Item 1B. Unresolved Staff Comments
ITEM 1B. UNRESOLVED STAFF COMMENTS.
Not applicable to a smaller reporting company.
ITEM 1C . CYBERSECURITY
Like all companies that utilize technology, we are subject to threats of breaches of our technology systems. To mitigate the threat to our business, we take a comprehensive approach to cybersecurity risk management. Our IT department and our management actively oversee our risk management program, including the management of cybersecurity risks. We have contracted with cybersecurity and risk assessment experts to help test our systems and guide the ongoing development of best practices policies. We have established policies, standards, processes and practices for assessing, identifying, and managing material risks from cybersecurity threats, including those discussed in our Risk Factors. We have devoted resources to implement and maintain security measures to meet regulatory requirements and shareholder expectations, and we intend to continue to make investments to maintain the security of our data and cybersecurity infrastructure. While there can be no guarantee that our policies and procedures will be properly followed in every instance or that those policies and procedures will be effective, we believe that our company’s sustained investment in these efforts and technologies have put the Company in a position to protect against potential compromises, and we do not believe that risks from prior cybersecurity threats have materially affected our business to date. We can provide no assurance that there will not be incidents in the future or that past or future attacks will not materially affect us, including our business strategy, results of operations, or financial condition.
Risk management and strategy .
We employ a multi-layered cybersecurity defense strategy that includes:
●
Network and endpoint protection: Utilizing firewalls, intrusion detection systems, antivirus software, and advanced encryption protocols to safeguard sensitive data and systems.
●
Multi-factor authentication, security and principle of least privileged (PoLP)
●
Employee training and awareness programs: Educating employees on cybersecurity best practices and conducting phishing simulations to promote vigilance against social engineering attacks.
●
Incident detection and response plans: Maintaining real-time monitoring and implementing a structured incident response plan that allows us to quickly detect, respond to, and recover from cyber incidents.
●
Third-party risk management: Vetting the cybersecurity controls of vendors and partners to ensure that their practices align with our standards for protecting sensitive information.
●
While we have not experienced a cybersecurity incident that has had a material impact to date, the threat of potential incidents remains high. We continually evaluate our exposure to risks such as:
○
Operational disruption from ransomware or other cyberattacks.
○
Data breaches that could compromise customer or proprietary information.
○
Regulatory and legal exposure arising from cybersecurity failures.
17
Table of Contents
As part of our risk management framework, we regularly assess whether any cybersecurity incidents, or the likelihood of such incidents, could materially affect our business. We are also committed to continuous improvements to address emerging threats.
Governance.
Our board of directors plays an active role in overseeing the company’s approach to managing cybersecurity risks. The board receives regular updates from senior management regarding the company's cybersecurity strategy, potential risks, and any incidents that may arise. These updates ensure that the board remains informed and able to provide guidance on cybersecurity matters.
The board is also regularly briefed by management on the Company’s cybersecurity policies, risk assessments, and mitigation strategies. This reporting structure allows the board to remain engaged with the company’s efforts to address and manage evolving cyber threats, ensuring that cybersecurity is aligned with our overall risk management framework.
Management, led by the IT department, plays a critical role in assessing and managing material risks related to cybersecurity. This includes implementing day-to-day cybersecurity measures, conducting regular risk assessments, and ensuring the timely response to any cyber threats or incidents. The IT department is responsible for ensuring that cybersecurity is integrated into our company’s broader risk management strategy, with direct reporting lines to both senior executives and the board of directors.
ITEM 2. DESCRIPTION OF PROPERTY.
We operate our executive offices and warehouse from an 80,000 square foot facility in Charlotte, North Carolina under a lease agreement which commenced in November 2019. Through February 2025 the agreement calls for an annual base monthly rent of $34,766, inclusive of monthly TICAM for the first year and the rent escalates 3% annually. Effective November 26, 2024 we entered into a Second Amendment to Lease to extend the lease. The amendment extends the term of the lease for a period of nineteen months beginning on March 1, 2025 with a new expiration date of September 30, 2026. The Company has no further rights to extend or renew the terms of the lease. The amendment provides for the monthly base rent of $65,000, with an annual base rent of $9.75 per square feet from March 1, 2025 through February 28, 2026, and $67,600 with an annual base rent of $10.14 per square feet from March 1, 2026 through September 30, 2026. The Company shall also continue to pay additional rent and all other amounts (other than “Monthly Base Rent”) in accordance with the terms of the lease, except the “Controllable CAM Charges" provision have been deleted. Furthermore, the landlord has approved certain subleases entered into by and between the Company and sub tenants for portions of the facility. This facility is sufficient for our current and anticipated operations through September 2026.
See footnote 11 to our financial statements including with this annual report for a discussion on the termination of our former executive office lease pursuant to agreements entered into in March 2024.
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.