Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments
None.
Item 1C. Cybersecurity
Risk Management and Strategy
Our information security and risk management program is designed to identify, assess, and manage material risks from cybersecurity threats to our applications, computer networks, third-party hosted services, communications systems, hardware and software, and our critical data, including intellectual property, confidential information that is proprietary, strategic or competitive in nature, personal information, or PHI (collectively, “Information Systems”).
Our information security program’s basis is a comprehensive set of policies and procedures covering various information security domains (collectively, “Information Security Policy”), including, but not limited to:
• Access control,
• Endpoint protection,
• Third-party oversight,
• Education, training, and awareness,
• Network security,
• Risk management,
• Incident response,
• Business continuity and disaster recovery,
• Data protection and privacy, and
• Other security domains.
Our risk management process is based on a standard methodology, and risks are identified based on:
• Annual risk assessments,
• Information on past incidents,
28
Table of Contents
• Internal audits,
• Security penetration tests, and
• Other security assessments.
All risks are documented in a central Risk Register and tracked for mitigation and other treatment decisions.
Our information security program is audited annually against a well-known security framework, by an accredited third-party via the SOC 2 assessment, which covers the trust services criteria of security, confidentiality, privacy, and accessibility.
Our external audits and assessments identify and evaluate material risks from cybersecurity threats against our overall business objectives on a periodic basis and form the basis of internal reports, which are shared with the management team, the Audit Committee of the Board (“Audit Committee”), and the Board to evaluate our overall enterprise risk.
Our incident response program consists of an Incident Response Plan document and a cross-functional Incident Response Team, which are defined in our Information Security Policies. All workforce members are trained on incident reporting procedures, and there is a single point of contact for reporting all incidents. Incident response training is conducted annually, followed by a tabletop exercise. Our Incident Response Plan instructs personnel on how to notify our Incident Response Team in case of an incident. Our Vice President (“VP”) of Information Security is the point person for incident responses and coordinates mitigation and remediation of cybersecurity incidents. We log all incidents and response plans for purposes of internal documentation. We report critical incidents to the management team, the Audit Committee, and the Board.
Our VP of Information Security is responsible for implementing the Information Security Policy on a day-to-day basis along with the Security Committee (as defined in the Information Security Policy), which includes the heads of the following departments, at a minimum: Information Security, Technology, Compliance, Product Management, Internal Audit, and Legal.
We use third-party service providers to perform a variety of functions throughout our business, including, but not limited to infrastructure support and maintenance, customer relationship management, contract management, product development, data hosting, and miscellaneous finance and accounting projects. We assess our vendors with respect to cybersecurity risk according to the services provided, the sensitivity of the Information Systems at issue, and the provider’s identity. In appropriate cases, we will seek enhanced contractual obligations or guarantees related to cybersecurity on the service provider. Vendor risk assessments are performed before each vendor is engaged, and annual reviews are conducted to ensure vendors continue to meet security requirements.
We also maintain technical errors and omissions insurance which includes a cyber incident endorsement of up to $20 million. This endorsement provides coverage for Network Security and Privacy, Privacy Regulation Proceeding, Privacy Event Expense Reimbursement, Extortion Demand Reimbursement, Data Restoration, Network Restoration, Business Interruption and System Failure. This coverage reimburses the most common costs for information security incidents, including attorney’s fees, consumer notification costs, and regulatory fines.
To our knowledge, during 2025, there were no material cybersecurity incidents or threats that materially affected or are reasonably likely to materially affect the Company’s business strategy, results of operations, or financial condition.
For more information on risks from cybersecurity threats that may materially affect the Company, see Item 1A. “Risk Factors”.
Governance
The Board’s oversight function includes cybersecurity risk management. The Board has three members with skills and experience in information security and cybersecurity through their experience as current and former executives of digital technology companies.
29
Table of Contents
The Board has tasked the Audit Committee with overseeing the Company’s cybersecurity risk management processes and determining which threats are likely to impact the Company’s strategy, business operations, and financial condition.
Pursuant to its charter, the Audit Committee reviews the Company’s policies regarding information technology security and protection from cyber risks. In particular, the Audit Committee reviews with management the Company’s key IT Systems and evaluates the adequacy of the Company’s information security program, compliance, and controls.
Our cybersecurity risk assessment and management processes are implemented and maintained by our VP of Information Security, our Senior VP of Internal Controls, and the Security Committee. For strategic decisions regarding cybersecurity, our VP of Information Security consults with our Chief Technology Officer, our Chief Financial Officer, our Chief Legal Officer, and our VP of Compliance.
Our VP of Information Security is responsible for hiring appropriate personnel, performing vendor risk assessments, and communicating information security priorities to relevant personnel, so that we can build cybersecurity risk considerations into our business practices. Our VP of Information Security also plans related budgets, designs cybersecurity processes, and reviews security assessments and related reports.