Unresolved Staff Comments.
−Removed: Our principal asset is a manufacturing plant situated on approximately 2,200 acres of land six miles southeast of Batesville in north central Arkansas fronting the White River.
−Removed: Approximately 500 acres of the site are occupied with batch and continuous manufacturing facilities, laboratories, and infrastructure, including on-site liquid waste treatment.
−Removed: Our subsidiary, FutureFuel Chemical Company, is the fee owner of this plant and the land upon which it is situated (which plant and land are not subject to any major encumbrances) and manufactures both biofuels and chemicals at the plant.
−Removed: Use of these facilities may vary with product mix and economic, seasonal, and other business conditions, but the plant is substantially used with the exception of facilities designated for capacity expansion of biodiesel.
−Removed: The plant, including approved expansions, has sufficient capacity for existing needs and expected near-term growth.
−Removed: We believe that the plant is well maintained, in good operating condition, and suitable and adequate for its uses.
+Added: Cybersecurity.
+Added: Risk Management and Strategy
+Added: The Company understands the importance of managing risks from cybersecurity incidents and utilizes a multilayered strategy guided by the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework for assessing, identifying, detecting and responding to threats and other potential incidents.
+Added: Key aspects of our strategy for managing risks of cybersecurity threats include:
+Added: Timely security patching of endpoints;
+Added: Network and endpoint-based monitoring with autonomous protection capabilities;
+Added: Backups which are regularly tested for recovery with key backups hardened against malicious access;
+Added: Third-party security services for audit, benchmarking, and improvement of our cyber security program;
+Added: Ongoing monitoring and evaluation of our cybersecurity posture and performance through regular vulnerability scans, simulated phishing tests, and penetration tests;
+Added: Oversight of third-party service providers by conducting vendor diligence upon onboarding and ongoing monitoring;
+Added: An incident response plan designed to coordinate the activities that we and our third-party security service providers take to prepare to respond and recover from cybersecurity incidents, which include processes to triage, assess severity, investigate, escalate, contain, and remediate incidents, as well as to comply with applicable legal obligations and mitigate any reputational damage;
+Added: Structured management of change process to ensure material changes to our systems or operations have an updated assessment of their potential impact associated with internal and external threats to the security, confidentiality, integrity, and availability of our data and systems, along with other material risks to our operations;
+Added: Ongoing, annual employee security awareness training;
+Added: Cybersecurity insurance coverage to help mitigate the risk of loss from cybersecurity incidents.
+Added: To date, the Company does not believe that cybersecurity incidents have materially affected the Company, its business strategy, results of operations, or financial condition.
+Added: The Company cannot provide assurance that it will not be materially affected by any future material cybersecurity incidents.
+Added: For more information about the cybersecurity risks the Company faces, see Item 1A, Risk Factors, above.
+Added: The Company’s Information Technology (“IT”) Director is responsible for developing and implementing our cybersecurity program and has over 20 years of cybersecurity experience in various roles involving information security, developing cybersecurity strategies, and implementing cybersecurity programs.
+Added: Our program includes that all employees complete annual cybersecurity awareness training.
+Added: The IT Director is responsible for reporting audit findings and risk information to the Company’s Chief Financial Officer (“CFO”).
+Added: Our board of directors is responsible for overseeing our enterprise risk management activities in general, and each of the committees of our board of directors assists the board of directors in the role of risk oversight.
+Added: The Audit Committee of the board of directors oversees our cybersecurity risk and receives reports from time to time from our CFO on cybersecurity risk management.
+Added: Promptly after becoming aware of a material cybersecurity incident affecting our IT systems or data, the IT Director would work with management to formulate a mitigation plan and review compliance with such plan, as well as to ensure compliance with any external regulatory or disclosure requirements, including any disclosures of material cybersecurity incidents.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.