A Dark Vector Cognition product

Item 1C. CYBERSECURITY

6K characters. Original on sec.gov · Markdown

Item 1C. CYBERSECURITY

Management has implemented a comprehensive cybersecurity program designed to manage risks and to protect the confidentiality, integrity, and availability of our information systems and the information of our customers and suppliers from cybersecurity threats that could materially and adversely affect our business, operations, or financial condition. The program includes processes and standards that leverage recognized cybersecurity frameworks, industry best practices, and U.S. Government guidance focused on cybersecurity and critical infrastructure. These processes are integrated with our enterprise risk management and incident response functions to support timely assessment, escalation, and disclosure when appropriate.

Cybersecurity Governance

Board of Directors

The Audit and Finance Committee (A&FC) of the Board of Directors oversees the company’s Enterprise Risk Management (ERM) program, including the processes that management uses to assess, identify, and manage risks associated with cybersecurity and information technology. The A&FC receives written reports and periodic briefings from the Chief Information Security Officer (CISO) that address topics such as the results of vulnerability assessments, independent external reviews, changes to the threat environment, technology trends, and benchmarking. The A&FC provides regular reports to the Board of Directors on data protection and cybersecurity matters. The company maintains an Enterprise Cybersecurity Incident Response Plan (ECIRP) which provides the framework for management’s response to cyber-related incidents and escalation protocols, including, reporting to the Board of Directors when appropriate.

Management

The CISO has extensive cybersecurity knowledge and skills gained through company experience and prior law enforcement service, supported by advanced professional certifications. The CISO is responsible for assessing and managing risks from cybersecurity threats and leads a team that implements, monitors, and maintains cybersecurity and data protection practices across the company. Personnel reporting to the CISO have relevant educational and industry experience in threat hunting and intelligence, digital standards, data privacy, cyber training, and security operations center management. In addition to internal capabilities, we regularly engage consultants and other third parties to assist with assessing, identifying, and managing cybersecurity risks. The CISO receives ongoing reporting on cybersecurity threats and, together with management, regularly reviews risk management measures to identify, assess, and mitigate data protection and cybersecurity risks. The CISO also works closely with the company’s Senior Counsel, Brand, Cyber & Privacy, to oversee compliance with legal, regulatory, and contractual security requirements, and coordinates with our executive leadership, as well as other leaders from our legal and finance organizations to support timely materiality assessments and, where required, public disclosure.

Risk Management and Strategy

As part of our ERM program, we conduct an annual evaluation of cybersecurity risks and share the results with management and the A&FC. The CISO and internal subject-matter experts review scenarios, such as data theft, cash theft, widespread outages, and business disruptions, and the potential consequences. We maintain a continuous monitoring program to detect and respond to potential threats in near real time. Log data from technical controls are collected, aggregated, and correlated in a Security Information and Event Management (SIEM) system that identifies and categorizes events and analyzes them. If the SIEM identifies a potential security event, it can direct controls to stop the activity and generate alerts for detection and response. Alerts are monitored by a managed security service provider that augments our dedicated internal Security Operations Center team.

Third‑Party Risk Management

We operate a third‑party risk management (TPRM) program to identify, assess, monitor, and mitigate risks associated with third‑party relationships, including cybersecurity risks. The TPRM program is designed to help confirm that appropriate controls and measures are in place to manage potential risks and vulnerabilities associated with third parties.

Our policies and procedures govern the lifecycle from initial due diligence, selection, and contracting through oversight and termination, and include provisions to address security incident notification and cooperation when appropriate.

Audit and Third-party Assessments

Our Internal Audit organization conducts audits across our information technology and operational technology environments to evaluate compliance with information security policies and standards. Process control network assurance audits are conducted on a risk‑based rotating schedule, providing coverage across each major operational business area at intervals no greater than five years. We also engage external cybersecurity experts to conduct assessments, penetration testing, and cybersecurity maturity assessments.

Incident Response

Our ECIRP provides a documented framework for responding to cybersecurity incidents, including investigating, containing, documenting, and mitigating incidents, with defined reporting to senior management and other key stakeholders and escalation to the Board, when appropriate.

Materiality and Disclosure Practices

We have experienced actual and attempted cybersecurity events and incidents on our networks and systems in the past; however, we do not believe that any of these events or incidents, individually, or in the aggregate, have materially affected our business, operations, or financial condition, or are reasonably likely to have such an effect. Our procedures include defined processes for prompt escalation of potentially material cybersecurity incidents to our management for materiality assessment and, if required, public disclosure in accordance with applicable securities laws and regulations. For additional information concerning cybersecurity risks, see “Item 1A. Risk Factors.”

Previous: Item 1B. UNRESOLVED STAFF COMMENTS · Next: Item 3. LEGAL PROCEEDINGS