Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments
Not Applicable.
Item 1C. Cybersecurity
Our cybersecurity program is designed to protect our information, and that of our customers, against cybersecurity threats
that may result in adverse effects on the confidentiality, integrity, and availability of our information systems. Our
cybersecurity risk management program, which is integrated into our overall enterprise risk management program, includes
policies, processes and technologies to assess, identify and manage risks from cybersecurity threats and leverages the
National Institute of Standards and Technology Cybersecurity Framework.
Governance
Our Board, with assistance from its Audit Committee, oversees the Company’s enterprise risk management process,
including the management of risks arising from cybersecurity threats. Our Audit Committee receives reports on significant
cybersecurity developments from the management team responsible for overseeing the Company’s risk and cybersecurity
management processes, including our Chief Compliance Officer and Chief Security Officer. We also have protocols by
which certain cybersecurity incidents are escalated within the Company and, where appropriate, reported to our Board in a
timely manner.
At the management level, our Chief Security Officer leads the team responsible for implementing, monitoring and
maintaining our cybersecurity risk management program across our business . He has extensive cybersecurity knowledge
and skills gained from over 20 years of relevant work experience, including various leadership and management roles in
information technology at the Company and elsewhere. He also has a Master of Science in information systems.
Risk Management and Strategy
Our cybersecurity program includes technical safeguards, including automated tools managed and monitored by our
cybersecurity team. Additionally, we regularly conduct penetration and vulnerability testing and tabletop exercises, along
with regular team member training on cybersecurity matters. We also employ systems and processes designed to oversee,
identify, and reduce the potential impact of a security incident at a third-party vendor, service provider or customer or
otherwise implicating the third-party technology and systems we use.
We engage independent third-party consultants and other service providers from time to time to conduct security
assessments and audits and to assess and enhance our cybersecurity practices. These third parties support our efforts to
assess the effectiveness of our cybersecurity controls, identify potential vulnerabilities, benchmark our practices against
industry standards and enhance our overall cybersecurity posture.
While we have not identified any material cybersecurity threats or incidents since the beginning of the last fiscal year that
have had a material adverse effect on our business, there can be no guarantee that we will not be the subject of future
successful attacks, threats or incidents. For more information on our cybersecurity related risks, see “Item 1A. Risk Factors
Risks Related to Our Business – Our business could be negatively impacted by cybersecurity threats and other
disruptions.” .
45
Table of contents
Item 2. Properties
We operate completely remotely and do not maintain any physical propertie s for our team members or the operation of our
business. We believe that our remote working operations are adequate to meet our needs for the immediate future, and that,
if necessary, suitable physical space will be available to accommodate any expansion of our operations.
Item 3. Legal Proceedings
For a description of material legal proceedings in which we are involved, see "Note 12 - Commitments and Contingencies"
to our consolidated financial statements included in Part II, Item 8 of this report, which is incorporated herein by reference.
Item 4. Mine Safety Disclosures
Not Applicable.
46
Table of contents
PART II