5 unchanged sentences
Those processes include response to and an assessment of internal and external threats to the security, confidentiality, integrity and availability of our data and systems along with other material risks to our operations, at least annually or whenever there are material changes to our systems or operations.
−Removed: Our Management Risk Committee (MRC) collaborates with our Head of IT and Chief Information Security Officer (CISO) along with the IT Department to evaluate and address cybersecurity risks in alignment with our business objectives and operational needs.
−Removed: Our Head of IT and CISO along with the IT Department implement processes and technologies to provide security monitoring and vulnerability management.
+Added: Our Management Risk Committee (MRC) collaborates with our Chief Technology Officer (CTO) and Chief Information Security Officer (CISO) along with the IT Department to evaluate and address cybersecurity risks in alignment with our business objectives and operational needs.
+Added: Our CTO and CISO along with the IT Department implement processes and technologies to provide security monitoring and vulnerability management.
We have an incident response plan in place with designated roles and responsibilities for responding to and escalating cybersecurity events and incidents.
6 unchanged sentences
The Audit Committee of our Board of Directors has primary responsibility for oversight of cybersecurity and is briefed on cybersecurity risks quarterly and following any material cybersecurity incidents.
−Removed: Our cybersecurity program is managed by our Head of IT and CISO , who reports to our Chief Administrative Officer and has served in this role since 2019.
−Removed: Our Head of IT and CISO has over 20 years of industry experience in information technology and maintains industry certifications such as the ISC2 CISSP.
−Removed: Reporting to the Audit Committee of our Board of Directors quarterly, our Head of IT and CISO may address overall assessment of the Company’s compliance with our cybersecurity policies and procedures, risk management, service provider arrangements, testing results and security incident response and makes recommendations for changes and updates to policies, procedures, and technologies related to cybersecurity and IT risk management.
+Added: Our cybersecurity program is managed by our CTO and CISO , who have served in this role since 2025.
+Added: Our CISO has over 25 years of industry experience in information technology and maintains industry certifications such as the ISC2 CISSP.
+Added: Reporting to the Audit Committee of our Board of Directors, our CTO and CISO may address overall assessment of the Company’s compliance with our cybersecurity policies and procedures, risk management, service provider arrangements, testing results and security incident response and makes recommendations for changes and updates to policies, procedures, and technologies related to cybersecurity and IT risk management.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.