UNRESOLVED STAFF COMMENTS
−Removed: Corporate Office
−Removed: We maintain our corporate offices in Tampa, Florida where we lease approximately 6,000 square feet of office space.
−Removed: We currently do not own any buildings or land.
−Removed: We believe our current leased facility is sufficient for our foreseeable needs.
−Removed: Don Diego Phosphorite Project
−Removed: We have one material mining project, the Don Diego Phosphorite Project, which is located in the Mexican Exclusive Economic Zone (the "Mexican EEZ") offshore Baja California Sur, Mexico in the Pacific Ocean.
−Removed: The exclusive mining concessions for the Don Diego Phosphorite Project are held by Exploraciones Oceánicas S.
−Removed: de CV ("ExO"), a Mexican company in which we hold, through other subsidiaries, a 56.14% interest.
−Removed: The Primary concession (concession No.
−Removed: 244813) was granted in 2012, and rights for the two additional adjacent concessions (Norte concession No.
−Removed: 242994 and Sur concession No.
−Removed: 242995) were acquired in 2014.
−Removed: Exploration has confirmed the Don Diego West Phosphorite Deposit lies within the Primary and Norte concessions.
−Removed: The Don Diego Phosphorite Project currently has no reportable mineral reserves.
−Removed: Location and Brief Description
−Removed: The Don Diego Phosphorite Project concession area is a sedimentary marine phosphorite deposit located in the Mexican EEZ offshore Baja California Sur, Mexico in the Pacific Ocean.
−Removed: The property is located using a multi-point polygonal property
−Removed: demarcation bounded by latitudes 26.1°, 25.4°, and longitudes -112.2°, -112.9°
−Removed: The property is roughly 20 to 45 kilometers from shore.
−Removed: Following is a map denoting the three concessions in relation to Baja California Sur, Mexico.
−Removed: Infrastructure and Access
−Removed: There is no material infrastructure located on the property where the concessions are located.
−Removed: Access to the site is by sea-going vessels dispatched from various nearby ports of opportunity.
−Removed: Project engineering anticipates use of existing dredging technology
−Removed: to recover the phosphorite ore, including a trailing suction hopper dredger, and on-site mechanical beneficiation using a floating production and storage platform to produce phosphate rock concentrate, none of which introduces chemicals to the marine environment.
−Removed: Description of Concessions
−Removed: Total concessions encompass approximately 114,775 hectares of seafloor at a water depth of approximately 80 meters and consist of three concessions in total (see section Location and Brief Description above).
−Removed: The concessions were granted to ExO by the Mexican Secretary of Economy, General Coordination of Mining, and are valid for 50 years, with an option for a 50-year extension.
−Removed: The Primary concession was granted in 2012, and rights for the other two concessions (Norte and Sur) were acquired thereafter in 2014.
−Removed: To commence further operations on the Don Diego Phosphorite Project, ExO must obtain approval of its Environmental and Social Impact Assessment ("ESIA") from the Mexican Ministry of Environment and Natural Resources ("SEMARNAT").
−Removed: See ExO Phosphate Project in the above ITEM 1.
−Removed: BUSINESS for additional information.
−Removed: The property is subject to rents, fees and other payments to the Government of Mexico or its designated government ministry or agency.
−Removed: The anticipated annual obligations for each of the years in the three-year period ending December 31, 2025 are set forth in the table below.
−Removed: Primary Concession
−Removed: Annual Rent, MxN Pesos, owed semesterly
−Removed: The above is based on 203.57 MXN per hectare per semester, with an
−Removed: increase in this rate from inflation
−Removed: The above is based on 203.57 MXN per hectare per semester, with an
−Removed: increase in this rate from inflation
−Removed: Norte Concession
−Removed: Annual Rent, Mx Pesos, owed semesterly
−Removed: Will be based on 115.68 MXN per hectare per semester, with an
−Removed: increase in this rate from inflation
−Removed: Will be based on 115.68 MXN per hectare per semester, with an
−Removed: increase in this rate from inflation
−Removed: Sur Concession
−Removed: Annual Rent, Mx Pesos, owed semesterly
−Removed: Will be based on 115.68 MXN per hectare per semester, with an
−Removed: increase in this rate from inflation
−Removed: Will be based on 115.68 MXN per hectare per semester, with an
−Removed: increase in this rate from inflation
−Removed: Work Completed
−Removed: The Don Diego Phosphorite Project has sufficient data to confirm the geological continuity of the deposit and the estimation of measured, indicated and inferred resource tonnes.
−Removed: ExO, through exploration operations conducted by Odyssey, explored the area, characterized the environmental baseline to enable drafting of the ESIA, and acquired approximately 200 vibracore samples for assay.
−Removed: These cores were split into individual strata core units each of approximately 1 meter length.
−Removed: The cores were assayed at Florida Industrial and Phosphate Research Institute in Bartow, Florida under the guidance of Mr.
−Removed: Related Matters
−Removed: This annual report on Form 10-K does not include a resource estimate for the Don Diego Phosphorite Project because currently we do not have a technical report summary for the project that meets the requirements of Item 601(b)(96) of Regulation S-K.
+Added: CYBERSECURITY
+Added: Cybersecurity Risk Management and Strategy
+Added: We are dedicated to protecting the integrity, confidentiality, and availability of our data, infrastructure and operating systems.
+Added: As part of our commitment to safeguarding our operations against cybersecurity threats, we employ a comprehensive strategy for the assessment, identification, and management of cybersecurity risks.
+Added: We engage a third-party CIO consulting firm and a managed services provider, which work together to provide wide-ranging services including risk assessments, threat detection, monitoring and response strategies, security audits and cybersecurity services, tools and training.
+Added: Cybersecurity Processes:
+Added: We conduct robust cybersecurity processes aligned with NIST and CMMC protocols.
+Added: Our comprehensive approach includes:
+Added: An enterprise firewall;
+Added: Implementation of Multi-Factor Authentication (MFA);
+Added: Adherence to the Zero Trust model;
+Added: Utilization of Managed Detection and Response (MDR);
+Added: Endpoint Detection and Response (EDR) technologies;
+Added: 24x7 Security Operations Center (SOC);
+Added: Employment of Security Information and Event Management (SIEM) systems to continuously monitor our network and respond to threats in real time.
+Added: Risk Assessment Procedures:
+Added: We conduct periodic risk assessments to identify potential cybersecurity threats and vulnerabilities within our IT infrastructure.
+Added: These assessments are conducted using various software tools and methodologies that enable us to evaluate our systems critically and comprehensively.
+Added: Our risk assessment process includes the analysis of:
+Added: Hardware and software configurations;
+Added: Network and data access protocols;
+Added: Encryption standards;
+Added: Compliance with relevant industry and regulatory standards.
+Added: Threat Identification:
+Added: We utilize advanced threat detection tools and services that continuously monitor our network for signs of unauthorized access, anomalies, and potential breaches.
+Added: Our third-party cybersecurity provider is equipped with sophisticated detection technologies that help to swiftly identify even the most subtle signs of compromise.
+Added: Real-time monitoring of our networks;
+Added: Regularly updated intrusion detection systems (IDS);
+Added: Deployment of endpoint detection and response (EDR) solutions;
+Added: Utilization of threat intelligence platforms to stay abreast of emerging threats.
+Added: Threat Management:
+Added: Upon identification of a potential threat, our managed service provider’s dedicated incident response team takes immediate action to mitigate any adverse impacts.
+Added: Our threat management procedures include:
+Added: Immediate isolation of affected systems to prevent the spread of threats;
+Added: Application of appropriate remediation measures, such as patches and software updates;
+Added: Conducting a thorough investigation to understand the breach’s nature and scope;
+Added: Implementing enhancements to prevent future occurrences.
+Added: Our incident response plan provides a concise strategy of how we will respond to an incident, including who will respond and their roles and responsibilities, the facilities that are in place to help with the management of the incident, how decisions will be taken with regard to our response to an incident, how communication will be handled both internally and externally, and defining what will happen once the incident is resolved and how we can learn and improve from the situation.
+Added: Integration into Overall Risk Management:
+Added: Our cybersecurity risk assessment processes are fully integrated into the broader risk management framework.
+Added: Cybersecurity is positioned as a core component of our risk management strategy, with direct reporting to our President and COO, who is guided by our third-party CIO firm.
+Added: The CIO firm provides strategic direction on policy, procedures and best practice.
+Added: The synergy between cybersecurity and risk management ensures a resilient posture against emerging cyber threats.
+Added: Engagement of Third Parties:
+Added: These providers are selected based on stringent criteria for cybersecurity expertise, particularly their capability to implement and manage NIST and CMMC protocols.
+Added: Third-Party Service Provider Oversight:
+Added: Our oversight processes include comprehensive due diligence checks for any new third-party service provider and continuous monitoring of our existing managed service provider and CIO firms’ activities.
+Added: We have established protocols for communication and incident response that align with our managed service provider’s operations, and industry best practice, ensuring swift action in the face of cybersecurity threats.
+Added: Furthermore, a scheduled series of meetings has been established to procure updates and deliberate upon cybersecurity strategy with our contracted third-party providers.
+Added: Impact of Cybersecurity Risks
+Added: Material Effects from Cyber Threats:
+Added: To date, our operations and financial condition have not been materially affected by cybersecurity threats, due in part to our proactive measures such as employee security training programs and advanced threat detection and response capabilities.
+Added: Our defensive strategies have successfully mitigated the risks of cyber incidents.
+Added: Potential Risk Exposure:
+Added: While we have not experienced significant disruptions from cyber threats, we recognize the evolving nature of cyber risks.
+Added: We continually evaluate the likelihood of potential cybersecurity incidents that could materially impact our strategic direction, operational efficacy, and financial stability.
+Added: Our investment in training, alongside our sophisticated SOC, SIEM, and Zero Trust architecture, positions us to identify and address potential cybersecurity challenges promptly.
+Added: Cybersecurity Governance
+Added: Our executive team is actively involved in overseeing our cybersecurity operations to ensure that they meet industry standards.
+Added: The executive team provides regular updates to the board of directors – specifically the audit committee – on the status of our cybersecurity efforts, including any potential risks, threats or incidents.
+Added: The President and COO, with guidance from our third-party managed services provider and CIO consulting firm, manages our cybersecurity risk management and strategy process.
+Added: Collectively, our consultants have 50+ years’ experience in the cybersecurity industry in various roles.
+Added: Processes for Informing the Board:
+Added: The audit committee is regularly informed about cybersecurity risks through quarterly briefings from the President and COO.
+Added: These briefings include risk assessment reports, incident response updates, changes to the cybersecurity landscape, and other relevant information.
+Added: In the case of a cybersecurity incident that meets reporting thresholds, the audit committee will be promptly notified and will receive continual updates until the situation is remedied.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.