Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments
None.
58
Item 1C. Cybersecurity
Risk Management and Strategy
We maintain a cybersecurity program designed to assess, identify, and manage risks from cybersecurity threats and to protect the confidentiality, integrity, and availability of our information systems and data. Our cybersecurity program is aligned with recognized cybersecurity frameworks, including the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF), and is integrated, where appropriate, into the Company’s broader enterprise risk management processes .
We have implemented administrative, technical, and physical safeguards designed to protect our information systems and data. These safeguards include ongoing monitoring of information technology systems, employee awareness training regarding phishing and other cyber risks, and processes intended to detect, prevent, and respond to potential cybersecurity incidents.
We engage external consultants and service providers, as appropriate, to assist in evaluating and enhancing our cybersecurity posture. Periodically, we conduct risk assessments, including third-party vulnerability assessments and penetration testing performed by reputable service providers. We also evaluate cybersecurity risks associated with certain third-party vendors that may have access to our systems or data. In addition, we maintain cybersecurity insurance coverage as part of our overall insurance portfolio.
To date, we have not identified any cybersecurity incidents that have had a material impact on our business strategy, results of operations, or financial condition. However, cybersecurity threats continue to evolve in sophistication, and there can be no assurance that our systems and processes will be successful in preventing or detecting cyberattacks or other breaches or that remediation efforts will be successful.
Governance Related to Cybersecurity Risks
The Audit Committee of the Board of Directors oversees management’s processes related to information technology and cybersecurity risks and reports significant cybersecurity matters to the full Board as appropriate.
Historically, the Company’s cybersecurity program was overseen by the Company’s Chief Information Security Officer (“CISO”) . The Company’s former CISO resigned in June 2025, and the Company is currently evaluating options regarding the role.
In the interim, certain cybersecurity monitoring and oversight activities are performed by the Company’s Senior Information Technology Systems Manager, who has over 15 years of experience in information technology and enterprise systems . The Senior Information Technology Systems Manager reviews aspects of the Company’s information security posture, cybersecurity controls, and monitoring activities and escalates matters to senior management as appropriate . The Company also utilizes external service providers to support certain cybersecurity monitoring and security management activities.
59