8 unchanged sentences
We migrate our acquired companies into Asbury’s current LMS.
−Removed: Our Chief Information Officer ("CIO") , who has over 35 years of experience in the technology field, oversees cybersecurity, data privacy and manages Asbury’s information and security procedures.
+Added: Our Chief Information Officer (“CIO”) oversees cybersecurity, data privacy and manages Asbury’s information and security procedures.
Asbury also has a Director of Cybersecurity, as well as a formal team of analysts.
−Removed: Our Board of Directors maintains ultimate oversight of the Company’s enterprise risk management program, which includes material cyber security risks.
+Added: Our Board of Directors maintains ultimate oversight of the Company’s enterprise risk management program, which includes material cybersecurity risks.
Under the oversight of the audit committee and capital allocation and risk management committee of the Company’s Board of Directors, and as directed by the Company’s Chief Executive Officer, our CIO is responsible for the assessment and management of material cybersecurity risks.
1 unchanged sentence
The CIO also coordinates with the Company’s legal counsel and third parties, such as consultants and legal advisors, to assess and manage material risks from cybersecurity threats.
−Removed: Our CIO is informed about and monitors the prevention, detection, mitigation, and remediation of cybersecurity incidents pursuant to criteria set forth in the Company’s incident response plan and related processes.
+Added: Our CIO is informed about and monitors the prevention, detection, mitigation, and remediation of cybersecurity incidents pursuant to criteria set forth in the Company’s data incident response plan and related processes.
The capital allocation and risk management committee of the Company’s Board of Directors assists the Board in the periodic review and evaluation of the Company’s risk profile and related risk management processes which identify and manage the Company’s key financial, strategic and operational risks.
The audit committee of the Company’s Board of Directors oversees, among other things, the adequacy and effectiveness of the Company’s internal controls, including internal controls designed to assess, identify, and manage material risks from cybersecurity threats.
−Removed: The audit committee is informed of material risks from cybersecurity threats pursuant to the escalation criteria as set forth in the Company’s disclosure controls and procedures.
+Added: The audit committee is informed of material risks from cybersecurity threats pursuant to the escalation criteria set forth in the Company’s disclosure controls and procedures.
Further, our CIO reports on cybersecurity matters, including material risks and threats, to the Company’s audit committee on a quarterly basis, and the audit committee provides updates to the Company’s Board of Directors at regular board meetings.
In addition, the audit committee and capital allocation and risk management committee hold a joint meeting annually during which the CIO provides a comprehensive update regarding the assessment and management of material cybersecurity risks.
−Removed: Our CIO also provides updates as appropriate to the Company’s Board of Directors.
+Added: Our CIO also provides ad hoc updates as appropriate to the Company’s Board of Directors.
Risk Management
3 unchanged sentences
The Company conducts security assessments of certain third-party providers before engagement and has established monitoring procedures in its effort to mitigate risks related to data breaches or other security incidents originating from third parties.
−Removed: The Company from time to time engages third-party consultants, legal advisors, and audit firms in evaluating and testing the Company’s risk management systems and assessing and remediating certain potential cybersecurity incidents as appropriate.
+Added: The Company from time to time engages
+Added: third-party consultants, legal advisors, and audit firms in evaluating and testing the Company’s risk management systems and assessing and remediating certain potential cybersecurity incidents as appropriate.
In an effort to effectively prevent, detect, and respond to cybersecurity threats, we employ a multi-layered cybersecurity risk management program supervised by our CIO, whose team is responsible for leading enterprise-wide cybersecurity strategy, policy, architecture, and processes.
1 unchanged sentence
To do so, our program leverages both internal and external techniques and expertise.
−Removed: Internally, among other things, we may perform penetration tests, internal tests/code reviews, and simulations using cybersecurity professionals to assess vulnerabilities in our information systems and evaluate our cyber defense capabilities.
+Added: Internally, among other things, we perform two penetration tests per year, internal tests/code reviews, and simulations using cybersecurity professionals to assess vulnerabilities in our information systems and evaluate our cyber defense capabilities.
Our cybersecurity capabilities, processes, and other security measures also include, without limitation:
5 unchanged sentences
Although we believe we have systems and processes in place to protect against risks associated with cybersecurity incidents in the future, depending on the nature of an incident, these protections may not be fully sufficient.
−Removed: We, or the business partners or services providers on which we rely, have experienced cybersecurity incidents in the past that have resulted in disruptions, technology failures, or unauthorized persons gaining access to certain information systems, and we could in the future experience similar incidents.
−Removed: As of the date of this Form 10-K, no cybersecurity incident or attack, or any risk from
−Removed: cybersecurity threat, has materially affected or has been determined to be reasonably likely to materially affect the Company, our business strategy, results of operations, or financial condition.
−Removed: For additional information regarding the risks from cybersecurity threats we face, see the section captioned.
−Removed: For further discussion of the risks associated with cybersecurity incidents, see " A failure of any of our information systems or those of our third-party service providers, or a data security breach with regard to personally identifiable information ("PII") about our customers or employees, could have a material adverse effect on our business, results of operations, financial condition and cash flows.
−Removed: " beginning on page 27 of the section entitled "Item 1A.
+Added: We, as well as the business partners or services providers on which we rely, have experienced cybersecurity incidents in the past that have resulted in disruptions, technology failures, or unauthorized people gaining access to certain information systems, and we could in the future experience similar incidents.
+Added: As of the date of this Form 10-K, no cybersecurity incident, or any risk from cybersecurity threat, has materially affected or has been determined to be reasonably likely to materially affect the Company, our business strategy, results of operations, or financial condition.
+Added: For further discussion of the risks associated with cybersecurity incidents, see “ A failure of any of our information systems or those of our third-party service providers, or a data security breach with regard to personally identifiable information ("PII") about our customers or employees, could have a material adverse effect on our business, results of operations, financial condition and cash flows.” beginning on page 28 of the section entitled “Item 1A.
Risk Factors” in this Form 10-K.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.