Unresolved Staff Comments
−Removed: Not applicable.
Cybersecurity
Risk Management and Strategy
−Removed: The Company recognizes the critical importance
−Removed: of developing, implementing, and maintaining robust cybersecurity measures to safeguard our information systems and protect the confidentiality,
−Removed: integrity , and availability of our data.
−Removed: We maintain cybersecurity insurance coverage that provides protection against potential
−Removed: losses arising from certain cybersecurity incidents.
−Removed: In addition, we have developed the following processes as part of our strategy for
−Removed: assessing, identifying, and managing material risks from cybersecurity threats.
−Removed: Managing Material Risks and Integrated Overall
−Removed: Risk Management
−Removed: We have integrated cybersecurity risk management
−Removed: into our risk management processes.
−Removed: This integration is intended to ensure that cybersecurity considerations are part of our decision-making
−Removed: We continuously evaluate and address cybersecurity risks in alignment with our business objectives and operational needs.
−Removed: We have adopted the standard 2FA (two factor authentication)
−Removed: for all our eData access (emails, online storage, etc.).
−Removed: In addition, all our applications and third-party applications have timed, authentication
−Removed: and environmental disposable cookie processes that force every user to reauthenticate their credentials.
−Removed: Our business transactional data
−Removed: includes dumb access controls that are vendor-specific, a set or specified range of costs, faceless entry point, and a unique 4FA (four
−Removed: factor authentication) process, protecting access to our banking and application systems.
−Removed: Moreover, our commitment to data security extends
−Removed: beyond industry standards through the implementation of advanced access controls.
−Removed: We have developed a sophisticated access control system,
−Removed: referred to as “dumb access controls,” which limits access to only specific vendors within a predefined range of costs.
−Removed: system operates through a faceless entry point with a unique 4FA process, ensuring that access to sensitive banking or application systems
−Removed: is strictly controlled and virtually nonexistent for unauthorized entities.
−Removed: These comprehensive security measures not only protect our
−Removed: business transactional data but also uphold the integrity and confidentiality of our systems and information assets.
−Removed: Engaging Risk Management Systems and Third-Party
−Removed: Recognizing the complexity and evolving nature
−Removed: of cybersecurity threats, we use risk management systems developed and tested by external experts, including cybersecurity assessors,
−Removed: consultants, and auditors.
−Removed: These risk management systems enable us to leverage specialized knowledge and insights as part of our cybersecurity
−Removed: strategies and processes.
−Removed: These systems are assessed and maintained with the assistance of third-party service providers, including a
−Removed: Technology Consultant engaged by the Company.
−Removed: Overseeing Third-Party Risk
−Removed: Because we are aware of the risks associated with
−Removed: third-party service providers, we implement processes to oversee and manage these risks.
−Removed: We conduct thorough security assessments of all
−Removed: third-party providers before engagement and maintain ongoing monitoring to ensure compliance with our cybersecurity standards.
−Removed: The monitoring
−Removed: includes regular assessments by our Chief Technology Officer.
−Removed: This approach is designed to mitigate risks related to data breaches or
−Removed: other security incidents originating from third parties.
−Removed: Risks from Cybersecurity Threats
−Removed: We have not encountered cybersecurity challenges
−Removed: that have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations,
−Removed: or financial condition.
−Removed: Board of Directors Oversight
−Removed: Our board of directors oversees the management
−Removed: of risks associated with cybersecurity threats.
−Removed: Management’s Role Managing Risk
−Removed: The Company’s Chief Technology Officer,
−Removed: Chief Operating Officer, and Technology Consultant are primarily responsible for assessing, monitoring and managing our cybersecurity
−Removed: Our Chief Technology Officer must ensure that all industry standard cybersecurity measures are functioning as required to prevent
−Removed: or detect cybersecurity threats and related risks.
−Removed: The Chief Technology Officer provides briefings on cybersecurity threats and related
−Removed: risks to our Chief Executive Officer on a regular basis.
−Removed: Our Chief Technology Officer has nine years of experience in the field of information
−Removed: The Chief Technology Officer oversees and tests our compliance with standards, remediates known risks, and leads our employee
−Removed: training program.
−Removed: The Company’s Chief Technology Officer and Technology Consultant have extensive experience in cybersecurity and
−Removed: possess the necessary knowledge, skills, background, and experience.
−Removed: Monitoring Cybersecurity Incidents
−Removed: The Company’s Chief Technology Officer and
−Removed: Technology Consultant are continually informed about the latest developments in cybersecurity, including potential threats and innovative
−Removed: risk management techniques.
−Removed: The Chief Technology Officer and Technical Consultant implement and oversee processes for the regular monitoring
−Removed: of our information systems.
−Removed: This includes the deployment of industry-standard security measures and regular system audits to identify
−Removed: potential vulnerabilities.
−Removed: In the event of a cybersecurity incident, the Chief Technology Officer and Technical Consultant will implement
−Removed: an incident response plan.
−Removed: This plan includes immediate actions to mitigate the impact and long-term strategies for remediation and prevention
−Removed: of future incidents.
−Removed: Reporting to Board of Directors
−Removed: Significant cybersecurity matters, and strategic
−Removed: risk management decisions, will be escalated to the board of directors.
+Added: We have implemented a comprehensive risk management framework, which includes policies and procedures designed for assessing, identifying, and managing material cybersecurity threats and facilitating timely disclosure of material cybersecurity incidents.
+Added: Our security approach is built on three core principles:
+Added: defense in depth (layered security), least privilege access, and a risk-based approach that prioritizes security resources based on risk assessment.
+Added: Our policies require mandatory annual cybersecurity awareness training for all employees, focusing on phishing and social engineering recognition and reporting, among other areas.
+Added: We evaluate potential security risks and conduct routine incident response tabletop exercises to practice responding to realistic cybersecurity incident and data breach scenarios.
+Added: We undertake annual reviews of our policies, which are designed to help ensure their effectiveness and relevance in light of evolving cybersecurity threats.
+Added: We have also implemented controls designed to identify and mitigate cybersecurity threats associated with our use of third-party service providers, including by reviewing evidence that their systems meet appropriate cybersecurity requirements for key service providers.
+Added: We collaborate with our service providers to understand developments within their cybersecurity framework and to seek to ensure service providers notify us promptly of
+Added: cybersecurity threats or incidents that may affect our systems or data.
+Added: Additionally, we maintain cyber insurance to help cover costs associated with cybersecurity events and to provide access to a panel of approved incident response partners, including forensics and incident response firms, law firms, breach notification providers, public relations firms, and distributed denial-of-service mitigation services.
+Added: We also engage third parties to assist in our cybersecurity mitigation and detection efforts, including a managed service provider ("MSP") that provides, among other things, cybersecurity monitoring and threat detection through a Security Information and Event Management system, security assessments and penetration testing, and Virtual Chief Information Security Officer services.
+Added: The MSP operates as an extension of our Corporate Strategy professionals, who, as discussed below, manage the Company’s information technology and cybersecurity risk management initiatives, and is bound by the same security and confidentiality obligations as the Company’s employees.
+Added: Our incident response and data breach procedures apply to all employees, contractors, and third-party users and are designed to provide a comprehensive, structured response to cybersecurity threats and incidents.
+Added: Upon receiving an incident report, Corporate Strategy and our MSP perform an initial assessment to determine severity level, whether escalation to executive leadership is needed, and whether cyber insurance notification and approved partner engagement is required.
+Added: For potentially significant cybersecurity incidents, we engage insurance-approved partners based on the nature and scope of the incident, and Corporate Strategy coordinates with our executive leadership to manage the incident response, investigation, notification, and remediation process.
+Added: In 2025, we have not identified any cybersecurity threats or incidents, including those resulting from any previous cybersecurity incidents, that have materially affected, or, to our knowledge, are reasonably likely to materially affect, us or our business strategy, results of operations or financial condition.
+Added: However, despite our efforts, we cannot eliminate all risks from cybersecurity threats or incidents, or provide assurances that we have not experienced an undetected cybersecurity incident.
+Added: For more information about these risks, please see “Risk Factors—Risks Related to Our Business—If we or our third-party service providers experience a security breach or cyberattack and unauthorized parties obtain access to our bitcoin holdings, or if our private keys are lost or destroyed, or other similar circumstances or events occur, we may lose some or all of our bitcoin and our financial condition and results of operations could be materially adversely affected.”
+Added: Our board of directors, in coordination with our Audit Committee, oversees our risk management process, including cybersecurity risks.
+Added: The Audit Committee receives regular reports from our executive leadership and our Vice President of Corporate Strategy on the threat landscape and the Company’s cybersecurity program.
+Added: Our Corporate Strategy department manages the Company's information technology operations and cybersecurity risk management and is responsible for receiving incident reports, performing initial assessments, coordinating approved partner engagement, leading investigations, overseeing remediation, and managing communications related to cybersecurity incidents.
+Added: The Vice President of Corporate Strategy , who is responsible for the establishment and maintenance of our cybersecurity program, as well as the assessment and management of cybersecurity risks, has significant experience in information technology and possesses the requisite education, skills, and experience expected of an individual assigned to these duties.
+Added: Our executive leadership, including our Chief Executive Officer, Chief Financial Officer, Chief Risk Officer, and Chief Legal Officer, provides oversight of our cybersecurity risk management program and receives regular updates from the Vice President of Corporate Strategy.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.