Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments
None.
Item 1C. Cybersecurity
Risk Management and Strategy
We regularly assess risks from cybersecurity threats, including through periodic risk assessments aligned with recognized cybersecurity risk management frameworks, and monitor our information systems for potential vulnerabilities. These activities are integrated into our enterprise risk management program and are designed to identify, escalate, investigate, resolve, and recover from cybersecurity incidents in a timely manner. The Company’s Chief Information Officer is responsible for developing and implementing our information security program and reporting on cybersecurity matters to the Board. Our Chief Information Officer has over a decade of experience leading cybersecurity oversight, and others on our IT security team have cybersecurity experience and certifications. We view cybersecurity as a shared responsibility, and we periodically perform simulations and tabletop exercises at a management level and engage external resources and advisors as needed. All employees are required to complete regular cybersecurity training through online courses and simulated exercises.
We collaborate with third parties to assess the effectiveness of our cybersecurity prevention and response systems and processes. These include cybersecurity assessors, consultants, and other external cybersecurity experts to assist in the identification, verification, and validation of cybersecurity risks, as well as to support associated mitigation plans when necessary. We have developed a third -party cybersecurity risk management process that applies a risk-based approach to due diligence and oversight of external entities, including vendors and service providers with access to Company systems or sensitive data.
To date, risks from cybersecurity threats, including those resulting from any previous cybersecurity incidents, have not materially affected our Company, including our business strategy, results of operations, or financial condition. We do not believe that cybersecurity threats resulting from any previous cybersecurity incidents of which we are aware are reasonably likely to materially affect our Company. For more information about the cybersecurity risks we face, see the risk factor entitled “Our business and operations would suffer in the event of a significant computer system failure, cyber-attack or deficiency in our cyber-security” in Item 1A. Risk Factors.
Governance
The full Board receives updates periodically or as needed during the year from the Company’s Chief Information Officer and actively participates in discussions with management and amongst themselves regarding cybersecurity risks. Updates delivered to the full Board typically include discussion of management’s actions to identify and detect threats, as well as planned actions in the event of a response or recovery situation. These updates also typically include a review of any recent enhancements to the Company’s defenses and management’s progress on its cybersecurity, as well as reports on key performance indicators, test results and related remediation, and recent threats and how the Company is managing those threats.