Item 1B. Unresolved Staff Comments
Item
1B. Unresolved Staff Comments.
None.
Item
1C. Cybersecurity.
Risk
Management and Strategy
The
Company has implemented a written information security program designed to address the confidentiality, integrity, and availability of
information systems and the non-public personal information the Company holds on behalf of its clients and business partners. The program
is designed to comply with applicable requirements under Regulation S-P and the Federal Trade Commission Safeguards Rule.
32
Program
Components.
The
Company’s cybersecurity risk management program includes the following key elements:
●
Threat
Detection and Response: The Company uses a combination of automated tools and manual procedures to detect, contain, and respond
to cybersecurity threats, including malicious code detection, network monitoring, and security incident response protocols
●
Vulnerability
Management: The Company engages a third-party cybersecurity service provider it believes is qualified to conduct periodic vulnerability
assessments, penetration testing, and risk evaluations of the Company’s information systems.
●
Third-Party
Vendor Risk Management: Before engaging service providers that will access, transmit, or store Company or client data, management
performs due diligence to evaluate their cybersecurity practices. The Company seeks to engage vendors that maintain cybersecurity
programs reasonably consistent with the Company’s own standards.
●
Employee
Training and Awareness: All officers and employees are subject to the Company’s information security policies and procedures
and are required to participate in periodic cybersecurity education and awareness training.
●
Integration
with Enterprise Risk Management: The Company’s cybersecurity risk management program
is integrated into its broader enterprise risk management framework and utilizes the same
common reporting channels and governance processes and the broader framework.
● Third-Party
Assessments. The Company engages an external cybersecurity services provider to assist
in assessing and managing cybersecurity risks. This provider supports threat monitoring,
incident response planning, and periodic assessments of the effectiveness of the Company’s
security controls.
● Material
Cybersecurity Incidents. To date, the Company has not experienced any cybersecurity incident
that has materially affected, or is reasonably likely to materially affect, the Company’s
business strategy, results of operations, or financial condition. However, we cannot guarantee
that future incidents will not occur or will not be material. See Part I, Item 1A., “Risk
Factors––Risks Related to Legal Proceedings and Regulatory Compliance––An
interruption in, or breach of security of, our information systems could adversely affect
us.”
Governance
Board
Oversight
The
Board of Directors recognizes that cybersecurity is an important component of the Company’s overall risk management framework.
The Board has delegated primary oversight responsibility for cybersecurity risk to management, which periodically briefs the Board
on the status of the cybersecurity program, material developments, and the threat environment. Management reviews and
discusses with the Board the guidelines and policies with respect to risk assessment and risk management of cybersecurity and other
relevant risks related to the Company’s information systems. The Board receives updates from management on cybersecurity
matters as needed or when a significant incident or emerging risk warrants attention.
Management
Responsibility
Day-to-day
responsibility for the cybersecurity program is managed by Jeremy Robinson, the Company’s Vice President of Information Technology,
who oversees the design, implementation, and maintenance of the Company’s information security program , including:
●
Monitoring
the prevention, detection, mitigation, and remediation of cybersecurity threats and incidents;
●
Managing
relationships with third-party cybersecurity service providers; and
●
Reporting
material cybersecurity threats or incidents to the Chief Executive Officer and, where appropriate, to the Board.
The
Company believes that Mr. Robinson has developed relevant knowledge, skills, and experience in information technology and cybersecurity
risk management through his career in the information technology sector, including his experience overseeing third-party vendors, evaluating
security controls, and responding to information security risks. The Chief Executive Officer is responsible for ensuring that material
cybersecurity matters are escalated to the Board in a timely manner , although Mr. Robinson may also report material cybersecurity threats
or incidents to the Board.
33
Incident
Response
The
Company maintains cybersecurity incident response procedures that provide a framework for identifying, assessing, containing, and remediating
cybersecurity incidents, including procedures for timely reporting to the Board and, where required, to regulators and affected individuals