Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED STAFF COMMENTS
None.
ITEM 1C. CYBERSECURITY
We manage risks from cybersecurity threats through our overall enterprise risk management process. Management has created an information security program, which encompasses a dedicated information security team and policies, procedures, and processes for assessing, identifying, and managing risks from cybersecurity threats. We “proactively” assess, identify, and manage risks from cybersecurity threats through various mechanisms, which from time to time may include internal audits, external audits, penetration tests, and engagement of third parties to conduct analyses of our information security program. Through our centralized enterprise risk management function, we also maintain processes for overseeing and identifying risks associated with third party service providers with whom we do business, including risks related to cybersecurity.
While to date we have not had a major cyber incident against our platforms, nor experienced significant data loss or any material financial losses related to cybersecurity attacks, it is possible that we could experience a significant event in the future. Risks and exposures related to cybersecurity attacks are expected to remain high for the foreseeable future due to the rapidly evolving nature and sophistication of these threats. See Item 1A. “Risk Factors.” – “Our business and operations could suffer in the event of cybersecurity breaches and we may incur significant legal and financial exposure.” for further discussion of potential risks related to cybersecurity incidents.
Our Senior Vice President of Technology and Innovation and Vice President of Network Infrastructure and Cyber Strategy oversee our cybersecurity program. They hold degrees in industrial engineering and computer science and information systems and decision science, respectively. The team responsible for administering our cybersecurity program has a combined 38 years of experience in cybersecurity, information security and information technology risk management, governance, risk, and compliance. Our board of directors and our audit committee are regularly updated on cyber security as part of their oversight of relevant cybersecurity risks. These reports address key cybersecurity topics, including the implementation and operation of preventative controls and the detection, mitigation and remediation of cybersecurity incidents.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.