Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments
None.
Item 1C. Cybersecurity
Management
and Strategy
The
Company has processes in place for assessing, identifying, preventing, and managing material risks from cybersecurity threats, including
related to the use of third party service providers. In addition, the Company leverages the security and monitoring tools of third party
service providers. These processes are integrated into the Company’s overall risk management program and systems, as overseen by
the Board, primarily through the Audit Committee.
We
maintain physical, technical and administrative safeguards to prevent and identify cybersecurity risks, and have implemented practices
and procedures to address cybersecurity risks. To this end, among other things, we:
● provide
annual mandatory training for our employees regarding cybersecurity threats as a means to
equip them with effective tools to address cybersecurity threats, and to communicate our
evolving information security policies, standards, processes and practices;
● conduct
regular simulation modules for all employees to enhance awareness and responsiveness to possible
threats;
● conduct
cybersecurity management and incident training for employees involved in our systems and
processes that handle sensitive data; and
● carry
cyber liability insurance that is intended to provide protection against the potential losses
arising from a cybersecurity incident.
We
are currently working with outside counsel to further develop a formal cybersecurity incident response plan.
While
we are regularly exposed to malicious technology-related events and threats, none of these threats or incidents, either individually
or in the aggregate of related occurrences, have materially affected the Company in the period covered by this Annual Report on Form
10-K. In determining materiality, cybersecurity incidents are reviewed not only for potential financial impacts, which could include
potential legal and regulatory penalties, stolen assets or funds, system damage, forensic and remediation costs, lost revenue or litigation
costs, but also the breadth and sensitivity of data exposure, data exfiltration, impacts on the ability to operate our business or provide
our services and loss of investor confidence.
Governance
The
Board executes its oversight responsibility for risk management both directly and through delegating oversight of certain of these risks
to its committees, and the Board has authorized the Audit Committee to oversee risks related to cybersecurity threats. Our Audit Committee
has primary oversight responsibility for cybersecurity and information security risk management and controls. As part of its oversight
function, the Audit Committee oversees the Company’s risk assessment and risk management policies, including related to cybersecurity
and the overall data protection program.
34
Our senior management is responsible for assessing and managing the
Company’s various exposures to risk, including those related to cybersecurity, on a day-to-day basis, including the identification
of risks through an enterprise risk management framework and the creation of appropriate risk management programs and policies to address
such risks. The Company’s Senior Manager, IT, has 24 years of experience in enterprise IT and has primary responsibility for managing
our cybersecurity program and efforts, and our finance and IT teams are responsible for the testing and audit of our information-technology
related internal controls.
See
Item 1A, Risk Factors , for additional information on the Company’s cybersecurity risk profile, in particular the risk factors
under the headings entitled “ Risks relating to data privacy could create additional liabilities for us ” and “ Security
breaches and other disruptions could compromise our information and expose us to liability, which would cause our business and reputation
to suffer ”.