UNRESOLVED STAFF COMMENTS
−Removed: Not applicable.
CYBERSECURITY
management and strategy
−Removed: recognize the importance of developing, implementing, and maintaining robust cybersecurity measures to protect our information systems
−Removed: and protect the confidentiality, integrity, and availability of our data.
−Removed: We have established policies and procedures to assess, identify,
−Removed: and manage material risk from cybersecurity threats.
−Removed: We assess risks from cybersecurity threats against our information systems that
−Removed: may result in adverse effects on our information systems or any information residing therein.
−Removed: We conduct periodic and ad-hoc assessments
−Removed: to identify cybersecurity threats.
−Removed: these risk assessments, we evaluate whether and how to re-design, implement, and maintain reasonable safeguards to mitigate identified
−Removed: risks and reasonably address any identified gaps in existing safeguards.
−Removed: Our IT specialist reports to our Chief Executive Officer (CEO)
−Removed: to manage the risk assessment and mitigation process.
−Removed: We monitor and test our safeguards and train our employees on the implementation
−Removed: of such safeguards, in collaboration with human resources, IT, and management.
−Removed: We aim to promote a company-wide culture of cybersecurity
−Removed: risk management.
+Added: recognize the critical importance of developing, implementing, and maintaining robust cybersecurity measures to safeguard our information
+Added: systems and protect the confidentiality, integrity, and availability of our data.
+Added: Material Risks & Integrated Overall Risk Management
+Added: have strategically integrated cybersecurity risk management into our broader risk management framework to promote a company-wide culture
+Added: of cybersecurity risk management.
+Added: This integration ensures that cybersecurity considerations are an integral part of our decision-making
+Added: processes at every level.
+Added: Our management team continuously evaluates and addresses cybersecurity risks in alignment with our business
+Added: objectives and operational needs.
+Added: Third-Party Risk
+Added: we are aware of the risks associated with third-party service providers, we have implemented stringent processes to oversee and manage
+Added: We conduct thorough security assessments of all third-party providers before engagement and maintain ongoing monitoring
+Added: to ensure compliance with our cybersecurity standards.
+Added: The monitoring includes annual assessments of the system and organization controls
+Added: (SOC) reports of our providers and implementing complementary controls.
+Added: This approach is designed to mitigate risks related to data breaches
+Added: or other security incidents originating from third parties.
from Cybersecurity Threats
1 unchanged sentence
year ended December 31, 2024.
+Added: We will continue to monitor and assess our cybersecurity risk management program as well as invest in and
+Added: seek to improve such systems and processes as appropriate.
+Added: If we were to experience a material cybersecurity incident in the future,
+Added: such an incident may have a material effect, including on our operations, business strategy, operating results, or financial condition.
+Added: For more information regarding cybersecurity risks that we face and potential impacts on our business related thereto, see the section
+Added: titled “ Risk Factors ” in Part I, Item 1A of this Annual Report on Form 10-K.
board of directors is responsible for monitoring and assessing strategic risk exposure.
1 unchanged sentence
risk oversight function directly as a whole, as well as through the Audit Committee.
−Removed: Our executive management team inform our audit committee
−Removed: on cybersecurity risks on a regular basis, at least once per year.
+Added: Our executive management team informs our Audit
+Added: Committee on cybersecurity risks on a regular basis, at least once per year.
+Added: Audit Committee is primarily responsible for assisting our board of directors in fulfilling its ultimate oversight responsibilities relating
+Added: to risk assessment and management, including relating to cybersecurity and other information technology risks.
+Added: The Audit Committee oversees
+Added: management’s implementation of our cybersecurity risk management program, including processes and policies for determining risk
+Added: tolerance, and reviews management’s strategies for adequately mitigating and managing identified risks, including risks relating
+Added: to cybersecurity threats.
cybersecurity coordinator is responsible for assessing and managing our material risks from cybersecurity threats, in close collaboration
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.