Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments
None.
Item 1C. Cybersecurity
Risk Management and Strategy
We have implemented and maintain various information security processes designed to identify, assess and manage material risks from cybersecurity threats to our critical computer networks, third-party hosted services, communications systems, hardware and software, and our critical data, including intellectual property, confidential information that is proprietary, strategic, or competitive in nature, and personal and financial data regarding our employees, suppliers, customers, and other business partners.
Our Information Technology department, under the leadership of our Operations Vice President, and with cross-functional internal and third-party support, helps identify, assess, and manage our cybersecurity threats and risks. The Information Technology department leverages the National Institute of Standards and Technology (NIST) Cybersecurity Framework to assess risks from cybersecurity threats and monitors our threat environment and our risk profile using various methods, which have included, for example, threat assessments (including through interaction with law enforcement when necessary), internal and external audits, threat environment scans and third-party threat assessments, vulnerability assessments, external intelligence feeds and third-party-conducted tabletop training exercises.
Depending on the environment and system, we implement and maintain certain technical and physical processes, standards and policies designed to manage and mitigate material risks from cybersecurity threats to our information systems and data, including, for example, a written incident response plan and incident response policy, business continuity plans, data encryption for certain data, implementation of certain security standards, network security and access controls, data segregation, asset tracking/disposal systems, penetration testing and required employee training programs.
Our assessment and management of material risks from cybersecurity threats are integrated into our overall enterprise risk management processes. Our Information Technology department and third-party providers work with our senior leadership team to prioritize our risk management processes and with the goal of mitigating cybersecurity threats that are likely to materially impact our business. Our senior leadership team evaluates material risks from cybersecurity threats against our overall business objectives and will report to the Audit Committee of our Board of Directors, which is responsible for evaluating our overall enterprise risk.
We use third-party service providers to assist us from time to time to identify, assess, and manage material risks from cybersecurity threats, these have included, for example, professional services firms, threat intelligence service providers, penetration testing providers, cybersecurity consultants, forensic investigators, training platforms, and managed cybersecurity service providers.
We have experienced, and may in the future experience, whether directly or through our third-party providers, cybersecurity incidents. While risks from cybersecurity threats, including prior incidents, have not had a material impact on us, future incidents could have a material impact on our business strategy, results of operations, and financial condition. For additional information about the Company’s cybersecurity risks, please refer to the subsection titled “Risks Related to Litigation and Regulation” in Item 1A of Part I of this Annual Report on Form 10-K.
Governance
Our Board of Directors is responsible for addressing our cybersecurity risk management as part of its general oversight function. Our Audit Committee has been delegated oversight of the assessment and management of the Company’s cybersecurity risks, and the steps management takes to monitor and control such exposures. Our Audit Committee will report to our Board of Directors on significant cybersecurity matters. Management is responsible for providing updates on the Company’s cybersecurity risks resulting from risk assessments to the Audit Committee.
Our cybersecurity risk assessment and management processes are implemented and maintained by certain members of our management, including the Company’s Operations Vice President, the Director of Information Technology and the Director of Security. The Operations Vice President is responsible for hiring appropriate personnel, helping to integrate cybersecurity risk considerations into our overall risk management strategy, helping to prepare for cybersecurity
59
Table of Contents
incidents, approving cybersecurity processes, reviewing security assessments and other security-related reports, and overseeing the Director of Information Technology and the Director of Security. Our Operations Vice President has over six years of experience with the Company in various management roles, and as a result understands the Company’s operations. The Director of Information Technology has 31 years of information technology experience as well as cybersecurity and compliance experience. The Director of Security has over four years of direct experience developing and implementing security compliance programs at the Company as well as 11 years of experience in active and reserve duty in Military Intelligence Officer roles conducting cybersecurity and conventional threat assessments.