12 unchanged sentences
These processes are managed and monitored by a dedicated
−Removed: Director of Information Technology.
−Removed: Our processes include mechanisms, controls, technologies, and systems designed to prevent or mitigate
−Removed: data loss, theft, misuse, or other security incidents or vulnerabilities affecting the data and maintain a stable information technology
−Removed: For example, we conduct penetration and vulnerability testing, and data recovery testing on a periodic basis.
−Removed: we consult with outside advisors and experts, when appropriate, to assist with assessing, identifying, and managing cybersecurity risks,
−Removed: including to anticipate future threats and trends, and their impact on the Company’s risk environment.
−Removed: We also provide cybersecurity training to our employees and are formalizing an ongoing information security training
−Removed: program for active employees and relevant consultants to address matters such as phishing, email security, and training on data privacy.
−Removed: We have not identified any cybersecurity incidents or threats that have
−Removed: materially affected us or are reasonably likely to materially affect us.
−Removed: However, like other companies in our industry, we and our third-party
−Removed: vendors have from time-to-time experienced threats to and security incidents relating to information systems.
−Removed: Additional information on cybersecurity risks we face is discussed in Part
−Removed: I, Item 1A, “Risk Factors,” under the heading “Risks related to cybersecurity.”
−Removed: Director of Information Technology, who reports to our CFO, is responsible for assessing and managing cybersecurity risks.
−Removed: of Information Technology has over 25 years of experience managing information technology and cybersecurity.
−Removed: He has a bachelor’s
−Removed: degree in electrical engineering from Wright State University as well as a master’s degree in business administration from Ashland
−Removed: He has certifications from various information technology vendors as well as experience in implementing security frameworks
−Removed: such as International Organization for Standardization (“ISO”) 27001 and National Institute of Standards and Technology (“NIST”).
−Removed: We report on our information security program, including
−Removed: the results of periodic testing, to the Audit Committee of the Board of Directors.
−Removed: Our Board’s Audit Committee is responsible for
−Removed: overseeing our cybersecurity and information security procedures.
−Removed: The Audit Committee reviews management presentations concerning cybersecurity-related
−Removed: issues, including information security, technology risks, policies, and risk mitigation programs.
−Removed: The Audit Committee reports matters
−Removed: to the Board of Directors as needed.
−Removed: Our CFO, with the support of our Director of Information Technology and third-party consultants,
+Added: Director of Information Technology and an Information Technology Security and Risk Manager.
+Added: We have developed a cybersecurity program
+Added: following the National Institute of Standards and Technology (“NIST”) cybersecurity framework that include mechanisms, controls,
+Added: technologies, and systems designed to prevent or mitigate data loss, theft, misuse, or other security incidents or vulnerabilities affecting
+Added: the data and maintain a stable information technology environment.
+Added: For example, we conduct penetration and vulnerability testing, and
+Added: data recovery testing on a periodic basis.
+Added: In addition, we consult with outside advisors and experts, when appropriate, to assist with
+Added: assessing, identifying, and managing cybersecurity risks, including to anticipate future threats and trends, and their impact on the
+Added: Company’s risk environment.
+Added: Risk Management
+Added: have processes to evaluate third-party service providers and vendors that have access to sensitive systems and company data, which may
+Added: include due diligence procedures such as assessments of that service provider’s cybersecurity posture or a recommendation of specific
+Added: mitigation controls.
+Added: Following an assessment, we determine and prioritize service provider risk based on potential threat impact and
+Added: likelihood, and such risk determinations drive the level of due diligence and ongoing compliance monitoring required for each service
+Added: and Awareness
+Added: also provide cybersecurity training to our employees and are formalizing an ongoing information security training program for active
+Added: employees and relevant consultants to address matters such as phishing, email security, social engineering and training on data privacy.
+Added: Director of Information Technology, who reports to our CFO, and the Information Technology Security and Risk Manager are responsible
+Added: for assessing and managing cybersecurity risks.
+Added: Our Director of Information Technology has over 25 years of experience managing information
+Added: technology and cybersecurity.
+Added: He has a bachelor’s degree in electrical engineering from Wright State University as well as a master’s
+Added: degree in business administration from Ashland University.
+Added: He has certifications from various information technology vendors as well
+Added: as experience in implementing security frameworks such as International Organization for Standardization (“ISO”) 27001 and
+Added: Our Information Technology Security and Risk Manager has a PhD in a scientific field and various information security certifications
+Added: such as Certified Ethical Hacker (“CEH”) and Holistic Information Security Practitioner (“HISP”).
+Added: decades of experience in managing information technology environments and information security such as security architecture, security
+Added: operations and governance risk and compliance.
+Added: report on our information security program, including the results of periodic testing, to the Audit Committee of the Board of Directors
+Added: on a quarterly basis.
+Added: Our Board’s Audit Committee is responsible for overseeing our cybersecurity and information security procedures.
+Added: The Audit Committee reviews management presentations concerning cybersecurity-related issues, including information security, technology
+Added: risks, policies, and risk mitigation programs.
+Added: The Audit Committee reports matters to the Board of Directors as needed.
+Added: Our CFO, with
+Added: the support of our Director of Information Technology, Information Technology Security and Risk Manager and third-party consultants,
assesses and manages cybersecurity risk, including preventing, mitigating, detecting, and addressing cybersecurity incidents, if any.
−Removed: Our CFO also works closely with other management positions and external legal counsel to ensure that we understands our cybersecurity
+Added: Our CFO also works closely with other management positions and external legal counsel to ensure that we understand our cybersecurity
risk management responsibilities.
+Added: In case of a cybersecurity incident or breach, our incident response plan defines in detail reporting
+Added: and escalation processes to management and the Board of Directors.
+Added: Cybersecurity Risk Posture
+Added: have not identified any cybersecurity incidents or threats that have materially affected us or are reasonably likely to materially affect
+Added: However, like other companies in our industry, we and our third-party vendors have from time-to-time experienced threats to and security
+Added: incidents relating to information systems.
+Added: Additional information on cybersecurity risks we face is discussed in Part I, Item 1A, “Risk
+Added: Factors,” under the heading “Risks related to cybersecurity.”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.