Item 1B. Unresolved Staff Comments
Item 1B.
UNRESOLVED STAFF COMMENTS
Not applicable.
Item 1C.
CYBERSECURITY
Risk management and strategy
We have implemented and maintain various information security processes designed to identify, assess, and manage material risks from cybersecurity threats to our critical computer networks, third party hosted services, communications systems, hardware and software, and our critical data, including intellectual property, confidential information that is proprietary, strategic, or competitive in nature, customer data, and the personal information of our employees (collectively, “Information Systems and Data”).
Our IT Manager, along with the information security and technical consultants hired by us, help identify, assess, and manage our cybersecurity threats and risks. They work to identify and assess risks from cybersecurity threats by monitoring and evaluating the threat environment using various methods including manual and automated tools, subscribing to reports and services that identify cybersecurity threats, evaluating our and our industry’s risk profile, conducting periodic audits and threat assessments, conducting regular vulnerability assessments, and utilizing external threat intelligence.
Depending on the environment, system, and data, we implement and maintain certain technical and organizational measures, processes, standards and policies designed to manage and mitigate material risks from cybersecurity threats to our Information Systems and Data, including, detection and incident response procedures, vulnerability management process, disaster recovery/business continuity plans, encryption, network security controls, user access controls including multifactor authentication and role-based access, data segregation, asset management, continuous systems monitoring, vendor risk management program, employee training, penetration testing and cybersecurity insurance with coverage limits appropriate to our risk profile.
Our assessment and management of material risks from cybersecurity threats are integrated into our overall risk management processes. We prioritize cybersecurity risks based on their potential impact and likelihood, focusing our resources on mitigating threats that are more likely to lead to a material impact to our business results of operations, or financial condition.
We use third -party service providers to assist us from time to time to identify, assess, and manage material risks from cybersecurity threats, including, professional services firms, cybersecurity consultants, managed cybersecurity service providers, penetration testing firms, and forensics investigators as needed.
We also use third -party service providers to perform a variety of functions throughout our business, such as application providers, hosting companies, and various supply chain resources. We have a vendor management program to manage cybersecurity risks associated with our use of these providers which includes, depending on the vendor, nature of the services provided, and sensitivity of the Information Systems and Data at issue: risk based assessments designed to help identify cybersecurity risks associated with the vendor, security questionnaires, review of independent security assessments, and imposition of contractual obligations related to cybersecurity.
As of the date of this Annual Report, we have not experienced any cybersecurity threats or incidents that have materially affected or are reasonably likely to materially affect our business, results of operation or financial condition.
Governance
Our Board oversees the Company’s cybersecurity risk management as part of its overall risk oversight function. The Audit Committee is responsible for overseeing our cybersecurity risk management processes, including oversight of mitigation of risks from cybersecurity threats. The Audit Committee reports to the Board at least quarterly regarding its oversight of cybersecurity risk matters.
Our cybersecurity risk assessment and management processes are implemented and maintained by certain members of Company management, including our IT Manager, who has twenty-five years of experience in cybersecurity, networking and system engineering.
11
Table of Contents