Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments
Not applicable.
Item 1C. Cybersecurity
Cybersecurity Risk Management and Strategy
We recognize the importance of assessing, identifying and managing material risks to our business associated with cybersecurity threats, as such term is defined in Item 106(a) of Regulation S-K. To address these risks, we have engaged a qualified third-party information technology and cybersecurity services provider to manage and oversee our cybersecurity program. We believe that outsourcing these functions to a dedicated third-party provider allows us to access cybersecurity expertise and capabilities that are commensurate with the risks we face, notwithstanding our size and resources as a smaller reporting company.
Our third-party IT and cybersecurity provider is responsible for the day-to-day management of our cybersecurity risk program, which includes the following principal elements:
Risk identification and assessment. Our third-party provider conducts ongoing monitoring and periodic assessments of our information technology environment to identify cybersecurity vulnerabilities and threats, including risks arising from our use of cloud-based platforms, remote access systems, and third-party software applications. Assessments consider both internal risks and external threat intelligence relevant to our industry and operational profile.
Technical and procedural safeguards . Our third-party provider has implemented and maintains a combination of technical controls, including access controls, network monitoring, endpoint protection, data backup and recovery procedure, and procedural safeguards governing acceptable use, credential management, and data protection. Our provider periodically reviews and updates these controls as our technology environment and the broader threat landscape evolve.
Third-party and vendor risk. Our third-party IT provider assists us in evaluating the cybersecurity practices of vendors and service providers that have access to our systems or data prior to engagement. We seek appropriate representations from key service providers regarding their security practices; however, we may have limited ability to verify such representations or to compel remediation in the event a third-party provider experiences a security incident that affects our data or operations.
Incident response. Our third-party IT provider maintains incident response procedures designed to detect, contain and remediate cybersecurity events. These procedures include defined escalation protocols to ensure that any significant cybersecurity incident is promptly communicated to our senior management and, where appropriate, to the Audit Committee of our Board.
We have not experienced any cybersecurity incidents that have materially impaired our operations or financial condition. However, there can be no assurance that we will not be subject to such incidents in the future, including incidents affecting our third-party IT provider or other vendors. Our reliance on a third-party provider means that we are dependent on that provider's continued performance, financial stability and operational integrity. A failure by our third-party IT provider to adequately perform its responsibilities, or a cybersecurity incident affecting the provider itself, could expose us to risks that we may not be able to detect or remediate in a timely manner. Additional information regarding risks arising from cybersecurity threats is provided under the risk factor captioned "The risk of loss of the Company's intellectual property, trade secrets or other sensitive business information or disruption of operations could negatively impact on the Company's financial results" in Item 1A of this Annual Report.
19
Table of Contents
Governance; Board Oversight
The Audit Committee of our Board is responsible for oversight of cybersecurity risk as part of its broader risk oversight function. Management provides periodic updates to the Audit Committee regarding the state of our cybersecurity program, including material developments reported by our third-party IT provider, any significant threats or incidents, and any recommended changes to our cybersecurity posture. The Audit Committee reports to the full Board on cybersecurity matters as appropriate.
At the management level, our senior management team maintains primary responsibility for our relationship with our third-party IT and cybersecurity provider, including reviewing the scope of services provided, evaluating the provider's performance, and ensuring that cybersecurity matters are escalated appropriately within the organization. While we do not employ a dedicated Chief Information Security Officer , we rely on the expertise of our third-party provider to supply the specialized knowledge and experience necessary to manage our cybersecurity risks effectively. We periodically assess whether the scope and capabilities of our third-party provider remain appropriate given the evolution of our business and the threat environment, and we engage additional specialists on an as-needed basis to address specific risks or conduct targeted assessments.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.