Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments.
None
Item 1C. Cybersecurity
Risk Management
We have implemented practices
to assess risks from cybersecurity threats; monitor our information systems for potential vulnerabilities; and test those systems pursuant
to our cybersecurity policies, processes, and practices, which are integrated into our overall risk management program. To protect our
information systems from cybersecurity threats, we rely on various security tools that are designed to help identify, escalate, investigate,
resolve, and recover from security incidents in a timely manner. We have chosen Microsoft Corporation as our main provider for Cybersecurity
and Governance services. Our technology management team assesses risks based on probability and potential impact to key business systems
and processes. Risks that are considered high are addressed promptly and documented to be incorporated into our overall risk management
program. A mitigation plan is developed for each identified high risk, with progress reported to the technology management team and tracked
as part of our overall risk management program overseen by Board and its Audit Committee.
24
To date, cybersecurity threats,
including those resulting from any previous cybersecurity incidents, have not materially affected our Company, including our business
strategy, results of operations, or financial condition. We do not believe that cybersecurity threats resulting from any previous cybersecurity
incidents of which we are aware are reasonably likely to materially affect our Company.
Governance
Our Board oversees our risk management process,
including as it pertains to cybersecurity risks, directly and through its committees. The Audit Committee of the board oversees our risk
management program, which focuses on the most significant risks we face in the short-, intermediate-, and long-term timeframe. The Audit
Committee reviews our cybersecurity risk profile with management on a periodic basis using key performance and/or risk indicators. These
key performance indicators are metrics and measurements designed to assess the effectiveness of our cybersecurity program in the prevention,
detection, mitigation, and remediation of cybersecurity incidents.
We take a risk-based approach
to cybersecurity and have implemented cybersecurity policies throughout our operations that are designed to address cybersecurity threats
and incidents.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.