Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments
None.
Item 1C. Cybersecurity
Risk Management and Strategy
We have an information security
program designed to identify, protect, detect and respond to, and manage reasonably foreseeable cybersecurity risks and threats. To protect
our information systems from cybersecurity threats, we utilize various security tools that help prevent, identify, escalate, investigate,
resolve, and recover from identified vulnerabilities and security incidents in a reasonably timely manner. These include, but are not
limited to, internal reporting and tools for monitoring and detecting cybersecurity threats.
We evaluate the risks associated
with technology and cybersecurity threats and monitor our information systems for potential weaknesses. We review and test our information
technology system on an as-needed basis and also utilize internal team personnel to evaluate and assess the efficacy of our information
technology system and enhance our controls and procedures. The results of these assessments are reported to our Audit Committee and, from
time to time, our Board of Directors.
There
can be no assurances that our cybersecurity risk management program and processes, including our policies, controls, or procedures, will
be fully implemented, complied with or are effective in protecting our systems and information.
As of the date of this report,
we are not aware of any cybersecurity incidents, that have had a materially adverse effect on our operations, business, results of operations,
or financial condition.
33
Governance
Our Board of Directors considers
cybersecurity risk as part of its risk oversight function. It has delegated oversight of cybersecurity and other information technology
risks to the Audit Committee of the Board of Directors. The Audit Committee oversees the implementation of the cybersecurity risk management
program.
The Audit Committee receives
periodic reports from management on potential cybersecurity risks and threats. The Audit Committee reports to the full Board of Directors
regarding its activities, including those related to cybersecurity. The full Board of Directors also receives briefings from management
on the cybersecurity risk management program as needed.
Management is responsible for
assessing and managing our material risks from cybersecurity threats. Management has primary responsibility for our overall cybersecurity
risk management program and supervises both the internal cybersecurity personnel and external cybersecurity consultants.
The management team supervises
efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include briefings
from internal security personnel, threat intelligence and other information obtained from governmental, public or private sources, including
external consultants; and alerts and reports produced by security tools deployed in the IT environment. Our cybersecurity incident response
plan governs our assessment and response upon the occurrence of a material cybersecurity incident, including the process for informing
senior management and our Board of Directors.
Item 2. Properties
Our executive office is located at 580 N. Berry Street, Brea, California
and our telephone number is (714) 784-6369.
As of December 31, 2023, we had 14 company-owned retail
locations across California, all of which are leased.