Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments
None.
Item 1C. Cybersecurity Risk Management, Strategy,
and Governance
In
the ordinary course of our business, we receive, process, use, store and share digitally large amounts of data, including user data as
well as confidential, sensitive, proprietary and personal information. We depend largely upon our information technology systems in the
conduct of all aspects of our operations. Maintaining the integrity and availability of our information technology systems and this information,
as well as appropriate limitations on access and confidentiality of such information, is important to our operations and business strategy.
To this end, we have implemented processes and systems designed to assess, identify, and manage risks from potential unauthorized occurrences
on or through our information technology systems to prevent adverse effects on the confidentiality, integrity, and availability of these
systems and the data residing in them.
In
2025, we did not identify any cybersecurity breaches that materially affected, or are reasonably likely to materially affect, our business
strategy, results of operations, or financial condition.
Management’s
Role
Our
management team is responsible for monitoring, preventing, detecting, mitigating and remediating cybersecurity incidents. Our Vice President
of IT and Systems brings over 13 years of expertise, with a proven track record in various leadership roles, including Director of Software
Delivery for the past two years. He has spearheaded the successful implementation and management of multiple website platforms, enterprise
resource planning (ERP) systems, retail store infrastructures, and cloud-based enterprise solutions. In his current role, he oversees
our cybersecurity team and outsourced managed services, while developing incident response plans and establishing clear communication
protocols with internal executives and external vendors. Our Network Systems Associate Director brings over 15 years of expertise in
enterprise IT, with a proven track record in various leadership roles, including 13 years in technical leadership roles. His distinguished
career includes leading the transition to a managed NOC/SOC, spearheading email security initiatives, architecting the migration to Okta
with multi-factor authentication (MFA) and automated user-access auditing, and designing robust showroom network infrastructure. He oversees
end-user technology and security operations, encompassing endpoints and Microsoft 365, identity policies, vulnerability management, incident
response, SOC and vendor collaboration, telecommunications, and SaaS platforms. He holds a B.S. in Information Technology from Utah Valley
University.
We
maintain a cybersecurity risk management program designed to identify, assess, manage, mitigate, and respond to cybersecurity threats.
Our cybersecurity risk management processes are being integrated into our overall risk management processes. We are making efforts to
incorporate cybersecurity considerations as a part of our business processes. We engage with external cybersecurity experts, including
assessors, consultants, and auditors, to enhance our cybersecurity measures and ensure compliance with industry best practices. For example,
a comprehensive cyber risk assessment, both physical and logical, was conducted by a third party, serving as an external penetration
test to validate our security posture. We have established processes to oversee and manage cybersecurity risks associated with our use
of third-party service providers, ensuring they adhere to our security standards. We review third-party service provider contracts to
ensure they contain data privacy and security provisions, aligning with our standards and regulatory requirements. Additionally, we have
established a Technology Review Committee (“TRC”) tasked with the role of evaluating new software tools and technologies
before their implementation. The TRC consists of experts from various domains within our organization, including information technology
security, compliance, legal, and operations. The TRC conducts assessments to ensure that any new software tools meet our standards for
security, compliance, and operational efficiency.
27
Board
of Directors Oversight
The
oversight of our cybersecurity is assigned to the Audit Committee of our Board of Directors. The Audit Committee receives regular reports
and briefings from management on our cybersecurity threat risk management and strategy processes, including on topics such as our data
security posture, results from third-party assessments, progress towards pre-determined risk-mitigation-related goals, incident response
plans, and cybersecurity threat risks or incidents and developments, as well as the steps management has taken to respond to these risks.
In addition, management updates the Audit Committee as necessary regarding any material cybersecurity incidents as well as any incidents
with lesser impact potential.