Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED STAFF
COMMENTS
None.
47
Table of Contents
ITEM 1C. CYBERSECURITY
Risk Management and Strategy
We rely on
information technology and data to operate our business effectively and recognize the importance of implementing and maintaining cybersecurity systems and processes that allow us to protect the confidentiality, integrity and availability of our
information systems and the data residing within them.
We maintain a comprehensive cybersecurity risk program to effectively identify,
assess, manage, and respond to cybersecurity risks and incidents. Our program is implemented by in-house personnel with experience in cybersecurity fields and is further enhanced by external partners that
specialize in cybersecurity services. Our program is built on recognized industry standards and frameworks that are regularly evaluated and updated to address emerging threats.
Key elements of our cybersecurity risk management program include regular and thorough risk assessments to identify potential cybersecurity
threats across our operations, the implementation of appropriate multi-layered security controls and advanced monitoring systems, comprehensive employee cybersecurity awareness training and education programs delivered throughout the year. A key
element of our cybersecurity response program is the regular and redundant point-in-time backup of critical configurations and files. The backup information is stored both locally and at off-site locations for additional security.
Governance
Our board of directors
oversees our cybersecurity risk management program through the Audit Committee. Our management team, including our Senior Vice President of Operations, provides periodic updates on cybersecurity matters to the Audit Committee, which relays them to
the board of directors as needed. Our Senior Vice President of Operations has primary responsibility for assessing and managing cybersecurity risks and leading our overall cybersecurity posture, including the engagement of external third parties to
assist us. Our Senior Vice President of Operations has 10 years of experience in the field of information systems and cybersecurity.
Impact of Risks
from Cybersecurity Threats
As of the date of this Annual Report, we are not aware of any previous cybersecurity incidents that have
materially affected or are reasonably likely to materially affect the Company, including our business strategy, results of operations and financial condition. We acknowledge that cybersecurity threats are continually evolving, and the possibility of
future cybersecurity incidents, material or otherwise, remains. Despite the implementation of our cybersecurity processes, our security measures cannot guarantee that a significant cybersecurity incident will not occur. While we devote resources to
our security measures designed to protect our systems and information, no security measure is infallible. For more information about the cybersecurity risks we face, refer to Item 1A. Risk Factors in this Annual Report.
ITEM 2. PROPERTIES
Information about our properties is incorporated herein by reference to Item 1. Business of Part I of this Annual Report. Our
corporate headquarters is located in leased office space in Morgantown, West Virginia. We also lease office space in Greenwich, Connecticut, Houston, Texas and Marietta, Ohio.