Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments.
None.
Item 1C. Cybersecurity.
We maintain a cyber risk management protocol designed
to identify, assess, manage, mitigate, and respond to cybersecurity threats.
The underlying processes and controls of our cyber
risk management protocol incorporate recognized best practices and standards for cybersecurity and information technology, including the
National Institute of Standards and Technology (“NIST”) Cybersecurity Framework (“CSF”). We have undertaken an
assessment of our networking risk management processes and controls to identify, quantify, and categorize material risks. In addition,
we have developed a risk mitigation plan to address such risks, and where necessary, remediate potential vulnerabilities identified through
the annual assessment process.
In addition, we maintain policies over areas such
as information security, access on/offboarding, and access and account management, to help govern the processes put in place by management
designed to protect our IT assets, data, and services from threats and vulnerabilities. We consult with a third-party specialist with
regard to our cyber risk management processes and controls.
52
Our management team is responsible for oversight and
administration of our cyber risk management protocol, and for informing senior management and other relevant stakeholders regarding the
prevention, detection, mitigation, and remediation of cybersecurity incidents. Our Audit Committee also provides oversight of risks from
cybersecurity threats.
As part of its review of the adequacy of our system
of internal controls over financial reporting and disclosure controls and procedures, the Audit Committee is specifically responsible
for reviewing the adequacy of our computerized information system controls and security related thereof. The cybersecurity stakeholders,
including member(s) of management assigned with cybersecurity oversight responsibility and/or third-party consultants providing cyber
risk services, brief the Audit Committee on cyber vulnerabilities identified through the risk management process, the effectiveness of
our cyber risk management program, and the emerging threat landscape and new cyber risks on at least an annual basis. In addition, cybersecurity
risks are reviewed by our Board of Directors at least annually, as part of the Company’s corporate risk oversight processes.
We face risks from cybersecurity threats that could
have a material adverse effect on our business, financial condition, results of operations, cash flows or reputation. We acknowledge that
the risk of cyber incidents is prevalent in the current threat landscape and that a future cyber incident may occur in the normal course
of its business. To date, we have not had a cybersecurity incident. We proactively seek to detect and investigate unauthorized attempts
and attacks against our IT assets, data, and services, and to prevent their occurrence and recurrence where practicable through changes
or updates to internal processes and tools and changes or updates to service delivery; however, potential vulnerabilities to known or
unknown threats will remain. Further, there is increasing regulation regarding responses to cybersecurity incidents, including reporting
to regulators, investors, and additional stakeholders, which could subject us to additional liability and reputational harm. See Item
1A. “Risk Factors” for more information on cybersecurity risks.