Item 1B. Unresolved Staff Comments
ITEM
1B. Unresolved Staff Comments
Not
Applicable
ITEM
1C. Cybersecurity
Cyberattacks
are a growing geopolitical risk, becoming larger, more frequent, more intricate and more relentless. These attacks represent a significant
threat to individual organizations and their ability to conduct daily operations. We rely on accounting, financial, and operational management
information systems to conduct our operations. Any disruption in these systems could adversely affect our ability to conduct our business.
Furthermore, as part of our normal business activities, we collect and store common confidential information about customers, employees,
vendors, and suppliers. This information is entitled to protection under a number of regulatory regimes.
Any
failure to maintain the security of the data, including the penetration of our network security and the misappropriation of confidential
and personal information, could result in business disruption, damage to our reputation, financial obligations to third parties, fines,
penalties, regulatory proceedings and private litigation with potentially large costs. This scenario may also result in a deterioration
of customer confidence in us and potentially other competitive disadvantages. As such, a cyberattack could have a material adverse impact
on our financial condition and results of operations.
While
we devote resources to implement and maintain security measures to protect our systems and data, these measures cannot provide absolute
security against a cyberattack. In such an event, the insurance coverage we maintain may be inadequate to cover claims, costs, and liabilities
relating to cybersecurity incidents.
While
we have not been subject to cyberattacks and other cyber incidents, we take cybersecurity preparedness seriously. Our risk management
framework considers cybersecurity risk alongside other company risks as part of our overall risk assessment process. We have plans to
implement cybersecurity training for all employees upon onboarding, and then annual follow-up training courses to ensure that all employees
understand the risk and implications of a cyber event.
We have implemented a Cybersecurity Committee which met three times
last year and is now responsible for the day-to-day management of cybersecurity risks, and the review our practices related to cyber events
and risk management. The Committee is composed of the Chief Financial Officer, Chief Legal Officer, Controller, and Head of Human Resources.
The Committee is responsible for developing and implementing cybersecurity risk mitigation strategies and activities, including the managing
of comprehensive incident response plans, overseeing the cybersecurity risks posed by third-party vendors, keeping our policies and procedures
current, assessing compliance with our cybersecurity policies and procedures, and receiving regular updates on cybersecurity-related matters.
Further, the Committee will, from time to time and as needed, engage subject matter experts such as consultants and auditors to assist
us in establishing processes to assess, identify, and manage potential and actual cybersecurity threats, to actively monitor our systems
internally using widely accepted digital applications, processes, and controls, and to provide forensic assistance to facilitate system
recovery in the case of an incident.
The Audit Committee of our Board of Directors (the “Audit Committee”)
oversees our policies and practices with respect to risk assessment and risk management, including the review, in coordination with our
management, of our management of cybersecurity. The Audit Committee receives regular updates from the Cybersecurity Committee on the state
of cybersecurity risks we face. This includes briefings on any significant cyber incidents and ongoing risk management efforts. These
updates enable the Audit Committee to provide informed reports on cybersecurity matters to the full Board.
As
of the date of this Annual Report on Form 10-K, we are not aware of any risks from cybersecurity threats that have materially affected
or are reasonably likely to materially affect us , our business strategy, results of operations or financial condition.
36