12 unchanged sentences
Our cybersecurity risk management program includes:
−Removed: • risk assessments designed to help identify material cybersecurity risks to our critical systems, information, and our broader enterprise IT environment;
+Added: • risk assessments designed to help identify material cybersecurity risks to our critical systems, information, and our broader enterprise information technology environment;
• a cybersecurity team principally responsible for managing our (1) cybersecurity risk assessment processes, (2) security controls, (3) vulnerability management program and (4) detection and response to cybersecurity incidents;
3 unchanged sentences
• a cybersecurity incident response plan that includes procedures for responding to cybersecurity incidents;
−Removed: • a third-party risk management process for critical IT service providers, suppliers, and vendors.
+Added: • a third-party risk management process for critical information technology service providers, suppliers, and vendors.
We are constantly assessing our environment for cybersecurity threats, and we face risks from cybersecurity threats that, if realized, are reasonably likely to materially affect us, including our operations, business strategy, results of operations or financial condition.
1 unchanged sentence
See Part I, Item 1A.
−Removed: Risk Factors – “ Evolving cybersecurity and data privacy requirements (in particular, compliance with applicable federal, state and foreign laws relating to handling of personal information about individuals) could increase our costs, and any significant cybersecurity or data privacy incident could disrupt our operations, harm our reputation, expose us to legal risks and otherwise materially adversely affect our business, results of operations and financial condition.
+Added: Risk Factors – “ Evolving data privacy requirements (in particular, compliance with applicable federal, state and foreign laws relating to handling of personal information about individuals) could increase our costs, and any significant data privacy incident could disrupt our operations, harm our reputation, expose us to legal risks and otherwise materially adversely affect our business, results of operations and financial condition.
Cybersecurity Governance
−Removed: Our Board of Directors consider cybersecurity risk as part of its risk oversight function and has delegated to the Audit Committee (Committee) oversight of cybersecurity and other information technology risks.
−Removed: The Committee oversees management’s implementation of our cybersecurity risk management program.
−Removed: The Committee receives quarterly reports from management on our cybersecurity risks.
−Removed: In addition, management updates the Committee, as necessary, regarding any material cybersecurity incidents, as well as certain incidents with lesser impact potential.
−Removed: The Committee reports to the full Board of Directors regarding its activities, including those related to cybersecurity.
+Added: Our Board of Directors consider cybersecurity risk as part of its risk oversight function and has delegated to the Audit Committee oversight of cybersecurity and other information technology risks.
+Added: The Audit Committee oversees management’s implementation of our cybersecurity risk management program.
+Added: The Audit Committee receives quarterly reports from management on our cybersecurity risks.
+Added: In addition, management updates the Audit Committee, as necessary, regarding any material cybersecurity incidents, as well as certain incidents with lesser impact potential.
+Added: The Audit Committee reports to the full Board of Directors regarding its activities, including those related to cybersecurity.
The full Board of Directors also receives periodic briefings from management on our cyber risk management program.
Board of Directors members receive presentations on cybersecurity topics from a combination of our CDIO, CISO, Deputy General Counsel, internal security staff, external counsel or external experts, as part of the Board of Director’s continuing education on topics that impact public companies.
−Removed: Our management team, including our CDIO, CISO, Vice President and Deputy General Counsel – Chief Privacy and Data Protection Officer, Vice President of Infrastructure and Operations and additional members of the ECRG are responsible for assessing and managing our material risks from cybersecurity threats.
+Added: Our management team, including our CDIO, CISO, Vice President and Deputy General Counsel – Chief Privacy and Data Protection Officer and additional members of the ECRG are responsible for assessing and managing our material risks from cybersecurity threats.
The team has primary responsibility for our overall cybersecurity risk management program and supervises both our internal cybersecurity personnel and our retained external cybersecurity consultants.
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.