Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments.
None.
Item 1C. Cybersecurity.
Risk Management and Strategy
We have implemented a comprehensive cybersecurity risk management program designed to identify, assess, and mitigate material risks from cybersecurity threats to our technology stack, products, and confidential information. Integrated with our overall enterprise risk management system, this program employs a risk-based approach designed to protect the confidentiality, integrity, and availability of our information systems. Our Cybersecurity Incident Response Plan (“CSIRP”) defines roles and responsibilities for incident handling and functions as an integral component within our broader program, which combines proactive risk identification and mitigation with responsive threat management.
Cybersecurity is one of Kodiak’s six critical safety pillars. Management is committed to minimize defects regarding IT infrastructure and maintains an active culture of excellence designed to reduce risks that could harm individuals or the Company’s finances and reputation. Our strategy includes:
• Identification and Detection : Active monitoring of systems and networks to identify unauthorized access, misuse, or compromise of protected information, including personal data.
• Third-Party Risk Management : We engage external assessors and consultants to independently evaluate our information security program, conduct penetration testing, and assist in the identification of material risks. In
50
Table of Contents
addition, our Chief Legal and Policy Officer oversees the engagement of third-party forensics vendors to assist in investigations under attorney-client privilege when necessary.
• Incident Containment : Standard protocols include isolating affected systems, blocking malicious domains, applying security patches, and rotating private keys or application secrets.
Risks from Threats and Incidents
We are subject to risks from cybersecurity threats that could lead to unauthorized access to, disruptions of, and other cybersecurity incidents impacting our technology stack, including products, or the compromise of personal information, which includes data capable of being associated with natural persons. As of the date of this report, we are not aware of any security incidents that have materially affected our business strategy, results of operations, or financial condition. However, for a detailed discussion of these risks, please refer to Item 1A, “Risk Factors.”
Governance
Our Board , primarily through its Audit Committee, oversees the Company's cybersecurity risk management program as an integrated part of overall enterprise risk oversight. The Audit Committee is responsible for assisting the Board in overseeing the integrity of internal controls and major financial risk exposures.
Our cybersecurity management is led by our Chief Information Security Officer (“CISO”) , who brings over 25 years of industry experience leading information security teams at renowned technology companies. Management’s responsibilities include:
• Incident Response Team : A cross-functional team including representatives from security, IT, engineering, legal, and, external affairs is authorized to act quickly in the event of a security incident.
• Reporting and Communication : The incident response team provides progress updates to management at least hourly during system outages. Only the Chief Legal Officer is authorized to declare a security incident as a data breach under applicable law.
Our CISO provides briefings to the Audit Committee regarding our cybersecurity risk management program. Our Audit Committee updates our Board on such reports.