Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED STAFF COMMENTS.
None.
ITEM 1C. CYBERSECURITY.
As part of our ordinary business operations, we collect and store information necessary for our operations, as well as data from our customers, employees, and business partners. We recognize that our networks and systems face evolving cybersecurity risks, which could materially impact our business if not effectively managed .
Cybersecurity is an integral part of our enterprise risk management program. Material cybersecurity risks are identified, assessed, and prioritized alongside financial, operational, and strategic risks. Findings from risk assessments, audits, and testing are incorporated into enterprise risk reporting, and remediation plans are aligned with our overall risk management approach. The Audit Committee of the Board oversees cybersecurity risk and receives regular updates from senior managment on material risks and mitigation efforts.
Senior management, including our Chief Technology Officer, Chief Financial Officer, General Counsel, and Senior Vice President of IT and Infrastructure , is responsible for managing material cybersecurity risks. These individuals have relevant experience overseeing technology systems, information security programs, risk management, regulatory compliance, and incident response, gained through their roles in technology leadership, financial oversight, legal and regulatory compliance, and IT infrastructure management. Our risk management process includes periodic assessments of cybersecurity risks that evaluate both the likelihood and potential impact of threats, as well as internal audits, testing, and independent third-party reviews. The company also conducts employee training and simulated phishing exercises to strengthen awareness and preparedness, and it maintains defined escalation procedures to ensure that cybersecurity incidents or significant findings are promptly reported to senior management and, when appropriate, to the Board or Audit Committee. These processes are reviewed and updated regularly to address emerging threats, regulatory changes, and evolving business operations.
Although we have not experienced any material cybersecurity incidents to date, future cyber-attacks could materially affect the Company, including loss of customer trust, employee departures, reputational harm, remediation costs, business disruption, or potential litigation or regulatory exposure. Compliance with evolving cybersecurity standards may also increase operational costs.
See the section titled Item 1A. Risk Factors, including “Our business is dependent upon the proper functioning of our internal business processes and information systems. The modification, change of, or interruption of such systems may disrupt our business, processes and internal controls,” for additional information about the risks from cybersecurity threats that may materially affect our business.
25
Table of Contents