Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments
Not applicable.
Item 1C. Cybersecurity
Cybersecurity Risk Management and Strategy
The Company’s cybersecurity program is designed to protect its assets and information, and to maintain the secure storage and of proprietary information relating to our customers, employees, applicants, vendors, and other parties, including financial information and personal information. The Company’s cybersecurity program is formed using a risk-based approach with recommendations from cybersecurity consultants, cybersecurity insurers, and other third-party consultants.
Our cybersecurity program includes, among others:
·
a cybersecurity education program with on-going employee activities, which include frequent phishing simulation and testing and annual training;
·
access management and access controls with periodic reviews;
·
when appropriate, use of external subject matter specialists, including assessors, insurers, and consultants, to provide incident response services and risk assessments;
·
engagement in security practices that include physical, administrative, and technical safeguards of systems and hardware;
The Company continues to invest in its cybersecurity program and performs assessments to identify opportunities to enhance training and awareness and improve processes and technology used to identify, prevent, detect, respond, and recover from cybersecurity incidents.
Governance
Our Board of Directors has overall responsibility for risk oversight and oversees the implementation and continuous improvement of our cybersecurity program and compliance with disclosure requirements. The Board of Directors receives regular reports and periodic briefings from the Chief Financial Officer on cybersecurity matters, including key risks to the Company, recent developments, and risk mitigation activities. Our cybersecurity program is overseen by the Chief Financial Officer in conjunction with a third-party service provider. The third-party service provider has the primary responsibility for the Company’s cybersecurity risk management program. At the time an incident is identified, the Company completes an evaluation and summarizes the incident that is shared with the Board of Directors to effectively manage resources to reduce risk and prevent future incidents.
10
Incident Disclosure
To date, the Company has been subject to cyber related incidents, as previously disclosed in the Company’s Quarterly Report for the quarters ended June 30, 2023 and September 30, 2023 and within this Annual Report. Since the identification of the incident, we have implemented additional safeguards designed to detect and prevent cybersecurity events that may have a material adverse effect on the Company.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.