Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED STAFF COMMENTS
None.
ITEM 1C. CYBERSECURITY
Administration
The Board of Directors of
our company is responsible for overseeing cybersecurity-related risks. The Board shall: (i) monitor the disclosure of cybersecurity matters
in current or periodic reports; (ii) review quarterly updates on significant cybersecurity incidents or major threat risks submitted by
management, along with any resulting disclosure issues; and (iii) examine cybersecurity disclosures in the annual report (Form 10-K) filed
by management.
At the managerial level,
our cybersecurity team is responsible for monitoring and mitigating cybersecurity risks, including those associated with third-party service
providers. The team investigates and responds to any suspicious activities within our data environment. Upon identifying significant cybersecurity
threats or incidents, our cybersecurity team reports them to the head of the Information Technology and Cybersecurity Department, who
assumes responsibility for managing risks related to such major cybersecurity incidents and oversees preventive, mitigation, and remediation
measures. The head of our IT and Cybersecurity functions must report the status of significant cybersecurity threats, major cybersecurity
incidents, or other relevant risks to the Board of Directors and, when necessary, discuss disclosure matters with the Board regarding
critical cybersecurity threats or incidents. The head of IT and Cybersecurity functions possesses extensive experience in cybersecurity,
with specialized expertise in cybersecurity risk management and compliance.
In the event of a cybersecurity
incident, our cybersecurity team will immediately assemble personnel to conduct an internal assessment. If further analysis determines
that the incident may constitute a major cybersecurity breach, our cybersecurity team will promptly report the incident and evaluation
results to the heads of our IT and cybersecurity departments, and engage external legal counsel for consultation when appropriate. Prior
to public disclosure, our management team must prepare disclosure materials regarding the cybersecurity incident for review and approval
by the board of directors.
Risk Management and Strategies
We have implemented comprehensive
procedures to ensure effectiveness in cybersecurity management, policies, governance, and reporting of cybersecurity risks. Additionally,
we have integrated cybersecurity risk management into our overall enterprise risk management system.
We have established a comprehensive
cybersecurity threat defense system to address both internal and external threats. This system covers multiple layers including network
security, host security, and application security, integrating systematic capabilities such as threat defense, monitoring, analysis, response,
deception, and countermeasures. We are committed to managing cybersecurity risks and protecting sensitive information through various
approaches, including technical safeguards, procedural requirements, a robust program for monitoring our enterprise networks and applications,
continuous testing of internal and external security vendors across all aspects of security posture, a well-established incident response
program, and regular employee training. Our cybersecurity team conducts regular monitoring of application operations, platform status,
and infrastructure health to enable rapid response to potential issues, including emerging cybersecurity threats.
As of the reporting date
of this annual report, we have not experienced any major cybersecurity incidents, nor have we identified any significant cybersecurity
threats that have affected or could reasonably affect the Company, its business strategies, operational results, or financial condition.
20
Governance
Our cybersecurity risk assessment
and management processes are implemented and maintained by a third-party service provider reporting to the Company’s management. Management
is also responsible for integrating cybersecurity considerations into our overall risk management strategy, communicating key priorities
to employees, approving budgets, helping to prepare for cybersecurity incidents, approving cybersecurity processes, reviewing security
assessments and making required disclosures. Management participates in cybersecurity incident response efforts by being a member of the
incident response team and helping direct our response to cybersecurity incidents.
Our board of directors addresses
our cybersecurity risk management as part of its general oversight function. The Audit Committee of the board of directors is responsible
for overseeing our cybersecurity risk management processes, including oversight and mitigation of risks from cybersecurity threats.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.