Item 1B. Unresolved Staff Comments
ITEM 1B.
UNRESOLVED STAFF COMMENTS
None.
ITEM 1C. CYBERSECURITY
Cybersecurity Risk Management and Strategy
The Company relies on information systems and the data stored on
them to conduct its operations. We have adopted and maintain a cybersecurity risk management program in accordance with our risk profile
and business that is informed by and incorporates elements of industry standards.
Our cybersecurity risk management program incorporates multiple
components, including, but not limited to, ongoing monitoring of critical risks from cybersecurity threats using automated tools. Additionally,
we have implemented an employee education and training program, which we provide on an annual basis, that is designed to raise awareness
of cybersecurity threats. To support our cybersecurity risk management program, we leverage managed service providers and other third-party
information technology and cybersecurity providers and consultants, including to perform regular system scans and threat intelligence
analysis. Additionally, we require certain third-party providers and consultants to adhere to contractual requirements relating to privacy
and cybersecurity standards.
We have not identified any cybersecurity incidents or threats that
have materially affected us or are reasonably likely to materially affect us, including our business strategy, results of operations,
or financial condition. However, like other companies in our industry, we and our third-party vendors have from time to time experienced
threats and security incidents that could affect our information or systems. For more information, please see the section entitled “Risk
Factors” in this Annual Report on Form 10-K.
Governance
Our audit committee, which reports directly to the board of directors,
is responsible for overseeing our cybersecurity risk management program. The audit committee receives periodic updates on cybersecurity
risks, mitigation strategies, and, in the event of a cybersecurity incident, incident response strategies from our Chief Financial Officer
(“CFO”). The audit committee updates the full board of directors on matters relating to cybersecurity risk management and
critical cybersecurity risks as appropriate.
Our Chief Technology Officer (“CTO”), who reports directly
to our Vice President of Finance and, ultimately, our Chief Financial Officer, is responsible for the day-to-day management of our cybersecurity
risk management program. The individual currently serving in this position is a third-party consultant who maintains 20 years of experience
advising similarly situated companies on information technology and cybersecurity risk management. Our CTO provides regular cybersecurity
updates to our Vice President of Finance and Chief Financial Officer on matters relating to our cybersecurity program and cybersecurity
risk management.
55
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the is authoritative for anything you rely on.