Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED STAFF COMMENTS
None.
ITEM 1C. CYBERSECURITY
The Company’s Board of Directors (the “Board”)
is responsible for overseeing the Company’s risk management program and cybersecurity is a critical element of this program. Management
is responsible for the day-to-day administration of the Company’s risk management program and its cybersecurity policies, processes,
and practices. The Company’s cybersecurity policies, standards, processes, and practices are based on recognized frameworks established
by the National Institute of Standards and Technology, the International Organization for Standardization and other applicable industry
standards and are fully integrated into the Company’s overall risk management processes. In general, the Company seeks to address
material cybersecurity threats through a company-wide approach that addresses the confidentiality, integrity, and availability of the
Company’s information systems or the information that the Company collects and stores, by assessing, identifying and managing cybersecurity
issues as they occur.
Cybersecurity Risk Management and Strategy
The Company’s cybersecurity risk management
strategy focuses on several areas:
● Identification and Reporting: The Company has implemented a comprehensive, cross-functional approach to assessing, identifying
and managing material cybersecurity threats and incidents. The Company’s program includes controls and procedures to properly identify,
classify and escalate certain cybersecurity incidents to provide management visibility and obtain direction from management as to the
public disclosure and reporting of material incidents in a timely manner.
● Technical Safeguards: The Company implements technical safeguards that are designed to protect the Company’s information
systems from cybersecurity threats, including firewalls, intrusion prevention and detection systems, anti-malware functionality, and access
controls, which are evaluated and improved through vulnerability assessments and cybersecurity threat intelligence, as well as assistance
from third party experts where necessary.
● Incident Response and Recovery Planning: The Company has established and maintains comprehensive incident response, business
continuity, and disaster recovery plans designed to address the Company’s response to a cybersecurity incident. The Company conducts
regular tabletop exercises to test these plans and ensure personnel are familiar with their roles in a response scenario.
● Third-Party Risk Management: The Company maintains a comprehensive, risk-based approach to identifying and overseeing material
cybersecurity threats presented by third parties, including vendors, service providers, and other external users of the Company’s
systems, as well as the systems of third parties that could adversely impact our business in the event of a material cybersecurity incident
affecting those third-party systems, including any outside consultants who advise on the Company’s cybersecurity systems.
● Education and Awareness: The Company provides regular, mandatory training for all levels of employees regarding cybersecurity
threats as a means to equip the Company’s employees with effective tools to address cybersecurity threats, and to communicate the
Company’s evolving information security policies, standards, processes, and practices.
The Company conducts periodic assessment and testing
of the Company’s policies, standards, processes, and practices in a manner intended to address cybersecurity threats and events.
This includes penetration testing of network infrastructure and phishing tests targeting the Adviser’s employees. The results of
such assessments and reviews are evaluated by management and reported to the Board, and the Company adjusts its cybersecurity policies,
standards, processes, and practices as necessary based on the information provided by these assessments and reviews.
Governance
The Board, in coordination with the Adviser, oversees
the Company’s risk management program, including the management of cybersecurity threats. The Board receives regular updates and
reports on developments in the cybersecurity space, including risk management practices, recent developments, vulnerability assessments,
third-party and independent reviews, the threat environment, and information security issues encountered by the Company’. The Board
also receives prompt and timely information regarding any cybersecurity risk that meets pre-established reporting thresholds, as well
as ongoing updates regarding any such risk. On an annual basis, the Board and the Adviser discuss the Company’s approach to overseeing
cybersecurity threats.
61
The Adviser has established an internal working group
that includes relevant representation from senior management including the CCO, CFO, and CISO, and CTO who work collaboratively to implement
a program designed to protect the Company’s information systems from cybersecurity threats and to promptly respond to any material
cybersecurity incidents in accordance with the Company’s incident response and recovery plans. Through ongoing communication with
these teams, the CISO, CTO and senior management are informed about and monitor the prevention, detection, mitigation and remediation
of cybersecurity threats and incidents in real time, and report such threats and incidents to the Board when appropriate.
The CTO and CISO have served in various roles in
information technology and information security for over 28 and 25 years respectively and hold relevant professional certifications. The
Adviser’s CCO and CFO, each hold undergraduate and graduate degrees in their respective fields, and each have over 15 and 28 years
of experience managing risk at the Company and at similar companies, including assessing cybersecurity threats.
Material Effects of Cybersecurity Incidents
Risks from cybersecurity threats, including
as a result of any previous cybersecurity incidents, have not materially affected and are not reasonably likely to materially affect the
Company, including its business strategy, results of operations, or financial condition.
ITEM 2. PROPERTIES
The headquarters of KA Credit Advisors, LLC is located at 717 Texas
Avenue, Suite 2200, Houston, TX 77002.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.