PHX MINERALS INC. - (PHX)
10-K Filing Date: March 12, 2024
Cybersecurity risk management is part of the Company’s overall enterprise risk management program. Our cybersecurity risk management program is designed to provide a framework for handling cybersecurity threats and incidents, including threats and incidents associated with the use of services provided by third-party service providers, and facilitate coordination across different departments of our company. This framework includes steps for assessing the severity of a cybersecurity threat, identifying the source of a cybersecurity threat including whether the cybersecurity threat is associated with a third-party service provider, implementing cybersecurity countermeasures and mitigation strategies and informing management and our Board of material cybersecurity threats
19
and incidents. We engage with third party service providers to perform penetration tests and to inform us of possible vulnerabilities. In addition, cybersecurity training is provided to all employees on a regular basis but at least annually.
Our Board has overall oversight responsibility for our risk management, including the cybersecurity risk management program. Management is responsible for identifying, considering and assessing material cybersecurity risks on an ongoing basis, establishing processes to ensure that such potential cybersecurity risk exposures are monitored, putting in place appropriate mitigation measures and maintaining cybersecurity programs. Our cybersecurity programs are under the direction of our Principal Accounting Officer, who receives reports from our cybersecurity consultants and monitors the prevention, detection, mitigation, and remediation of cybersecurity incidents. Any significant cybersecurity incidents are reported to the audit committee, which is 100% independent, and ultimately to our Board. There were no such cybersecurity incidents in fiscal 2023, 2022, or 2021. Management presents an assessment of our cybersecurity processes, procedures, and results of testing to the Audit Committee at least annually.
Despite our efforts, we cannot eliminate all risks from cybersecurity threats, or provide assurances that we have not experienced an undetected cybersecurity incident. For more information about these risks, please see “Risk Factors – We may be subject to information technology system failures, network disruptions, cyber-attacks or other breaches in data security.” in this Form 10-K.