Item 4. Controls and Procedures
ITEM 4. CONTROLS AND PROCEDURES
Disclosure Controls and Procedures. The effectiveness of the Partnership’s disclosure controls and procedures (as such term is defined in Rules 13a-15(e) and 15d-15(e) under the Securities Exchange Act of 1934, as amended (the “Exchange Act”)) have been evaluated as of the end of the period covered by this report. Based on that evaluation, under the supervision and with the participation of the Hamilton Company, Inc. (the “Management Company”), Management concluded that IT control and related procedures that support financial reporting were not effective as of September 30, 2022 due to the material weaknesses described below that prevented the recording, processing, summarizing and reporting, on a timely basis, information required to be disclosed by the Partnership in the reports that it files or submits under the Exchange Act.
Management Report on Internal Control over Financial Reporting. On October 3, 2022, the Management Company was the target of a ransomware attack. The Partnership did not incur any monetary damage nor any loss of financial data due to the incident. After becoming aware of the incident, the Management Company conducted an internal investigation into their digital environment and discovered that all on premise computer systems were encrypted by an outside party. The Partnership, along with the Management Company, worked with independent third-party cybersecurity specialists to help with the restoration of the environment and to return operations securely. Off-site data backups, which were verified to have not been compromised by the ransomware attack, were utilized to restore the data that had been encrypted. The Partnership, along with the Management Company, has successfully recovered the impacted files and rebuilt its computer systems. However, Management determined that the inordinate amount of time to recover this data and rebuild the financial reporting system prevented the Partnership from filing this Quarterly Report on a timely basis.
The Partnership is committed to remediating the material weaknesses in a timely manner. With the assistance of cybersecurity specialists, the Partnership and the Management Company have added additional security features designed to protect its systems and data from future attacks including multifactor authentication for domain sign-on, restricted server access, enhanced security awareness training, and updated multi-location secure backup with regular recovery testing. In addition to these steps already taken, remediation will also include the documentation and testing of the additional IT procedures implemented.
Limitations on Effectiveness of Controls. Our management is responsible for establishing and maintaining adequate internal control over financial reporting (as such term is defined in Rules 13a-15(f) and 15d-15(f) under the Exchange Act). Our internal control system is designed to provide reasonable assurance regarding the preparation and fair presentation of our financial statements for external purposes in accordance with GAAP. All internal control systems, no matter how well designed, have inherent limitations and can provide only reasonable assurance that the objectives of the internal control system are met.
Changes in Internal Control over Financial Reporting. Except for the above noted material weaknesses and the remediation activities that have already begun, there were no other changes in the Management Company’s internal control over financial reporting identified in connection with the evaluation required by paragraph (d) of Exchange Act Rule 13a-15 that occurred during the quarter ended September 30, 2022 that have materially affected or are reasonably likely to materially affect, the Management Company’s internal control over financial reporting.
42
Table of Contents
PART II — OTHER INFORMATION
Item 1. Legal Proceedings
There are no material legal proceedings, other than ordinary routine litigation incidental to its business, to which the Partnership is a party to or to which any of the Properties is subject.
Item 1A. Risk Factors
There have been no material changes to the Risk Factors in Item 1A, “Risk Factors” in our annual report on Form 10K for the year ended December 31, 2021.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.