ThermoGenesis Holdings, Inc. - (THMO)

10-K Filing Date: April 15, 2024
ITEM 1C.

Cybersecurity

 

Cybersecurity risk management is part of the Company's overall enterprise risk management program. Our cybersecurity risk management program is designed to provide a framework for handling cybersecurity threats and incidents, including threats and incidents associated with the use of services provided by third-party service providers, and facilitate coordination across different departments of our company. This framework includes steps for assessing the severity of a cybersecurity threat, identifying the source of a cybersecurity threat including whether the cybersecurity threat is associated with a third-party service provider, implementing cybersecurity countermeasures and mitigation strategies and informing management and our board of directors of material cybersecurity threats and incidents. We engage with third party service providers to perform penetration tests and to inform us of possible vulnerabilities. In addition, cybersecurity training is provided to all employees on a regular basis but at least annually.

 

Our board of directors has overall oversight responsibility for our risk management, including the cybersecurity risk management program. Management is responsible for identifying, considering and assessing material cybersecurity risks on an ongoing basis, establishing processes to ensure that such potential cybersecurity risk exposures are monitored, putting in place appropriate mitigation measures and maintaining cybersecurity programs. Our cybersecurity programs are under the direction of our Vice President of Operations who monitors the prevention, detection, mitigation, and remediation of cybersecurity incidents. Any significant Cyber incidents are reported to the audit committee and ultimately to the board of directors.

 

© 2025 Material-Incidents. All rights reserved.