Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments
None.
SMCI | 2026 Form 10-K | 34
Table of Contents
Item 1C. Cybersecurity
Risk Management and Strategy
We have in place certain infrastructure, systems, policies, and procedures that are designed to proactively and reactively address risks from cybersecurity threats. This includes processes for assessing, identifying, and managing material risks from cybersecurity threats. Our information security management program seeks to follow processes set forth in recognized industry standards, and we evaluate and evolve our security measures as appropriate. The incident response plan is periodically tested through tabletop exercises, simulations, and management and operational reviews, and is updated based on lessons learned, threat intelligence, and changes in the Company's operating environment. The identification, assessment and management of cybersecurity risk is integrated into our overall enterprise risk management program that is ultimately overseen by the Board.
We consult with external parties, such as third-party cybersecurity firms, to provide, among other things, monitoring of systems, threat intelligence, and employee cybersecurity training. We also use third parties to assist our risk management processes by conducting security assessments. Third-party risk assessments are prioritized based on the nature of services provided, access to systems or data, criticality to operations, and applicable regulatory obligations.
We also have a vendor risk assessment process to oversee and identify risks from cybersecurity threats associated with our use of third-party service providers. These processes consist of the distribution and review of questionnaires designed to identify cybersecurity risks associated with the engagement of third parties. We also audit cybersecurity practices of certain third-party service providers, and take steps designed to ensure that such vendors have implemented data privacy and security controls that help mitigate the cybersecurity risks associated with these vendors, depending on the nature and sensitivity of the supplier and data it processes on our behalf. We routinely assess our high-risk suppliers’ conformance to industry standards (e.g., ISO 27001, ISO 28001, and C-TPAT), and evaluate them for additional information, product, and physical security requirements.
Additional cybersecurity measures include security monitoring, vulnerability and patch management processes, identity and access controls, network security controls, data protection technologies, threat intelligence activities, and incident detection and response capabilities.
As of the date of this filing, we have not identified any cybersecurity threats, including as a result of prior incidents, that have materially affected or are reasonably likely to materially affect the Company, including our business strategy, results of operations, or financial conditions. Refer to “Risk Factors” in Item 1A of this Form 10-K for additional information about cybersecurity-related risks.
Governance
As part of its broader risk oversight activities, our Board maintains oversight of cybersecurity matters, including managing and assessing risks from cybersecurity threats. The Audit Committee also reviews the adequacy and effectiveness of our information security policies and practices and the internal controls regarding information security risks. The Audit Committee receives periodic updates regarding cybersecurity risks, threat trends, significant incidents, third-party risks, remediation activities, and the status of key cybersecurity initiatives.
Our cybersecurity efforts are managed by a team of executive cybersecurity, IT, engineering, and operations professionals, including senior information security and IT leadership (comprised of the Senior Director of Information Security and Senior Director of IT Security) who possess extensive experience in cybersecurity, incident response, risk management, and security operations.
These individuals have decades of experience in managing cybersecurity risk for public companies. Additionally, we have established a cross-functional Cybersecurity Committee, consisting of executive-level leadership, including representatives from Finance, IT, Legal, and other teams, that meets regularly to review cybersecurity risks, incidents, and assess emerging threats. The Cybersecurity Committee is also informed of our responses to such risks, incidents and threats.
The Company continuously evaluates emerging cybersecurity risks, including risks associated with artificial intelligence technologies, enhanced social engineering techniques, and evolving threat actor capabilities.
SMCI | 2026 Form 10-K | 35
Table of Contents
Our cybersecurity incident response plan also contains mechanisms to notify executive management of cybersecurity incidents. As part of the plan, an executive-level leadership team may be activated and can act to direct our response efforts, to include mitigation and remediation activities, when appropriate.