edgarwiki

Cybersecurity disclosure

124 staff comments in this corpus, to 86 registrants, across 6 of the 7 calendar quarters this corpus covers.

Coverage is partial and not continuous. This corpus holds CORRESP filings from 2023Q1–2024Q2 (82–96% of each quarter's EDGAR total); 2025Q4 (16% of the 861 CORRESP filings EDGAR indexed that quarter). It holds nothing at all from 2024Q3, 2024Q4, 2025Q1, 2025Q2 or 2025Q3, and nothing filed after 2025-12-31. If an issue page shows no comment from one of those periods, the reason is that edgarwiki has no data for it — not that the staff raised nothing. Counts on this site are counts within this corpus and are not SEC-wide totals. Every quotation is verbatim and links to its filing; what is incomplete is coverage, not accuracy. Per-quarter figures: Methodology.
MeasureValue
Comments raising this issue124
Share of all 51,900 comments in the corpus0.2%
Distinct registrants86
With a recorded company response124

When these comments were filed

By the quarter the CORRESP filing was filed. The third column is how much of that quarter's EDGAR CORRESP output this corpus holds — read it before comparing two rows. A quarter marked never ingested contributes no comments to this page for reasons that have nothing to do with the SEC.

QuarterComments here Corpus coverage of that quarter
2023Q12293%
2023Q22691%
2023Q32293%
2023Q41996%
2024Q11493%
2024Q22182%
2024Q30% — never ingested
2024Q40% — never ingested
2025Q10% — never ingested
2025Q20% — never ingested
2025Q30% — never ingested
2025Q4016%

The exchanges

Verbatim, most recent first. Quotations are exact spans from the filing linked beneath each one; long passages are truncated with an ellipsis and never altered.

SEC staff comment
10. Disclosure in the Prospectus Summary and The Company sections under the sub-sections titled “ Blackstone Credit Strengths—Value-Added Capital Provider and Partner Leveraging the Blackstone Value Creation Program ” states that “ [t]he preferred partnership program also assists smaller and medium sized companies in gaining access to … and helped companies correct 90 critical cybersecurity issues. ” Please revise this disclosure to be in plain English.
The company responded
While respectfully noting that it may update the disclosure further in the ordinary course, the Fund confirms that it will revise the disclosure, as follows, in response to the Staff’s comment to revise this disclosure to be in plain English: 6 Securities and Exchange Commission June 25, 2024 The preferred partnership program also assists smaller and medium sized companies in gaining access to enterprise level sales teams which that can be more attentive in addressing service issues they these companies may experience. One of the biggest differentiators within the program is our access to the Blackstone Sourcing Center, which is a team of 13 + procurement professionals, who run eRFPs and eAuctions for companies at no cost. This team has run over 280 projects and tensioned over $750 million worth of RFPs and eAuctions for Blackstone Credit companies. As of June 30 As of December 31 ,…
Blackstone Private Credit Fund · filed 2024-06-25 · 0001193125-24-167929
SEC staff comment
Comment 8 : Please add a risk factor addressing that at times, there has been a single entity that has reportedly controlled around or in excess of 33% of the total staked ether on the Ethereum network which poses centralization concerns and could permit the entity to attempt to interfere with transaction finality or block confirmations. Address the concern that if such an entity, or a bad actor with a similar sized stake, were to attempt to interfere with transaction finality or block confirmations, it could negatively affect the use and adoption of the Ethereum network, the value of ether, and thus the value of your shares. Additionally, please revise your “Ethereum is subject to a cybersecurity risk” discussion on page 32 to also address the possibility of a 33% attack and a 66% attack.
The company responded
The Trust has incorporated this comment and the following disclosure will be added: Liquid staking applications pose risks associated with concentration of control. Validators must deposit 32 ether to activate a unique validator key pair that is used to sign block proposals and attestations on behalf of its stake (i.e., vote on its view of the chain). For every 32 ether deposit that is staked, a unique validator key pair is generated. An application built on the Ethereum network, or a single node operator, can manage many validator key pairs. For example, Lido, an application that provides a so-called “liquid staking” solution which permits holders of ether to deposit them with Lido, which stakes the ether while issuing the holder a transferrable token, is reported by some sources to have or have had up to 275,000 validator key pairs (each representing 32 staked ether) divided across…
21Shares Core Ethereum ETF · filed 2024-06-21 · 0001213900-24-054718
SEC staff comment
1. We note the statement that you experienced a cybersecurity incident that has not had a material impact on your operations. Please advise us as to why you determined to file under Item 1.05 of Form 8-K given the statement that the incident has not had a material impact on your operations, and you have not determined the incident is reasonably likely to materially impact your financial condition or results of operations.
The company responded
We filed disclosure regarding the Cybersecurity Incident under Item 1.05 of Form 8-K for the following reasons, notwithstanding our determination that the Cybersecurity Incident had not had a material impact on our operations and was not reasonably likely to materially impact our financial condition or results of operations: 1. At the time of our initial filing, the Commission’s cybersecurity incident disclosure rule pursuant to Item 1.05 of Form 8-K (the “New Rule”) had been in effect less than two months, and only a small number of issuers had disclosed cybersecurity incidents pursuant to the New Rule. Moreover, there was limited staff guidance regarding compliance with the New Rule. Therefore, it was highly uncertain how companies should approach compliance during the course of a potentially significant cybersecurity incident, what investor and other market participant expectations…
PRUDENTIAL FINANCIAL INC · filed 2024-06-21 · 0001193125-24-165215
SEC staff comment
1. We note the statement that you experienced a cybersecurity incident. Please advise us as to why you determined to file under Item 1.05 of Form 8-K given the statement that the incident has not had a material impact on your financial condition or operations, and you do not believe the incident is reasonably likely to materially impact your financial condition or results of operations. Company
The company responded
The Company respectfully acknowledges the Staff’s comment. In response to the Staff’s comment, the Company determined to file the Initial Form 8-K under Item 1.05 of Form 8-K because the Company determined that it had experienced a material cybersecurity incident. In reaching its determination of materiality, the Company took into consideration the directives of the Commission in Release Nos. 33-11216; 34-97989; 88 FR 51896 (Cybersecurity Risk Management, Strategy, Governance and Incident Disclosure) (hereafter, the “Final Rule Release”) as highlighted below: The Final Rule Release states, in relevant respect, as follows: “The rule’s inclusion of ‘financial condition and results of operations’ is not exclusive; companies should consider qualitative factors alongside quantitative factors in assessing the material impact of an incident. By way of illustration, harm to a company’s…
BRANDYWINE REALTY TRUST · filed 2024-06-20 · 0000790816-24-000029
SEC staff comment
1. We note the statement that you experienced a cybersecurity incident, and your investigation of the incident and its scope remains ongoing. Please advise us as to why you determined to file under Item 1.05 of Form 8-K given the statement that the incident has not had a material impact on your operations, and you have not determined the incident is reasonably likely to materially impact your financial condition or results of operations.
The company responded
We respectfully acknowledge the Staff’s comment. First, our interpretation of Item 1.05(a) is that the disclosure trigger for Item 1.05(a) is the registrant’s determination that a cybersecurity incident is “material” – as the adopting release states, “[t]he obligation to file the Item 1.05 disclosure is triggered once a company has developed information regarding an incident sufficient to make a materiality determination….” (emphasis added). 1 The adopting release explains this trigger as follows: In the majority of cases, the registrant will likely be unable to determine materiality the same day the incident is discovered. The registrant will develop information after discovery until it is sufficient to facilitate a materiality analysis. At that point, we believe investors are best served knowing, within four business days after the materiality determination, that the incident occurred…
Hewlett Packard Enterprise Co · filed 2024-06-18 · 0001645590-24-000111
SEC staff comment
1. We note the statement you experienced a cybersecurity incident that, as of the date of the filing, did not have a material on your overall operations. Please advise us as to why you determined to file under Item 1.05 of Form 8-K given the statement that, as of the date of the filing, the incident did not you have a material impact on the Company’s overall operations and you had not yet determined the incident is reasonably likely to materially impact your financial condition or results of operations. Company’s
The company responded
Out of an abundance of caution based on the fluidity of a materiality determination while a cybersecurity incident investigation is ongoing and review of the disclosures from other issuers being filed under Item 1.05 of Form 8-K, we felt that it was appropriate to disclose our cybersecurity incident promptly with the information we had at the time. Based on the Statement from the Director of the Division of Corporation Finance of the Commission released on May 21, 2024 (Disclosure of Cybersecurity Incidents Determined to be Material and Other Cybersecurity Incidents) and the ultimate results of our cybersecurity incident investigation, in retrospect it appears that a filing under Item 8.01 of Form 8-K would have been more appropriate. In the event of any future cybersecurity incidents, we understand the materiality requirement for disclosure under Item 1.05 of Form 8-K. Thank you for…
RADIANT LOGISTICS, INC · filed 2024-06-18 · 0000950170-24-074835
SEC staff comment
Comment. Please consider adding a risk factor describing cybersecurity risk.
The company responded
The Registrant respectfully directs the Staff’s attention to disclosure in the Fund’s registration statement, which reads: Cybersecurity Risk. Investment companies, such as the Fund, and their service providers are exposed to operational and information security risks resulting from cyberattacks, which may result in financial losses to the Fund and its shareholders. Cyber-attacks include, among other behaviors, stealing or corrupting data maintained online or digitally, denial of service attacks on websites, “ransomware” that renders systems inoperable until ransom is paid, the unauthorized release of confidential information, or various other forms of cybersecurity breaches. Cyber-attacks affecting the Fund, Calamos Advisors, custodian, transfer agent, distributor, market maker, authorized participants, administrator, intermediaries, trading counterparties, and other third-party…
Calamos ETF Trust · filed 2024-06-13 · 0001104659-24-071221
SEC staff comment
Comment. Please consider adding a risk factor describing cybersecurity risk.
The company responded
The Registrant respectfully directs the Staff’s attention to disclosure in the Fund’s registration statement, which reads: Cybersecurity Risk. Investment companies, such as the Fund, and their service providers are exposed to operational and information security risks resulting from cyberattacks, which may result in financial losses to the Fund and its shareholders. Cyber-attacks include, among other behaviors, stealing or corrupting data maintained online or digitally, denial of service attacks on websites, “ransomware” that renders systems inoperable until ransom is paid, the unauthorized release of confidential information, or various other forms of cybersecurity breaches. Cyber-attacks affecting the Fund, Calamos Advisors, custodian, transfer agent, distributor, market maker, authorized participants, administrator, intermediaries, trading counterparties, and other third-party…
Calamos ETF Trust · filed 2024-06-13 · 0001104659-24-071304
SEC staff comment
1. We note the statement that you experienced a cybersecurity incident that resulted in an operational disruption that “could be considered material.” Item 1.05 was added to Form 8-K to require the disclosure of a cybersecurity incident “that is determined by the registrant to be material.” Please advise us as to why you determined to file under Item 1.05 of Form 8-K given this statement.
The company responded
Upon detecting that a third party had gained unauthorized access to portions of the Company’s information technology environment, the Company expeditiously assessed the impact of the incident with third-party advisors pursuant to the Company’s previously established cyber incident response protocols. In light of the containment measures, which included shutting down certain of the Company’s systems, and understanding the importance of prompt disclosure, the Company determined that it was appropriate to file a Current Report on Form 8-K to disclose the incident under Item 1.05. The Company is aware of the statement issued by Erik Gerding, Director, Division of Corporation Finance of the Commission, on May 21, 2024, which was subsequent to the filing of the Company’s Current Report on Form 8-K, clarifying the Staff’s position with respect to the use of Item 1.05 and Item 8.01 to report…
Frontier Communications Parent, Inc. · filed 2024-06-13 · 0001193125-24-160519
SEC staff comment
1. We note the statement that you experienced a cybersecurity incident in your Form 8-K filed on March 12, 2024. Please advise us as to why you determined to file under Item 1.05 of Form 8-K given the statement that the incident had not had a material impact on your operations, and you were still in the process of determining whether the incident was reasonably likely to materially impact your financial conditions or results of operations.
The company responded
On March 10, 2024, MarineMax determined that it had experienced a cybersecurity incident. More specifically, MarineMax was the victim of a ransomware attack. Upon detection, MarineMax immediately took containment actions and initiated its business continuity protocols. Although the containment action resulted in some disruption to a portion of its business, MarineMax’s business and retail operations were not disrupted for an extended period of time, and the company’s operation was able to continue in all material respects. As such, as of March 12, 2024, the incident and containment efforts did not have a material impact on the company’s operations. Nevertheless, the Supreme Court has held that a fact is material if there is “a substantial likelihood that the . . . fact would have been viewed by the reasonable investor as having significantly altered the ‘total mix’ of information made…
MARINEMAX INC · filed 2024-06-11 · 0001193125-24-159090
SEC staff comment
1. We note the statement that you experienced a cybersecurity incident and are still investigating the extent of any sensitive information contained within the accessed systems. Please advise us as to why you determined to file under Item 1.05 of Form 8-K given the statement that the incident has not had a material impact on your operations, financial systems or financial condition, and you do not anticipate that the incident will have a material impact on your financial condition and results of operations moving forward.
The company responded
The Company respectfully acknowledges the Staff’s comment and hereby provides the following explanation. OraSure Technologies, Inc. 220 East First Street Bethlehem, PA 18015 Upon becoming aware of a cybersecurity incident (“Incident”), the Company took steps to contain the Incident and secure its networks and data. Concurrently with these efforts, the Company initiated a process to assess whether the Incident had, or would have, a material impact on the Company’s financial condition or results of operations. As a result of this assessment, the Company concluded that the Incident did not have a material impact on the Company’s operations, financial systems, or its financial condition. However, in accordance with SEC guidance, the Company also considered qualitative factors, such as potential reputational harm and impact on customer and vendor relationships, and the possibility of…
ORASURE TECHNOLOGIES INC · filed 2024-06-10 · 0001193125-24-158340
SEC staff comment
1. We note the statement that you experienced a cybersecurity incident in your Form 8-K filed on February 9, 2024. Please advise us as to why you determined to file under Item 1.05 of Form 8-K given the statement that the incident had not had a material impact on your operations, and you had not determined it was reasonably likely to materially impact your financial condition or results of operations.
The company responded
The Company respectfully acknowledges the Staff’s comment and notes that as of February 9, 2024, the date of the original Form 8-K, the Company’s investigation into the facts, circumstances and the impact of the cybersecurity incident remained ongoing. As a result, the Company was balancing the need for prompt disclosure for the benefit of investors and the Company’s other stakeholders against the dynamic and ongoing fact-finding process, and ultimately elected to file the Form 8-K under Item 1.05 out of an abundance of caution given the Company was unable at the time to assess materiality conclusively. Subsequent to the Company’s original Form 8-K filed on February 9, 2024 and the Company’s amended Form 8-K filed on March 29, 2024, the Commission released the statement of the director of the Division of Corporation Finance dated May 21, 2024 containing guidance for public companies…
SouthState Corp · filed 2024-06-03 · 0000950103-24-007629
SEC staff comment
1. We note you do not include Item 1.C Cybersecurity. Please revise or advise us why you do not provide disclosure as applicable under Item 106 of Regulation S-K.
The company responded
We have revised this accordingly in the amended filing.
EOS INC. · filed 2024-05-30 · 0001575872-24-000598
SEC staff comment
Comment: Please review the last two paragraphs of “Cyber Security Risk” as they appear to be related to “Currency Risk.”
The company responded
The Registrant has moved the referenced disclosure to Currency Risk. * * * * * * * * * * * * Please feel free to contact me at (617) 235-4636 to discuss any questions or comments you may have regarding the foregoing responses. Thank you for your assistance. Sincerely, /s/ Jessica Reece Jessica Reece, Esq. cc: Andrew Lawson, Esq. Barbara Nelligan 4 APPENDIX A FEE AND EXPENSE TABLE AND EXPENSE EXAMPLE Shareholder Fees (Fees paid directly from your investment) Maximum Sales Charge (Load) Imposed on Purchases (as a percentage of offering price) None Maximum Deferred Sales Charge (Load) (as a percentage of amount redeemed) None Redemption Fee (as a percentage of amount redeemed) None Annual Fund Operating Expenses (Expenses that you pay each year as a percentage of the value of your investment) Management Fees 1.00 % Distribution (12b-1) Fees None Other Expenses 3.01 % Total Annual Fund…
Datum One Series Trust · filed 2024-05-21 · 0001193125-24-144027
SEC staff comment
3. To the extent material, please address the following risks as related to SEALCOIN: · Risks relating to your planned SEALCOIN business operations, such as risks relating to implementation, technology, cybersecurity and adoption, as well as any reliance on another network, application, or off-network code or entity; · Risks relating to the unique characteristics of SEALCOIN including digital form, the rights of holders or their lack of rights, liquidity, supply, and custody; · Regulatory challenges of securities, tax, and AML/KYC regulations; and · Impact of technological developments on the value and functionality of SEALCOIN over time. 6
The company responded
In response to the Staff’s comment, we note the following: The SEALCOIN project is currently in the R&D stage – that is, as noted above, research of the technical feasibility and analysis of the development of potential service applications. As such, we are not in a position to meaningfully assess the risks that would be associated with the SEALCOIN project once implemented, and the materiality of some or all of such risks from the perspective of our shareholders. For example, at the present time we do not know if we will choose to issue a new cryptocurrency or build out the project implementation with pre-existing cryptocurrency to tokenize access to the SEALCOIN Service Platform, or if we will decide to create a new entity to issue the tokens, or line up a third party to issue the tokens. It is only when the SEALCOIN project is further along in its development that the assessment of…
SEALSQ Corp · filed 2024-05-17 · 0001193805-24-000678
SEC staff comment
3. To the extent material, please address the following risks as related to SEALCOIN: · Risks relating to your planned SEALCOIN business operations, such as risks relating to implementation, technology, cybersecurity and adoption, as well as any reliance on another network, application, or off-network code or entity; · Risks relating to the unique characteristics of SEALCOIN including digital form, the rights of holders or their lack of rights, liquidity, supply, and custody; · Regulatory challenges of securities, tax, and AML/KYC regulations; and · Impact of technological developments on the value and functionality of SEALCOIN over time. 6
The company responded
In response to the Staff’s comment, we note the following: The SEALCOIN project is currently in the R&D stage – that is, as noted above, research of the technical feasibility and analysis of the development of potential service applications. As such, we are not in a position to meaningfully assess the risks that would be associated with the SEALCOIN project once implemented, and the materiality of some or all of such risks from the perspective of our shareholders. For example, at the present time we do not know if we will choose to issue a new cryptocurrency or build out the project implementation with pre-existing cryptocurrency to tokenize access to the SEALCOIN Service Platform, or if we will decide to create a new entity to issue the tokens, or line up a third party to issue the tokens. It is only when the SEALCOIN project is further along in its development that the assessment of…
SEALSQ Corp · filed 2024-05-17 · 0001193805-24-000679
SEC staff comment
Comment 3. Please consider adding a cybersecurity risk disclosure.
The company responded
The Registrant believes the cybersecurity risk disclosure included in Item 9 under the “Principal Investment Risks” heading is sufficient. * * * * * If you have any questions or additional comments, please call the undersigned at 614-469-3353. Very truly yours, /s/ Andrew Davalla Andrew Davalla
Collaborative Investment Series Trust · filed 2024-05-16 · 0001999371-24-006181
SEC staff comment
8. Under the “Principal Investment Risks” section in the Fund’s prospectus, please consider including a “cybersecurity” risk factor to Item 9 of Form N-1A, in the Fund’s statutory prospectus.
The company responded
The Trust acknowledges the Staff’s comment; however, it does not believe that cybersecurity is a principal risk for the Fund. The Trust believes that the “ Special Risks Related to Cyber Security ” language contained in the Fund’s SAI Part B of Form N-1A adequately discloses any associated cyber security risks inherent to each ETF’s investment strategy. Accordingly, the Trust respectfully declines to make any changes in response to this comment.
PROFESSIONALLY MANAGED PORTFOLIOS · filed 2024-05-14 · 0000894189-24-003300
SEC staff comment
3. Key Information—D. Risk Factors—Risks Related to Doing Business in the People’s Republic of China. —Any actions by the Chinese government, including any decision to intervene or influence the operations of the operating entities or to exert control over any offering of securities conducted overseas and/or foreign investment in China-based issuers, may cause us to make material changes to the operations of the PRC operating entities, may limit or completely hinder our ability to offer or continue to offer securities to investors, and may cause the value of such securities to significantly decline or be worthless.” We are subject to legal and operational risks associated with being based in and having the majority of our operations in China. These risks may result in a material change in our operations, or a complete hindrance of our ability to offer or continue to offer our securities…
The company responded
In response to the Staff’s comment, we respectfully advise the Staff that we will revise our disclosure as follows: Pursuant to the Basic Law, which is a national law of the PRC and the constitutional document for Hong Kong, national laws of the PRC shall not be applied in Hong Kong except for those listed in Annex III of the Basic Law and applied locally by promulgation or local legislation. The Basic Law expressly provides that the national laws of the PRC which may be listed in Annex III of the Basic Law shall be confined to those relating to defense and foreign affairs as well as other matters outside the autonomy of Hong Kong. The basic policies of the PRC regarding Hong Kong as a special administrative region of the PRC are reflected in the Basic Law, providing Hong Kong with a high degree of autonomy and executive, legislative and independent judicial powers, including that of…
Akso Health Group · filed 2024-05-07 · 0001213900-24-040323
SEC staff comment
Comment. Please consider adding a risk factor describing cybersecurity risk.
The company responded
The Registrant respectfully directs the Staff’s attention to disclosure in the Fund’s registration statement, which reads: Cybersecurity Risk. Investment companies, such as the Fund, and their service providers are exposed to operational and information security risks resulting from cyberattacks, which may result in financial losses to the Fund and its shareholders. Cyber-attacks include, among other behaviors, stealing or corrupting data maintained online or digitally, denial of service attacks on websites, “ransomware” that renders systems inoperable until ransom is paid, the unauthorized release of confidential information, or various other forms of cybersecurity breaches. Cyber-attacks affecting the Fund, Calamos Advisors, custodian, transfer agent, distributor, market maker, authorized participants, administrator, intermediaries, trading counterparties, and other third-party…
Calamos ETF Trust · filed 2024-04-22 · 0001104659-24-049729
SEC staff comment
Comment 8. The SAI discloses cybersecurity risk. Please consider whether to include this risk disclosure in the Fund's prospectus in response to Items 4 and 9 of Form N-1A.
The company responded
The Trust confirms that it does not consider cybersecurity risk to be a principal risk for the Fund.
Advisor Managed Portfolios · filed 2024-04-10 · 0000894189-24-002299
SEC staff comment
Comment 14. The SAI discloses Cybersecurity Risk. Please consider whether to include this risk disclosure in the prospectus in response to items 4 and 9.
The company responded
The Trust confirms that it does not consider Cybersecurity Risk to be a Principal Risk for the Fund.
Advisor Managed Portfolios · filed 2024-02-21 · 0000894189-24-001106
SEC staff comment
Comment: The disclosure states, “[t]he Index is designed and maintained by Indxx (the ‘Index Provider’) and generally consists of listed securities in either developed or emerging markets, both in the United States and internationally, that are involved in providing data security and protection, data privacy, and cybersecurity products and services, as described in greater detail below.” Mr. Asen Parachkevov U.S. Securities and Exchange Commission February 20, 2024 Page 7 a. Please explain why the qualification “generally” is included. b. Please match the disclosure with the rest of the filing and be consistent with the description of the index and its components throughout. For instance, the summary prospectus also states, “[t]he Index is comprised of constituents that have business operations that are related to the overall Privacy theme, as defined by the five sub-themes, and derive…
The company responded
The Registrant has revised the Registration Statement in response to the Staff’s comment to remove the reference to generally, harmonize the disclosure in the summary and statutory prospectuses, and specify that the “substantial portions of their revenue” means greater than 50%. 19.
Grayscale Funds Trust · filed 2024-02-20 · 0001680359-24-000068
SEC staff comment
9. Please disclose whether you are subject to material cybersecurity risks in your supply chain based on third-party products, software, or services used in your products, services, or business and how a cybersecurity incident in your supply chain could impact your business. Discuss the measures you have taken to mitigate these risks.
The company responded
In response to the Staff’s comment, the Company has revised the disclosure on page 68 of the Registration Statement. Background of the Business Combination, page 115
Above Food Ingredients Inc. · filed 2024-02-09 · 0001104659-24-012931
SEC staff comment
1. We note your disclosure that you submitted your application for cybersecurity review with the CCRC and that you will not complete the offering and listing without first receiving from the CRO the approval or the conclusion that the assessment is not needed under Cybersecurity Review Measures. Please tell us how you plan to notify investors about CRO approval or the conclusion that the assessment is not needed.
The company responded
In response to the Staff’s comment, we have revised our disclosures on the cover page, Prospectus Summary, Risk Factor and elsewhere of the Amendment No.2. We respectfully advise the Staff that we have made disclosures of our completion of the cybersecurity review in Amendment No.1. (2) Ordinary shares issued to Shanghai Xinhui Investment Consulting Co., Ltd. (“Shanghai Xinhui”), page F-22
Zhibao Technology Inc. · filed 2024-02-07 · 0001213900-24-011302
SEC staff comment
1. We note your response to comment 4 and reissue. Please describe the cybersecurity risks faced by the Company in connection with the Company’s supply chain/suppliers/service providers.
The company responded
In response to this comment, the Company has revised the risk factor under the heading “ Improper activities by third parties, exploitation of encryption technology, new data-hacking tools and discoveries and other events or developments may result in future intrusions into or compromise of our networks and technology systems. ” on page 16 of the Registration Statement. Capitalization, page 25
Fly-E Group, Inc. · filed 2024-02-01 · 0001213900-24-009229
SEC staff comment
20. You disclose that management has determined that its managed security service practice is a bundle of cybersecurity software tools, and expert 24x7x365 monitoring and breach resolution service that is accounted for as a single performance obligation that is delivered over time which is typically a month; the components of the bundle have individual commercial value; however, management believes assigning stand-alone value to each component is impractical because each component would not be able to be fully implemented or utilized if not packaged with the other components; therefore, management believes the MSSP can only be sold as a bundle package over time. Please provide us with your analysis regarding how you determined that the components and services in these contracts should be combined. Clarify your disclosures that indicate the performance obligation is delivered over time,…
The company responded
Drawing on ASC 606-10-25-19 through 22. Cycurion’s management provides the following analysis of its MSSP service offering that should be accounted for as a single performance obligation. >> Distinct Goods or Services 25-19 - A good or service that is promised to a customer is distinct if both of the following criteria are met: a. The customer can benefit from the good or service either on its own or together with other resources that are readily available to the customer (that is, the good or service is capable of being distinct). Cycurion does not sell monitoring time, security software-tools, and breach resolution as stand-alone services as the customer would Not receive the benefits of these items if they were not sold as an integrated package. The cybersecurity needs to regularly monitor the customer cybersecurity environment, stay up to date on cyberthreats and solutions, maintain…
Western Acquisition Ventures Corp. · filed 2024-01-29 · 0001104659-24-007915
SEC staff comment
22. Please clarify your disclosures that indicate that your software as a service is a suite of cybersecurity tools are delivered remotely or on customer premises. Clarify your disclosures that indicate that the service is delivered on a monthly basis.
The company responded
Cycurion’s SaaS is delivered continuously over time; it is a subscription service where Cycurion provisions a suite of security software tools to its customers accessed via the internet that allows a customer to protect itself from cyber attack using multiple tools within the suite. This subscription service is recognized to revenue on a monthly basis.
Western Acquisition Ventures Corp. · filed 2024-01-29 · 0001104659-24-007915
SEC staff comment
25. Your risk factors describe security breaches and cybersecurity risks and risks of data loss due to security breaches as a material risk. Since cybersecurity and cyber-attacks are a potential risk, please also disclose in an appropriate place the nature of the board’s role in overseeing your cybersecurity risks, including in connection with the company’s third party providers. Please also confirm the accuracy of the statement that your data is stored electronically in locations around the United States, as you disclose in the first sentence.
The company responded
The Company respectfully acknowledges the Staff’s comment and has addressed the Staff’s comment revising the risk factors at pages 44-45 of the Amended DRS. 7 Risk Factors Relating to the Business Combination, page 57
K Wave Media Ltd. · filed 2024-01-26 · 0001829126-24-000469
SEC staff comment
Comment : The staff notes that the Secondary Listings Risk and Cyber Security Risk included in “Additional Risks of Investing in the Fund ¾ Principal Risks” are not among the principal risks in the summary prospectus. Please add these risks to the summary prospectus or move to the “Additional Risks of Investing in the Fund ¾ Additional Risks” section.
The company responded
The Trust has moved the noted risks to the Additional Risks section. 24.
AIM ETF Products Trust · filed 2024-01-18 · 0001137439-24-000527
SEC staff comment
3. Please disclose whether and how your business segments, products, lines of service, projects, or operations are materially impacted by supply chain disruptions, especially in light of in light of the effectiveness of the Uyghur Forced Labor Protection Act (the “UFLPA”). For example, discuss whether you have or expect to: · suspend the production, purchase, sale or maintenance of certain items due to a lack of raw materials, parts, or equipment; inventory shortages; closed factories or stores; reduced headcount; or delayed projects; · experience labor shortages that impact your business; · experience cybersecurity attacks in your supply chain; · experience higher costs due to constrained capacity or increased commodity prices or challenges sourcing materials (e.g. steel, lithium, nickel, manganese, beryllium, copper, gold or other raw material sourced from Western China); · experience…
The company responded
Pursuant to the comment, we have revised the disclosure on page 37 of the Registration Statement. Cover Page
ZJK Industrial Co., Ltd. · filed 2024-01-18 · 0001731122-24-000096
SEC staff comment
16. Please describe the extent and nature of the role of the board of directors in overseeing cybersecurity risks, including in connection with the company’s supply chain/suppliers/service providers. Sarah Sidwell Division of Corporation Finance Office of Manufacturing U.S. Securities and Exchange Commission January 18, 2024 Page 7 of 13
The company responded
The Company respectfully advises the Staff that a new risk factor entitled “Our cybersecurity measures may not protect us from system failures or interruptions.” has been added on page 44 of the Registration Statement, which includes a description of the role of the board of directors in overseeing cybersecurity risks. Any disruption in the supply chain of raw materials and our products could adversely impact our ability to produce and deliver products., page 34
ZJK Industrial Co., Ltd. · filed 2024-01-18 · 0001731122-24-000096
SEC staff comment
Comment 15 – Performance The Staff notes the following disclosure appears in the “Performance Section:” The Fund was reorganized on or about ___, 2023 from the ETFMG Prime Cyber Security ETF (the “Predecessor Fund”), a series of the ETF Managers Trust, a Delaware statutory trust, into Amplify ETF Trust, a Massachusetts business trust. The Fund is a continuation of the Predecessor Fund and, therefore adopts the performance information of the Predecessor Fund (as shown below), which was managed by ETF Managers Group LLC. The Predecessor Fund commenced operations on November 11, 2014. Please revise the disclosure to reference the correct Fund. - 6 -
The company responded
In accordance with the Staff’s comment, the above referenced disclosure has been deleted in its entirety and replaced with the following: The Fund was reorganized on or about ___, 2024 from the ETFMG Prime Mobile Payments ETF (the “Predecessor Fund”), a series of the ETF Managers Trust, a Delaware statutory trust, into Amplify ETF Trust, a Massachusetts business trust. The Fund is a continuation of the Predecessor Fund and, therefore adopts the performance information of the Predecessor Fund (as shown below), which was managed by ETF Managers Group LLC. The Predecessor Fund commenced operations on July 15, 2015.
Amplify ETF Trust · filed 2024-01-12 · 0001213900-24-003252
SEC staff comment
Comment 1 – Investment Objective. The Staff notes that the investment objective states, “The Amplify Cybersecurity ETF seeks investment results that generally correspond (before fees and expenses) to the total return performance of the Nasdaq ISE Cyber Security Select Index (the “Index”).” Please change “correspond” to “correlate” as the Staff believes “correlate” is a more accurate term.
The company responded
The disclosure has been revised in accordance with the Staff’s comment.
Amplify ETF Trust · filed 2024-01-12 · 0001213900-24-003266
SEC staff comment
Comment 4 – Principal Investment Strategies The Staff notes the following statement set forth in the section entitled “Principal Investment Strategies”: “To be included in the Index, companies from the Prime Index must derive at least 90% of their revenues from cyber security and must have a Revenue Contribution score of at least 1.25%.” Please confirm the reference to “Prime Index” is correct.
The company responded
In accordance with the Staff’s comment, the above-referenced disclosure has been revised as follows: “To be included in the Index, companies from the Parent Index must derive at least 90% of their revenues from cyber security and must have a Revenue Contribution score of at least 1.25%.”
Amplify ETF Trust · filed 2024-01-12 · 0001213900-24-003266
SEC staff comment
Comment . Please consider including a cybersecurity risk as a principal risk for the Fund.
The company responded
The Registrant respectfully declines to include cybersecurity risk as a principal risk for the Fund in the Fund’s summary prospectus but notes the following text is included as a non-principal risk for the Fund in response to Item 9 of Form N-1A. Cybersecurity Risk. Investment companies, such as the Fund, and their service providers are exposed to operational and information security risks resulting from cyberattacks, which may result in financial losses to the Fund and its shareholders. Cyber- attacks include, among other behaviors, stealing or corrupting data maintained online or digitally, denial of service attacks on websites, “ransomware” that renders systems inoperable until ransom is paid, the unauthorized release of confidential information, or various other forms of cybersecurity breaches. Cyber-attacks affecting the Fund, Calamos Advisors, custodian, transfer agent,…
Calamos ETF Trust · filed 2023-12-26 · 0001104659-23-129096
SEC staff comment
19. Please disclose whether you are subject to material cybersecurity risks in your supply chain based on third-party products, software, or services used in your products, services, or business and how a cybersecurity incident in your supply chain could impact your business. Discuss the measures you have taken to mitigate these risks.
The company responded
In response to the Staff’s comment, the Company notes that GCT has not experienced any cybersecurity incidents or risks in its supply chain based on third party products that had a significant impact on its business operation and financial performance. In addition, GCT has not identified any material trend or uncertainties in cybersecurity risk in the supply chain that will affect its financial performance in the foreseeable future. Therefore, the Company does not believe that a discussion on this topic in the MD&A will be warranted. Nevertheless, in response to the Staff’s comment, the Company has enhanced the risk factor disclosure on page 37 of the Amended Registration Statement to provide additional discussion on this topic.
Concord Acquisition Corp III · filed 2023-12-21 · 0001104659-23-128378
SEC staff comment
1. We note the disclosure added to the cover page that "because of the location where we are based, we are subject to the following China-based risks." However, we continue to note the disclosure on the cover page that if you "enter into a business combination with a target business operating in China, the combined company may face risks associated with regulatory approvals of the proposed business combination between us and the target, offshore offerings, anti-monopoly regulatory actions, and cybersecurity and data privacy." Please revise this disclosure in this section and throughout the prospectus to disclose that you currently face such risks, even without a business combination with a company operating in China, based upon the location of the company in the PRC. Your disclosure should make clear whether these risks could result in a material change in your operations, including…
The company responded
The Company has revised the disclosure on the cover page and on pages [34, 84, and 110] of the Amended Registration Statement in response to the Staff’s comment. Financial Statements Unaudited Financial Statements of JVSPAC Acquisition Corp., page F-1
JVSPAC Acquisition Corp. · filed 2023-12-21 · 0001104659-23-128150
SEC staff comment
3. We note your disclosure about cyber-attacks and that “future disruptions from unauthorized access to, fraudulent manipulation of, or tampering with [y]our computer systems and technological infrastructure, or those of third parties, could result in a wide range of negative outcomes, each of which could materially adversely affect [y]our business, financial condition, results of operations and prospects.” Please revise to disclose the nature of the board’s role in overseeing the company’s cybersecurity risk management, the manner in which the board administers this oversight function and any effect this has on the board’s leadership structure.
The company responded
We have revised the document to disclose the nature of the oversight role of the board of directors to note that while our board of directors will oversee the management of our cybersecurity risk, our management will be responsible for the implementation and monitoring of day-to-day risk management policies, procedures and processes. Our board of directors has tasked our Chief Technology Officer and other appropriate management with the responsibility to manage our cybersecurity initiatives, including with respect to our customer data and game suppliers databases. Our board of directors will receive regular reports from management, including our Chief Technology Officer at least quarterly, on material cybersecurity risks and the degree of our Company’s exposure to those risks, and the development and implementation of appropriate policies and procedures to mitigate those risks.…
High Roller Technologies, Inc. · filed 2023-12-20 · 0001753926-23-001611
SEC staff comment
Comment : Consider adding “Cybersecurity Risk” to the “Principal Risks” section. □ Registrant’s
The company responded
Comment complied with. The following has been added to the “Principal Risks” section: Cybersecurity Risk: Cybersecurity incidents may allow an unauthorized party to gain access to Fund assets, customer data, (including private shareholder information), or proprietary information, or cause the Funds, the Adviser, and/or other service providers (including custodians, sub-custodians, transfer agents and financial intermediaries) to suffer data breaches, data corruption or loss of operational functionality. A cybersecurity incident may disrupt the processing of shareholder transactions, impact a Fund’s ability to calculate its net asset values, and prevent shareholders from redeeming their shares. 9. Staff
Segall Bryant & Hamill Trust · filed 2023-12-08 · 0001580642-23-006585
SEC staff comment
Comment 5. Please consider adding a cybersecurity risk disclosure under the “Principal Risks” heading for the Funds.
The company responded
The Registrant believes the cybersecurity risk disclosure included in Item 9 under the “Principal Investment Risks” heading is sufficient.
Collaborative Investment Series Trust · filed 2023-11-28 · 0001999371-23-000601
SEC staff comment
3. Key Information—D. Risk Factors—Risks Related to Our Business” in its future Form 20-F filings (with changes marked in italics, deletions as strike-through and additions underlined): “ Our business is subject to complex and evolving Chinese and international laws and regulations regarding data privacy and cybersecurity. Failure to protect confidential information of our customers and network against security breaches could damage our reputation and brand and substantially harm our business and results of operations. As the regulations regarding data privacy and cybersecurity are quickly evolving in China and globally, we may become subject to new laws and regulations applying to the solicitation, collection, processing or use of personal or consumer information that could affect how we store, process and share data with our customers, suppliers and third-party merchants. Significant…
The company responded
The Company respectfully advises the Staff that during China Glory’s operations from December 2020 to February 2022, the Company had not generated any revenue from, and had only incurred nominal expenses for, the operations of China Glory. In 2020, 2021 and 2022, the expenses incurred relating to China Glory were RMB1.6 million, RMB3.8 million and RMB1.5 million (US$224 thousand), respectively. These expenses were included in the “operating costs and expenses” of the Company’s consolidated statements of operations for each year, and consist primarily of payroll and related expenses. U.S. Securities and Exchange Commission Page 10 In response to the Staff’s comment, the Company respectfully proposes to revise the referenced disclosure on page 76 under “Item
Yiren Digital Ltd. · filed 2023-11-17 · 0001104659-23-119330
SEC staff comment
1. We continue to note the disclosure on the cover page that if you "enter into a business combination with a target business operating in China, the combined company may face risks associated with regulatory approvals of the proposed business combination between us and the target, offshore offerings, anti-monopoly regulatory actions, and cybersecurity and data privacy." Please revise this disclosure and similar disclosure throughout the prospectus to disclose that you currently face such risks, even without a business combination with a company operating in China, based upon the location of the company in the PRC. Your disclosure should make clear whether these risks could result in a material change in your operations, including your search for a target business.
The company responded
The Company has revised the disclosure on the cover page and on pages 10 and 110 of the Registration Statement in response to the Staff’s comment. Summary, page 2
JVSPAC Acquisition Corp. · filed 2023-11-15 · 0001104659-23-118628
SEC staff comment
31. Your disclosures on page D-9 state “The MSSP business, like Managed Solutions, is subscription based. The key difference is that the MSSP business segment relates to cybersecurity, and this is also known as a SOC-as-a-Service.” Please explain how you recognize SOC-as-a-Service revenues.
The company responded
Management of Cycurion has determined that its managed security service practice is a bundle of cybersecurity software tools, and expert “24x7x365” monitoring and breach resolution services that are accounted for as a single performance obligation of Cycurion that is delivered over time (typically one month). The components of the bundle have individual commercial value; however, management believes that assigning a stand-alone value to each component would be impractical because, individually, each component could not be fully implemented or utilized unless packaged with the other components. Therefore, management concluded that the MSSP can only be sold as a bundle over time. At the time that Cycurion recognizes revenue, it has either already received funds in advance from its customer or is reasonably assured that it will collect funds from its customer. Funds that are received in…
Western Acquisition Ventures Corp. · filed 2023-11-13 · 0001104659-23-116492
SEC staff comment
4. Please revise the description of your business to address the following: • Please disclose your current stage of business development. For example, disclose whether you have developed the app through which customers will speak with healthcare professionals. Disclose whether you have signed any agreements for the employment of doctors for your app. • To the extent material, please disclose here and in your risk factors risks pertaining to cybersecurity. • Please describe how you will structure the service fee for appointments that run longer than 15 minutes. For example, disclose whether you will charge customers per minute or at a flat rate. • Please disclose who your "pharmacy partner" is. If you do not yet have a pharmacy partner, please revise your disclosure to clarify that, and disclose where you are in the process of finding one. Please also disclose how you anticipate…
The company responded
Please see revised description of the business addressing business pages 17, 18 and 19. Principal Shareholders, page 21
DOC.COM INC. · filed 2023-11-09 · 0001925674-23-000007
SEC staff comment
9. In the second paragraph under “Principal Investment Strategies of the Fund – The Index,” define “carrier edge network management equipment, colocation and data center services” and clarify how “government IT services” falls into the category of cybersecurity. In addition, in the last sentence of the first paragraph on page 30 of the prospectus, please confirm that the reference to “digital software” should be “digital security software.”
The company responded
As noted in the response to Comment 8, the Registrant has removed the references to each of the sub-industries, including those noted in the comment, for clarity and to be consistent with the Index Methodology White Paper. The Registrant has inserted “security” so that the disclosure now reads as follows: “In order to be classified in the digital security software category, RBICS requires that a company generate at least 50% of its revenue from digital security software.” Themes European Luxury ETF
Themes ETF Trust · filed 2023-11-09 · 0001829126-23-007245
SEC staff comment
6. Please disclose whether you are subject to material cybersecurity risks in your supply chain based on third-party products, software, or services used in your products, services, or business and how a cybersecurity incident in your supply chain could impact your business. Discuss the measures you have taken to mitigate these risks.
The company responded
We have included a risk factor stating that we are subject to material cybersecurity risks in our supply chain. We have addressed the measures taken to mitigate the cybersecurity risks in our supply chain.
SHOREPOWER TECHNOLOGIES INC. · filed 2023-11-03 · 0001493152-23-039380
SEC staff comment
2. We note the disclosure on the cover page that if you "enter into a business combination with a target business operating in China, the combined company may face risks associated with regulatory approvals of the proposed business combination between us and the target, offshore offerings, anti-monopoly regulatory actions, and cybersecurity and data privacy." Please revise this disclosure and similar disclosure throughout the prospectus to disclose that you currently face such risks, even without a business combination with a company operating in China, based upon the location of the company in the PRC. Your disclosure should make clear whether these risks could result in a material change in your operations, including your search for a target business.
The company responded
The Company has revised the disclosure on the cover page and on pages 10, 76, 109, 110 and 111 of the Amended Registration Statement in response to the Staff’s comment. Summary, page 2 2. We reissue comment
JVSPAC Acquisition Corp. · filed 2023-10-26 · 0001104659-23-111707
SEC staff comment
7. We note on page 74 Horizon’s risk factor describing security breaches and cybersecurity risks and risks of data loss due to security breaches as a material risk to Horizon’s business. Since cybersecurity and cyber-attacks are a potential risk, please also disclose in this section the nature of the board’s role in overseeing Horizon’s cybersecurity risks, including in connection with the company’s third party providers.
The company responded
The Company respectfully acknowledges the Staff’s comment and advises the Staff that it has revised the disclosure on page 76 of the Amended Registration Statement as requested. 2 Forward Purchase Agreement, page 119
Pono Capital Three, Inc. · filed 2023-10-20 · 0001013762-23-005573
SEC staff comment
10. Comment : The Staff notes that “Absence of Regulation”, “Cash Management and Defensive Investing”, “Conflicts of Interest”, “Cybersecurity and Operations”, “Early Close/Late Close/Trading Halt”, “Expenses”, “Legal and Regulatory”, “Operational”, “Redemption”, “Regulatory”, “Securities Lending”, “Strategies and Styles” and “Tax” risks are not summarized in the Fund’s Item 4 Principal Investment Risk section. Please revise the Fund’s Principal Risk section to include such investment risk or indicate that these risks are not principal risks.
The company responded
The Registrant notes that certain risks are not considered Principal Risks, but the Registrant believes such risks are appropriately included in the “More on Risks of Investing in the Fund” section of the prospectus. Please direct any comments or questions concerning this filing to the undersigned at (727) 299-1821. Very truly yours, /s/ Dennis P. Gallagher Dennis P. Gallagher Chief Legal Officer and Secretary Transamerica Funds
TRANSAMERICA FUNDS · filed 2023-10-20 · 0001193125-23-259728
SEC staff comment
3. Key Information—D. Risk Factors—Risks Related to Doing Business in China—The filing procedure with the CSRC shall be fulfilled and the approval of other PRC government authorities may be required in connection with our future offshore offering under PRC law, and, we cannot predict whether or for how long we will be able to complete the filing procedure with the CSRC and obtain such approval or complete such filing, if required.” In addition, if future regulatory updates mandate clearance of cybersecurity review or other specific actions to be completed by China-based companies listed on foreign stock exchanges or traded in foreign over the counter trading markets, such as us, we face uncertainties as to whether such clearance can be timely obtained, or at all. See “Item 3. Key Information—D. Risk Factors—Risks Related Doing Business in China—Failure to comply with governmental…
The company responded
In response to the Staff’s comment, the Company undertakes to refrain from using terms such as “we” or “our” when describing activities or functions of the VIE and implying that the historical contractual agreements were equivalent to equity ownership in the VIE in its future Form 20-F filings. The Company also undertakes to revise the relevant disclosure in its future Form 20-F filings as follows (with deletions shown in strikethrough and additions in underline showing the changes against the disclosure in the 2022 Form 20-F), subject to such updates and adjustments to be made in connection with any material developments of the subject matter being disclosed. “ INTRODUCTION … ● “VIE” refers to Long-Spring Education Holding Group Limited , the variable interest entity, whose financial results have been consolidated into our consolidated financial statements based solely on contractual…
First High-School Education Group Co., Ltd. · filed 2023-10-18 · 0001013762-23-004624
SEC staff comment
3. KEY INFORMATION … D. Risk Factors Summary Risk Factors … Risks related to doing business in China ● Changes changes in China’s economic, political or social conditions or government policies, laws and regulations, which could adversely affect the education services market and harm our business . As of the date of this annual report, we have not received any inquiry or notice or any objection in connection with our previous issuance of securities to foreign investors from the CSRC, the CAC or any other PRC governmental authorities that have jurisdiction over our operations. However, given the current regulatory environment in the PRC, there remains uncertainty regarding the interpretation and enforcement of PRC laws, which can change quickly and subject to any future actions within the discretion of PRC authorities. See “—Risks Related to Doing Business in China—PRC economic,…
The company responded
In response to the Staff’s comment, the Company respectfully advises the Staff to refer to the Company’s response to comment #4 above. October 18, 2023 Page 31
First High-School Education Group Co., Ltd. · filed 2023-10-18 · 0001013762-23-004624
SEC staff comment
4. C. Organizational Structure – The VIE Agreements”; and for the risks associated with the VIE Agreements and the VIE structure, see “ITEM 3D. Risk Factors – Risks Related to Our Corporate Structure”. We are subject to risks associated with our VIE structure. Investors may never directly hold equity interests in the VIEs. If the PRC government finds that the contractual arrangements which establish the structure of our business operations do not comply with PRC laws and regulations, or if these regulations or their interpretations change in the future, we could be subject to severe penalties or be forced to relinquish our interests in those operations, which would result in the VIEs being deconsolidated. A majority of our assets, including the necessary licenses to conduct business are held by the VIEs and their subsidiaries. Substantially all of our revenue is generated by the VIEs.…
The company responded
We acknowledge the Staff’s comment, and will revise the risk factor as follows in future filings: The disclosures in our reports and other filings with the SEC and our other public pronouncements may be subject to the scrutiny of regulatory bodies in the PRC. Our reports and other filings with the SEC are subject to SEC review in accordance with the rules and regulations promulgated by the SEC under the Securities Act and the Exchange Act. Our SEC reports and other disclosures and public pronouncements are currently not subject to the review or scrutiny of any PRC regulatory authority, except as described herein below. For example, the disclosure in our SEC reports and other filings are not subject to the review by the CSRC, a PRC regulator that is responsible for oversight of the capital markets in China. On February 17, 2023, with the approval of the State Council, the CSRC released…
Sentage Holdings Inc. · filed 2023-10-18 · 0001013762-23-004838
SEC staff comment
9. Please add a risk factor to disclose the nature of your board of director's role in overseeing your cybersecurity risk management, the manner in which the board administers this oversight function and any effect this has on the board’s leadership structure.
The company responded
In response to the Staff’s comment, we have included the following risk factor on pages 50 – 51 of the Registration Statement, which includes a disclosure of Bancorp 34’s board of directors’ role in overseeing cybersecurity risk management and the manner in which the board administers this oversight function. The board of directors’ role in overseeing cybersecurity risk management will not have an effect on the board’s leadership structure. Additional Risk Factor on pages 50 – 51: Our board and its committees oversee our cybersecurity, disaster recovery and business continuity risk management framework. Our governance oversight of cybersecurity, disaster recovery and business continuity risk management framework may not be effective in mitigating risks and/or losses. Our board of directors oversees our cybersecurity, disaster recovery and business continuity risk management framework.…
Bancorp 34, Inc. · filed 2023-10-16 · 0001552781-23-000404
SEC staff comment
18. We note from page 108 that BANC’s former Executive Vice President and Chief Risk Officer terminated employment on June 30, 2023. It appears from the BANC website that Olivia Lindsay is the current CRO and that Ms. Sullivan terminated employment on June 30, 2023. Please clarify the timing of the transition. Please also disclose the extent to which PACW and BANC have preliminarily agreed to a post-consummation structure for board oversight of financial risks, including operational, cybersecurity and other risks.
The company responded
The Company respectfully advises the Staff that the Company’s former Executive Vice President and Chief Risk Officer, Lynn Sullivan, retired from these positions effective as of December 31, 2022. Ms. Sullivan remained an employee of the Company as an Advisor until June 30, 2023 to assist with the transition of her previous roles. Olivia Lindsay, then Deputy Chief Risk Officer, was promoted to Chief Risk Officer of the Company effective as of January 1, 2023. Furthermore, the Company respectfully advises the Staff that the Company intends to maintain the current risk oversight structure of the board of directors (the “Board”) that is currently in place; however, no decision has been made and the structure may change post-consummation once the combined company’s board of directors meets. Please see the description of the current risk oversight of the Board below, excerpted from the…
BANC OF CALIFORNIA, INC. · filed 2023-09-29 · 0001140361-23-046066
SEC staff comment
9. In the second paragraph under “Principal Investment Strategies of the Fund – The Index,” define “carrier edge network management equipment, colocation and data center services” and clarify how “government IT services” falls into the category of cybersecurity.
The company responded
As noted in the response to Comment 8, the Registrant has removed the references to each of the sub-industries, including those noted in the comment, for clarity and to be consistent with the Index Methodology White Paper. Themes European Luxury ETF
Themes ETF Trust · filed 2023-09-11 · 0001829126-23-006042
SEC staff comment
Comment . Please consider including a cybersecurity risk as a principal risk for the Fund in the Fund’s summary prospectus.
The company responded
The Registrant respectfully declines to include cybersecurity risk as a principal risk for the Fund in the Fund’s summary prospectus but notes the following is included as a principal risk for the Fund in response to Item 9 of Form N-1A. 6 Cybersecurity Risk. Investment companies, such as the Fund, and their service providers are exposed to operational and information security risks resulting from cyberattacks, which may result in financial losses to the Fund and its shareholders. Cyber-attacks include, among other behaviors, stealing or corrupting data maintained online or digitally, denial of service attacks on websites, “ransomware” that renders systems inoperable until ransom is paid, the unauthorized release of confidential information, or various other forms of cybersecurity breaches. Cyber-attacks affecting the Fund or Calamos Advisors, custodian, transfer agent, distributor,…
CALAMOS INVESTMENT TRUST/IL · filed 2023-09-07 · 0001104659-23-098922
SEC staff comment
4. We note your statement that the Cyberspace Administration of China “launched an investigation which recently culminated in an announcement favouring plans to delist in the US in favour of Hong Kong.” This description does not appear to explain the recent actions of the CAC. Please revise to explain the recent actions taken by the CAC, including the Measures for Cybersecurity Review and the Draft Regulations on Network Data Security. Make similar changes elsewhere that you discuss the CAC.
The company responded
We have updated the Registration Statement as requested.
SSHT S&T Group Ltd. · filed 2023-09-05 · 0001829126-23-005901
SEC staff comment
2. Please state affirmatively whether you: (i) have been required to obtain any permission from or complete any filing with the CSRC, and (ii) have been required to go through a cybersecurity review by the CAOC. If so, state affirmatively whether you have received all requisite permissions or approvals, or whether any have been denied. If you have determined that no permissions are required, please clarify your basis for such determination, including whether you relied on the opinion of counsel.
The company responded
As a preliminary matter, we note that the Company mistakenly included two references in the 2022 Form 20-F to the “CRSC,” when it intended to refer to the “CSRC,” which is the acronym typically used for the China Securities Regulatory Commission. The Company used the correct acronym in several other places where it referenced the CSRC in the 2022 Form 20-F. To avoid any continuing confusion, we have also inserted the corrected acronym into our transcription of the Staff’s comment above. The Company wishes to advise the Staff that the Company (i) has not been required by the CSRC to obtain approval of or complete any filing with the CSRC with respect to any offering of the Company’s securities (collectively, the “ Prior Offerings ”), including the initial public offering of the Company’s predecessor Sohu.com Inc. on Nasdaq, which was completed before the Overseas Listing Laws (as defined…
Sohu.com Ltd · filed 2023-08-30 · 0001193125-23-224508
SEC staff comment
Comment . Please consider including a cybersecurity risk as a principal risk for the Fund in the Fund’s summary prospectus or tell the Staff why one is not needed.
The company responded
The Registrant respectfully declines to include cybersecurity risk as a principal risk for the Fund in the Fund’s summary prospectus but notes the following text is included as a non-principal risk for the Fund in response to Item 9 of Form N-1A. Cybersecurity Risk. Investment companies, such as the Fund, and their service providers are exposed to operational and information security risks resulting from cyberattacks, which may result in financial losses to the Fund and its shareholders. Cyber- attacks include, among other behaviors, stealing or corrupting data maintained online or digitally, denial of service attacks on websites, “ransomware” that renders systems inoperable until ransom is paid, the unauthorized release of confidential information, or various other forms of cybersecurity breaches. Cyber-attacks affecting the Fund, Calamos Advisors, custodian, transfer agent,…
Calamos ETF Trust · filed 2023-08-25 · 0001104659-23-095127

Showing the 60 most recent of 124.