Company received comments from the Staff during fiscal year 2023.
−Removed: The Company’s responses to certain unresolved comments that the Company considers material are still under review by the Staff and are set forth below.
−Removed: Revenue recognition .
−Removed: The Staff commented on the Company’s accounting convention to recognize its noncash (bitcoin) revenue using fair value that is not at contract inception.
−Removed: The Company has evaluated the difference between its current accounting policy and fair value at contract inception and has determined that any differences in revenue are not material for all periods stated.
−Removed: Accounting policy for classifying digital assets as current.
−Removed: The Staff commented on whether bitcoin held at the end of the Company’s fiscal periods are properly reflected as current assets.
−Removed: The Company concludes that bitcoin are included in current assets in the consolidated balance sheets due to the Company’s ability to sell it in a highly liquid marketplace and its intent to liquidate its bitcoin to support operations when needed.
−Removed: Classification of proceeds from sale of bitcoin as an operating activity and not an investing activity.
−Removed: The Staff commented on the Company’s recording of the proceeds from bitcoin sales and why the Company classifies its proceeds as operating cash flows rather than investing cash flows.
−Removed: The Company records its proceeds from sales of bitcoin as operating activities since the bitcoin that is sold is typically held for 7 days or less.
−Removed: Impairment of bitcoin.
−Removed: The Staff commented on the Company’s calculation of impairment of bitcoin using a daily closing price.
−Removed: The Company had evaluated the difference using the daily closing price as compared to the intraday low bitcoin price on our principal market (Coinbase) and determined the difference to not be material for the periods stated.
−Removed: However, beginning in the quarter ended June 30, 2023, the Company began utilizing the intraday low price to calculate the bitcoin impairment.
−Removed: Additionally, the Staff requested clarification on how often the bitcoin impairment testing is performed and recorded.
−Removed: The Company responded that the impairment analysis is calculated on the bitcoin held as of the end of each reporting period, rather than on a daily basis.
−Removed: Bitcoin breakeven analysis .
−Removed: The Staff has requested further disclosure on a comprehensive breakeven analysis that compares the cost to earn or mine one bitcoin with the value of one bitcoin.
−Removed: The Company has revised its disclosures in response to the Staff’s request.
−Removed: Clean and renewable energy resources .
−Removed: The Staff has requested further disclosure on the Company’s use of clean and renewable energy resources.
−Removed: The Company has revised its disclosures in response to the Staff’s request.
−Removed: Custody procedures.
−Removed: The Staff has requested further disclosure on the Company’s custody procedures and arrangements with third-party custodians.
−Removed: The Company has revised its disclosures in response to the Staff’s request.
−Removed: Cybersecurity and insurance .
−Removed: The Staff has requested further disclosure on the Company’s insurance coverage as it relates to cybersecurity.
−Removed: The Company has revised its disclosures in response to the Staff’s request.
−Removed: Hosting and Profit-sharing Fees .
−Removed: The Staff has requested further information on the trends related to the Company’s hosting and profit-sharing fees.
+Added: Cyber security
+Added: Cybersecurity risk may adversely impact our business.
+Added: The impact could include weakened financial condition, litigation risk, degrading mining operations, loss of competitiveness, fraud, extortion, harm to employees, violation of applicable privacy or other regulations that could result in regulatory action and fines.
+Added: We have developed and implemented a cybersecurity program to manage the confidentiality, integrity and availability of our data and information systems that support our business.
+Added: The program is aligned with the National Institute of Standards and Technology Cybersecurity Framework 2.0 and is integrated into our overall risk management program.
+Added: It is designed to develop appropriate strategies for preserving the confidentiality, integrity and availability of our data and information systems that can evolve with the changing cybersecurity threat landscape.
+Added: We have implemented policies, procedures and technological tools to prevent, detect and mitigate cybersecurity risks posed by third parties.
+Added: We use third party providers to help us consistently monitor and evaluate our cybersecurity program and performance through actions that include hiring a contract Chief Information Security Officer (“CISO”) with decades of cybersecurity experience to help manage our program.
+Added: We also use industry standard technology tools including vulnerability scans, penetration tests, firewalls, endpoint detection and threat intelligence.
+Added: A written cybersecurity incident response plan that we tabletop yearly and cybersecurity insurance are also important pillars in our approach to managing the risk of a cyber event.
+Added: Our incident response plan contains a materiality analysis framework based on Federal Information Processing Standards Publication 199.
+Added: This materiality framework allows us to identify and classify cybersecurity events based on their impact to our data or information systems.
+Added: This framework will assist us in expediting review of cyber events for materiality purposes that could require disclosure to the SEC.
+Added: We have implemented a third party risk management policy that categorizes the cybersecurity risk posed by third party vendors along with the type of cybersecurity controls we may require of those vendors.
+Added: These may include employee training, cybersecurity tools like multi-factor authentication, and contractual requirements that vendors maintain appropriate technical, administrative and physical cybersecurity controls.
+Added: This is in addition to the policies and practices we maintain to monitor access of our information systems and data using our internal staff and third party vendors.
+Added: As part of communicating the importance of cybersecurity at an enterprise wide level, we require that all company employees participate in annual cybersecurity training.
+Added: Our IT Steering and Risk Committee (“ITSRC”) has been delegated the responsibility for managing cybersecurity risk for the company.
+Added: This committee is chaired by our Chief Technology Officer and includes a diverse cross section of company stakeholders including the Senior IT Manager, General Counsel, VP of Organizational Development and a member of our Third Party Audit team.
+Added: As of July 1, 2024, we added an outsourced virtual CISO who is a key advisor to the ITSRC, specifically for his decades of expertise in managing and maturing a cybersecurity program that includes mitigation, incident prevention, detection and remediation disciplines.
+Added: The ITSRC meets at least semi-annually to assess our approach to evolving cybersecurity threats and its impact on our cybersecurity program.
+Added: The ITSRC is also responsible for maintaining and monitoring legal and regulatory requirements and compliance as well as oversight of the adequacy of company cyber insurance.
+Added: Our third party security vendors, in collaboration with our Senior IT Manager, keep the ITSRC apprised of efforts surrounding the prevention, detection, mitigation and remediation of any cyber threats or cybersecurity incidents.
+Added: The Board of Directors (the “Board”) is entrusted with the oversight of the management of cybersecurity risk and our cybersecurity program.
+Added: The Board administers this oversight through its audit committee and the ITSRC.
+Added: The ITSRC committee chair is responsible for reporting to the Board’s audit committee with respect to cybersecurity at least twice per calendar year.
+Added: The audit committee, as necessary, reports any findings and recommendations to the Board.
+Added: As cyber threats evolve and as our cybersecurity program matures, the Board will consider further developing specific cybersecurity oversight functions and protocols.
+Added: For more information on our cybersecurity related risks, see Part I, Item 1A.
+Added: “Risk Factors” of this Annual Report on Form 10-K.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.