Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED STAFF COMMENTS
Not applicable.
ITEM 1C. CYBERSECURITY
1. Board and Audit Committee Oversight
Our Board of Directors oversees our risk management process, including risks from cybersecurity threats. The Board administers its cybersecurity risk oversight function directly and through the Audit Committee. The Board and Audit Committee receive quarterly updates from management, including reports from our Global IT Director, regarding cybersecurity risks, mitigation efforts, and any significant incidents or vulnerabilities identified. These updates include assessments of the effectiveness of our cybersecurity controls and recommendations for improvements.
Our Chief Financial Officer and Information Technology department are primarily responsible for assessing and managing material risks from cybersecurity threats and overseeing key cybersecurity policies and processes. Our Global IT Director leads the day-to-day management of cybersecurity risk and has over 20 years of experience in the design, implementation, and support of information technology infrastructure and security systems. Management regularly evaluates cybersecurity risks and reports significant findings to senior management and the Board of Directors.
Network and information systems and other technologies play an important role in our business activities. We also obtain certain confidential, proprietary and personal information about our charterers, personnel, and vendors. To protect our data, we have employed cybersecurity protocols which are designed to work in tandem with internal controls to safeguard our information technology environment. Our information technology infrastructure is designed with commercial flexibility, data integrity, and safety in mind. We utilize a layered approach of systems and policies intended to provide a secure operating environment and promote business continuity. Our hardware and software systems are equipped with technology intended to offer access and intrusion protection, software and communications systems protections, and mitigate cybersecurity threats.
2. Incident Response and Materiality Assessment
We maintain a formal incident response plan that outlines procedures for detecting, containing, investigating, and remediating cybersecurity incidents. This plan includes escalation protocols to senior management and the Board , as appropriate. We assess the materiality of any cybersecurity incident based on its potential impact on our operations, financial condition, and reputation, in accordance with SEC guidance. To date, no cybersecurity incidents have had a material impact on the Company’s business, operations, or financial results.
61
3. Risk Management Processes
We utilize industry standard software packages such as RSA and Cisco Firepower to secure our networks. We also hold online cybersecurity training for our employees. Our cybersecurity risk management processes are integrated into our enterprise risk management framework and include regular risk assessments, vulnerability scans, and penetration testing. We prioritize risks based on their likelihood and potential impact, and implement mitigation strategies accordingly. Management reviews the results of these assessments and reports significant findings and remediation actions to the Board and Audit Committee.
4. Third-Party Risk Management
We evaluate cybersecurity risks associated with third-party service providers through initial and ongoing security assessments, contractual requirements for data protection, and continuous monitoring of their cybersecurity practices. Any significant risks or incidents involving third-party providers are promptly reported to management and, if material, to the Board and Audit Committee.
5. Reference to Risk Factors
For a more detailed discussion of risks related to cybersecurity threats, including potential impacts and mitigation strategies, please refer to Item 1A, ‘Risk Factors.