Energy Recovery, Inc. - (ERII)
10-K Filing Date: February 21, 2024
Item 1C — Cybersecurity
Managing Material Risks & Integrated Overall Risk Management
We have strategically integrated cybersecurity risk management into our broader risk management framework to promote a company-
wide culture of cybersecurity risk management. This integration ensures that cybersecurity considerations are an integral part of our
decision-making processes at every level. Our Risk Management Team (see “Management’s Role Managing Risk” below for details
regarding the team members and scope) works closely with our Information Technology (“IT”) team to continuously evaluate and address
cybersecurity risks in alignment with our business objectives and operational needs.
Engage Third-parties on Risk Management
Recognizing the complexity and evolving nature of cybersecurity threats, we engage with a range of external experts, including
cybersecurity consultants in evaluating and testing our risk management systems. These partnerships enable us to leverage specialized
knowledge and insights, ensuring our cybersecurity strategies and processes remain at the forefront of industry best practices. Our
collaboration with these third-parties includes regular audits, threat assessments, and consultation on security enhancements.
Oversee Third-party Risk
Because we are aware of the risks associated with third-party service providers, we have implemented stringent processes to oversee
and manage these risks. We conduct thorough security assessments of all third-party providers before engagement and maintain ongoing
monitoring to ensure compliance with our cybersecurity standards. The monitoring includes an initial assessment by our Director, Information
Technology and IT team, and on an ongoing basis of a few key high-risk third-party systems by our security engineers. We also rely upon
certain third-party system providers, including cloud and non-cloud programs provided by software developers such as Microsoft Corporation,
Blackline Systems, Inc., Workiva, Inc., and others, to review and notify their customers of any data breach. This approach, both internal and
reliance on external review notification, is designed to mitigate risks related to data breaches or other security incidents originating from third-
parties.
Risks from Cybersecurity Threats
While we have a cybersecurity program designed to protect and preserve the integrity of our information systems, we also maintain
cybersecurity insurance to manage potential liabilities resulting from specific cyber-attacks. However, it's important to note that although we
maintain cybersecurity insurance, there can be no guarantee that our insurance coverage limits will protect against any future claims or that
such insurance proceeds will be paid to us in a timely manner. As of December 31, 2023, no risks from cybersecurity threats, including as a
result of any previous cybersecurity incidents, have materially affected, or are reasonably likely to materially affect, us, including our business
strategy, results of operations, or financial condition.
Energy Recovery, Inc. | 2023 Form 10-K Annual Report | 25