Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED STAFF COMMENTS
None.
ITEM 1C. CYBERSECURITY
Risk Management and Strategy
The Company has processes, policies and procedures for identifying, assessing, managing, and responding to cybersecurity threats and incidents. These are integrated into our overall risk management systems , as overseen by the Board, primarily through the Audit Committee. Our policies and procedures include protocols for assessing potential material impacts from cybersecurity threats, escalating to management and the Board of Directors, engaging external stakeholders, and reporting incidents based on applicable legal requirements.
We use specialized IT tools and services, including with the support of third-party service providers, to understand, manage, mitigate and continually remediate identified threats. The Company logs identified cybersecurity threats and tracks corresponding risk management activities. Identified cybersecurity threats are discussed with management for resolution planning and escalation.
Testing of our security controls in connection with the auditing of our financial systems is completed annually. At least annually, we conduct training and awareness for our employees to help identify, avoid and mitigate cybersecurity threats.
We regularly evaluate the cybersecurity threats associated with third-party suppliers and service providers that have access to the Company’s networks, confidential information, and information systems. We provide third-party vendors, consultants, and partners with detailed security requirements for securing their connections to our IT networks. In addition, we seek to make third-party service providers contractually responsible for identifying and remediating security issues within their technology and service environment.
Management has not identified risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect the Company, including its business strategy, results of operations or financial condition . While we have implemented a cybersecurity program, the techniques used to compromise IT systems continue to evolve. Accordingly, we may not be able to timely detect cybersecurity threats or anticipate and implement adequate security measures. For additional information regarding risks relating to privacy and cybersecurity, see “Item 1A – Risk Factors.”
Governance
The Board is responsible for overseeing the assessment and management of enterprise-level risks that may impact the Company. The Audit Committee has primary responsibility for overseeing risk management, including oversight of risks from cybersecurity threats. The Chief Executive Officer and Chief Financial Officer of the Company report on cybersecurity matters, including material threats, to the Audit Committee at regularly scheduled Audit Committee meetings, which are then discussed with the Board .
It is management’s responsibility to manage cybersecurity threats, as described above, and bring to the Board’s attention any material threats . Under the oversight of the Audit Committee, the Chief Executive Officer of the Company is primarily responsible for the assessment and management of cybersecurity threats and utilizes third-party consultants retained by the Company for advice.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.