Item 1B. Unresolved Staff Comments
Item
1B. Unresolved Staff Comments
None.
40
Item 1C. Cybersecurity
In recent years, cyberattacks, including denial-of-service attacks, ransomware attacks, business email compromises, computer malware, viruses, social engineering (including phishing) and other tactics designed to gain access to and exploit sensitive information by breaching mission critical systems of large organizations have increased in volume and sophistication. RET’s information technology systems and automated machinery, which it will rely on to operate its business, could be exposed to such tactics. RET may also experience unavailable systems, unauthorized access or disclosure due to employee theft or misuse, sophisticated nation-state and nation-state supported actors and advanced persistent threat intrusions. RET may be unable to implement adequate preventative measures or stop security breaches while they are occurring, and attackers may sabotage or obtain unauthorized access to RET’s systems, networks, or physical facilities. Actual or perceived breaches of RET’s security measures or the accidental loss, inadvertent disclosure or unapproved dissemination of proprietary information or sensitive or confidential data about RET, its partners, its clients or third parties could expose us and the parties affected to a risk of loss or misuse of this information, resulting in litigation and potential liability, paying damages, regulatory inquiries or actions, damage to the RET brand and reputation or other harm to the RET business. Additionally, cyberattacks that impact RET’s ability to operate its platform could result in production errors, processing inefficiencies and unscheduled downtime/degradation of operations, in turn causing the loss of sales and clients, and decreased revenue and increased overhead costs, which could have a material adverse effect on our results of operations.
Our board of directors has oversight of our strategic and business risk management and oversees management’s execution of our cybersecurity risk management program. Management is responsible for identifying, assessing, and managing cybersecurity risks on an ongoing basis, establishing processes to ensure that such potential cybersecurity risk exposures are monitored, putting in place appropriate mitigation measures, maintaining cybersecurity policies and procedures, and providing regular reports to our board of directors. In the event of an incident, we intend to follow our incident response plan, which outlines the steps to be followed from incident detection to mitigation, recovery and notification, including notifying functional areas (e.g. legal), as well as senior leadership and the board, as appropriate.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.