Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED STAFF COMMENTS
Not applicable.
ITEM 1C. CYBERSECURITY
NextPlat uses, stores, and processes data for and about our customers, employees, partners and suppliers. We have implemented a cybersecurity risk management program that is designed to identify, assess, and mitigate risks from cybersecurity threats to this data, our systems, and our business operations.
Cyber Risk Management and Strategy
Our cybersecurity risk management processes are integrated into our overall risk management processes. Our strategy consists of utilizing a combination of employee education, preventative controls, detective controls, and periodic third-party cybersecurity testing. We engage with external cybersecurity experts, including assessors, consultants, and auditors, to enhance our cybersecurity measures and ensure compliance with industry best practices. We have established processes to oversee and manage cybersecurity risks associated with our use of third-party service providers, ensuring they adhere to our security standards. We review third-party service provider contracts to ensure they contain data privacy and security provisions, aligning with our standards and regulatory requirements. We use the National Institute of Standards and Technology Cybersecurity Framework to guide our approach, ensuring a structured and comprehensive strategy for managing cybersecurity risks. As of the date of filing this Annual Report on Form 10-K, we are not aware of any cybersecurity threats or incidents that have materially affected or are reasonably likely to materially affect the Company, including our business strategy, results of operations, cash flows, or financial condition.
Risk Management Oversight and Governance
Our Chief Compliance Officer and the Chief Financial Officer lead the oversight of company-wide cybersecurity strategy, policy, standards and processes. We utilize third-party IT consultants to help manage cybersecurity risks. Our Chief Compliance Officer and Chief Financial Officer have the requisite experience in risk assessment and a strong understanding of business operations, including experience with security frameworks, compliance regulations, and the ability to communicate effectively with both technical and non-technical stakeholders. Our consultants have the requisite combination of technical experience in network security, system administration, and incident response.
Our Audit Committee liaises with our management team to communicate with and monitor management’s mitigation efforts to reduce cybersecurity risks by monitoring incident response, discussing and assisting with identifying potential cyber threats, analyzing vulnerabilities, and prioritizing risks.
29
Table of Contents
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the is authoritative for anything you rely on.