Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED STAFF COMMENTS
None.
ITEM 1C. CYBERSECURITY
Risk Management and Strategy
The Company has developed and maintained a comprehensive cybersecurity program which is integrated within the Company’s enterprise risk management program and encompasses the corporate and operational technology environments, as well as client-facing products and services . Our cybersecurity program has implemented a governance structure and process to identify, assess, manage, mitigate, respond to and report on cybersecurity incidents and risks within an ever-changing threat landscape.
We utilize cybersecurity policies and frameworks based on industry and government standards, including the National Institute of Standards and Technology Cyber Security Framework (“NIST CSF”). This does not imply that we meet any particular technical standards, specifications, or requirements, but rather that we use NIST CSF as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
To validate the effectiveness of our security posture, we engage third-party security experts to conduct annual deep-dive penetration tests. We maintain transparency regarding our security posture by making attestations and compliance summaries available to relevant stakeholders. Furthermore, our infrastructure is subject to regular external audits against rigorous industry standards, including SOC 2, PCI, and HITRUST. These audits validate that our internal controls are designed appropriately and are functioning effectively in practice.
Our cybersecurity program includes an incident response plan, which establishes (1) a framework for classifying security incidents according to their severity level, considering the nature and scope of the incident; and (2) protocols for the escalation of incidents.
To support this, the Company operates a 24 x 7 security operations center (“SOC”) which monitors our global cybersecurity solutions and production environments to detect and respond to potential anomalies. The SOC serves as a central location for the reporting of cybersecurity matters. The roles and responsibilities of the SOC and our cybersecurity team in the incident response context are established by the incident response plan, as well as in associated playbooks and other procedural documentation. Beyond annual testing, we utilize automated scanning and continuous internal assessments designed to identify and remediate vulnerabilities in our applications, software, and networks to mitigate risks proactively.
We partner with third parties to support and evaluate our cybersecurity program . The services provided by third parties span areas including cybersecurity maturity assessments, incident response, penetration testing, and consulting on best practices.
Our processes also address cybersecurity threat risks associated with our use of third-party service providers, including those who have access to our data or our systems. Third-party risks are included within our risk assessment of vendors, as well as our cybersecurity-specific risk identification program. Cybersecurity considerations affect the selection and oversight of third-party service providers. We perform diligence on third parties—particularly those that have access to our systems, data, or facilities that house such systems or data—and continually monitor cybersecurity threat risks identified through such diligence.
We view security as a shared responsibility across the organization. We maintain a cybersecurity awareness program designed to foster a vigilant security culture, covering topics such as phishing, social networking safety, password security, and mobile device usage. This includes regular phishing simulations to test and reinforce employee awareness. We communicate these and other pertinent security issues or compliance changes through our regular internal communications cadence. Additionally, the Company has mandatory security awareness training addressing cybersecurity, privacy, and confidential information.
36
Table of Contents
In 2024 and 2025, we did not identify any cybersecurity threats that have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition . Please refer to “ Item 1A. Risk Factors ” for further information about the material risks associated with various cybersecurity threats.
Governance
Our Board considers cybersecurity risk as part of its risk oversight function and has delegated to its Audit Committee oversight of cybersecurity and other information technology risks. Our Audit Committee oversees management’s ongoing activities related to our cybersecurity risk management and compliance programs.
Our cybersecurity program is led by our Chief Technology Officer (“CTO”), who has two decades of experience in various cybersecurity, software development, product management, and other technology-related roles. Our CTO oversees teams across the company supporting our security functions to “identify, prevent, detect, respond, and recover”. These teams are comprised of personnel with a broad range of experience across the private and public sectors, the technology industry, and different geographic regions.
Our Audit Committee receives periodic reports from our CTO and management on our cybersecurity risks and the current threat landscape trends. In addition, management will update the Board directly, as necessary, regarding cybersecurity incidents. The full Board also receives presentations on cybersecurity topics from our CTO and other security management staff as part of the Board’s continuing education on topics that impact the Company .