Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments
None.
Item 1C. Cybersecurity
Cybersecurity Risk Management and Strategy
Cybersecurity risks are considered within our broader enterprise risk management framework as part of our overall risk assessment process. We maintain a comprehensive Information Security Program designed to identify, assess, manage, contain, and recover from material cybersecurity risks, including emerging threats, and to safeguard the Company, our assets, and customer and employee data. We regularly enhance our controls, monitoring capabilities, and governance practices to address evolving threats and changes in our business and technology environment, including the adoption of new technologies. We also assess cybersecurity risks that may arise from emerging technologies (including risks arising from AI and machine-learning technologies) and integrate those considerations into our risk management processes and control design. The Information Security Program addresses cybersecurity risks associated with third-party service providers through processes designed to assess and reduce the likelihood and impact of a cybersecurity incident involving a third-party. However, we rely on our third-party partners to implement information security programs commensurate with the risk associated with their relationships with us, and we cannot ensure in all circumstances that their efforts are successful. The Information Security Program aligns with the Center for Internet Security Controls, a cybersecurity framework acknowledged worldwide, and is designed to comply with applicable laws and guidelines.
We maintain a cybersecurity incident response and recovery plan that guides how we respond to incidents that may affect the function and security of the Company, our information technology assets, customer and employee data, information resources, and business operations. We maintain cyber and data security policies that address, among other matters, user access, incident response, third-party compliance , use of personal devices, and data privacy, and we review these policies annually. We also maintain insurance that covers certain costs that may be incurred in connection with cybersecurity incidents, should they occur.
Our Information Security Program is supported by regular employee education and awareness training. Training includes an annual assessment, focused on security, appropriate use, incident reporting, and social engineering, as well as multiple courses each year on global security trends and emerging risks. We also provide educational materials about emerging cybersecurity threats and communicate updates when our information security policies change.
We regularly evaluate our Information Security Program using software vendor assessments and reports, insurance underwriter evaluations, and internal and external audits, including customer audits, and refine our monitoring, detection, and response capabilities, including through the evaluation and adoption of emerging security technologies, while assessing the new risks these technologies may introduce. We also periodically engage third parties to review the effectiveness and maturity of our Information Security Program. To date, these engagements include third-party penetration testing, risk identification activities, and a fiscal year 2023 comprehensive evaluation of program maturity.
Management has determined that no cybersecurity incidents that we have experienced to date have resulted in, or are reasonably likely to result in, a material adverse effect on our financial condition, results of operations, or business strategy. For additional information on risks from cybersecurity threats and potential related impacts on the Company, please see Item 1A. “Risk Factors.”
Cybersecurity Governance
Board Oversight
The Board is ultimately responsible for oversight of our Information Security Program and delegates to the Audit Committee primary oversight responsibility for information security and technology (including cybersecurity) risk management. The Audit Committee periodically reviews the program and related information security, cybersecurity, and technology risks. As part of this oversight, the Audit Committee reviews management’s ongoing efforts to advance security governance and monitoring, including how the Company evaluates and manages risks and opportunities associated with emerging technologies. At least quarterly, the Audit Committee reviews and discusses with management and senior information security and technology leaders the Information Security Program, including its structure, operation, and enhancements made in response to third-party reviews or identified risks. The Audit Committee regularly briefs the Board on these discussions. In addition, our Incident Response Policy outlines procedures under which cybersecurity incidents or risks are escalated within the Company, and as applicable, are timely reported to the Audit Committee and the Board.
19
Management Oversight
Our Information Security Program is a comprehensive framework of policies, procedures, and guidelines designed to ensure the security, availability, and confidentiality of our systems. We regularly improve this framework and related governance to keep pace with evolving threats, changing business needs, and emerging technologies.
Our Chief Information Officer (CIO) and Corporate Director of Information Technology Security (CDIS) , in coordination with our Information Technology Department and other appropriate personnel, are responsible for assessing and managing our risks from cybersecurity threats. The CIO has over 25 years of experience in information technology and information security, served in this role for more than 10 years, and holds a B.S. degree in Computer Science. The CIO also holds industry certifications, including Microsoft Certified Professional (MCP) and Project Management Professional (PMP) certifications.
The program is led by our CDIS, who operates under the direction of the CIO. With over 30 years of experience in IT and cybersecurity, the CDIS heads our global Information Security team and the Security Steering team. This multidisciplinary team comprises experts from IT, Information Security, Legal, Audit, and Risk. The CDIS brings expertise across a diverse array of platforms, services, and technologies.
A third-party security operations center, which operates at all times, monitors logs, events, and alerts from our Endpoint Detection & Response platforms and cloud deployed services. This third party quarantines systems displaying suspicious behavior for automatic or approved remediation. Our Information Technology Department maintains oversight of this third party’s actions by monitoring alerts displayed on the threat management dashboard to identify and respond to irregularities that could be associated with threats. Significant threats are promptly reported to our Information Security Steering Team, which assesses the threat, consults external advisers as necessary, and initiates a plan to address it. The Information Security Steering Team advises the General Counsel and the Audit Committee of significant threats as well as third parties or authorities that are required to be notified under applicable law or contract.
20