Item 1B. Unresolved Staff Comments
Item 1B. Unresolved Staff Comments.
None.
Item C. Cybersecurity.
Cybersecurity risk management and strategy
Our cybersecurity risk management is based on
recognized cybersecurity industry frameworks and standards, including those of the National Institute of Standards and Technology, the
Center for Internet Security Controls, and the International Organization for Standardization. This does not imply that we meet any particular
technical standards, specifications, or requirements, only that we use the aforementioned frameworks and standards as a guide to help
us identify, assess, and manage cybersecurity risks relevant to our business. We use these frameworks, together with information collected
from internal assessments, to develop policies for the use of our information assets (for example, TI business information and information
resources such as mobile phones, computers and workstations), access to specific intellectual property or technologies, and protection
of personal information. We protect these information assets through industry-standard techniques, by strong Identity and Access Management
framework, such as Role Based Access Control, principle of Least Privilege, multi factor authentication as obligatory second factor to
our core resources. We also thoroughly improved our endpoint protection by deploying an endpoint detection and response tool. Its core
mission is to defend our endpoints and systems against the newest malware, rootkits, spywares and ransomware. We also work with internal
stakeholders across the company to integrate foundational cybersecurity principles throughout our organization’s operations, including
the employment of multiple layers of cybersecurity defenses, restricted access based on business needs, and integrity of our business
information. Throughout the year, we also regularly train our employees on cybersecurity awareness on social engineering attacks, confidential
information protection, emerging threats and simulated phishing attacks to improve self-awareness of our employees.
42
We have standing engagements with incident response
experts and external counsel through our cyber insurance. We frequently collaborate with industry experts and cybersecurity practitioners
at other companies to exchange intelligence about potential cybersecurity threats, best practices and trends. We also have our own incident
response team who is engaged in dealing with security events triggered by our Security Information and Event Management (SIEM) system.
Our cybersecurity risk management extends to
risks associated with our use of third-party service providers. For instance, we conduct risk and compliance assessments of third-party
service providers by checking on a permanent basis every new vendor that is going to cooperate with the Company. The aim is to verify
if vendors due diligence and risks associated with it are within our risk tolerance set by management.
Our cybersecurity risk management is an important
part of our comprehensive business continuity program and enterprise risk management. Our global information security team periodically
engages with a cross-functional group of subject matter experts and leaders to assess and refine our cybersecurity risk posture and preparedness.
For example, we regularly evaluate and update contingency strategies for our business in the event that a portion of our information
resources were to be unavailable due to a cybersecurity incident. We practice our response to potential cybersecurity incidents through
regular tabletop exercises, threat hunting and red team exercises.
We also verify the resilience of our security
posture by regularly conducting vulnerability management programs, where we test on potential vulnerabilities of our systems, endpoints
connected to the company perimeter and remediate it to stay free from any software or configuration holes.
Governance of cybersecurity risk management
The board of directors, as a whole, has oversight
responsibility for our strategic and operational risks and sets associated risk parameters and tolerance levels. The audit committee
assists the board of directors with this responsibility by reviewing and discussing the defined risks, its assessment and proposed mitigation
strategies, including cybersecurity risks, with members of management. The audit committee, in turn, periodically reports on its review
with the board of directors.
Management is responsible for day-to-day assessment and management
of cybersecurity risks and reports regularly to the audit committee.
Zedge’s Cybersecurity risk governance has several components
that can help our organization understand and implement cybersecurity governance practices achieve long-term cybersecurity goals beyond
the day-to-day information security tasks, align with legal and regulatory compliance, and the direction of the Company through:
● Developing a mature cybersecurity culture which ensures that
all employees understand they are stakeholders in cybersecurity. Employees not only engage
with cybersecurity controls but must be proactive in risk mitigation and remediation.
● Cyber risk assessments which identify cybersecurity business
risks and the Company’s cybersecurity gaps and vulnerabilities. Using agreed-upon key
performance indicators (KPIs), stakeholders can measure the Company’s cybersecurity
capabilities clearly and objectively. This facilitates our ability to audit the effectiveness
of future vulnerabilities and remediation activities.
● An Accountability Framework which measures performance across
departments and systems and ensures that those identified as responsible for meeting objectives
are aware of the results and work with the cyber risk governance team leader to achieve and
enhance them. With consistent feedback and the ability to reference established metrics,
we can successfully monitor, review, and enforce cyber risk governance plans. In turn, through
these processes, we improve our framework, remediate serious issues, and update organizational
cyber risk governance roadmaps accordingly.
43