Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments.
None.
60
Item 1C. Cybersecurity .
We have adopted processes designed to identify, assess and manage material risks from cybersecurity threats to our information systems. Those processes include response to and an assessment of internal and external threats to the security, confidentiality, integrity and availability of our data and systems along with other material risks to our operations, at least annually or whenever there are material changes to our systems or operations. These processes include plans to be used in the event of a cybersecurity incident, including incident reporting and business continuity. As part of our risk management process, we engage outside providers to conduct periodic internal and external penetration testing . We store our data in cloud environments with security appropriate to the data involved and have adopted controls around, among other things, vendor risk assessment, access and acceptable use and backup and recovery. Although we have experienced cybersecurity incidents in the past, cybersecurity threats, including as a result of previous cybersecurity incidents, have not materially affected the Company , including its business strategy, results of operations or financial condition.
Our executive team, along with our Audit Committee, assess and manage cybersecurity risk as part of our overall business strategy, financial planning and capital allocation. Our Audit Committee and Board of Directors engage with members of the executive team and are briefed on cybersecurity risks at least once each calendar year and with respect to any potentially material cybersecurity incidents. Our Chief Information Officer reports regularly, and at least annually, to our Audit Committee and such report may address overall assessment of our compliance with our cybersecurity policies, and include topics such as risk assessment, risk management and control decisions, service provider arrangements, test results, security incidents and responses, and recommendations for changes and updates to policies and procedures . Our Chief Information Officer has served in various senior information technology roles, responsible for information security for over 20 years.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.