Item 1B. Unresolved Staff Comments
ITEM
1B. UNRESOLVED STAFF COMMENTS
None.
ITEM
1C. CYBERSECURITY
Cybersecurity
Risk Management and Strategy
We
rely on information systems and the data stored on them to conduct our operations. We
have adopted
and maintain a cybersecurity risk management program in accordance with our risk profile and business that is informed
by and incorporates elements of industry standards.
Our
cybersecurity risk management program incorporates multiple components, including, but not limited to, ongoing monitoring of critical
risks from cybersecurity threats using automated tools. Additionally, we have implemented an employee education and training program,
which we provide on an annual basis, that is designed to raise awareness of cybersecurity threats. To support our cybersecurity risk management
program, we leverage managed service providers and other third-party information technology and cybersecurity providers and consultants,
including to perform regular system scans and threat intelligence analysis. Additionally,
we require certain
third-party providers and consultants to adhere to contractual requirements relating to privacy and cybersecurity standards.
We
have not identified any cybersecurity incidents or threats that have materially affected us or are reasonably likely to materially affect
us, including our business strategy, results of operations, or financial condition. However, like other companies in our industry, from
time to time we and our third-party vendors have experienced threats and security incidents that could affect our information or systems .
For more information, please see the section entitled “Risk Factors - Risks Related to Our Intellectual Property and Information
Technology” in this Annual Report on Form 10-K.
Governance
Our
audit committee, which reports directly to the board of directors, is responsible for overseeing our cybersecurity risk management program. The
audit committee receives periodic updates on cybersecurity risks, mitigation strategies, and, in the event of a cybersecurity incident,
incident response strategies from our Chief Financial Officer. The audit committee updates the full board of directors on matters relating
to cybersecurity risk management and critical cybersecurity risks as appropriate.
Our
Chief Technology Officer (“CTO”), who reports directly to our Chief
Financial Officer , is responsible for the day-to-day management of our cybersecurity risk management program. The
individual currently serving in this position is a third-party consultant who maintains 20 years of experience advising similarly situated
companies on information technology and cybersecurity risk management. Our
CTO provides regular cybersecurity updates to our Chief
Financial Officer on matters relating to our cybersecurity program and cybersecurity risk management.
68
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the is authoritative for anything you rely on.