Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments
None.
Item 1C. Cybersecurity
Risk Management and Strategy
Our cybersecurity measure
is primarily focused on ensuring the security and protection of computer systems and networks. We primarily utilize an in-house IT service
provider, as well as external resources as a supplement, to monitor and, as appropriate, respond to cybersecurity risks. We maintain various
protections designed to safeguard against cyberattacks, including firewalls and virus detection software. We also periodically scan our
environment for any vulnerabilities and perform penetration testing. In addition, to promote security awareness, we provide cybersecurity
risk training to all employees at least annually.
Oversight responsibility for
information security matters is shared by our Board, our Chief Financial Officer (“CFO”), our management team and our internal
IT resources. Our CFO and management team oversee our cybersecurity risk management program, including risk mitigation strategies, systems,
processes, and controls, and receive quarterly updates from IT on cybersecurity and information security matters. The CFO communicates
with the Board periodically regarding the state of our cybersecurity risk management, current and evolving threats and recommendations
for changes. We have also implemented a cyber incident response plan that provides a protocol to report certain incidents to the CFO with
the goal of timely assessment of such incidents, determining applicable disclosure requirements and communicating with the Board for timely
and accurate reporting of any material cybersecurity incident.
We face risks from cybersecurity
threats that could have a material adverse effect on our business, results of operations, financial condition, cash flows or reputation.
We acknowledge that the risk of a cyber incident is prevalent in the current threat landscape and that a future cyber incident may occur
in the normal course business. However, prior cybersecurity incidents have not had a material adverse effect on our business, financial
condition, results of operations, or cash flows. We proactively seek to detect and investigate unauthorized attempts and attacks against
our IT assets, data, and services, and to prevent their occurrence and recurrence where practicable through changes or updates to internal
processes and tools and changes or updates to service delivery; however, potential vulnerabilities to known or unknown threats will remain.
Further, there is increasing regulation regarding responses to cybersecurity incidents, including reporting to regulators, investors,
and additional stakeholders, which could subject us to additional liability and reputational harm.
21
As of the date of this Annual
Report on Form 10-K, we are not aware of any material risks from cybersecurity threats, that have materially affected or are reasonably
likely to materially affect us, including our business, results of operations, financial condition, cash flows or reputation. See Item
1A. “Risk Factors” for more information on cybersecurity risks.