HALLADOR ENERGY CO 10-K Cybersecurity GRC - 2024-03-14

Page last updated on April 11, 2024

HALLADOR ENERGY CO reported their cybersecurity risk management and governance process in a yearly 10-K filed on 2024-03-14 16:51:30 EDT.

Filings

10-K filed on 2024-03-14

HALLADOR ENERGY CO filed an 10-K at 2024-03-14 16:51:30 EDT
Accession Number: 0001437749-24-007870

Note: filing items unformatted. Drop us a note with the above URL to help us prioritize formatting it!

Item 1C. Cybersecurity.

ITEM 1C. CYBERSECURITY. Risk Management and Strategy We rely on information technology to operate our business. We have endpoint and other protection systems, and incident response processes, both internally and through third-party consultants, designed to protect our information technology systems. These established processes assist us to continuously assess and identify threats to our systems and minimize impact to our business in the event of a breach or other security incident. With our third-party consultants, the processes protect our information systems and allow us to resolve issues timely. As new threats to security may be identified, our personnel are notified, with instruction to increase awareness of the threat and how to react if such a threat or actual breach appears to be encountered. Periodic educational notices are also disseminated to all personnel. Additionally, as our systems are modified and upgraded, all personnel are notified, with instruction as appropriate. Responsibility for the identification and assessment of risks and the recommendation of upgrades to our systems resides with our expert consultants who report to our IT Director. Governance Our Board oversees the risks involved in our operations as part of its general oversight function, integrating risk management into the Company s compliance policies and procedures. With respect to cybersecurity, the Board has the ultimate oversight responsibility, with the Audit Committee and IT Steering Committee each having certain responsibilities relating to risk management of cybersecurity. Among other things, the Audit Committee discusses with management the Company s major policies with respect to risk assessment and risk management, including cyber-security, as they relate to the integrity of the Company s accounting and financial reporting processes and the Company s compliance with legal and regulatory requirement. In addition to its other responsibilities, the IT Steering Committee oversees operational information technology risks, including cybersecurity, as they relate to the technical aspects of the Company s operations. The IT Steering Committee and/or the full Executive Team receive at least quarterly reports from management on information technology matters, including cybersecurity. The reports address upgrades to hardware, software, and IT systems throughout the Company, and include the identification of IT and cybersecurity risks. Security scores, risk management, and mitigation measures are routinely presented. As discussed above, we maintain endpoint and other protection systems, and incident response processes, both internally and through third-party experts. As these systems, processes, training, and upgrades are implemented, updates are provided to the Executive Team. We have not identified an indication of a substantive cyber security incident that would have a material impact on our business, results of operations or financial statements. For additional information regarding risks from cybersecurity threats, please refer to Item 1A, Risk Factors, above.


Company Information

NameHALLADOR ENERGY CO
CIK0000788965
SIC DescriptionSilver Ores
TickerHNRG - Nasdaq
Website
CategoryAccelerated filer
Smaller reporting company
Fiscal Year EndDecember 30