CHINA AUTOMOTIVE SYSTEMS INC - (CAAS)
10-K Filing Date: March 28, 2024
ITEM 1C. CYBERSECURITY.
We recognize the importance of developing, implementing, and maintaining robust cybersecurity measures to safeguard our information systems and protect the confidentiality, integrity, and availability of our data. We have established policies and processes for assessing, identifying, and managing material risk from cybersecurity threats. We assess risks arising from cybersecurity threats against our information systems that may result in adverse effects on our information systems or any information residing therein. We conduct periodic assessments to identify such cybersecurity threats.
Following these risk assessments, we evaluate whether and how to re-design, implement, and maintain reasonable safeguards to mitigate identified risks and reasonably address any identified gaps in existing safeguards. Our IT leadership reports to our Chief Executive Officer (CEO) periodically and on an as-needed basis to manage our risk assessment and mitigation process. We monitor and test our safeguards and regularly conduct training for our employees on these safeguards, in collaboration with human resources, IT, and management. We are committed to promoting a company-wide culture of cybersecurity risk management.
We have not encountered cybersecurity risks, threats or incidents that have materially affected or are reasonably likely to materially affect the Company, our business strategy, results of operations, or financial condition during the financial year ended December 31, 2023.
31 | Page
Our board of directors as a whole has overall responsibility for monitoring and assessing strategic risk exposure. Our board of directors administers its cybersecurity risk oversight function directly as a whole. Our CEO and our executive management team are responsible for briefing our board on cybersecurity risks on a regular basis. Our cybersecurity coordinator is responsible for assessing and managing our material risks from cybersecurity threats, in close collaboration with our IT team, and briefs our senior management and CEO on cybersecurity risks and policies. This ensures that the senior management are kept abreast of the cybersecurity posture and potential risks faced by the Company.