Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED STAFF COMMENTS
None.
9
Table of Contents
ITEM 1C. CYBERSECURITY
Risk Management and Strategy
The Company's policies and practices are based on frameworks and standards that address risks through a comprehensive, cross-functional approach that assess, identify, monitor, and mitigate material risks from cybersecurity threats as part of the overall enterprise risk management ("ERM") process. This includes the collection and storage of data and being responsive to incidents as they occur. Further, the Company's processes and technology are utilized to develop, implement, and maintain appropriate measures to safeguard information systems in protecting the integrity, availability, and confidentiality of data. Additionally, the Company engages certain third parties to assist in network monitoring and control testing, among other functions of similar capacity.
The Company's cybersecurity program focuses on the following areas:
•
Technological safeguards that are designed to protect the Company's information systems from cybersecurity threats, including the prevention and detection of system applications, access controls, and firewalls, which the Company assesses the vulnerability and severity of potential information security threats and makes necessary improvements.
•
Utilization of third parties as part of the Company's risk-based approach in identifying and overseeing cybersecurity risks.
•
The Company maintains an incident plan that addresses the Company's response to an cybersecurity event, which is periodically reviewed and updated.
The Company's on-going investment in information systems and utilization of external 3rd parties represents the best means for extensively testing both the design and operational effectiveness of cybersecurity controls, and to ensure continuity and functionality of the Company's operating systems.
As of the date of this report, the Company has not experienced any material cybersecurity events. However, the presence of new or more advanced forms of cybersecurity threats could have a material and adverse impact on the business, results of operations, and financial position. For further discussion relating to this topic, see Item 1A. Risk Factors "The Company's information technology systems may be negatively affected by cybersecurity threats."
Governance
The Audit Committee of the Board of Directors has the responsibility of overseeing the Company's cybersecurity risks. The Director of Information Technology provides periodic updates to the Board of Directors regarding actions taken to mitigate the Company's exposure and protection from cybersecurity risks. Management routinely evaluates the Company's security processes, procedures, and systems to determine if enhancements are needed to reduce the possibility of a future cybersecurity event. This includes safeguards implemented by the Company, such as a multi-factor authentication process; restricted firewall settings; security and network monitoring, security awareness training, email phishing tests, and enhancing the Company's backup recovery strategy, among others.
The Director of Information Technology is responsible for assessing, monitoring, and managing the Company's cybersecurity risks. The Director of Information Technology has extensive experience in leading the Company's information systems and has previously led information security teams for several large global organizations prior to joining the Company.
The Director of Information Technology, along with members of management, inform the Audit Committee on cybersecurity risks by providing periodic updates regarding (i) Status of ongoing cybersecurity initiatives and strategies, (ii) The overall state of the Company's security program and potential exposure to risks, and (iii) Incident reports and learning from any cybersecurity events. Further, the Director of Information Technology maintains an open dialogue regarding any significant developments in cybersecurity risks, ensuring the Audit Committee's oversight is proactive and responsive.
In addition to periodic updates to the Audit Committee, the Director of Information Technology, in his capacity, regularly informs the Chief Executive Officer ("CEO") and the Chief Financial Officer ("CFO") regarding matters related to cybersecurity risks and incidents. This ensures the highest level of management are informed of potential risks associated with cybersecurity that could have a material and adverse effect on the Company.
10
Table of Contents