Item 1B. Unresolved Staff Comments
ITEM 1B. Unresolved Staff Comments
None.
ITEM 1C. Cybersecurity
Risk management and strategy
We recognize the critical
importance of developing, implementing, and maintaining robust cybersecurity measures to safeguard our information systems and protect
the confidentiality, integrity, and availability of our data.
25
Managing Material Risks & Integrated Overall
Risk Management
We have strategically integrated cybersecurity risk management
into our broader risk management framework to promote a company-wide culture of cybersecurity risk management. Our Chief Technology
Officer (CTO) evaluates and addresses cybersecurity risks in alignment with our business objectives and operational needs.
Engage Third-parties on Risk Management
Recognizing the complexity
and evolving nature of cybersecurity threats, we have engaged with a range of external experts, including cybersecurity assessors,
consultants, and auditors in evaluating and testing our risk management systems in an ongoing and as needed basis. These partnerships
enable us to leverage specialized knowledge and insights, ensuring our cybersecurity strategies and processes remain at the
forefront of industry best practices. Our collaboration with these third-parties includes regular audits, threat assessments, and consultation
on security enhancements.
Oversee Third-party Risk
Because we are aware of the risks associated with third-party service
providers, we implement stringent processes to oversee and manage these risks. We conduct thorough security assessments of all third-party
providers before engagement and maintain ongoing monitoring to ensure compliance with our cybersecurity standards. The monitoring includes
quarterly assessments by our CTO. This approach is designed to mitigate risks related to data breaches or other security incidents originating
from third-parties.
Risks from Cybersecurity Threats
We have not encountered cybersecurity challenges
that have materially impaired our operations or financial standing.
Governance
The Board of Directors is acutely aware of the critical nature of managing
risks associated with cybersecurity threats. The Board has established oversight mechanisms to ensure effective governance in
managing risks associated with cybersecurity threats because we recognize the significance of these threats to our operational
integrity and stakeholder confidence,
Board of Directors Oversight
The Audit Committee is central
to the Board’s oversight of cybersecurity risks and bears the primary responsibility for this domain. The Audit Committee
is composed of board members with diverse expertise including, risk management, technology, and finance, equipping them to oversee cybersecurity risks
effectively.
Management’s Role Managing Risk
The CTO and the Chief Executive
Officer (“CEO”) play a pivotal role in informing the Audit Committee on cybersecurity risks. The CTO keeps the CEO apprised
of any noteworthy activity on an ongoing basis. The CEO in turn provides comprehensive briefings to the Audit Committee on a regular basis,
with a minimum frequency of once per year. These briefings encompass a broad range of topics, including:
●
Current cybersecurity landscape and emerging threats;
●
Status of ongoing cybersecurity initiatives and strategies;
●
Incident reports and learnings from any cybersecurity events; and
●
Compliance with regulatory requirements and industry standards.
26
In addition to our scheduled
meetings, the Audit Committee and CEO maintain an ongoing dialogue regarding emerging or potential cybersecurity risks. Together,
they receive updates on any significant developments in the cybersecurity domain, ensuring the Board’s oversight is proactive
and responsive.