DIGI INTERNATIONAL INC 10-K Cybersecurity GRC - 2024-11-22

Page last updated on November 22, 2024

DIGI INTERNATIONAL INC reported their cybersecurity risk management and governance process in a yearly 10-K filed on 2024-11-22 13:12:37 EST.

Filings

10-K filed on 2024-11-22

DIGI INTERNATIONAL INC filed a 10-K at 2024-11-22 13:12:37 EST
Accession Number: 0000854775-24-000033

Note: filing items unformatted. Drop us a note with the above URL to help us prioritize formatting it!

Item 1C. Cybersecurity.

ITEM 1C. CYBERSECURITY Cybersecurity Risk Management and Strategy We have established processes for assessing, identifying, and managing material risks from cybersecurity threats. We are committed to periodically reviewing these processes internally as well as discussing these threats and our processes with members of our Board as part of our overall cybersecurity risk management system. We have implemented information security policies and standards across the company. We provide ongoing cybersecurity training for employees and conduct employee phishing tests. We maintain business continuity, disaster recovery, and incident management plans. We conduct tabletop exercises and penetration testing. We use third-party security tools that help prevent, identify, investigate and resolve vulnerabilities in our systems and products. Certain Ventus offerings are PCI DSS 4.0 compliant, which requires auditing by an external auditor. We also have processes to oversee and identify cybersecurity threat risks associated with our use of new third-party service providers, including those who have access to our customer and employee data or our systems. To date, we do not believe we have encountered cybersecurity threats or previous cybersecurity incidents that have materially affected or are reasonably likely to materially affect us, our business strategy, results of operations, or financial condition. However, there can be no assurance that our controls and procedures will be sufficient, and that we will not be materially affected in the future. While we have customary insurance coverage in place designed to address certain cybersecurity risks, such insurance coverage may be insufficient to cover all insured losses or all types of claims that may arise. For more information regarding our cybersecurity risks, see “Technology and Cybersecurity Risks” included as part of our risk factor disclosures in Part I, Item 1A of this report. Cybersecurity Governance Our Board of Directors and executive management team oversee cybersecurity risk. Our Chief Information Officer is responsible for day-to-day management of cybersecurity risk. Our Chief Information officer periodically provides reports to executive management and our Board (which receives a report at least annually) on information security, including cybersecurity risk and the prevention, detection, mitigation and remediation of cybersecurity incidents. Our executive management is notified of potentially material cybersecurity incidents according to our cybersecurity incident management procedures. Our Chief Information Officer, who reports to the Chief Executive Officer, has over twenty years of experience in IT, including IT security. In addition, one of our Board members, Hatem Naguib, is the President and Chief Executive Officer of Barracuda, a cybersecurity solutions provider, and brings expertise in IT security.


Company Information

NameDIGI INTERNATIONAL INC
CIK0000854775
SIC DescriptionComputer Communications Equipment
TickerDGII - Nasdaq
Website
CategoryAccelerated filer
Fiscal Year EndSeptember 29