Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments
None.
Item 1C. Cybersecurity
Risk Management and Strategy
We have implemented a comprehensive risk management framework, which includes policies and procedures designed for assessing, identifying, and managing material cybersecurity threats and facilitating timely disclosure of material cybersecurity incidents. Our security approach is built on three core principles: defense in depth (layered security), least privilege access, and a risk-based approach that prioritizes security resources based on risk assessment.
Our policies require mandatory annual cybersecurity awareness training for all employees, focusing on phishing and social engineering recognition and reporting, among other areas. We evaluate potential security risks and conduct routine incident response tabletop exercises to practice responding to realistic cybersecurity incident and data breach scenarios. We undertake annual reviews of our policies, which are designed to help ensure their effectiveness and relevance in light of evolving cybersecurity threats. We have also implemented controls designed to identify and mitigate cybersecurity threats associated with our use of third-party service providers, including by reviewing evidence that their systems meet appropriate cybersecurity requirements for key service providers. We collaborate with our service providers to understand developments within their cybersecurity framework and to seek to ensure service providers notify us promptly of
46
cybersecurity threats or incidents that may affect our systems or data. Additionally, we maintain cyber insurance to help cover costs associated with cybersecurity events and to provide access to a panel of approved incident response partners, including forensics and incident response firms, law firms, breach notification providers, public relations firms, and distributed denial-of-service mitigation services.
We also engage third parties to assist in our cybersecurity mitigation and detection efforts, including a managed service provider ("MSP") that provides, among other things, cybersecurity monitoring and threat detection through a Security Information and Event Management system, security assessments and penetration testing, and Virtual Chief Information Security Officer services. The MSP operates as an extension of our Corporate Strategy professionals, who, as discussed below, manage the Company’s information technology and cybersecurity risk management initiatives, and is bound by the same security and confidentiality obligations as the Company’s employees.
Our incident response and data breach procedures apply to all employees, contractors, and third-party users and are designed to provide a comprehensive, structured response to cybersecurity threats and incidents. Upon receiving an incident report, Corporate Strategy and our MSP perform an initial assessment to determine severity level, whether escalation to executive leadership is needed, and whether cyber insurance notification and approved partner engagement is required. For potentially significant cybersecurity incidents, we engage insurance-approved partners based on the nature and scope of the incident, and Corporate Strategy coordinates with our executive leadership to manage the incident response, investigation, notification, and remediation process.
In 2025, we have not identified any cybersecurity threats or incidents, including those resulting from any previous cybersecurity incidents, that have materially affected, or, to our knowledge, are reasonably likely to materially affect, us or our business strategy, results of operations or financial condition. However, despite our efforts, we cannot eliminate all risks from cybersecurity threats or incidents, or provide assurances that we have not experienced an undetected cybersecurity incident. For more information about these risks, please see “Risk Factors—Risks Related to Our Business—If we or our third-party service providers experience a security breach or cyberattack and unauthorized parties obtain access to our bitcoin holdings, or if our private keys are lost or destroyed, or other similar circumstances or events occur, we may lose some or all of our bitcoin and our financial condition and results of operations could be materially adversely affected.”
Governance
Our board of directors, in coordination with our Audit Committee, oversees our risk management process, including cybersecurity risks. The Audit Committee receives regular reports from our executive leadership and our Vice President of Corporate Strategy on the threat landscape and the Company’s cybersecurity program.
Our Corporate Strategy department manages the Company's information technology operations and cybersecurity risk management and is responsible for receiving incident reports, performing initial assessments, coordinating approved partner engagement, leading investigations, overseeing remediation, and managing communications related to cybersecurity incidents. The Vice President of Corporate Strategy , who is responsible for the establishment and maintenance of our cybersecurity program, as well as the assessment and management of cybersecurity risks, has significant experience in information technology and possesses the requisite education, skills, and experience expected of an individual assigned to these duties. Our executive leadership, including our Chief Executive Officer, Chief Financial Officer, Chief Risk Officer, and Chief Legal Officer, provides oversight of our cybersecurity risk management program and receives regular updates from the Vice President of Corporate Strategy.