Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments.
None.
Item 1C. Cybersecurity.
Cybersecurity is a critical element of our information security program. Security controls are implemented in a manner that protects the confidentiality, integrity and availability of our information assets without hindering business operations. Management is responsible for the day-to-day administration of our cybersecurity policies, processes, and practices. Our cybersecurity policies, standards, processes, and practices are based on recognized frameworks established by the National Institute of Standards and Technology (the “NIST”) and management’s knowledge of best practices in the cybersecurity industry. In general, we seek to address material cybersecurity threats through a company-wide approach that addresses the confidentiality, integrity and availability of our information systems or the information that we collect and store, by proactively monitoring for cybersecurity threats and assessing, identifying and managing cybersecurity issues as they occur.
We routinely assess material risks from cybersecurity threats, including any potential unauthorized occurrence on or conducted through our information systems that may result in adverse effects on the confidentiality, integrity, or availability of our information systems or any information residing therein. Key elements of our cybersecurity risk management strategy include:
• We require an annual Service Organization Control 2 Type 1 report from all third-party providers attesting to the presence of security processes. Additionally, we require that SaaS/PaaS providers perform risk assessments and manage the security risks associated with their services.
• We have established and maintain a comprehensive incident response plan designed to address our response to a cybersecurity incident. We conduct regular training scenarios to test these plans and ensure personnel are familiar with their roles in a response scenario.
• We provide regular, mandatory training for employees regarding cybersecurity threats as a means to equip our employees with effective tools to address cybersecurity threats, and to communicate our evolving information security policies, standards, processes and practices.
• We use a third party to conduct a periodic assessment of our cybersecurity risk posture and maturity against the NIST Cybersecurity Framework. The results are evaluated by management and the Audit Committee and are used to adjust our cybersecurity policies, standards, processes and practices as necessary.
• The Company studies and evaluates threats in cyber landscape and aims to regularly improve our risk posture by learning from those lessons.
Our Audit Committee receives quarterly presentations and reports on developments in the cybersecurity space, including risk management practices, recent developments, vulnerability assessments, third-party and independent reviews, the threat environment, and information security issues encountered by other public companies. In addition to these oversight activities, the Audit Committee and the Board play a pivotal role in ensuring the Company’s cybersecurity strategy aligns with its overall risk management framework. They are responsible for reviewing and approving major cybersecurity policies, monitoring the effectiveness of the Company’s risk mitigation efforts, and staying informed about significant incidents or threats that may impact business operations. The Board also ensures that management has the resources and authority needed to implement cybersecurity initiatives and provides guidance on prioritizing investments in information security.
The Senior Director of IT acts as the Incident Manager and meets regularly with our Incident Response Team, including members of Financial Risk Management, IT Security, legal counsel, Internal Control and Human Resources senior management to discuss the necessary measures to take prior to and during an incident. Management’s responsibilities extend to the day-to-day administration of cybersecurity policies, processes, and practices. This includes proactively monitoring for threats, conducting vulnerability assessments, responding to incidents, and providing regular training to employees. In the event of an incident, the Incident Manager collaborates closely with executive leadership, keeping them informed of the incident’s status and coordinating response actions. Management is also tasked with continuously improving the Company’s cybersecurity posture by learning from past incidents and adapting policies and procedures accordingly. Furthermore, management ensures compliance with recognized frameworks such as the NIST Cybersecurity Framework and oversees the engagement of third-party providers for independent risk assessments. The Board and the Audit Committee receive prompt updates from management regarding any cybersecurity risks that meet reporting thresholds and are briefed on lessons learned after the recovery phase, reinforcing their role in strategic oversight and accountability.
The Senior Director of IT, in collaboration with a team of IT professionals, legal counsel, Internal Control, and Human Resources,
127
implements programs designed to protect information systems from cybersecurity threats and manage material risks. With over 20 years of experience, the Senior Director of IT is responsible for overseeing the prevention, detection, mitigation, and remediation of cybersecurity threats and incidents in real time. Senior management monitors these activities and reports significant threats and incidents to the Audit Committee. Management’s operational responsibilities are complemented by the Board’s strategic oversight, ensuring that the Company stays ahead of evolving cybersecurity risks and maintains a comprehensive risk management strategy.
Risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, have not materially affected and are not reasonably likely to materially affect our Company, including our business strategy, results of operations, or financial condition as of December 31, 2025 . For more information, please see the risk factor disclosures included in Item 1A of this Annual Report on Form 10-K. This ongoing assessment and communication between management and the Board ensures that cybersecurity risks are managed effectively and that both operational and strategic responses are aligned with the Company’s objectives.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.