Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED STAFF COMMENTS.
Not applicable.
ITEM 1C. Cybersecurity
We are committed to protecting our information systems against cybersecurity threats. Any cybersecurity incident can adversely affect our business and disrupt our operations as described in greater detail in our Risk Factors relevant to cybersecurity risks. Our senior leadership, in consultation with our board of directors, has assigned responsibilities for ensuring and overseeing the operation of our information security program to the Marchex Information Security Committee (“ISC”) comprised of senior representatives of departments across our organization.
Effective risk management is a critical component of our operations. The ISC conducts a formal cybersecurity risk assessment annually. The assessment methodology is designed to identify cybersecurity threats to our information systems and considers a range of relevant risk factors that include both intentional and unintentional human acts by our or our vendors’ personnel, or malicious third-party actors, risks inherent to technology/equipment we and our service providers use, as well as natural and environmental risks. The ISC discusses and documents mitigation strategies based on the risks identified. Results of assessments are reported to senior leadership and our board of directors. To the extent that any control deficiencies or material changes in the threat environment are identified, the ISC may make recommendations for new or improved controls and threat mitigation strategies.
The ISC also oversees day-to-day cybersecurity risk mitigation efforts, which include, but are not limited to monitoring systems for availability, performance, and security issues, periodic vulnerability scans, penetration testing performed at least annually by independent , reputable, third-party vendors, as well as evaluating any risks associated with prospective third-party service providers who require access to sensitive customer data and implementing any additional controls to address significant risks identified. Furthermore, the ISC meets quarterly to discuss and analyze any relevant developments within the organization and industry relative to cybersecurity, reviews our internal policies and operational procedures relevant to cybersecurity at least annually, and promulgates updates when deemed necessary or advisable.
23
Table of Contents
ITEM 2. PROPERTIES.
Our headquarters are located in Seattle, Washington and consist of approximately 12,000 square feet of leased office space. We lease additional office space in Wichita, Kansas. See Item 1 of this Annual Report on Form 10-K under the caption “Information Technology and Systems.”
We believe that our existing facilities are adequate for our near-term business needs.
ITEM 3. LEGAL PROCEEDINGS.
See Note 10: Commitments, Contingencies, and Taxes of the Notes to Consolidated Financial Statements contained in this Annual Report on Form 10-K.
ITEM 4. MINE SAFETY DISCLOSURES.
Not applicable.
24
Table of Contents
PART II
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.