Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED STAFF COMMENTS
We received Staff comments during the year ended December 31, 2022, many of which we have worked with the Staff to address in 2023, but which remain unresolved. In addition, we have received certain Staff comments during the year ended December 31, 2023 and the year ending December 31, 2024, some of which are related to certain restated items in this Annual Report.
• Revenue Recognition. The Staff commented on our revenue recognition policy in our capacity as a pool operator and in our capacity as a pool participant, with specific attention to our previous net recognition of revenue as an operator of a pool. We have restated our financial results in response to the comment, and revised our revenue to include gross revenue earned as pool operator with any amounts remitted to third party pool participants as cost of revenue. The Staff further commented on our accounting convention to recognize our noncash (bitcoin) revenue using fair value that is not at contract inception. We evaluated the difference between our current accounting policy and fair value at contract inception and determined that any differences in revenue are not material for all periods stated.
• Impairment of Bitcoin. The Staff objected to our calculation of impairment of bitcoin using a daily closing price. We have, in our restated financial results, revised our calculation to calculate impairment of bitcoin using the intraday low price of bitcoin.
34
Table of Contents
• Accounting for Investment Fund. The Staff commented on whether we should have consolidated the NYDIG Fund, an investment fund in which we were the sole limited partner and, if so, whether our accounting for the income and expenses of the investment fund were appropriately classified within our Statements of Comprehensive Income (Loss). We agreed to consolidate the NYDIG Fund and updated our classification of income and expenses of the investment fund within the Statements of Comprehensive Income (Loss) as part of our restated financial results.
• Statements of Comprehensive Income (Loss) Presentation. The Staff commented on the classification and inclusion of certain items in loss from operation versus in other income (expense). These items include realized gain (loss) on sales of digital assets, interest income, impairment on digital assets and patents, and gain on sale of equipment. We have revised our presentation prospectively and in the restated financial results.
• Embedded Leases in Hosting and Power Arrangements. The Staff requested we disclose a comprehensive analysis assessing whether each of our server hosting arrangements contains embedded leases. We provided such analysis in the Notes to our Consolidated Financial Statements.
• Investments. The Staff requested fulsome analysis of our accounting for various Simple Agreements on Future Equity and our investment in equity of certain investees. We have provided such analysis and have included impacts of any change in accounting for such investments in the restated financial results.
• Risk Factors. The Staff has requested further disclosure on material risks due to regulations, ability to obtain financing, reputational harm, and depreciation of digital assets prices. We considered such risks and updated our disclosures accordingly.
• Bitcoin as Collateral. The Staff has raised several comments regarding our accounting for bitcoin used as collateral within our lending arrangements. We continue to cooperate with and respond to the Staff’s comments based on our application of U.S. GAAP, and we have not changed our classification of such bitcoin used as collateral as digital assets, restricted.
ITEM 1C. CYBERSECURITY
Information Security Program
The mission of our information security organization is to design, implement, and maintain an information security program that protects our systems, services, and data against unauthorized access, disclosure, modification, damage, and loss. The information security organization is comprised of internal and external security and technology professionals. We continue to make investments in information security resources to mature, expand, and adapt our capabilities to address emerging cybersecurity risks and threats. The information security organization is overseen by the Information Security Advisory Team, further detailed under the caption “Cybersecurity Governance” below.
Cybersecurity Risk Management and Strategy
Cybersecurity risk management is one component of our information security program that guides continuous improvement to, and evaluates the confidentiality, integrity, and availability of our critical systems, data, and operations.
Our approach to controls and risk management is based on guidance from the National Institute of Standards and Technology (“NIST”) and the CryptoCurrency Security Standard (“CCSS”). This does not mean that we meet any particular technical standards, specifications, or requirements, but rather that we use the NIST and CCSS as a guide to help us identify, assess, and manage cybersecurity controls and risks relevant to our business.
Our cybersecurity risk management program includes:
• Identifying cybersecurity risks that could impact our facilities, third-party vendors/partners, operations, critical systems, information, and broader enterprise IT environment. Risks are informed by threat intelligence, current and historical adversarial activity, and industry specify threats;
• Performing a cybersecurity risk assessment to evaluate our readiness if the risks were to materialize; and
• Ensuring risk is addressed and tracking any necessary remediation through an action plan.
While we face a number of ongoing cybersecurity risks in connection with our business, such risks have not materially affected us to date, including our business strategy, results of operations, or financial condition.
35
Table of Contents
Cybersecurity Governance
Our Board considers cybersecurity risk as part of its risk oversight function and has delegated the oversight of cybersecurity and other information technology risks to the Board’s Audit Committee. As part of this oversight, we created the Information Security Advisory Team (the “Task Force”). The Task Force is comprised of senior managers and executives from multiple departments within the Company, including the IT, finance, legal and operations departments. The Task Force oversees our information security program and our strategy, including management’s implementation of cybersecurity risk management.
The Task Force meets at least quarterly to discuss matters involving cybersecurity risks.
The Task Force ultimately provides information to our Audit Committee regarding its activities, including those related to cybersecurity risks. The Audit Committee also receives a briefing and continuing education from a member of the Task Force relating to our cyber risk management program at least annually. The Task Force is responsible for notifying the Audit Committee of material cybersecurity incidents.