Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED STAFF COMMENTS
None.
ITEM 1C. CYBERSECURITY DISCLOSURE
Risk Management and Strategy
We acknowledge the significance of cybersecurity in protecting our operations, data, and shareholders’ interests, and have made cybersecurity a fundamental component of our overall risk management framework. Our cybersecurity program is based on the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework. This framework guides our efforts to protect critical assets, identify potential threats, respond to incidents, and strengthen resilience, while simultaneously allowing us to assess and enhance the maturity of our program. The cybersecurity program is an integral part of our Enterprise Risk Management (“ERM”) process and relies on internal and external expertise. We proactively evaluate and refine our security controls by utilizing best practices and threat intelligence to mitigate cyber risks. We also utilize third parties for some cybersecurity services, including managed security services, external penetration testing, and social engineering tests. Additionally, we maintain an incident response plan that aligns with industry standards to ensure timely detection, containment, and remediation of security incidents.
51
Cybersecurity Program Components
Our cybersecurity program is focused on exposure management, business resilience and governance through people, process and technology. Key components include incident prevention, detection, containment and response capabilities, employee training programs, threat intelligence monitoring, and the implementation of advanced technologies. Our risk management processes include regular assessments of internal and third-party risks, which are aligned with our ERM strategy. We enforce cybersecurity policies, standards, and governance practices, ensuring they align with regulatory requirements and industry best practices. Additionally, we conduct periodic business impact analyses to strengthen resilience and inform risk-based decision-making.
The cybersecurity program incorporates multiple layers of security controls to safeguard our systems and data. Access controls are established based on the principle of least privilege, and all employees engage in cybersecurity awareness training to cultivate a security-conscious culture. We train our employees through periodic security training, phishing simulations and regular communications about timely security topics to enhance their understanding of cybersecurity threats and their ability to identify and escalate potential cybersecurity events. We maintain robust security configuration management and regularly update systems to minimize vulnerabilities.
Our cybersecurity team continuously monitors network activity using advanced threat detection and exposure management. Through advanced analytics, automated alerts, behavioral analytics, threat intelligence and artificial intelligence, security anomalies are identified in a timely manner. Routine vulnerability scanning and independent penetration testing further enhance our ability to detect weaknesses before they can be exploited.
Recovery strategies are in place and supervised by a crisis management plan to restore critical operations following a cybersecurity event. We maintain secure, redundant backups and regularly test them for integrity and availability. Our recovery strategies prioritize minimizing downtime and rapid service restoration. We strive to incorporate lessons learned from past incidents, strengthening our resilience against future threats.
Third-party risk management is a core component of our IT risk framework. We evaluate new vendors to identify potential risks and to establish required security and notification obligations. We also monitor risks associated with existing providers. Our assessments include a standardized questionnaire and evaluations of financial, reputational, information security, cybersecurity and business resiliency risks.
Impact of Cybersecurity Risks and Threats
While some of our third-party service providers have experienced cybersecurity incidents and we have experienced threats to our data and systems, as of the date of this report, our management is not aware of any cybersecurity threats or incidents that have materially affected our business strategy, results of operations, or financial condition. While we remain vigilant, there can be no guarantee that we will not be the subject of future threats or incidents. Additional information on cybersecurity risks we face can be found in “Item 1A. Risk Factors—Risks Relating to Our Business and Operations—We are increasingly dependent on IT, and our business and reputation could suffer if we are unable to protect our IT systems against, or effectively respond to, cyberattacks, other cyber-incidents or security breaches or if our IT systems are otherwise disrupted,” which should be read in conjunction with the foregoing information.
Governance
Board of Directors and Audit Committee
Our Board of Directors has delegated oversight of the Company’s ERM program, including cybersecurity, to the Audit Committee. The Audit Committee receives updates regarding our enterprise-wide cybersecurity programs on a quarterly basis from our Senior Vice President, Information Technology (“SVPIT”) or Chief Information Security Officer (“CISO”). These updates may address data management and security initiatives, significant existing and emerging cybersecurity risks, and any material cybersecurity incidents and their impact on us and our stakeholders.
52
Management
Our management is responsible for identifying, assessing, and managing our exposure to cybersecurity risk. We have an internal team that is supported by cybersecurity technologies, third-party experts, and threat intelligence resources in support of cybersecurity risk reduction. Our SVPIT oversees the team responsible for leading the enterprise-wide IT strategy, policy, standards, architecture, and processes. This team includes our Cybersecurity Department and incorporates input from personnel from different functions, levels, and operating regions to support a high level of visibility and accountability throughout our company and to incorporate multiple vantage points on risks and potential mitigations. Our Cybersecurity Department is led by the CISO, who reports to the SVPIT and is responsible for overseeing the execution of cybersecurity strategy and maturing the Company’s cybersecurity posture. The Cybersecurity Department has extensive experience in cybersecurity, including graduate degrees in information security and Certified Information Security Systems Professional certifications. Our SVPIT has over 20 years of experience in the IT industry, and our CISO has over 30 years of experience in cybersecurity, providing a firm foundation from which IT and cybersecurity decisions and strategies can be made. We have established an Executive Cybersecurity Committee, comprised of interdisciplinary executive leadership, that meets quarterly and provides oversight for cyber protection, cybersecurity programs, exposure management, and risk tolerance. Cybersecurity considerations are incorporated into our disclosure controls and procedures, and our Disclosure Committee is notified of cybersecurity incidents that could require evaluation under SEC reporting standards, ensuring timely assessment of potential materiality.
53