|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Sep. 30, 2025
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Role of Management [Text Block]
|
ITEM 1C. CYBERSECURITY
Cybersecurity Risk Management and Strategy
We have established processes for assessing, identifying, and managing material risks from cybersecurity threats. We are committed to periodically reviewing these processes internally as well as discussing these threats and our processes with members of our Board as part of our overall cybersecurity risk management system.
We have implemented information technology and product security policies and standards across the company. We provide ongoing cybersecurity training for employees and conduct employee phishing tests. We maintain business continuity, disaster recovery, and incident management plans. We conduct tabletop exercises and penetration testing. We use third-party security tools that help prevent, identify, investigate and resolve vulnerabilities in our systems and products. Certain Ventus offerings are PCI DSS 4.0 compliant, and SmartSense and Jolt have achieved SOC 2 Type II attestation. These certifications require independent audits by external auditors. We are actively pursuing similar certifications for other product lines. We also have processes to oversee and identify cybersecurity threat risks associated with our use of new third-party service providers, including those who have access to our customer and employee data or our systems.
To date, we do not believe we have encountered cybersecurity threats or previous cybersecurity incidents that have materially affected or are reasonably likely to materially affect us, our business strategy, results of operations, or financial condition. However, there can be no assurance that our controls and procedures will be sufficient, and that we will not be materially affected in the future. While we have customary insurance coverage in place designed to address certain cybersecurity risks,
such insurance coverage may be insufficient to cover all insured losses or all types of claims that may arise. For more information regarding our cybersecurity risks, see “Technology and Cybersecurity Risks” included as part of our risk factor disclosures in Part I, Item 1A of this report.
Cybersecurity Governance
Our Board of Directors and executive management team oversee cybersecurity risk. Our Chief Information Officer is responsible for day-to-day management of cybersecurity risk. Our Chief Information officer periodically provides reports to executive management and our Board (which receives a report at least annually) on information security, including cybersecurity risk and the prevention, detection, mitigation and remediation of cybersecurity incidents. Our executive management is notified of potentially material cybersecurity incidents according to our cybersecurity incident management procedures.Our Chief Information Officer, who reports to the Chief Executive Officer, has over twenty years of experience in IT, including IT security. In addition, a member of our board of directors, Hatem Naguib, recently retired from his role as President and Chief Executive Officer of Barracuda, a cybersecurity solutions provider, and brings expertise in IT security.
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef