Item 1C cybersecurity risk-factor disclosure stating the company has not historically experienced cybersecurity incidents that materially impacted its business. Describes risk-management practices: third-party service provider for software/hardware upgrades, multi-factor authentication, encrypted storage, and outsourced credit card processing. No actual breach or incident is disclosed.