UNRESOLVED STAFF COMMENTS
−Removed: We currently maintain our executive offices at
−Removed: 14 Wall Street, 20 th Floor, New York, NY 10005.
−Removed: The cost for the space is included in the up to $10,000 monthly fee that we
−Removed: pay our sponsor for office space, administrative and support services.
−Removed: We consider our current office space adequate for our current operations.
−Removed: Legal Proceedings
−Removed: To the knowledge of our management, there is no
−Removed: material litigation, arbitration or governmental proceeding currently pending against us or any members of our management team in their
−Removed: capacity as such.
−Removed: Mine Safety Disclosures
−Removed: Not applicable.
+Added: CYBERSECURITY
+Added: Risk management and strategy
+Added: We are in the process of implementing
+Added: various information security procedures designed to identify, assess and manage material risks from cybersecurity threats to our critical
+Added: computer networks, third party hosted services, communications systems, hardware and software, and our critical data, including intellectual
+Added: property, confidential information that is proprietary, strategic or competitive in nature.
+Added: Our Chief Information Officer,
+Added: Chief Executive Officer, Vice President of Human Resources and Vice President of Operations help identify, assess and manage the Company’s
+Added: cybersecurity threats and risks.
+Added: They will identify and assess risks from cybersecurity threats by monitoring and evaluating our threat
+Added: environment using various methods including, for example manual and automated tools, subscribing to reports and services that identify
+Added: cybersecurity threats, conducting scans of the threat environment, evaluating threats reported to us, internal and external audits, conducting
+Added: threat assessments for internal and external threats, third-party threat assessments and conducting vulnerability assessments to identify
+Added: vulnerabilities.
+Added: Depending on the environment,
+Added: we are in the process of implementing various technical, physical, and organizational measures, processes, standards and policies designed
+Added: to manage and mitigate material risks from cybersecurity threats to our Information Systems and Data, including, for example:
+Added: response plan, incident detection, vulnerability management policy, network security controls, access controls, physical controls, systems
+Added: monitoring, vendor risk management program, employee training, penetration testing, systems monitoring.
+Added: Our assessment and management
+Added: of material risks from cybersecurity threats will be integrated into the Company’s overall risk management processes.
+Added: our Information Security Management committee will evaluate material risks from cybersecurity threats against our overall business objectives
+Added: and reports to the audit committee of the board of directors, which evaluates our overall enterprise risk.
+Added: We use third-party service
+Added: providers to assist us from time to time to identify, assess, and manage material risks from cybersecurity threats, including for example
+Added: professional services firms, including legal counsel, cybersecurity consultants, cyber security software providers and penetration testing
+Added: We use third-party service
+Added: providers to perform a variety of functions throughout our business, such as application providers and hosting companies.
+Added: For a description of the risks
+Added: from cybersecurity threats that may materially affect the Company and how they may do so, see our risk factors under Part I.
+Added: Risk Factors in this Annual Report on Form 10-K, including “Any unauthorized access to or disclosure or theft of personal information
+Added: we gather, store or use could harm our reputation and subject us to claims or litigation.”
+Added: Our board of directors addresses
+Added: the Company’s cybersecurity risk management as part of its general oversight function.
+Added: The board of directors’ audit committee
+Added: is responsible for overseeing Company’s cybersecurity risk management processes, including oversight of mitigation of risks from
+Added: cybersecurity threats.
+Added: Our Vice President of Information
+Added: Technology is responsible for hiring appropriate personnel, helping to integrate cybersecurity risk considerations into the Company’s
+Added: overall risk management strategy, and communicating key priorities to relevant personnel.
+Added: The Chief Financial Officer is responsible
+Added: for approving budgets, helping prepare for cybersecurity incidents, approving cybersecurity processes, and reviewing security assessments
+Added: and other security-related reports.
+Added: Our cybersecurity incident
+Added: response Policy is being designed to escalate certain cybersecurity incidents to members of management depending on the circumstances.
+Added: The Company’s Chief Executive Officer and Chief Information officer work to help the Company mitigate and remediate cybersecurity
+Added: incidents of which they are notified.
+Added: In addition, the Company’s incident response Policy will include reporting to the audit committee
+Added: of the board of directors for certain cybersecurity incidents.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.