UNRESOLVED STAFF COMMENTS
−Removed: Not applicable.
CYBERSECURITY
−Removed: We recognize the critical importance of developing,
−Removed: implementing, and maintaining cybersecurity measures to safeguard our information systems and protect the confidentiality, integrity,
−Removed: and availability of our data.
−Removed: We address cybersecurity risks by implementing security measures on our internal computer systems and ensuring
−Removed: that third parties and business partners implement similar measures.
−Removed: These security measures include firewalls, intrusion prevention and
−Removed: detection systems, antimalware functionality and access controls, which are evaluated by our external IT consultant and improved through
−Removed: vulnerability assessments and cybersecurity threat intelligence.
−Removed: Our senior director of operation is responsible
−Removed: for day-to-day assessment and management of risks from cybersecurity threats, including the prevention, mitigation, detection, and remediation
−Removed: of cybersecurity incidents.
−Removed: The Audit Committee is responsible for reviewing
−Removed: our policies with respect to cybersecurity risks and relevant contingent liabilities and risks that may be material to the Company, including
−Removed: risks from third parties and business partners.
−Removed: The Audit Committee receives quarterly updates from management with respect to risks from
−Removed: cybersecurity threats.
−Removed: Such updates cover the Company’s information technology security program, including its current status, capabilities,
−Removed: changes during the last quarter, objectives and plans, as well as the evolving cybersecurity threat landscape.
−Removed: To date, risks from cybersecurity threats have
−Removed: not materially affected us and we do not currently believe any risks from cybersecurity threats are reasonably likely to affect the Company,
−Removed: including our business strategy, results of operations or financial condition.
−Removed: For further information, see “ Risk Factors —
−Removed: Our business and operations would suffer in the event of computer system failures, cyber-attacks or deficiencies in our cyber-security.
+Added: recognize the critical importance of developing, implementing, and maintaining cybersecurity measures to safeguard our information systems
+Added: and protect the confidentiality, integrity, and availability of our data.
+Added: We address cybersecurity risks by implementing security measures
+Added: on our internal computer systems and ensuring that third parties and business partners implement similar measures.
+Added: These security measures
+Added: include firewalls, intrusion prevention and detection systems, antimalware functionality and access controls, which are evaluated by
+Added: our external IT consultant and improved through vulnerability assessments and cybersecurity threat intelligence.
+Added: vice president of operations is responsible for day-to-day assessment and management of risks from cybersecurity threats, including the
+Added: prevention, mitigation, detection, and remediation of cybersecurity incidents.
+Added: Audit Committee is responsible for reviewing our policies with respect to cybersecurity risks and relevant contingent liabilities and
+Added: risks that may be material to the Company, including risks from third parties and business partners.
+Added: The Audit Committee receives updates
+Added: from management with respect to risks from cybersecurity threats.
+Added: Such updates cover the Company’s information technology security
+Added: program, including its current status, capabilities, changes during the last quarter, objectives and plans, as well as the evolving cybersecurity
+Added: threat landscape.
+Added: date, risks from cybersecurity threats have not materially affected us and we do not currently believe any risks from cybersecurity threats
+Added: are reasonably likely to affect the Company, including our business strategy, results of operations or financial condition.
+Added: information, see “ Risk Factors — Our business and operations would suffer in the event of computer system failures, cyber-attacks
+Added: or deficiencies in our cyber-security.
” in Item 1A of this Annual Report.
We maintain a cyber liability insurance policy.
−Removed: However, our cyber liability insurance policy may not
−Removed: cover all claims made against us, and defending a suit, regardless of its merit, could be costly and divert management’s attention
−Removed: from our business and operations.
+Added: our cyber liability insurance policy may not cover all claims made against us, and defending a suit, regardless of its merit, could be
+Added: costly and divert management’s attention from our business and operations.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.