Item 1C. CYBERSECURITY
6K characters. Original on sec.gov · Markdown
Item 1C. CYBERSECURITY
Risk Management and Strategy
We recognize the critical importance of developing, implementing, and maintaining robust cybersecurity measures to
maintain the security, confidentiality, integrity, and availability of our business systems and confidential information,
including personal information and intellectual property. Our cybersecurity program includes systems and processes for
assessing, identifying and managing material risks from cybersecurity threats and include maintenance and monitoring of
information security policies aligned with global regulatory controls and aligned with National Institute of Standards and
Technology Cybersecurity Framework and System and Organization Controls 2. The program includes user and employee
awareness of cyber policies and practices; information systems configuration management; third-party risk management
systems; identity and information asset protection; infrastructure security systems; and cyber threat operations with
continuous monitoring and threat hunting. This program also includes processes to oversee and identify material risks from
cybersecurity threats associated with our use of third-party service providers. We engage a range of third-party experts in
connection with various development, implementation, and maintenance activities related to our cybersecurity program,
including audit and compliance, threat hunting, monitoring, and end-user support.
Our cybersecurity program is integrated into our overall risk management systems, including our annual enterprise risk
management program, internal audit program, business continuity and crisis management programs, third-party risk
management program, insurance risk management program, and employee compliance programs. As part of our overall risk
management program, we maintain a global insurance portfolio with comprehensive cyber coverage. Our Chief Information
Security Officer (“CISO”) and the Information Security function advises, consults with, or provides input to each of these
programs to ensure that material risks from cybersecurity threats are appropriately assessed, identified, and managed.
As of the date of this report, there have been no cybersecurity threats that have materially affected or are reasonably
likely to materially affect our business, operations, or financial condition. Similar to other companies, we have experienced
cybersecurity incidents, including temporary service interruptions of third-party suppliers. As of the date of this report,
however, known cybersecurity incidents, individually or in aggregate, have not had a material impact on our company. Over
the last three years, net expenses incurred from any information security breaches, including any penalties and settlements,
are not material relative to our total revenue. For additional discussion on cybersecurity risks we face, see Item 1.A, Risk
Factors – “A breakdown or breach of our information technology systems, or unauthorized access to confidential
information could adversely affect our business.” of this Annual Report on Form 10-K
Governance
While our board of directors has oversight responsibility for risk management generally, the Audit and Finance
Committee (“Audit Committee”) is specifically responsible for overseeing our cybersecurity risk management program to
ensure that cybersecurity risks are identified, assessed, managed, and monitored. Our CISO provides quarterly updates to the
Audit Committee in this regard, and covers the state of our cybersecurity program, supported by key performance indicators
across the range of cybersecurity functions related to risk management and governance, identity and information asset
protection, core security and endpoint security, and cyber threat operations. These updates include descriptions of
cybersecurity incidents of interest, including those associated with our third-party service providers; the board will be
informed promptly of material risks from cybersecurity threats.
We strive to create a culture of cybersecurity resilience and awareness and believe that cybersecurity is the responsibility
of every employee and contractor. At the same time, primary responsibility for assessing, monitoring, and managing our
cybersecurity risks lies with our CISO. Our CISO has more than 35 years of experience in security and information systems
and spent 25 years with Raytheon Technologies, most recently as Chief Technology Officer of Cybersecurity, Special
Missions, Training & Services. Our CISO supported the U.S. President's National Security Telecommunications Advisory
Committee for more than 20 years, is a member of the Massachusetts Cybersecurity Strategy Council, and previously served
as Chair of the Kogod Cybersecurity Governance Center at American University. He also served on the Rhode Island
Homeland Security Advisory Board and was a member of various commercial cyber product councils.
Our CISO oversees a team of skilled cybersecurity professionals who have Certified Information Systems Security
Professional credentials, Global Information Assurance Certification from the SANS Institute, and other security and network
certifications. The cybersecurity team monitors and evaluates our cybersecurity posture and performance on an ongoing
basis, including through regular vulnerability scans, penetration tests, and threat intelligence feeds. The cybersecurity team
uses various tools and methodologies to manage cybersecurity risk that are tested on a regular cadence, and assesses and
evaluates cybersecurity incidents, escalating certain cybersecurity incidents to the CISO according to protocol. The CISO is
continually informed regarding the performance of the cybersecurity program, as well as the latest developments in
cybersecurity, including potential threats and innovative risk management techniques aligned with industry standards. The
CISO reports to our Chief Digital and Information Officer, who is a Senior Vice President of the Company and reports
directly to our Chief Operating and Financial Officer (“COFO”). Our COFO is an Executive Vice President and an executive
officer of the Company, and reports directly to our CEO.
Previous: Item 1B. UNRESOLVED STAFF COMMENTS · Next: Item 2. PROPERTIES